Researchers and industry reporting revealed that Intel processors were affected by a broader set of speculative-execution vulnerabilities beyond the original Meltdown and Spectre disclosures, including eight additional issues dubbed Spectre-NG. Several of the newly reported flaws were described as high risk, with at least one capable of crossing virtual machine boundaries and threatening cloud environments by exposing sensitive data such as passwords and cryptographic keys; reports also said Intel SGX protections were not sufficient against some of these attacks. The wider Spectre/Meltdown family affected Intel most heavily for Meltdown and Intel, AMD, and Arm for Spectre, reinforcing warnings that complete remediation would ultimately require hardware changes rather than software alone.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Intel disclosed mitigation coverage for Spectre and Meltdown across several processor families at its Fall Desktop PC event. It said some 9th Gen Coffee Lake Refresh chips included hardware fixes for Meltdown Variant 3 and L1 Terminal Fault, while other lines such as Xeon W-3175X still depended on software and firmware mitigations.
Intel documented a speculative buffer overflow issue as part of the Spectre-NG vulnerability set. This marked a technical disclosure step that added detail on one of the newly identified speculative-execution flaws.
Follow-up reporting said Intel delayed disclosure of the Spectre-NG issues because patches were not yet ready. The report said an initial wave would cover four medium-risk flaws and disclose two high-risk flaws, with fixes for the high-risk issues expected later.
A report said Intel processors were affected by eight additional previously unknown speculative-execution vulnerabilities, dubbed Spectre-NG, with four rated high risk and four medium risk. The report highlighted risks to cloud environments, possible cross-VM attacks, and exposure of SGX-protected data, while Intel said it had reserved CVEs and was coordinating disclosure.
Intel scaled back plans to release Spectre variant 2 microcode updates for certain legacy CPUs, including Core 2 processors and some first-generation Core models. The change reversed earlier plans to support some of those older architectures.
Intel announced partitioning-based hardware protections against Spectre for upcoming Cascade Lake Xeon processors and 8th Gen Core chips planned for the second half of 2018. It also said firmware updates were available for Intel products launched in the previous five years, while Meltdown would continue to rely on software mitigation.
Dell issued a notice on the impact of CVE-2017-5715, CVE-2017-5753, and CVE-2017-5754 on its enterprise products. The guidance described mitigation steps involving BIOS microcode, operating system patches, and in some cases NVIDIA driver updates.
Microsoft said mitigations for the CPU flaws could noticeably slow older PCs, especially older Windows versions and older Intel processors. It said Spectre variant 2 mitigations were the main source of slowdown, while Intel separately said average users should not see major impact in common tasks.
Researchers disclosed the Meltdown and Spectre processor vulnerabilities, which can leak sensitive memory contents from affected devices. At disclosure, there was no evidence they had been exploited in the wild, and vendors and CERT advised applying available software and browser updates while noting hardware replacement would be needed for full remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
dell.com
Open sourcev8.dev
Open sourceweb.archive.org
Open sourceheise.de
Open sourceweb.archive.org
Open sourcedell.com
Open sourcepcworld.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.