Multi-CloudIncident TeardownsRetrospectives

Meltdown and Spectre (Jan 2018): When the CPU Itself Was the Vulnerability

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2018, written in 2026 with the benefit of hindsight.

On January 3, 2018, researchers disclosed Meltdown and Spectre, a family of vulnerabilities in the way modern processors execute instructions speculatively. They affected almost every computer, phone and cloud server in the world.

What the flaws allowed

Processors speed things up by guessing which instructions will run next and executing them in advance. The researchers showed that traces of this speculative work leaked through the processor's cache, allowing one program to read memory it should not be able to see. Meltdown broke the boundary between user programs and the operating system kernel; Spectre broke boundaries between programs.

Why the cloud was at the center

In public clouds, many customers share the same physical servers. A flaw that could let one virtual machine read another's memory challenged the core promise of multi-tenant isolation. Microsoft Azure, AWS and Google Cloud had been briefed in advance and rushed to patch their hypervisors, rebooting large parts of their fleets — in Azure's case, ahead of its scheduled maintenance window when details leaked early.

Shared responsibility in practice

Providers patched hosts. Customers still had to patch guest operating systems, update browsers and in some cases recompile software. Some patches caused performance slowdowns, forcing capacity planning decisions.

Lessons in hindsight

  • Hardware can be vulnerable. Defense in depth matters even below the operating system.
  • Know your half of shared responsibility. Provider patches did not fix your VMs.
  • Maintenance windows are not always yours to choose. Design for instances being rebooted.
  • Coordinated disclosure works — but leaks happen, so plans must be ready.

Speculative-execution research continued for years, producing new variants and steady patching. The isolation guarantees of cloud computing held, but they required constant work to maintain.

meltdown spectre cloudMeltdown & Spectre2018

More on this story