{"id":21334,"date":"2018-12-07T23:59:13","date_gmt":"2018-12-07T23:59:13","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/"},"modified":"2018-12-07T23:59:13","modified_gmt":"2018-12-07T23:59:13","slug":"in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/","title":{"rendered":"In case you&#8217;re not already sick of Spectre&#8230; Boffins demo Speculator tool for sniffing out data-leaking CPU holes"},"content":{"rendered":"<p><strong class=\"trailer\">Analysis<\/strong> You&#8217;ve patched your Intel, AMD, Power, and Arm gear to crush those pesky data-leaking speculative execution processor bugs, right? Good, because IBM eggheads in Switzerland have teamed up with Northeastern University boffins in the US to cook up Spectre exploit code they&#8217;ve dubbed SplitSpectre.<\/p>\n<p>SplitSpectre is a proof-of-concept built from Speculator, the team&#8217;s automated CPU bug-discovery tool, which the group plans to release as open-source software. Their work <a target=\"_blank\" href=\"https:\/\/domino.research.ibm.com\/library\/cyberdig.nsf\/1e4115aea78b6e7c85256b360066f0d4\/d66e56756964d8998525835200494b74!OpenDocument&amp;Highlight=0,RZ3933\">is described here<\/a> in an academic paper emitted earlier this week.<\/p>\n<p>Andrea Mambretti, told <em>The Register<\/em> that he and his Speculator coauthors \u2013 Engin Kirda, William Robertson of Northeastern University and IBM&#8217;s Matthias Neugschwandtner, Alessandro Sorniotti, and Anil Kurmus \u2013 aren&#8217;t trying to scare the world with yet more chip vulnerability exploits, but rather want to prise open the secrets of CPU microarchitecture.<\/p>\n<p>The big silicon design houses keep details of the inner mechanisms of their processors under tight wraps, which means discovering speculative execution flaws and suchlike requires a non-trivial amount of reverse-engineering.<\/p>\n<p>Thus, Speculator tries to automate that discovery process. Spec-ex is one of the key drivers of processor speed, which is why CPU engineers and their bosses don&#8217;t like to talk about it, in case they spill any secrets to competitors.<\/p>\n<p>Mambertti explained to <em>The Register<\/em> Speculator came about from \u201cthe analysis of common elements of [speculative exexecution] attacks,&#8221; and should &#8220;help the analysis of new and old attacks.<\/p>\n<p>\u201cSplitSpectre is the result of our analysis, and thanks to Speculator, we could precisely measure the characteristics required for an attack to succeed as well as study general behaviors of the CPU during speculation that before were not known or documented.\u201d<\/p>\n<h3 class=\"crosshead\"><span>SplitSpectre: If you patched, relax<\/span><\/h3>\n<p>Speculator was able to find a \u201cnovel variation&#8221; in the techniques needed to exploit <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/01\/05\/spectre_flaws_explained\/\">Spectre variant 1<\/a> vulnerabilities in processors. These are those flaws you&#8217;ve heard so much about, the ones that can be <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/spectreattack.com\/\">abused<\/a> by dodgy applications and malware to leak passwords, crypto-keys, secrets, and other data from the computer&#8217;s memory that should be off-limits.<\/p>\n<p>This particular variation was dubbed SplitSpectre, and it differs from previous exploits by \u201crequiring a smaller piece of vulnerable code available in the victim\u2019s attack surface.\u201d Spectre exploitation relies on specific sequences of code running in the software you&#8217;re trying to spy on. SplitSpectre requires a shorter chain of instructions in its victim, which means code thought to be invulnerable to Spectre may actually be snooped on by this new technique.<\/p>\n<p>Having said that, today&#8217;s mitigations for Spectre should thwart this version of SplitSpectre. Future versions may be more successful, or &#8220;viable,&#8221; as the researchers put it. It is a proof-of-concept of Speculator, after all, and is written in JavaScript to run in Mozilla&#8217;s SpiderMonkey JS engine.<\/p>\n<p>One key point is that SplitSpectre can snoop on the underlying JavaScript engine, meaning it could in theory peek at private and sensitive data used by other JavaScript code running at the same time on the engine, say, in other tabs within a browser.<\/p>\n<p>One defense mechanism is to, therefore, securely sandbox browser tabs and windows so that malicious JavaScript cannot snoop on other pages and scripts via Spectre, which is what modern web browsers tend to do now. Again, the point of SplitSpectre is to demonstrate how Speculator can explore and potentially uncover future weaknesses in CPU microarchitectures.