🎥 Video | YoutubeGoogle Ads: What if you could 10x your ad creative?(09.09.2026 um 23:39 Uhr)
🎥 Video | YoutubeHow to link your Google Ads manager account to a payments profile(10.09.2026 um 14:14 Uhr)
🎥 Video | YoutubeGoogle Ads: PMax for store goals: Boost in-store sales(10.09.2026 um 14:24 Uhr)
🎥 Video | YoutubeGoogle Ads: How to build a modern measurement stack(10.09.2026 um 17:46 Uhr)
🎥 Video | YoutubeGoogle Ads: What if you could 10x your ad creative?(09.09.2026 um 23:39 Uhr)
🎥 Video | YoutubeHow to link your Google Ads manager account to a payments profile(10.09.2026 um 14:14 Uhr)
🎥 Video | YoutubeGoogle Ads: PMax for store goals: Boost in-store sales(10.09.2026 um 14:24 Uhr)
🎥 Video | YoutubeGoogle Ads: How to build a modern measurement stack(10.09.2026 um 17:46 Uhr)

🎥 IT Security Video 🕛 vor 23 Std. 2 Min Lesezeit SECURITY-FEED
0

USENIX: WOOT '26 - PowerHooK: Enabling Software-Based Power Side Channels Against AMD SEV Technologies...

↗ Quelle (YouTube · USENIX)
🗣️ Stimme:
📺
YouTube · USENIX
103 YouTube-Aufrufe
PowerHooK: Enabling Software-Based Power Side Channels Against AMD SEV Technologies via Transient-Execution Replay

Mathias Oberhuber, Martin Unterguggenberger, and Martin Wistauder, Graz University of Technology; Andreas Kogler, Graz University of Technology Alumni; Rishub Nagpal and Stefan Mangard, Graz University of Technology

Confidential computing technologies, such as AMD SEV, enable secure execution of cloud workloads on shared physical hardware. AMD SEV technologies implement the VM trust model through AMD SEV-ES, encrypting memory and CPU register state, and AMD SEV-SNP, providing integrity protection for VM memory. While AMD SEV provides heavy-weight architectural isolation, it remains unclear whether it is susceptible to power side channels.
In this paper, we present PowerHooK, a new attack on AMD SEV technologies that enables software-based power side channels by speculatively replaying victim code paths via transient execution. Specifically, we repurpose page-fault-based transient replay to establish a transient-execution replay hook for power measurements. PowerHooK allows a malicious hypervisor to re-execute vulnerable victim code paths, thereby enabling continuous collection of power traces, reducing significant system noise. This capability allows the attacker to perform power analysis attacks on denoised datasets.
We demonstrate PowerHooK’s methodology by recovering AES key bytes across all AMD SEV defenses. Here, the attacker only needs to consider 1320 samples to perform a CPA on AES-NI executed in AMD SEV-SNP running in an experimental setting. We systematically analyze architectural, speculative, and transient power leakage across different AMD CPU generations and evaluate how AMD’s virtualization levels affect PowerHooK. Moreover, we present a real-world AES key byte recovery attack targeting VM-isolated cloud workers that run OpenSSL's constant-cycle AES-NI CBC implementation. Thereby, we demonstrate that transient replay gadgets are present in the OpenSSL library, showcasing that PowerHooK effectively enables the extraction of secrets.

View the full WOOT '26 program at https://www.usenix.org/conference/woot26/technical-sessions
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)