Hardware backdoors found in some x86 CPUs - Rosenbridge documents a hidden execution layer

Security & Trust à l'instant0Ajouter aux favoris

Hardware backdoors found in some x86 CPUs - Rosenbridge documents a hidden execution layer
Illustration : Léa Fontaine

A researcher has documented undisclosed execution capabilities in certain x86 processors - a hidden RISC core that runs below the OS and hypervisor with no visibility to security monitoring tools.

In plain terms: The Rosenbridge research (github.com/xoreaxeaxeax/rosenbridge, DEF CON 2018) documents hidden RISC cores inside certain x86 processors that can execute instructions with no visibility to the OS or hypervisor. An attacker with initial access could run code below kernel privilege rings - in a space that security monitoring tools cannot reach.

The research is not theoretical. The coprocessor is activated via a model-specific register (MSR) that enables a hidden execution mode. The MSR value is undocumented and undisclosed by the chip vendor. x86's long history of undocumented instructions makes this class of vulnerability structurally plausible beyond the specific silicon documented.

[Under the hood] CPU privilege rings (ring 0-3) are the foundation of OS security. A backdoor operating below ring 0 defeats kernel-level detection, hypervisor isolation, and most EDR tooling. Detection requires hardware-level attestation - not software scanning.

So what: As AI workloads concentrate on commodity x86 server fleets (including shared cloud infrastructure), hardware supply chain trust becomes a harder problem. This belongs in the threat model of any team running sensitive AI inference on shared or third-party hardware - especially across jurisdictions where CPU manufacturing provenance is opaque.

Ressources, à tester

Article produit par intelligence artificielle, relu sous contrôle éditorial humain.

Notre rédaction
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
Cet article vous a-t-il été utile ?

0 personnes ont aimé cet article

J'aime
S
Sofia AdlerSécurité & confiance
🇩🇪 Sécurité IA, sûreté des modèles, cyber.
Partager :
Commentaires (0)

Connectez-vous pour rejoindre la discussion.

Soyez le premier à commenter.

Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
Rubriques
Explorer
Informations