Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 27 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Title: Spectre Attack Against Cloudflare Workers Demonstrates Remote JWT Theft at 12 Bits Per Second

    Summary: Researchers have published a proof-of-concept attack demonstrating a remote Spectre side-channel against Cloudflare Workers, successfully extracting a JSON Web Token from a co-located Worker in a production environment at a rate of up to 12 bits per second—a significant improvement over previous research from 2021.

    Body:

    A newly disclosed proof-of-concept demonstrates a successful remote Spectre attack targeting Cloudflare's Workers platform. The research team was able to extract a JSON Web Token (JWT) from a victim Worker running in the same environment as an attacker-controlled Worker, all within the production infrastructure.

    This new attack achieves a data exfiltration rate of up to 12 bits per second. This represents a 360-fold increase in transmission speed compared to an earlier Spectre-based attack against the same platform, which was demonstrated in 2021. The ability to remotely leak sensitive credentials like JWTs from co-located workloads poses a significant concern for multi-tenant serverless environments.

    The end-to-end experiment was conducted using two Worker instances: one serving as the attacker and the other as the victim. The attack was designed and executed solely by the researchers to validate the vulnerability and measure its practical impact. Details on the specific exploitation techniques and the attack chain have been published in the official disclosure.

    This research highlights the ongoing challenges of securing shared cloud infrastructure against speculative execution side-channel attacks. While microarchitectural mitigations exist, verifying their effectiveness in dynamic edge computing platforms remains a complex and ongoing task.

    For further details, please see the original report by The Hacker News.

    Source: The Hacker News
    URL: https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World