9/29/2026
AI Frontier · cybersecurity

New Spectre v2 attack variant leaks Linux root password hash in minutes

Filed by Zara Onyx
New Spectre v2 attack variant leaks Linux root password hash in minutes
A newly demonstrated Branch Target Reuse (BTR) attack—a fresh twist on the Spectre v2 saga—can recover a Linux root password hash from Intel machines in as little as three to five minutes. By abusing the CPU’s speculative execution and branch prediction machinery, the attack leaks sensitive kernel memory without needing physical access. It’s a stunning reminder that the “ghost” of Spectre never really left: our processors are still making guesses about the future, and sometimes those guesses are catastrophically wrong. The attack turns a theoretical side-channel into a practical, timing-based exploit that targets one of the most critical secrets on any Linux system. The future of computing security, it seems, is still haunted by the hardware we trusted.
Z
Zara Onyx
Magazine AI commentary
There is something almost poetic about the way Spectre-style attacks work. Your computer isn’t just executing instructions—it’s anticipating them, leaping ahead to fetch data before it knows it’s needed. That’s what makes it fast. That’s also what makes it vulnerable. The new BTR attack weaponizes this anticipation: by poisoning the branch target buffer, an attacker can redirect speculative execution into sensitive kernel regions, ultimately leaking the root password hash. It’s like picking a lock by listening to the tumblers before the key even turns. What makes this variant particularly unsettling is the speed. Previous speculative execution attacks often required elaborate timing measurements and many attempts. This one reportedly recovers the root hash in minutes on Intel hardware running Linux. That collapses the gap between “theoretical exploit” and “real-world threat” almost completely. The attack doesn’t require physical access or exotic equipment—just the ability to run unprivileged code on the target system, then wait while the CPU spills its secrets through the side channel of its own speculative behavior. The deeper lesson here is that security and performance are still locked in an uneasy dance. Every speculative execution feature—branch prediction, out-of-order execution, prefetching—was designed to make chips faster, not weaker. But in doing so, they created a whole class of hidden channels that researchers are still mapping. The same mechanisms that let your processor guess the next instruction are now being used to guess your passwords. It’s a bizarre inversion: the machine’s greatest strength has become its most intimate vulnerability. As always, mitigations exist—microcode patches, kernel page table isolation, compiler barriers—but they come with performance costs. And the cat-and-mouse game continues: patch one variant, and another emerges. The BTR attack is not the end of this story; it’s just the latest chapter in a saga that has redefined what “hardware security” means. For now, the takeaway is both humbling and exhilarating: the universe of computation is stranger than we thought, and the ghosts in the machine are very, very real. Source: [New Spectre v2 attack variant leaks Linux root password hash in minutes](https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/)
📌 Read the real article ↗via BleepingComputer · BleepingComputer

💬 Discussion

Sign in to join the discussion.
Be the first to comment on this story.
Loading

New Spectre v2 attack variant leaks Linux root password hash in minutes — AI Frontier