<\/p>\n<div class=\"CaptionedImage Right Float\"><a target=\"_blank\" href=\"https:\/\/regmedia.co.uk\/2018\/12\/07\/splitspectre_graph.jpg\"><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2018\/12\/07\/splitspectre_graph.jpg\" alt=\"Flow of SplitSpectre\" title=\"Flow of SplitSpectre\" width=\"200\"\/><\/a><\/div>\n<p>The team&#8217;s paper has an illustration of the SplitSpectre technique \u2013 <em>pictured right<\/em> \u2013 and explained the nitty-gritty: \u201cA V1 gadget consists of a bounds check and two array accesses &#8230; In order to mount a regular Spectre V1 attack, we would require a complete Spectre V1 gadget available in the JavaScript engine. The intuition behind SplitSpectre permits us to relax this requirement and only require the first half of a V1 gadget, i.e. the bounds check and the first array access.\u201d<\/p>\n<p>Mambretti stressed it&#8217;s not a browser-reliant exploit, nor reliant on JavaScript. It pretty much affects code running concurrently on a shared interpreter. JavaScript was chosen because it can be embedded in malicious web pages or in emailed documents by miscreants attempting to pull private data out of the underlying environment. It&#8217;s a relatively realistic attack scenario, in other words.<\/p>\n<p>\u201cWe are only talking about SpiderMonkey and not browsers,\u201d he said in an email. \u201cSplitSpectre crosses the privilege boundary, between attacker-controlled JavaScript and the runtime environment, within the SpiderMonkey engine.\u201d<\/p>\n<p>The paper added: \u201cThe attack works &#8230; we leak a string of ten characters with a success rate of over 80 per cent, and we leak the full string with a success rate of 10 per cent.\u201d<\/p>\n<p>Mambretti emphasized that a system fully patched against Spectre would be immune to SplitSpectre as it stands. The exploit is not tied to any particular CPU architecture, though the boffins tested their JavaScript on Intel Broadwell and Skylake CPUs, and AMD Ryzen chips. The research didn&#8217;t specifically look at Arm-compatible components.<\/p>\n<p>We pinged AMD and Intel for comment. AMD insisted its <a target=\"_blank\" href=\"https:\/\/www.amd.com\/en\/corporate\/security-updates#paragraph-313561\">existing defense mechanisms<\/a> block SplitSpectre. Intel declined to comment. We understand, though, Chipzilla&#8217;s engineers are confident today&#8217;s software mitigations defeat SplitSpectre.<\/p>\n<h3 class=\"crosshead\"><span>Fuzzing the CPU&#8217;s performance counter, for fun, and speculative execution<\/span><\/h3>\n<p>As Mambretti mentioned, the biggest road-bump spec-ex researchers face is that CPU vendors don&#8217;t publish enough detail on their microarchitectures. The boffins decided they wanted a \u201ctool whose purpose is to reverse-engineer the behaviour of different CPUs,\u201d so they looked at the signals processors give the outside world that could identify two things: when spec-ex is happening, and, much more difficult, how to use that information to siphon data from memory holding sensitive information.<\/p>\n<div class=\"CaptionedImage width_85\" readability=\"7\"><a href=\"https:\/\/regmedia.co.uk\/2018\/12\/05\/speculator_architecture.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2018\/12\/05\/speculator_architecture.jpg?x=648&amp;y=281&amp;infer_y=1\" alt=\"Speculator architecture\" title=\"Speculator architecture\" height=\"281\" width=\"648\"\/><\/a><\/p>\n<p class=\"text_center\">Speculator&#8217;s architecture &#8211; click to embiggen<\/p>\n<\/div>\n<p>They drilled down on an interface CPU vendors provide to help optimise software: hardware performance counters.<\/p>\n<p>The Speculator paper noted that these counters reveal \u201cmicroarchitectural state changes such as cache accesses, retired instruction, and mispredicted branches,\u201c which can be used to &#8220;accurately measure microarchitectural state attributes associated to the speculative portion of the execution of user-supplied snippets of code.\u201d<\/p>\n<p>In other words, these counters keep track of how hard the CPU is working behind the scenes, and what exactly it may be up to, so as to maximize the rate of execution; this information can be used to pull off Spectre-based attacks. The kinds of thing Speculator observes in order to sniff out exploitable spec-ex weaknesses include:<\/p>\n<ul>\n<li>Which code snippets are speculatively executed<\/li>\n<li>What triggered spec-ex to start and stop<\/li>\n<li>How specific instructions affect its behavior<\/li>\n<li>Which security boundaries prevent spec-ex, for example the boundaries between kernel and user mode, and between a runtime engine and interpreted code<\/li>\n<li>The consistency of CPU behavior within the same architecture or across different architectures.