Security roundup: new Spectre attacks via JIT, 1200 Linux vulns, and Asos hacked
Researchers demonstrated that JIT compilers (SpiderMonkey, eBPF, GraalVM) can revive Spectre-v2 attacks using self-modifying code. Google shut down its Open Source Vulnerability Rewards Program after being flooded with AI-generated fake reports, while retailer Asos was hit by ransomware that pushed extortion demands to customers via app notifications.
- Attack uses self-modifying JIT code to bypass Spectre-v2 kernel mitigations
- SpiderMonkey in Firefox, eBPF in Linux, and GraalVM in Python are affected
- Google closed its Open Source Vulnerability Rewards Program over AI fakes
- Asos breached: ransomware crew sent demands via app push notifications
Read next
Security