FILTERING BY: CLEAR FILTER

LoongLeak: Architectural Cache Vulnerability in Loongson Processors

Researchers from the Helmholtz Center for Information Security discovered "LoongLeak," an architectural vulnerability in the LoongArch ISA affecting Loongson processors, specifically the 3A6000 series. The flaw resides in the L1 data cache, where a fuzzer-discovered instruction allows unprivileged users, containers, or virtual machines to leak 32 bits of cached data directly into a memory register. This enables the bypass of critical security primitives including ASLR and stack canaries, facilitating cross-boundary data exfiltration. Demonstrated exploits include full-disk AES key recovery from the kernel and Guest-to-Host VM leakage. Remediation varies from a firmware update for the 3A6000 to total hardware replacement or disabling hyperthreading for older iterations.

Hardware Provenance & Supply Chain Risks: U.S. Diplomatic Mandate for Hardware Destruction Following China Summit

The mandate for U.S. officials to discard all physical gifts and mobile devices following a diplomatic summit in China signals a critical shift in the assessment of state-sponsored hardware espionage. This directive underscores a high-confidence intelligence determination that traditional hardware inspection is insufficient to detect sophisticated, embedded implants designed for persistent signals intelligence (SIGINT) collection.


LINK COPIED TO CLIPBOARD