Security news aggregator

Latest coverage for Side-Channel

Explore the latest on Side-Channel attacks, where cyber security vulnerability studies reveal information leaks from hardware and software. Stay updated.

54 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Side-Channel Attacks are a class of cyber threats in information security where an attacker can glean sensitive information from the physical implementation of a system rather than exploiting software vulnerabilities. These attacks hinge on the observation of physical side effects that occur during the execution of a computer process, such as timing information, power consumption, electromagnetic leaks, or even sound to discern confidential data.

In the context of information security, side-channel attacks pose a significant risk because they can bypass traditional security measures and encryption. Consequently, they have become an area of great concern for security professionals, particularly when addressing the security of cryptographic systems and devices like smart cards, mobile devices, and IoT hardware where physical access is a realistic threat vector. Defending against side-channel attacks often involves implementing measures that obfuscate or minimize these emissions or otherwise increase the difficulty of accurate measurement for would-be attackers.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 54 Filtered view

Encryption protects content, not context Mischief-makers can guess the subjects being discussed with LLMs using a side-channel attack, according to Microsoft researchers. They told The Register that models from some providers, including Anthropic, AWS, DeepSeek, and Google, haven't been fixed, putting both personal users and enterprise communications at risk.…

Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with capabilities to observe network traffic to glean details about model conversation topics despite encryption protections under certain circumstances

A group of academic researchers from Georgia Tech, Purdue University, and Synkhronix have developed a side-channel attack called TEE.Fail that allows for the extraction of secrets from the trusted execution environment (TEE) in a computer's main processor, including Intel's Software Guard eXtensions (SGX) and Trust Domain Extensions (TDX) and AMD's Secure Encrypted Virtualization with Secure

Android devices from Google and Samsung have been found vulnerable to a side-channel attack that could be exploited to covertly steal two-factor authentication (2FA) codes, Google Maps timelines, and other sensitive data without the users' knowledge pixel-by-pixel

AMD Zen hardware and Intel Coffee Lake affected If you thought the world was done with side-channel CPU attacks, think again. ETH Zurich has identified yet another Spectre-based transient execution vulnerability that affects AMD Zen CPUs and Intel Coffee Lake processors by breaking virtualization boundaries.…

A team of security researchers from Georgia Institute of Technology and Ruhr University Bochum has demonstrated two new side-channel attacks targeting Apple silicon that could be exploited to leak sensitive information from web browsers like Safari and Google Chrome

It's another cousin of Spectre, here to read your email, browsing history, and more Many recent Apple laptops, desktops, tablets, and phones powered by Cupertino's homegrown Silicon processors can be exploited to reveal email content, browsing behavior, and other sensitive data through two newly identified side-channel attacks on Chrome and Safari.…

Loading more headlines...