Threat Intelligence

Researchers Demonstrate Data-Leaking Attack on Cloudflare Workers

The Hacker News · 20 Aug 2026
Key Takeaway Small businesses using cloud or edge computing services should ensure authentication tokens expire quickly and stay updated on vendor security patches to limit exposure from emerging hardware-level attacks.

Cybersecurity researchers have revealed a remote 'Spectre' attack targeting Cloudflare Workers, a popular platform businesses use to run code close to their customers for faster website and app performance. The attack allowed a malicious Worker to slowly leak a JSON Web Token (JWT) — a type of digital credential often used to verify user identity — from another Worker running on the same physical server, achieving a leak rate of up to 12 bits per second. That may sound slow, but it's 360 times faster than a similar attack demonstrated back in 2021, showing that these side-channel techniques are becoming more practical over time.

The researchers conducted their test in a controlled, end-to-end experiment using both an attacker-controlled Worker and a victim Worker, successfully proving the technique works in a real production-like environment rather than just theoretically. Spectre-style attacks exploit flaws in how modern computer processors handle speculative execution, a performance-boosting technique, rather than relying on traditional software bugs — making them notoriously difficult to fully patch.

While this particular research focused on Cloudflare's infrastructure, it highlights a broader concern for any business relying on shared cloud or edge computing environments: sensitive data can potentially be exposed through subtle hardware-level side channels, even when applications are properly coded. Businesses should stay informed about vendor security advisories and ensure sensitive credentials have short lifespans to limit exposure.

Cloudflare Spectre Attack Cloud Security JWT Side-Channel Attack

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.