Zombies!

Zombies!

Marko Helenius
Marko Helenius

2 Jun 2019

2 min read

In the beginning of 2018 vulnerabilities like Spectre [1] and Meltdown changed the world of computing. They were from the family of next generation vulnerabilities, found in CPU hardware layer, instead of the traditional defects existing in computing software layer. What makes these CPU vulnerabilities more serious and dangerous is the fact that they exists in the hardware layer underneath the workload and even the operating system. Situation is extremely critical in virtualized environments, for example in the Cloud, where multiple tenants operate in same resources seamlessly. In May 2019 Intel announced a new set of vulnerabilities similar to Spectre and Meltdown, called Microarchitectural Data Sampling (MDS). All previously mentioned vulnerabilities reside in Intel CPUs (Cores and Xeon) and particularry in Intel implementation of Hypertreading and speculative execution. Exploiting these vulnerabilities, attacker can obtain leaked data across processes, privilege boundaries and Hyperthread. As this feature resides in the hardware itself, all know operating systems, all hypervisors and container solutions running on top of Intel processor are affected. How to mitigate Zombie(load)s [Z] in the Cloud? If you run untrusted or unpatched software stack, multiple tenants and/or services open to the Internet, you have increased risk of being bit by a Zombieload. Here is a list of steps we have performed for our customers to mitigate Zombies:

Share this post

Marko Helenius

Marko Helenius

Field Notes

Related Articles

Continue exploring cloud technology and best practices

Zombies!

Security

2 min read

One SSL renewal used to last a year. By 2029 you'll need eight.

SSL/TLS certificate validity is shrinking fast — from 398 days to 47. If your team is still renewing by hand, the math no longer works.

Read more
Zombies!

AI

Cloud

3 min read

Run Claude in your own AWS environment: Cloud2 is now an Anthropic Authorised Reseller

Nordic organizations can now purchase Anthropic's Claude AI models directly from Cloud2 via Amazon Bedrock with EU data residency and enterprise-grade governance from day one.

Read more
Zombies!

Modernization

8 min read

SQL Server 2016 ends in July. Your modernization clock just started.

On 14 July 2026 SQL Server 2016 reaches end of extended support, Windows Server 2016 follows in January 2027. Here is what actually happens, the real options, and the steps to take before the clock runs out.

Read more

Ready to discuss your cloud strategy?

Let's talk about how Cloud2 can help your organization.

Field Notes

Stay ahead of the cloud

Practical insights on AWS, Azure, security and AI. Delivered to your inbox.

No spam. Unsubscribe any time.