Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitycloud-service-vulnerabilitywidely-deployed-product-advisoryopen-source-dependency-vulnerability

Intel Faced Expanded Spectre-Class CPU Flaws as Mitigations Shifted to Hardware

Updated 15d agoFirst seen May 25, 202615 sources

Researchers and industry reporting revealed that Intel processors were affected by a broader set of speculative-execution vulnerabilities beyond the original Meltdown and Spectre disclosures, including eight additional issues dubbed Spectre-NG. Several of the newly reported flaws were described as high risk, with at least one capable of crossing virtual machine boundaries and threatening cloud environments by exposing sensitive data such as passwords and cryptographic keys; reports also said Intel SGX protections were not sufficient against some of these attacks. The wider Spectre/Meltdown family affected Intel most heavily for Meltdown and Intel, AMD, and Arm for Spectre, reinforcing warnings that complete remediation would ultimately require hardware changes rather than software alone.

Share:
Intel Faced Expanded Spectre-Class CPU Flaws as Mitigations Shifted to Hardware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Oct 8, 20188y ago

Intel details hardware mitigations in new Core and Xeon processors

Intel disclosed mitigation coverage for Spectre and Meltdown across several processor families at its Fall Desktop PC event. It said some 9th Gen Coffee Lake Refresh chips included hardware fixes for Meltdown Variant 3 and L1 Terminal Fault, while other lines such as Xeon W-3175X still depended on software and firmware mitigations.

Intel’s New Core and Xeon W-3175X Processors: Spectre and Meltdown Security Update
Jul 11, 20188y ago

Intel documents a speculative buffer overflow in Spectre-NG

Intel documented a speculative buffer overflow issue as part of the Spectre-NG vulnerability set. This marked a technical disclosure step that added detail on one of the newly identified speculative-execution flaws.

Spectre-NG: Intel dokumentiert "spekulativen Buffer Overflow" | heise online
May 8, 20188y ago

Report says Intel postponed disclosure of Spectre-NG flaws

Follow-up reporting said Intel delayed disclosure of the Spectre-NG issues because patches were not yet ready. The report said an initial wave would cover four medium-risk flaws and disclose two high-risk flaws, with fixes for the high-risk issues expected later.

Intel Postpones Patching 'Spectre NG' CPU Flaws | Tom's Hardware
May 3, 20188y ago

Heise reports eight new Intel speculative-execution flaws

A report said Intel processors were affected by eight additional previously unknown speculative-execution vulnerabilities, dubbed Spectre-NG, with four rated high risk and four medium risk. The report highlighted risks to cloud environments, possible cross-VM attacks, and exposure of SGX-protected data, while Intel said it had reserved CVEs and was coordinating disclosure.

Spectre-NG: Intel-Prozessoren von neuen hochriskanten Sicherheitslücken betroffen, erste Reaktionen von AMD und Intel | heise online
Apr 4, 20188y ago

Intel drops some Spectre microcode plans for older processors

Intel scaled back plans to release Spectre variant 2 microcode updates for certain legacy CPUs, including Core 2 processors and some first-generation Core models. The change reversed earlier plans to support some of those older architectures.

Intel drops plans to develop Spectre microcode for ancient chips - Ars Technica
Mar 15, 20188y ago

Intel announces hardware redesigns for Spectre protections

Intel announced partitioning-based hardware protections against Spectre for upcoming Cascade Lake Xeon processors and 8th Gen Core chips planned for the second half of 2018. It also said firmware updates were available for Intel products launched in the previous five years, while Meltdown would continue to rely on software mitigation.

Intel announces hardware fixes for Spectre and Meltdown on upcoming chips - TechCrunch
Feb 8, 20188y ago

Dell publishes impact guidance for side-channel CPU flaws

Dell issued a notice on the impact of CVE-2017-5715, CVE-2017-5753, and CVE-2017-5754 on its enterprise products. The guidance described mitigation steps involving BIOS microcode, operating system patches, and in some cases NVIDIA driver updates.

Seitenkanal-Sicherheitslücken von Mikroprozessoren (CVE-2017-5715, CVE-2017-5753 und CVE-2017-5754): Auswirkungen auf Server, Storage und Netzwerke von Dell Technologies | Dell Österreich
Jan 9, 20188y ago

Microsoft reports performance impact from Spectre and Meltdown patches

Microsoft said mitigations for the CPU flaws could noticeably slow older PCs, especially older Windows versions and older Intel processors. It said Spectre variant 2 mitigations were the main source of slowdown, while Intel separately said average users should not see major impact in common tasks.

Microsoft tests show Spectre patches drag down performance on older PCs | PCWorld
Jan 4, 20188y ago

Meltdown and Spectre vulnerabilities are publicly disclosed

Researchers disclosed the Meltdown and Spectre processor vulnerabilities, which can leak sensitive memory contents from affected devices. At disclosure, there was no evidence they had been exploited in the wild, and vendors and CERT advised applying available software and browser updates while noting hardware replacement would be needed for full remediation.

Who’s affected by computer chip security flaw | The Augusta Chronicle
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

36 LINKEDOpen in app
Affected products
14 linked
Wyse ThinlinuxThinosUbuntuRed Hat Enterprise LinuxSuse Linux EnterpriseWindows Embedded Standard 7ChromeosWindowsSurfaceWindows ServerFirefoxIphoneMacosAndroid
Organizations
19 linked
IntelAdvanced Micro DevicesMicrosoft CorporationGoogleDell TechnologiesRed HatNvidiaSuseCanonicalArmGrammarlyMozillaThe RegisterTom's HardwareAppleSignal MessengerPCWorldHeise MedienAnandTech
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.