Researchers disclosed Microarchitectural Data Sampling (MDS) vulnerabilities in Intel processors that can allow a malicious program to infer data belonging to other processes, bypassing normal memory-isolation protections. In virtualized environments, the flaws could expose sensitive data from the host or other guest virtual machines; a demonstrated proof of concept could be delivered through malicious web content.
Intel released microcode mitigations for affected processors, with operating-system and software vendors issuing updates to deploy or support those protections. Organizations should identify affected systems, apply firmware and platform updates, and assess mitigation-related performance effects before broad rollout. At disclosure, no active exploitation was known.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Intel released microcode patches to remediate the processor vulnerability, and other software vendors released updates to enable or deploy the mitigations. The NCSC advised organizations to assess potential performance effects and apply the updates based on risk.
Research involving Vrije Universiteit identified a flaw in Intel processors that can allow a program to access memory belonging to other programs, including potentially exposing host and guest data in virtualized environments. Researchers demonstrated a website-delivered proof of concept, though it was not publicly released; active exploitation was not known at the time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.