(no title)
thijsr | 5 months ago
We've demonstrated our attack on real-world KVM-based cloud solutions. Both Google Cloud [1] and AWS [2] wrote a blog post in response to this attack, where they describe how they mitigate against L1TF Reloaded and how they harden their systems against unknown transient execution attacks. Google also decided to award us a bug bounty of $151,515, the highest bounty of their Cloud VRP yet.
PoC is available at https://github.com/ThijsRay/l1tf_reloaded
[1] this submission
[2] https://aws.amazon.com/blogs/security/ec2-defenses-against-l...
No comments yet.