The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers have disclosed a new hardware attack, called DDRop, that silently drops writes to a server's memory so processors in Intel TDX and AMD SEV-SNP confidential computing environments read old encrypted data as if it were current.
- The attack needs an attacker who already controls the server's software and can briefly insert an interposer board, costing under $200 to build, between the processor and a memory module.
- DDPop is the first active interposer attack to work on DDR5 memory in cloud servers and the first to break the integrity of an up-to-date Intel TDX system, letting researchers read victim virtual machines' private memory and forge launch measurements.
- The flaw exists because confidential computing designs omit a memory freshness check to handle large memory sizes, so Intel TDX, Intel Scalable SGX, and AMD SEV-SNP are all affected, including services on AWS, Microsoft Azure, and Google Cloud.
- There is no simple patch because the weakness is in the hardware design, and fixing it would require new memory-encryption hardware that adds both integrity and freshness checks.
What to watch next
- Release of the interposer board designs, firmware, and attack code on GitHub alongside the research paper
- Presentation of DDRop at the ACM CCS 2026 conference in November
- Vendor and cloud provider responses, including software mitigations and possible future hardware changes adding freshness checks
Coverage1
1 report
English national1
All filed from India
Named Belgium · Switzerland · United Kingdom · United States · AMD · AWS · Google Cloud · Intel · Microsoft Azure · Durham University · ETH Zurich · Google · KU Leuven
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
