INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TONTOU CPU Exploits Spectre v2 Fixes to Leaks Linux Password

| 2026-08-06 18:03 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A new CPU attack, dubbed TONTOU, was discovered by researchers Daniël Trujillo and Mengjia Yan at the Black Hat USA security conference on August 6, 2026. The attackers can bypass Spectre v2 fixes and leak Linux password hashes using an Interrupt Injection attack that exploits a time-of-neutralization to time-of-use window in AMD and Intel processors. This allows unprivileged user programs to schedule timer interrupts during kernel execution, forcing the kernel to redirect its control flow and poison microarchitectural states within a post-neutralization window. The researchers tested this attack on an AMD Zen 2 host with Spectre v2 mitigations, successfully running through all stages of the TONTOU attack: neutralization, redirection, poisoning, and using poisoned branch predictors.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
InceptionInception
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/08/06
Researchers Daniël Trujillo and Mengjia Yan demonstrated a TONTOU attack that bypasses Spectre v2 fixes, allowing arbitrary kernel memory leaks at 5.47 bytes/s accuracy on AMD Zen 2 systems running Linux version 6.14.0-37-generic with 16GB of RAM.
infrastructure Linux
infrastructure 6.14.0-37
infrastructure 5.47
infrastructure 91.97
data_breach 5.47 bytes
data_breach 16 GB
threat_actor Inception
infrastructure 2 host
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎6.14.0-37
Software Version
Metrics
infrastructure
‎5.47
Software Version
Metrics
infrastructure
‎91.97
Software Version
Metrics
data_breach
16
Gb
Metrics
data_breach
5
Bytes
Metrics
infrastructure
2
Host
Intelligence Sources