New hardware device can RAM into encrypted memory, expose your data
- ID
- 24395
- Status
- summarized
- Published
- 15 Sep 2026, 2:31 AM
- Fetched
- 15 Sep 2026, 5:49 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 15 Sep 2026, 5:52 AM
- Tags
- Audience
- developersdatabase_learners
What happened
Researchers from KU Leuven, ETH Zurich, Durham University, and Google built a sub-$200 hardware interposer called DDRop that sits between a CPU and DDR5 memory module to silently drop encrypted writes, enabling replay attacks on confidential VMs. The attack breaks Intel TDX, Scalable SGX, and AMD SEV-SNP trusted execution environments, and was demonstrated on a current Intel TDX server where they forced a protected VM into debug mode and read private memory in plaintext. It requires physical access to the server, making it mainly a threat model concern for cloud providers offering confidential computing guarantees.
Why it matters
If you build or procure services that depend on confidential VMs (Intel TDX, AMD SEV-SNP) for compliance or multi-party computation guarantees, this attack means physical-access insiders or colocation attackers can defeat those guarantees with cheap hardware. For most SaaS founders and developers not using TEEs, no action is needed; for those relying on confidential computing attestation, treat physical access as a broken trust boundary until vendors patch the freshness-check gap.
Discussion angle
Does anyone in the community actually ship confidential VMs in production, or is TEE-based confidential computing still a niche compliance checkbox that this attack doesn't meaningfully change for Malaysian builders?