Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing Security Protocols




A new hardware attack, dubbed DDRop, has successfully breached the memory protection mechanisms of Intel TDX, Intel Scalable SGX, and AMD SEV-SNP confidential computing architectures. The attack, which exploits a critical design flaw in the DDR5 memory architecture, allows an attacker to silently drop writes to a server's memory, effectively compromising the confidentiality of the encrypted data. The researchers behind the attack have released their findings and have urged the development of new memory-encryption hardware that adds both integrity and freshness to the memory bus.



  • DDRop, a novel hardware attack, has breached the memory protection mechanisms of Intel TDX, Intel Scalable SGX, and AMD SEV-SNP architectures.
  • The attack exploits a critical design flaw in DDR5 memory architecture, allowing silent writes to a server's memory and compromising confidentiality.
  • The attack requires a small circuit board ($200) to be inserted between the processor and a memory module.
  • The attack can be executed with relative ease, even without physical access to the server, and can forge a machine's own attestation.
  • The implications are far-reaching, affecting cloud services that use these architectures to protect customer data.
  • Researchers have released the interposer's designs, controller firmware, and attack code on GitHub.
  • Intel and AMD have acknowledged the findings but not offered mitigation guidance or a patching timeline.
  • Experts recommend developing new memory-encryption hardware, restricting memory-management features, and checking important writes.
  • The discovery highlights the importance of ongoing security research and continuous monitoring of emerging threats.



  • The cybersecurity landscape has been shaken by the revelation of a novel hardware attack, dubbed DDRop, which has successfully breached the memory protection mechanisms of Intel TDX, Intel Scalable SGX, and AMD SEV-SNP confidential computing architectures. The research team behind this attack, comprising experts from KU Leuven, ETH Zurich, Durham University, and Google, has disclosed their findings, which highlight the critical vulnerability of these cutting-edge security protocols.

    DDRop is a stealthy attack that exploits a critical design flaw in the DDR5 memory architecture, allowing an attacker to silently drop writes to a server's memory. This, in turn, enables the processor to read old, encrypted data as if it were current, effectively compromising the confidentiality of the encrypted data. The attack relies on the insertion of a small circuit board, known as an interposer, between the processor and a memory module, which costs under $200 to build.

    The researchers behind DDRop have demonstrated that this attack can be executed with relative ease, even in the absence of physical access to the server. The attack is particularly concerning because it does not require any prior knowledge of the system or its configuration. Furthermore, the attackers can use the interposer to forge a machine's own attestation, which can be used to gain access to the system.

    The implications of DDRop are far-reaching, as all three architectures that it affects - Intel TDX, Intel Scalable SGX, and AMD SEV-SNP - are commonly used in cloud services to protect customer data. The fact that an attacker can undermine the protection offered by these services using a cheap piece of hardware underscores the need for improved security protocols.

    The attack is not limited to cloud servers; it can also be executed on home computers or phones. However, the researchers emphasized that the attack is aimed at cloud servers, which are more vulnerable due to the large amounts of memory that they use.

    The researchers have released the interposer's board designs, controller firmware, and attack code on GitHub, alongside their research paper. They have also stated that they have no evidence of DDRop or a comparable active interposer being used outside a laboratory.

    In response to the discovery of DDRop, Intel and AMD have acknowledged the findings and have stated that they will issue security bulletins on the disclosure date. However, neither company has offered mitigation guidance or a timeline for patching the vulnerability.

    In order to address the critical vulnerability exposed by DDRop, researchers and security experts are advocating for the development of new memory-encryption hardware that adds both integrity and freshness to the memory bus. They also recommend restricting memory-management features that DDRop abuses and checking that important writes actually landed.

    The discovery of DDRop highlights the importance of ongoing security research and the need for continuous monitoring of emerging threats. It also underscores the need for more robust security protocols that can effectively protect against the types of attacks that DDRop exploits.

    In conclusion, the DDRop attack is a significant reminder of the critical importance of robust security protocols in protecting sensitive data. As the cybersecurity landscape continues to evolve, it is essential that security researchers and experts remain vigilant and proactive in identifying and mitigating emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-DDRop-Attack-Breaks-Intel-TDX-and-AMD-SEV-SNP-Confidential-Computing-Security-Protocols-ehn.shtml

  • https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html

  • https://vulners.com/thn/THN:6CD207976E0B6FA46C67A9B8AEB72BB4


  • Published: Mon Sep 14 12:36:41 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us