Spectre is back: the BTR flaw reads memory on Intel, AMD and Arm chips
BTR, a Spectre variant, pulled the Linux root password hash in minutes during tests. Also: 12.9 million records for sale in Mexico, the America.gov chatbot and Earth's core.
TL;DR Quick summary
- Researchers published BTR, a Spectre v2 variant that affects Intel, AMD and Arm processors; Linux has already merged patches.
- In tests it pulled the root password hash from a Linux machine with an Intel chip in 3 to 5 minutes, at about 8 bytes per second.
- Mexico is investigating the sale on Telegram of 12.9 million personal records attributed to call centers.
- The United States launched America.gov, a chatbot running on Gemini and Grok that searches about 29,000 federal websites.
- A study in Nature links the turning of Earth's inner core to the milliseconds by which the day changes.
The briefing on video
Video transcript
Good morning. Spectre, the processor flaw from twenty eighteen, is back under a new name, and this time it pulls secrets out of a Linux machine in minutes.
Researchers from Vrije Universiteit Amsterdam and the Sant'Anna School in Italy published an attack called BTR on September twenty-ninth. It affects Intel, AMD and Arm processors. Linux has already merged patches, and no source reports real-world attacks.
Your processor guesses what you are about to order, like the cook who starts your usual before you say a word. The problem: when a program recycles memory, the processor keeps the memory of the previous customer and starts the wrong order. For that instant, it peeks at data it should not see.
The numbers: eight bytes per second, and three to five minutes to extract the administrator's password hash on Intel test machines. Three chip makers affected.
We have been patching the same idea for eight years. Speed was built on guessing, and guessing always leaves a trace.
In Mexico, the Anticorruption and Good Government Ministry is investigating the sale on Telegram of twelve point nine million personal records attributed to call centers. The statement is dated September twenty-fourth. If your bank calls and already knows everything about you, hang up and call them yourself.
The United States launched America dot gov, a chatbot running on Gemini and Grok that searches about twenty-nine thousand federal websites. Reportedly, on day one it contradicted the president and then stopped answering political questions.
And a study in Nature proposes that Earth's inner core, by turning about two degrees relative to the mantle, changes the length of the day by a few milliseconds over decades.
Every source is linked at ankincloud dot com slash noticias. I just read them for you.
That is all. I am going to see if my processor can guess what I want for breakfast. I will disappear until further notice.
Today's topic is a flaw that isn't in a program, but in the way processors have worked for decades. It's called BTR and it's a direct relative of Spectre, the 2018 flaw we all swore we'd left behind.
This is on the researchers' page, which you are never going to open. So I'll read it for you, and while I'm at it I'll tell you what happened to your data in Mexico, with a government chatbot and with the center of the planet.
BTR, a new Spectre variant, affects Intel, AMD and Arm processors
On September 29, researchers from VUSec and the Scuola Superiore Sant'Anna published BTR, a Spectre v2 variant that affects Intel, AMD and Arm processors.
The full name is Branch Target Reuse. VUSec is a group at Vrije Universiteit Amsterdam; Sant'Anna is in Italy. The attack targets the JIT engines found in browsers, language runtimes and the operating system kernel. In their demonstration against the Linux kernel it leaked memory at about 8 bytes per second and recovered the root password hash in 3 to 5 minutes, on test machines with Intel Raptor Cove and Lion Cove cores that had all earlier patches applied. They also showed a proof of concept in SpiderMonkey, the Firefox engine, and an escape from Oracle GraalVM's isolation. There is still no complete attack from a web page.
Linux has already merged fixes, tracked as CVE-2026-64507 and CVE-2026-64508. Oracle changed the location of its code cache, and Mozilla said it will prioritize finishing site isolation. AMD responded that its existing Spectre v2 guidance mitigates the technique; Intel and Arm did not respond to SecurityWeek. None of the sources report real-world attacks.
Key facts
- 8 bytes/sleak rate on Linux
- 3-5 minto extract the root hash
- 3vendors: Intel, AMD and Arm
Explained for humans
What is speculative execution?
It's a speed trick: the processor guesses which instruction comes next and gets ahead on it, like the cook at your regular diner who starts on your usual order.
If the guess was wrong, it throws out what it prepared. The catch is that throwing it out leaves a trace on the griddle. BTR exploits the fact that certain programs, JIT engines, recycle chunks of memory: the processor still remembers the previous customer at that table and, for an instant, starts the wrong order with data it has no business touching.
That's why it matters here: it's not a virus you download, it's a habit of the chip. It gets fixed with system updates, not by buying another computer.
- JIT engine
- frees and reuses
- Recycled memory
- the memory stays
- Stale prediction
- early jump
- Leaked data
Why should you care?
At home the risk is low today: the attack needs to run code on your machine, and there's no complete version from a web page. For a small business, the concern is shared or rented Linux servers. It gets fixed with updates, not new hardware.
