FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·CriticalBreaking

New Attack Spies Using SSDs

Abstract visualization of a side-channel attack where data signals emanate from an SSD chip towards browser icons, representing the FROST attack.

TL;DR: A new technique called FROST allows websites to monitor user activity by measuring tiny delays in solid-state drive (SSD) performance. This browser-based attack can track other open websites and applications, creating a significant privacy risk by using standard web APIs without special permissions.

By Neeraj Dhiman·3h ago·1 min read·updated 51m ago
Source

Key facts

Category
Cybersecurity
Impact
Critical
Published
3h ago
Source
Slashdot

Full summary

A new browser-based attack called FROST can spy on your activity across websites and apps by measuring your SSD's performance.

Researchers have detailed a new browser-based spying technique called FROST. The method allows a malicious website to monitor a user's activity by analyzing the performance of their solid-state drive (SSD). It works by using standard web APIs to perform rapid read/write operations. By measuring the time these operations take, the website can detect subtle delays caused by other applications or browser tabs accessing the SSD. This timing information acts as a side-channel, revealing what else is running on the user's computer without needing special permissions or exploiting a traditional vulnerability.

The primary concern with FROST is its ability to compromise user privacy. An attacker could use this technique to create a fingerprint of a user's browsing habits, identifying which other websites they have open or which desktop applications are active. Because it leverages legitimate browser features, it bypasses many conventional security measures. This poses a challenge for developers and security teams who rely on the browser's sandboxing model to isolate websites from each other and the underlying system. The attack shows how benign web standards can be combined to extract sensitive information.

As a proof-of-concept, FROST highlights the continuous need for vigilance in web API design. Browser developers and standards bodies will likely need to evaluate the implications and consider potential mitigations. These could include introducing timing noise or further restricting access to high-precision performance measurements to prevent such fingerprinting methods from being effective in the wild.

Why it matters

This is a novel, browser-based side-channel attack that bypasses traditional sandboxing by using standard web APIs. It poses a significant privacy risk by allowing websites to monitor user activity across tabs and applications without requiring special permissions.

Business impact

This attack could undermine user trust in web applications. For businesses handling sensitive data, the risk of cross-site information leakage, even indirectly, could have compliance and reputational implications. It highlights a new threat vector that security teams must consider.

Tags

#Privacy#security#side-channel attack#browser#ssd#frost

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: Slashdot

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube