New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction
Researchers from the Netherlands and Italy have published a scientific paper describing a new attack belonging to the Spectre-v2 class. The original Spectre-v2 technique, demonstrated in 2018, exploits the branch prediction mechanisms in modern CPUs to execute a chosen malicious instruction and then read its results from cache via a side channel.
The new research replaces instruction injection with a method that reuses existing information inside the branch predictor. The required Branch Target Reuse state is created by the operation of a JIT compiler, a scenario previously considered impractical for attacks. The published study demonstrates successful secret extraction when branch prediction features are combined with the cBPF JIT compiler present in the Linux kernel.
The same researchers also examined the SpiderMonkey JIT compiler used in Firefox and the GraalVM engine. The JIT compiler was employed to train the branch predictor, while the actual attack became possible when different code was loaded at the same memory addresses. This created conditions for speculative execution that granted access to secret data.
A practical demonstration targeted the su process on Linux and extracted the hashed root password from CPU cache. The required result was achieved in an average of three to five minutes, which is relatively fast for complex Spectre-class attacks. A full attack was shown using the cBPF compiler. With SpiderMonkey and GraalVM only partial success was recorded: branch predictor training was possible, yet realistic attacks could not be demonstrated.
The researchers confirmed that the attack works on all major modern CPU types, including AMD, Intel, and ARM architectures.
What else happened
Specialists from Kaspersky published an analysis of methods for detecting traces of attacks against 1C servers, extending their earlier research on real incidents. Last week Debian released a record kernel update addressing more than 1,300 vulnerabilities. Dangerous flaws were found in both client and server components of TeamViewer. A zero-day vulnerability in Core Graphics was fixed in iOS and macOS updates. Google closed its bug bounty program for open-source projects it supports due to the large volume of automatically generated reports produced by AI assistants. Critical vulnerabilities were also disclosed in Dell Container Storage Modules, including two issues with a maximum CVSS score of 10 that allow authentication bypass.
Related articles
Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score
Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.
Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286
Fortinet has begun distributing updates for its FortiMail email security product to address the zero-day vulnerability CVE-2026-104286. The flaw allows unauthenticated attackers to write arbitrary files to the system by sending specially crafted HTTP requests. The company first published a security advisory on October 1, 2026, confirming active exploitation and providing Indicators of Compromise while preparing fixes. On October 5, 2026, Fortinet updated the advisory and released patched versions including FortiMail 8.0.2, 7.6.7, and 7.4.9. Organizations still running the 7.2 branch are advised to migrate to the 7.4 branch or later to obtain protection. The advisory reference is FG-IR-26-175.
Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution
A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.
Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes
Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.