New Intel Processor Vulnerability, “Foreshadow,” Allows Attackers to Steal Data

New Intel Processor Vulnerability, “Foreshadow,” Allows Attackers to Steal Data Featured Image

It just gets harder and harder to keep our technology safe from prying eyes and hands. It seems every time we turn around a new security flaw is turning up. This newest flaw, called “Foreshadow,” affects Intel processors. This means the same parts that are designed as the “brains” of our machines are also making our systems less secure.

Identifying Foreshadow

Researchers from five different academic institutions located this vulnerability. Intel processors are supposed to be secure, as they are defended by Software Guard Extensions (SGX) that allow programs to set up secure enclaves on the processors.

Yet, these researchers explain Foreshadow as a “speculative execution attack on Intel processors which allows an attacker to steal sensitive information stored inside personal computers or third party clouds.

“Foreshadow has two versions: the original attack designed to extract data from Software Guard Extensions (SGX) enclaves and a Next-Generation version which affects Virtual Machines (VMs), hypervisors (VMM), operating system (OS) kernel memory, and System Management Mode (SMM) memory.”

Wired published a report that states the research speaks “to longstanding questions and concerns about reliance on SGX – and whether for all its benefits it also has the downside of becoming a single point of failure for everyone’s most sensitive software and data.”

news-foreshadow-hacker

They add that while “not every user relies on SGX, more and more secure services are exploring the possibility of using it in their consumer products – like the password manager 1Password and the end-to-end encrypted messaging app Signal.”

One of the researchers, Yuval Yaron, a microarchitecture security researcher, stressed the seriousness of Foreshadow by stating it’s “not an attack on a particular user; it’s an attack on infrastructure.”

The Fix

Intel started releasing a fix for Foreshadow via updates on August 14, 2018. Leslie Culbertson, the executive vice president of production assurance and security for Intel, wrote in a blog post that they are not aware of any method being used in real-world exploits yet.

Regardless of that, Intel is still encouraging users to keep everything up to date on their systems and to take all necessary precautions to prevent malware.

The researchers set up a website where they detail why they chose to call this new chip vulnerability Foreshadow.

news-foreshadow-risk

“In literature ‘foreshadowing’ is used to indicate a trick where a writer provides a subtle hint of what is to come later in the story. Analogous to how a good storyteller tries to keep the outcome of the story (mostly) secret, the speculative execution mechanisms found in modern processors do not directly leak secrets.

“In the storytelling analogy the Foreshadow attack shows, however, that clever adversaries can abuse subtle hints in the present to reconstruct secrets from future instructions.”

Will This Lead to a Worrisome Future?

That explanation provided by the researchers is particularly ominous and doesn’t leave a safe feeling. Sure, they’ve identified this vulnerability, but it hasn’t hit yet. And along with their name, “Foreshadow,” we know there’s a hint of something bad on the horizon. Perhaps it’s even worse than researchers are imagining.

Above all, it’s super important here to follow Intel’s advice to keep your system up to date, as they’re working on rolling out a fix. And as they suggested, make sure you take all necessary steps to neutralize malware.

How does this news sit with you? Are you still worried about what’s to come in the future? Or are you comfortable with Intel saying they are releasing a fix? Add your thoughts and concerns regarding Foreshadow in the comments section below.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

The U.S. Army has officially pushed “jailbroken” software updates to active weapon systems in the Middle East — a frantic, 30-day tactical sprint designed to strip away manufacturer code restrictions so legacy anti-drone cameras and missile radars can finally talk to each other
Five years ago, a group of researchers walked out of OpenAI over safety concerns to build a quiet rival named Claude — and after a historic $65 billion funding round that valued the company at $965 billion, those ex-employees have officially leapfrogged their former bosses to create the most valuable AI startup on Earth
Anthropic’s unreleased Claude Mythos AI has proven so terrifyingly good at hacking legacy software that the firm locked it behind a secret vetting program — and global central banks are now holding emergency briefings over fears the model could easily “crack open” the invisible, decades-old code holding the world’s banking systems together
OpenAI has launched a massive $4 billion corporate engineering initiative called “DeployCo” to embed elite developers directly into global banks and enterprises — a quiet, aggressive push to replace traditional software workflows with custom, domain-specific AI networks that operate entirely on their own
A breakthrough in solid-state lithium-sulfur batteries has quietly achieved double the energy density of standard EV batteries — a quiet laboratory victory that could finally eliminate “range anxiety” and cut the weight of electric cars in half
The Ediacaran fossil beds of the Flinders Ranges in South Australia preserve animals from 550 million years ago that predate the Cambrian explosion — soft, frond-like creatures with no mouths, no guts, and no clear relationship to any living group, suggesting a first experiment in complex multicellular life that simply ended and was replaced
When the Apollo 11 astronauts came back, they had to sign a customs declaration on landing in Hawaii — the cargo listed as “moon rock and moon dust samples,” with the departure point given as the Moon
Apple Investing Billions in the U.S. for Manufacturing and AI