Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New BTR Attack Compromises Linux Despite Defenses

New BTR Attack Compromises Linux Despite Defenses

Posted on September 29, 2026 By CWS

A recent discovery by researchers from VUSec and Scuola Superiore Sant’Anna has unveiled a new variant of the Spectre CPU vulnerability. This variant, known as Branch Target Reuse (BTR), affects Just-In-Time (JIT) engines across various platforms, including web browsers, language runtimes, and operating system kernels. The vulnerabilities span multiple CPU vendors, posing significant security concerns.

Understanding the BTR Vulnerability

The BTR variant, identified by researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida, capitalizes on the failure of modern CPUs to invalidate stale indirect branch prediction entries. This flaw allows attackers to exploit JIT engines by reusing stale branch targets, resulting in potential control-flow hijacking and data leakage. The vulnerability was tested on Mozilla Firefox’s SpiderMonkey, GraalVM, and the Linux kernel’s cBPF JIT, revealing varying levels of exploitability and data leakage rates.

In a demonstration, the researchers developed exploits capable of leaking and recovering the root password hash from a fully patched Intel system, showcasing the severity of the BTR threat even when default protections are enabled.

Implications for CPU Security

Originally discovered in 2017, Spectre vulnerabilities exploit speculative execution, a performance-enhancing technique used by modern processors. By manipulating this process, attackers can trick CPUs into executing speculative operations that reveal sensitive information through cache timing side channels. Spectre v2, a specific variant, abuses indirect branch prediction to achieve similar objectives, compromising system security.

BTR specifically targets JIT engines by exploiting the interaction between Self-Modifying Code (SMC) and indirect branch prediction, offering attackers previously unavailable transient-execution opportunities. The attack sequence involves manipulating JIT engines to allocate and deallocate memory chunks, leading to control-flow hijacking and data disclosure.

Mitigation and Future Outlook

Following the responsible disclosure of the BTR vulnerability, mitigations have been integrated into the Linux kernel, identified as CVE-2026-64507 and CVE-2026-64508. These measures aim to address the flaws by preventing stale Branch Target Buffer (BTB) entries from being exploited. Meanwhile, GraalVM has adopted randomization techniques to hinder region reuse, while Mozilla is prioritizing the deployment of site isolation over indirect branch prediction barrier-based mitigations.

This disclosure coincides with a recent speculative execution attack technique called Interrupt Injection, unveiled by MIT CSAIL researchers. The ongoing discoveries underscore the persistent challenge of securing modern processors against sophisticated vulnerabilities, necessitating continuous advancements in defensive strategies.

As the landscape of CPU vulnerabilities evolves, the focus remains on enhancing existing defenses and developing innovative techniques to safeguard sensitive data from malicious exploits.

The Hacker News Tags:Branch Target Reuse, BTR attack, CPU security, GraalVM, Intel systems, JIT engines, Linux kernel, Linux security, Mozilla Firefox, Scuola Superiore Sant'Anna, Spectre vulnerability, VUSec

Post navigation

Previous Post: Ethereum Used for Covert Malware Communication
Next Post: Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk

Related Posts

Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped The Hacker News
Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties The Hacker News
Linux GoGra Backdoor Targets South Asia via Microsoft API Linux GoGra Backdoor Targets South Asia via Microsoft API The Hacker News
ZionSiphon Malware Targets Israeli Water Systems ZionSiphon Malware Targets Israeli Water Systems The Hacker News
FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE The Hacker News
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk
  • New BTR Attack Compromises Linux Despite Defenses
  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk
  • New BTR Attack Compromises Linux Despite Defenses
  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark