Half Spectre, Full Exploit: Hardening Rowhammer Attacks with Half-Spectre Gadgets

Training Solo: On the Limitations of Domain Isolation Against Spectre-v2 Attacks

InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2

GhostRace: Exploiting and mitigating speculative race conditions

Leaky Address Masking: Exploiting Unmasked Spectre Gadgets with Noncanonical Address Translation

FloatZone: Accelerating Memory Error Detection Using the Floating Point Unit [pdf]

Let Me Unwind That For You: Exceptions to Backward-Edge Protection

Branch History Injection

Rage Against the Machine Clear

Constantine: Automatic side-channel resistance using data flow linearization

[PDF] Who’s Debugging the Debuggers? Exposing Debug Information Bugs in Optimized Binaries

Speculative Probing: Hacking Blind in the Spectre Era

TagBleed: Breaking KASLR on the Isolated Kernel Address Space using Tagged TLBs

CROSSTalk: the first MDS cross-core attack

TRRespass: Rowhammer against DDR4

NetCAT — network-based cache side-channel attacks on Intel DDIO

ECCploit: ECC Memory Vulnerable to Rowhammer Attacks After All

TLBleed

Grand Pwning Unit: Accelerating Microarchitectural Attacks with the GPU

AnC (MMU caching-based attack against ASLR)

Flip Feng Shui: Cross-VM Bitflipping SSH Compromise