cross-posted from: https://lemmy.sdf.org/post/59167483

Requires physical access:

The attack requires an attacker who already controls the server’s software and can briefly access the machine to insert a small circuit board, called an interposer, between the processor and a memory module.

So not like Spectre or Meltdown. I suspect we’ll only see more and more vulnerabilities like this exposed as LLMs are used by capable security researchers and computer criminals to reduce the amount of work required to explore concepts that wouldn’t have been worthwhile in the past.