In January 2018, two security exploits called Spectre and Meltdown showed how attackers could take advantage of commonly implemented CPU technology to access data they shouldn't have. Then a similar flaw, Foreshadow, emerged late last year, and now researchers have uncovered four different techniques that exploit Intel's technology in a similar way.

The website CPU.fail has collected information on each vulnerability – collectively referred to as Microarchitectural Data Sampling (MDS) – including Zombieload, RIDL & Fallout, and Store-to-Leak Forwarding. The code used as an example shows how attacks can be launched using malicious JavaScript, and the researchers say it would be difficult for antivirus software to detect, but they have not found evidence of anyone using the technology in attacks so far.
If you have a computer using an Intel processor released since 2011, then congratulations – you've probably gained a vulnerability, since only 8th and 9th generation Core CPUs as well as second-generation Xeon Scalable processors have hardware protection against the attacks.
Closing the security holes requires a combination of firmware and software updates. macOS, Windows, ChromeOS, and Linux already have software updates to address MDS attacks, while Intel has also issued microcode updates for some hardware that you need to pass through motherboard and system vendors.
