
- ETH Zurich researchers found a new Spectre-BTI attack called VMSCAPE that lets a VM steal host data
- It affects cloud setups using KVM/QEMU on AMD and Intel CPUs, bypassing existing defenses
- They propose flushing the branch predictor on VMEXIT as a low-cost fix
If Ghostbusters taught us anything, it’s that spectres are notoriously difficult to get rid of.