FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·CriticalBreaking

Websites Can Secretly Track You Via Your SSD

A security researcher analyzes JavaScript code on a laptop, which is being used to monitor SSD performance for a side-channel attack.

TL;DR: Researchers found a new attack called FROST that lets a malicious website track other sites and apps you open. It works by measuring your SSD's response time using only JavaScript, requiring no special permissions.

By Neeraj Dhiman·3h ago·2 min read·updated 59m ago
Source

Key facts

Category
Cybersecurity
Impact
Critical
Published
3h ago
Source
The Hacker News

Full summary

A new attack called FROST lets any website secretly track other sites and apps you open just by timing your SSD.

Researchers at Graz University of Technology have developed a new side-channel attack named FROST. This method allows a malicious website to track which other websites you visit and what applications you launch on your computer. The attack is remarkably stealthy, operating from a single, inactive browser tab using only standard JavaScript. It requires no browser extensions, no native code installation, and does not trigger any permission prompts from the user. FROST works by continuously measuring the response time of the system's Solid-State Drive (SSD). When a user opens another application or navigates to a new website, these actions create a brief period of resource competition, or "contention," on the SSD. The malicious script detects these minute timing variations, effectively creating a digital fingerprint that corresponds to specific user activities, such as opening a productivity app or visiting a banking site.

The discovery of FROST presents a significant privacy and security challenge for developers, IT teams, and business leaders. Its ability to operate without any special permissions means it can bypass many conventional security models and sandboxing techniques designed to isolate web applications. Unlike traditional malware or exploits that target software vulnerabilities, FROST leverages a physical characteristic of modern hardware, making it difficult to detect with existing antivirus or browser security tools. This technique turns the high performance of contemporary SSDs into a liability, creating an information leak that can be exploited by any website. For security teams and CTOs, this introduces a new and subtle threat vector that is not easily addressed through simple software patches. It demonstrates that even passive background tabs can pose a serious risk, exfiltrating sensitive data about user behavior without their knowledge or consent. The attack's simplicity and effectiveness underscore the growing complexity of securing systems where hardware and software interactions create unforeseen vulnerabilities that challenge established security paradigms.

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026
  • CompareSSO vs SCIM

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Primary source: The Hacker News

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube