Security News

Cybersecurity news aggregator

HIGH Vulnerabilities SC Media

DDRop attack bypasses Intel and AMD confidential computing defenses

The DDRop hardware attack bypasses Intel and AMD confidential computing defenses by using a custom interposer board to silently drop memory writes, causing processors to read outdated encrypted data. This exploits the lack of a memory freshness guarantee in Intel TDX, Intel Scalable SGX, and AMD SEV-SNP, allowing an attacker with brief physical access and existing software control to compromise protected virtual machines. The vulnerability is hardware-based, so a simple software patch is not feasible, and vendors note the attack falls outside their threat models due to the physical access requirement.
Read Full Article →

Hardware DDRop attack bypasses Intel and AMD confidential computing defenses September 15, 2026 Share By SC Staff (Adobe Stock) As reported by The Hacker News, researchers from KU Leuven, ETH Zurich, Durham University, and Google have disclosed a novel hardware attack named DDRop that undermines the memory protection mechanisms of Intel and AMD confidential computing technologies. This attack operates by silently dropping writes to a server's memory, causing the processor to continue reading outdated encrypted data as if it were current. The DDRop attack requires an adversary with existing software control of a server and brief physical access to install a custom interposer circuit board between the processor and memory modules. This interposer, costing under $200, exploits a weakness in confidential computing implementations like Intel TDX, Intel Scalable SGX, and AMD SEV-SNP, which encrypt server memory to protect data privacy. The attack capitalizes on the absence of a memory freshness guarantee in these systems, allowing old encrypted data to be read as if it were the latest value. Researchers demonstrated that DDRop can achieve full control of protected virtual machines on Intel TDX by manipulating page table writes, enabling unauthorized memory access and attestation forgery. While the impact on AMD SEV-SNP is more limited, all three technologies are affected due to their lack of a freshness check. The researchers have released the attack's design and code, noting that a simple software patch is not feasible due to the hardware-level vulnerability. Both Intel and AMD acknowledge the findings, stating the attack falls outside their defined threat models due to the physical access requirement. Source: The Hacker News SC Staff Related Hardware GrapheneOS may drop Pixel 11 support over missing MTE security feature SC Staff September 1, 2026 The GrapheneOS team discovered the lack of MTE support after attempting a partial port to the Pixel 11. Hardware Loongson processors vulnerable to LoongLeak cache attack SC Staff August 13, 2026 German researchers from the Helmholtz Center for Information Security discovered that Loongson processors, which utilize the LoongArch instruction set architecture, possess caches that leak data. Hardware Defcon badges feature new open-source chip for enhanced security SC Staff August 3, 2026 The Baochip-1x is a "mostly" open-source microcontroller that allows for verifiable security. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article