Skip to Content

Security News Update: How Can a Spectre Attack Leak Your Linux Root Password Hash in 3 Minutes? and more

Spectre Leaks Linux Root Hash in Minutes

A new Spectre v2 attack dubbed Branch Target Reuse (BTR) can leak a Linux root password hash in three to five minutes on tested Intel systems. It exploits stale CPU predictions lingering after just-in-time code changes. Before you panic-format your drives, know that this local lab exploit required unprivileged code execution, and a hash is not a ready-to-use plaintext password. No attacks in the wild are reported yet.

The underlying behavior was confirmed on tested Intel, AMD, and Arm CPUs, but the Linux exploit was only flexed on Intel. Linux fixes for CVE-2026-64507 and CVE-2026-64508 are available. Patch your distribution’s kernel immediately, especially if you run shared systems.

Spectre apparently never forgets—and that’s the real problem.

OpenSSL Fixes DTLS Flaw That Could Leak Memory

OpenSSL recently plugged a high-severity DTLS vulnerability (CVE-2026-84782) that essentially hands over unencrypted chunks of your application’s heap memory to a connected peer—or just crashes the whole process entirely. This digital oversharing triggers when the protocol impatiently resends a handshake message while a previous write is stuck in transit. Thankfully, no one has reported any active exploitation yet.

If your stack relies on DTLS, it’s time to hunt down system packages and any OpenSSL instances quietly lurking inside third-party products. Bump your active branches up to versions 4.0.3, 3.6.5, 3.5.9, or 3.4.8. Still running outdated branches? You’ll need a premium support contract to secure those, though some Linux distros might generously backport the patch behind the scenes.

A digital handshake really shouldn’t include a complimentary souvenir of your server’s memory.

Pentagon Data Breach Hits More Than 3 Million

A vulnerability in a Pentagon file-sharing system exposed unencrypted personal data tied to more than 3 million people.

The records included Social Security numbers and military job details that could enable identity fraud and targeted social engineering.

This reminds me of the 2015 OPM breach, when millions had data stolen and victims just received credit monitoring. A decade later, another massive government breach raises the same question: Is monitoring enough, or should agencies face greater accountability for failing to protect your sensitive data?

Encrypt sensitive data by default and monitor for unusual file access or bulk downloads.

Kiteworks Pulls Systems Offline, Uncovers Critical Flaw

Kiteworks took customer systems offline after a threat warning and uncovered a previously unknown critical vulnerability.

The company found no evidence of exploitation, but the incident shows why security teams may need to act before a compromise is confirmed.

This is a good example of threat intelligence being useful before an attack happens.

Define clear triggers for escalating threat intelligence and know which systems you’re prepared to take offline.

Nvidia Builds New Security Layer for AI Agents

Nvidia has introduced a safety platform that uses sandboxing and hardware-isolated monitoring to control AI agent activity.

The approach gives organizations another security boundary as agents gain access to credentials, files, APIs, and enterprise systems.

I like the shift from trusting an AI agent to behave correctly to assuming it eventually won’t. That puts the focus back on containment rather than perfect behavior.

Limit agent permissions, isolate credentials, and keep a human in the loop where needed.

Spectre Attack Steals Linux Root Password Hash

Researchers demonstrated a new Spectre v2 attack that leaked a Linux root password hash from memory in as little as three minutes.

There’s no evidence of active exploitation, but the underlying processor behavior was found across tested Intel, AMD, and Arm CPUs.

A root hash leaked in minutes grabs attention, but context matters. This was a controlled demonstration, not an active attack.

Apply current Linux kernel updates, prioritizing shared systems where untrusted code runs alongside sensitive workloads.

TeamViewer Flaw Opens Door to Remote Code Execution

TeamViewer has released fixes for five high-severity vulnerabilities, including one that could lead to remote code execution.

There’s no evidence of active exploitation in the wild.

No active exploitation is good news, but TeamViewer is already abused by ransomware groups.

Patch TeamViewer and disable unattended access on systems that don’t require it.