<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second]]></title><description><![CDATA[<p dir="auto"><strong>Title:</strong> Spectre Attack Against Cloudflare Workers Demonstrates Remote JWT Theft at 12 Bits Per Second</p>
<p dir="auto"><strong>Summary:</strong> Researchers have published a proof-of-concept attack demonstrating a remote Spectre side-channel against Cloudflare Workers, successfully extracting a JSON Web Token from a co-located Worker in a production environment at a rate of up to 12 bits per second—a significant improvement over previous research from 2021.</p>
<p dir="auto"><strong>Body:</strong></p>
<p dir="auto">A newly disclosed proof-of-concept demonstrates a successful remote Spectre attack targeting Cloudflare's Workers platform. The research team was able to extract a JSON Web Token (JWT) from a victim Worker running in the same environment as an attacker-controlled Worker, all within the production infrastructure.</p>
<p dir="auto">This new attack achieves a data exfiltration rate of up to 12 bits per second. This represents a 360-fold increase in transmission speed compared to an earlier Spectre-based attack against the same platform, which was demonstrated in 2021. The ability to remotely leak sensitive credentials like JWTs from co-located workloads poses a significant concern for multi-tenant serverless environments.</p>
<p dir="auto">The end-to-end experiment was conducted using two Worker instances: one serving as the attacker and the other as the victim. The attack was designed and executed solely by the researchers to validate the vulnerability and measure its practical impact. Details on the specific exploitation techniques and the attack chain have been published in the official disclosure.</p>
<p dir="auto">This research highlights the ongoing challenges of securing shared cloud infrastructure against speculative execution side-channel attacks. While microarchitectural mitigations exist, verifying their effectiveness in dynamic edge computing platforms remains a complex and ongoing task.</p>
<p dir="auto">For further details, please see the original report by The Hacker News.</p>
<p dir="auto"><strong>Source:</strong> The Hacker News<br />
<strong>URL:</strong> <a href="https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html</a></p>
]]></description><link>https://xploitlk.com/topic/45/cloudflare-workers-spectre-attack-leaks-jwt-from-co-located-worker-at-12-bits-second</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 11:43:19 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/45.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 19 Aug 2026 20:34:04 GMT</pubDate><ttl>60</ttl></channel></rss>