[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes-msk9pky8":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"a7b58705-51ee-4978-8fad-745e7f5a4b9a","New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes","new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes-msk9pky8","Researchers disclosed TONTOU, a new CPU-level attack that bypasses Spectre v2 mitigations on Intel and AMD processors. Unprivileged code can exploit a branch predictor window to leak sensitive data including Linux password hashes. This affects all systems running vulnerable CPUs regardless of current patches.","high","advisory",[],[13,14,15,16],"Linux","AMD","Intel","Zen 2","Monitor for unusual local process behavior and failed authentication attempts. Coordinate with infrastructure teams to assess CPU vulnerability status. No patch available yet; escalate to vendor security teams for guidance on interim controls.",[19],"da2b2621-18a3-48e1-a5c9-e3d17c1d32ab",null,[22],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes\u002F","archived","2026-08-10T11:05:44.235+00:00","2026-08-08T11:05:49.39129+00:00","2026-08-10T12:06:11.854424+00:00",[28],{"id":19,"title":6,"url":22}]