<\/li>\n<\/ul>\n<p>Running Speculator showed Mambretti and his collaborators how to craft their new technique, SplitSpectre. They focused on instructions that are speculatively executed, but not retired, because those instructions provided insight into architectural side effects, side effects that formed a side-channel from which to lift bytes of private data. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1792\/-6900\/five-steps-to-dealing-with-the-insider-threat?td=wptl1792\">Five steps to dealing with the insider threat<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2018\/12\/07\/splitspectre_attack\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>First proof-of-concept, SplitSpectre, requires fewer instructions in victim Analysis\u00a0 You&#8217;ve patched your Intel, AMD, Power, and Arm gear to crush those pesky data-leaking speculative execution processor bugs, right? Good, because IBM eggheads in Switzerland have teamed up with Northeastern University boffins in the US to cook up Spectre exploit code they&#8217;ve dubbed SplitSpectre.\u2026  READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":21335,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-21334","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>In case you&#039;re not already sick of Spectre... Boffins demo Speculator tool for sniffing out data-leaking CPU holes 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"In case you&#039;re not already sick of Spectre... Boffins demo Speculator tool for sniffing out data-leaking CPU holes 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-12-07T23:59:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"610\" \/>\n\t<meta property=\"og:image:height\" content=\"812\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"In case you&#8217;re not already sick of Spectre&#8230; Boffins demo Speculator tool for sniffing out data-leaking CPU holes\",\"datePublished\":\"2018-12-07T23:59:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/\"},\"wordCount\":1192,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/\",\"name\":\"In case you're not already sick of Spectre... Boffins demo Speculator tool for sniffing out data-leaking CPU holes 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg\",\"datePublished\":\"2018-12-07T23:59:13+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg\",\"width\":610,\"height\":812},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"In case you&#8217;re not already sick of Spectre&#8230; Boffins demo Speculator tool for sniffing out data-leaking CPU holes\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"In case you're not already sick of Spectre... Boffins demo Speculator tool for sniffing out data-leaking CPU holes 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/","og_locale":"en_US","og_type":"article","og_title":"In case you're not already sick of Spectre... Boffins demo Speculator tool for sniffing out data-leaking CPU holes 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-12-07T23:59:13+00:00","og_image":[{"width":610,"height":812,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"In case you&#8217;re not already sick of Spectre&#8230; Boffins demo Speculator tool for sniffing out data-leaking CPU holes","datePublished":"2018-12-07T23:59:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/"},"wordCount":1192,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/","url":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/","name":"In case you're not already sick of Spectre... Boffins demo Speculator tool for sniffing out data-leaking CPU holes 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg","datePublished":"2018-12-07T23:59:13+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes.jpg","width":610,"height":812},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/in-case-youre-not-already-sick-of-spectre-boffins-demo-speculator-tool-for-sniffing-out-data-leaking-cpu-holes\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"In case you&#8217;re not already sick of Spectre&#8230; Boffins demo Speculator tool for sniffing out data-leaking CPU holes"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/21334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=21334"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/21334\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/21335"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=21334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=21334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=21334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}