What to do
- If you manage Linux servers, install your distribution's kernel updates (they include the fixes CVE-2026-64507 and CVE-2026-64508) and reboot so they take effect.
- If you rent a server or shared hosting, ask your provider whether it has already applied the kernel patches for BTR.
- On your computer and your phone, keep the operating system and the browser up to date; the defenses against this family of flaws arrive that way.
- Don't buy new hardware over this: according to the manufacturers, the fixes are applied in software.
Frank's take
Eight years of patching Spectre and it keeps popping up through another window. It's nobody's carelessness in particular: we decided computers should be fast at guessing, and anyone who guesses leaves clues about what they were thinking. Today's patch doesn't fix the processor; it asks the system to wipe the guesser's memory every so often. It works. It's also an admission that the chip you bought is a very fast stranger you trust with everything, and who now and then talks in its sleep.
Glossary
5 terms
- Speculative execution
- The processor gets ahead on work by guessing which instruction comes next. If it guesses wrong, it discards the work, but leaves traces.
- JIT engine
- Part of a browser or of the system that translates code into processor instructions on the fly.
- Hash
- A scrambled fingerprint of a password. To get the original, the attacker still has to crack it by brute force.
- Kernel
- The core of the operating system: the piece that hands out processor, memory and permissions to every program.
- Root
- The administrator account on Linux, the one that can do anything on the machine.
Sources
- Branch Target Reuse: Spectre-v2 Attacks in JIT Engines (opens in a new tab) vusec.net
- New Spectre v2 attack variant leaks Linux root password hash in minutes (opens in a new tab) bleepingcomputer.com
- New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks (opens in a new tab) securityweek.com
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses (opens in a new tab) thehackernews.com
Mexico investigates the sale on Telegram of 12.9 million personal records
Mexico's Anticorruption and Good Government Ministry (Secretaría Anticorrupción y Buen Gobierno) is investigating an offer on Telegram of more than 12.9 million personal records attributed to various call centers.
It announced this on September 24 in its statement 113/2026: it detected a post circulated on September 22 in which a user is selling those databases. According to the ministry, they would include full name, email, phone numbers, date of birth, Mexico's tax ID (RFC), home address and banking data, among other things. The ministry obtained a sample of 13,000 records from 13 different databases. The preliminary analysis shows 23 business names, among them banks such as BBVA, Banamex, Banorte, HSBC and Santander, and stores such as Amazon, Liverpool and Soriana. The ministry clarified that it has not verified all of the records and that the appearance of a business name does not mean that company is responsible. It announced it will open investigations on its own initiative under the Federal Law on the Protection of Personal Data Held by Private Parties.
The statement is six days old; I found no new developments, but we hadn't covered it and it affects you directly.
Key facts
- 12.9 Mrecords offered on Telegram
- 13,000records in the official sample
- 23brands named in the sample
Explained for humans
Why does a call center have your data?
A call center is a company that others hire to call their customers: to sell, collect payments or provide support. To do that, it receives a copy of the customer list. It's like a duplicate key: you gave your key to the bank, the bank made a copy for the collection agency, and now the security of your house depends on the most neglected door of all.
With your name, RFC, address and bank, a scammer no longer has to guess anything: they call you already knowing who you are, and that makes the call sound legitimate.
Why should you care?
The names that show up are the banks and stores half of Mexico uses. If part of that database is real, what comes next is very convincing calls and messages with your correct data. For a small business the lesson cuts both ways: you also share customer lists with third parties, and the law holds you responsible for protecting them.
What to do
- If someone calls "from your bank" and already knows your name, RFC or address, hang up and dial the number on the back of your card yourself.
- Don't give out verification codes, PINs or passwords by phone, text or email, even if the caller has all your data.
- Turn on transaction notifications in your bank's app and check your accounts over the next few days.
- Change your online banking password if you reuse it on other services, and turn on two-step verification wherever it's available.
Frank's take
No joke here. You didn't lose your data: you gave it to a bank or a store, and someone else let it out. The only thing you do control is what you do when the phone rings and the person on the other end knows your name, your RFC and your address. Knowing who you are doesn't prove they are who they say they are.
Glossary
3 terms
- Call center
- A company that takes or makes calls on behalf of others (sales, collections, support) and receives their customers' data to do it.
- RFC
- Registro Federal de Contribuyentes: Mexico's tax ID, the code the tax authority (SAT) uses to identify every person or company in Mexico.
- Database
- An organized file where a company keeps its customer records: one row per person, one column per piece of data.
Sources
- Investigan venta de bases de datos de call centers: Vulneran 12.9 millones de registros de 23 empresas (opens in a new tab) elfinanciero.com.mx
- Buen Gobierno investiga venta de 12.9 millones de registros con datos personales en posesión de call centers (opens in a new tab) heraldodemexico.com.mx
- Datos personales en venta: Buen Gobierno investiga posible filtración de 12.9 millones de registros (opens in a new tab) informador.mx
The United States launches America.gov, a chatbot running on Gemini and Grok
On September 29, the United States government presented America.gov at an event at the Andrew W. Mellon Auditorium in Washington. It's a chatbot that works as a single entry point to federal services: it pulls together information from about 29,000 government websites. According to Joe Gebbia, the government's chief design officer, it runs on Google's Gemini and xAI's Grok. It is operated by the General Services Administration.
