
ISC StormCast for Thursday, July 14th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
Spectre Branch Target Injection Attacks - How to Leak Cernel Memory
Researchers at the eth surric came up with yet another way to take advantage of speculative execution in modern sps. The exploit is actually roughly straight forward, at least in hindside. Just abuse the basic open command and use the standard in option in order to pass a file to python which is then executed despite the limitations of the sand box.
Play episode from 02:23
Transcript


