Security News

Cybersecurity news aggregator

HIGH News SC Media

Confidential computing's remote attestation protocol may have fundamental flaw

  • What: Potential flaw in confidential computing's remote attestation protocol
  • Impact: May affect secure cloud communications
Read Full Article →

Cloud Security Confidential computing’s remote attestation protocol may have fundamental flaw July 6, 2026 Share By SC Staff (Adobe Stock) Confidential computing, touted as a key technology for Europe's sovereign cloud ambitions, may have a fundamental flaw in its security protocol. A security protocol used to prove cryptographic trust in these systems, known as remote attestation, has been found to be vulnerable to diversion attacks, according to a recent report by The Register. New research led by Muhammad Usama Sardar, a researcher at TU Dresden, indicates that the attested TLS protocol, designed to ensure clients are communicating with genuine, unmodified Trusted Execution Environments (TEEs), is susceptible to diversion attacks. These attacks allow a connection intended for a legitimate server to be silently redirected to a compromised machine without the client's knowledge. The flaw lies in the protocol's focus on software integrity rather than server location. Seven different methods of cryptographically binding attestation evidence to the underlying connection were tested, and none prevented relay attacks where a client verifies a legitimate server but ends up encrypting data to a malicious one. This vulnerability affects real-world implementations, including Meta's Private Processing system for WhatsApp and Edgeless Systems' Contrast, with CVE-2026-33697 being assigned a high severity rating. While the IETF's SEAT working group is incorporating formal verification into its standards, the core issue of trusting the hardware manufacturer remains, and the effectiveness of confidential computing for true digital sovereignty is being questioned by researchers and regulatory bodies like Germany's BSI. Source: The Register An In-Depth Guide to Cloud Security Get essential knowledge and practical strategies to fortify your cloud security. Learn More SC Staff Related Cloud Security Amazon Q Developer extension vulnerability could have exposed cloud credentials SC Staff June 26, 2026 The vulnerability, tracked as CVE-2026-12957, allowed attackers to execute arbitrary commands by embedding malicious code in workspace configuration files. Cloud Security Google Cloud Vertex AI SDK flaw allowed model hijacking and code execution SC Staff June 17, 2026 The attack exploited a weakness in how the SDK selected temporary Cloud Storage buckets for model uploads. API security Security researcher reportedly accesses FIFA World Cup broadcast controls via API flaw SC Staff June 16, 2026 The researcher, known as BobDaHacker, said they exploited a flaw in FIFA's back-end API by registering as a player agent. Related Events Cybercast From prompt to exploit: How LLMs are changing API attacks Mon Jul 27 Cybercast Cloud Security: The AI Effect and How to Proceed On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Cloud Computing Greynet You can skip this ad in 5 seconds

Share this article