For now it answers questions and sends you to the official page for each service; the goal is that in 2027 people can complete applications and track them without leaving the site. FedScoop notes that questions about the contracts with the providers, and about how the data of the people who write to it is protected, remain unanswered.
The Next Web documented that on day one the chatbot said official sources show no widespread fraud that changed the outcome of the 2020 election, and called the Pentagon the headquarters of the Department of Defense, contrary to the president's position. Reportedly, hours later the site started refusing political questions.
Key facts
- 29,000federal websites searched
- 2models: Gemini and Grok
- 2027full applications on the site
Explained for humans
How does a government chatbot answer?
It doesn't know the answers by heart: first it searches the official websites and then it writes a reply with what it found. It's the information desk: it doesn't decide anything, it checks the rulebook and tells you which floor to go to.
That's why it answers what the documents say and not what the boss thinks. And that's also why it can get things wrong when it summarizes: always open the official page it sends you to.
Why should you care?
If you deal with paperwork in the United States (a visa, taxes, a business that exports), this is going to be the front door. And it's the dress rehearsal for something that sooner or later will reach every government's service counters. The questions worth asking are the boring ones: who keeps what you type, and who is accountable if the chatbot gives you bad information.
What to do
- If you use it, treat the answer as guidance and confirm requirements and dates on the official page it links you to.
- Don't type anything into a chatbot that you wouldn't put on a public form: ID numbers, accounts or passwords.
Frank's take
They had two models read 29,000 government websites and were surprised when they answered with what the government websites say. A chatbot has no loyalties: it has documents. If you don't like the answer, the problem is in the file or in whoever is asking. What keeps me up at night is the boring part: which server ends up holding what people confess to the information desk.
Glossary
2 terms
- Chatbot
- A program you talk to by text or voice. Current ones use a language model to write their replies.
- Language model
- A program trained on huge amounts of text to predict and write language. Gemini and Grok are two of them.
Sources
A study links Earth's inner core to the milliseconds by which the day changes
A study published in Nature by Huifeng Zhang and Mathieu Dumberry, of the University of Alberta, proposes an explanation for an old mystery: why the length of the day rises and falls by a few milliseconds over decades. According to the work, which the university publicized on September 28, the main cause is the planet's solid inner core.
The inner core oscillates relative to the mantle, by about 2.35 degrees over a cycle of roughly 70 years, with a change of direction around 2010. As it moves, its gravity pulls on the denser and less dense regions of the mantle and very slightly alters how fast the surface spins. The authors combined seismic reconstructions of the core with models of the outer core and compared them with length-of-day records from 1964 to 2019. They caution that the reconstructions carry uncertainty: some estimates vary by up to 30 percent depending on the model.
Key facts
- 2.35°core's turn against the mantle
- 70 yearsapprox. length of the cycle
- 2010the turn changes direction
Explained for humans
Why isn't a day exactly 24 hours long?
Earth isn't a solid ball: it has a crust and a mantle of rock, an outer core of liquid metal and, at the center, a solid inner core. Each layer can spin at a slightly different rate.
Think of a half-full water jug: if you spin it, the water doesn't follow right away and you feel it tug at you. Here the jug is the mantle, where we stand, and what's inside speeds it up or slows it down just a little. We're talking thousandths of a second, but atomic clocks and satellite navigation need to know exactly how much the planet turns.
Why should you care?
You won't feel a thing, and you don't need to adjust your watch. But your phone's GPS, bank clocks and internet time depend on measuring Earth's spin with a precision of fractions of a millisecond. Understanding where those variations come from helps keep those systems on time.
Frank's take
The floor you stand on turns at a pace that depends on an iron ball nobody has seen and nobody will ever see. We invented atomic clocks only to find out the planet doesn't keep the beat. I find it comforting: if Earth can run a few milliseconds late, so can I.
Glossary
2 terms
- Inner core
- The solid ball of iron and nickel at the center of the Earth, with a radius of about 1,220 kilometers.
- Mantle
- The thick layer of rock between the crust and the core. The surface we live on rests on top of it.
Sources
Learn more
-
Spectre (vulnerability) — Wikipedia (in Spanish) (opens in a new tab)
es.wikipedia.org
The story of the original 2018 flaw and why it has no single, definitive fix.
-
Speculative execution — Wikipedia (in Spanish) (opens in a new tab)
es.wikipedia.org
Explains the processor speed trick behind this whole family of attacks.
-
Earth's inner core — Wikipedia (in Spanish) (opens in a new tab)
es.wikipedia.org
What it is, what it's made of and how you study something nobody can see.