Spectre Variant Returns: Branch Target Reuse Attack Extracts Root Password Hash from Linux Memory
Researchers from VUSec and Scuola Superiore Sant’Anna have published details of Branch Target Reuse (BTR), a new variant of the Spectre v2 attack. The technique exploits the fact that modern CPUs retain branch predictor state even after the original code has been replaced in memory.
When a JIT compiler frees a memory region and later reuses the same virtual address for new executable code, the processor’s branch predictor may still hold an outdated entry. During speculative execution the CPU follows the stale prediction, executes instructions from the previous code, and leaves observable traces in the cache that allow secret data to be recovered.
The researchers confirmed the problematic behavior across tested Intel, AMD, and Arm processors. They examined JIT engines in Firefox, GraalVM, and the Linux kernel, although practical exploitation results varied significantly between environments.
The most concrete demonstration involved two exploits against the Linux kernel. On an Intel system running with current mitigations active, the attackers were able to extract the root password hash within minutes. The attack recovers only the hash; it does not yield the plaintext password or enable direct root login.
A proof-of-concept was also prepared for Firefox, although turning it into a reliable browser exploit still requires additional work. In GraalVM experiments, predictor-state clearing made reliable exploitation difficult. Successful attacks require the ability to run unprivileged code inside a suitable JIT environment; processor model alone does not guarantee exploitability.
Defenses have already been implemented in the Linux kernel and GraalVM. Mozilla is focusing on completing site isolation deployment. The disclosure once again shows that Spectre-class vulnerabilities continue to surface as long as processors use speculative execution to improve performance.
Related articles
Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ
SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.
WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution
WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.
EASM Uncovers Forgotten Perimeter Assets Including 11-Year-Old Servers Invisible to Standard Scanners
EASM solutions continuously discover external attack surfaces by starting from public data such as company names, domains, WHOIS records, Certificate Transparency logs, and internet-wide scanners like Shodan and Censys. Unlike traditional vulnerability scanners that only check assets from a predefined list, EASM maps unknown shadow IT including forgotten test servers, abandoned marketing subdomains, exposed APIs, and cloud buckets left open to the internet. The technology follows the same reconnaissance path used by attackers and has become essential for mature vulnerability management programs after years of being considered exotic. Major vendors including Palo Alto Networks Cortex Xpanse, CyCognito, Qualys, Rapid7, and Tenable now lead the market, while Russian providers such as Positive Technologies PT EASM, BI.ZONE EASM, and CyberOK PenOps have grown rapidly since 2022. Without an established process for prioritization and remediation, EASM implementations risk generating overwhelming alert volumes rather than reducing risk. The approach is now viewed as a core component of Continuous Threat Exposure Management (CTEM) frameworks.
Mozilla Releases Firefox 157 with 76 Security Fixes, Shifts to Individual CVE Reporting
Mozilla Foundation has released Firefox 157, addressing 76 vulnerabilities rated at various severity levels. The update also includes patches for the extended support releases Firefox ESR 153.4, ESR 140.17, and ESR 115.42. A key change in this release involves Mozilla's new approach to publishing security advisories, moving from grouping multiple memory safety issues under single CVEs to reporting them individually. Among the high-severity issues fixed are sandbox escape flaws, privilege escalation bugs, use-after-free errors, uninitialized memory problems, and JIT compiler mistakes affecting components such as DOM, Graphics, WebGPU, WebAssembly, and Networking. The ESR versions received 62, 43, and 31 fixes respectively, with 34 rated high in the latest branch. All listed CVEs range from CVE-2026-100756 through CVE-2026-100831.