AI Weekly Malaysia

Back to items Summaries

New hardware device can RAM into encrypted memory, expose your data

ID
24395
Status
summarized
Published
15 Sep 2026, 2:31 AM
Fetched
15 Sep 2026, 5:49 AM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
3.5
Created
15 Sep 2026, 5:52 AM
Tags
Audience
developersdatabase_learners

What happened

Researchers from KU Leuven, ETH Zurich, Durham University, and Google built a sub-$200 hardware interposer called DDRop that sits between a CPU and DDR5 memory module to silently drop encrypted writes, enabling replay attacks on confidential VMs. The attack breaks Intel TDX, Scalable SGX, and AMD SEV-SNP trusted execution environments, and was demonstrated on a current Intel TDX server where they forced a protected VM into debug mode and read private memory in plaintext. It requires physical access to the server, making it mainly a threat model concern for cloud providers offering confidential computing guarantees.

Why it matters

If you build or procure services that depend on confidential VMs (Intel TDX, AMD SEV-SNP) for compliance or multi-party computation guarantees, this attack means physical-access insiders or colocation attackers can defeat those guarantees with cheap hardware. For most SaaS founders and developers not using TEEs, no action is needed; for those relying on confidential computing attestation, treat physical access as a broken trust boundary until vendors patch the freshness-check gap.

Discussion angle

Does anyone in the community actually ship confidential VMs in production, or is TEE-based confidential computing still a niche compliance checkbox that this attack doesn't meaningfully change for Malaysian builders?

Top