Filter
Exclude
Time range
-
Near
15 Sep 2025
IntelとAMDのCPUの新たな脆弱性VMScope (CVE-2025-40300)について。チューリッヒ工科大学の研究。マイクロアーキテクチャ上の欠陥で、Spectre-BTIの新種。近隣仮想マシンに干渉できるVMエスケープの脆弱性。Coffee LakeとZen第1-5世代に影響。 securityonline.info/vmscape-…
6
1,016
15 Sep 2025
ETHチューリッヒの研究者らは、IntelやAMD CPUの分岐予測器に残る状態を悪用し、仮想マシンの隔離を突破する「VMScope」攻撃を実証した。これにより悪意あるゲストVMがハイパーバイザーのメモリを直接盗み見でき、暗号鍵や顧客データが流出する恐れがある。 研究チームは「VMSCAPE」と名付けたSpectre-BTI系の攻撃手法を開発し、AMD Zen 4環境でQEMUプロセスから任意のメモリを1秒あたり32バイト抽出できることを示した。従来のSpectre攻撃は非現実的な前提を必要としたが、VMSCAPEは既存ソフトに改変を加えず成立する初の実用的なVMエスケープである。対象はAMD Zen 1〜5とIntel Coffee Lakeで、クラウド隔離モデルを根本から揺るがす。 LinuxカーネルではIBPB-on-VMEXIT(ゲストからホストへ切り替わる際に分岐予測器をフラッシュする手法)が緩和策として導入され、性能への影響は限定的とされる。研究者らは「既存のハードウェア対策があっても依然として攻撃可能である」と強調している。 securityonline.info/vmscape-…
2
7
1,696
Replying to @mhernand40 @htorrex
Yes thats true, but that'll only cause problems when you launch a coroutine in vmscope, without specifying any dispatcher. Inject dispatchers and dont forget to use them with every coroutine being launched. This is what you meant, right? @CatalinGhita4
1
2
hesgoal but the thing dey lag rn
1
2
Oh my, what happened exactly ??
1
Excellent event. Thank you for the invitation. Great to see so much innovation across the field!
2
5
Had one recently and had several in the past. This happens generally when I am the only interviewer, though some have been bold enough to say it with more people in the room. My fav low-key way is "When should I expect my interviewer to come?" when I step into the room.
2
5
5 Sep 2021
Bruh. The game was over before I got in.
1
2
4 Sep 2021
He's a good finisher and his heading is on point
1
2
No, there are enough developers in Australia at the moment so there wouldn’t be need for that. We will find them locally without too much hassle.
2
This fits perfect
2
2
IT WAS HER DECISION SO RESPECT HER DECISION #COYS
1
Yesss it’s on my list
1
1
19 Jul 2021
Fulani Bandits attacking Hausa communities... ...reason for the lethargic response from Buhari's government.
3
3
Then why start what he can't finish In a bid to sound politically correct, people just ending up defending rubbish
1
5
Focus on trains by using $600k to launch an airline logo 5 years before you need it. ✌🏾
4
Rail on wrong ruites that can't even generate money to run it talk more of paying back loans used to build it? Must be nice
1
2