Researchers from Vrije Universiteit Amsterdam developed 'L1TF Reloaded,' a novel attack combining L1TF (Foreshadow) and half-Spectre, successfully leaking VM memory from Google Cloud despite existing mitigations. The exploit enabled extraction of sensitive data, such as TLS keys, from co-tenant VMs and the hypervisor, even under high-noise conditions. Standard mitigations were insufficient, and only advanced protections like those on AWS limited the impact to non-sensitive data leaks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cloudflare reported blocking a new record-breaking distributed denial-of-service attack peaking at 22.2 Tbps. The reference indicates the mitigation was publicly disclosed on the publication date, which is used as the estimated event date.
A new L1TF Reloaded exploit that bypasses existing cloud mitigations was recognized with a $150,000 award, indicating a significant technical disclosure affecting cloud security assumptions. The reference does not provide a more specific event date, so the publication date is used as the estimate.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.