DDRop active interposer attack analysis on DDR5 confidential-computing memory protection
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers disclosed DDRop, a hardware interposer attack that breaks Intel TDX and AMD SEV-SNP memory protection on DDR5 cloud servers, letting stale encrypted data be reused as current. The technique needs only a brief physical visit and a low-cost interposer, but it can undermine protected guest memory and attestation state. The disclosure shows that confidential-computing designs can lose integrity when they lack a freshness check on server memory.
Related Happenings
Intel TDX and AMD SEV-SNP freshness gap security flaw
Vulnerability
H score11
First: 14.09.2026 19:58
Last: 14.09.2026 19:58
Sources 1
How related:
To cover the large amount of memory that a cloud server uses, though, these designs omit a guarantee called freshness. The processor can confirm that memory is encrypted, but not that it holds the latest written value, and that old encrypted data still decrypts correctly.
About this happening:
A freshness flaw in Intel TDX and AMD SEV-SNP lets a DDR5 interposer attack make stale encrypted memory look current, undermining confidential-computing integrity....
Intel TDX and AMD SEV-SNP freshness gap security flaw
VulnerabilityHow related: To cover the large amount of memory that a cloud server uses, though, these designs omit a guarantee called freshness. The processor can confirm that memory is encrypted, but not that it holds the latest written value, and that old encrypted data still decrypts correctly.
About this happening: A freshness flaw in Intel TDX and AMD SEV-SNP lets a DDR5 interposer attack make stale encrypted memory look current, undermining confidential-computing integrity....
NVIDIA GPUThor mitigation advisory
Advisory/Mitigation
H score29
First: 26.08.2026 21:48
Last: 26.08.2026 21:48
Sources 1
About this happening:
University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA workstation GPUs with GDDR6 memory that can bypass ECC, trigger denial...
NVIDIA GPUThor mitigation advisory
Advisory/MitigationAbout this happening: University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA workstation GPUs with GDDR6 memory that can bypass ECC, trigger denial...
TRACE open standard for AI runtime evidence and hardware-attested AI governance records
Security Tool/Service
H score11
First: 26.08.2026 12:10
Last: 26.08.2026 12:10
Sources 1
About this happening:
TRACE introduces a new way to prove AI runtime evidence, giving organizations a verifiable security control for what agents actually did, which policies applied, and which...
TRACE open standard for AI runtime evidence and hardware-attested AI governance records
Security Tool/ServiceAbout this happening: TRACE introduces a new way to prove AI runtime evidence, giving organizations a verifiable security control for what agents actually did, which policies applied, and which...
INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux
Technical Analysis
H score24
First: 06.08.2026 19:17
Last: 06.08.2026 19:17
Sources 1
About this happening:
MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to s...
INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux
Technical AnalysisAbout this happening: MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to s...
AMD Zen 1 through Zen 4 Safe RET Interrupt security flaw
Vulnerability
H score37
First: 06.08.2026 19:17
Last: 06.08.2026 19:17
Sources 1
About this happening:
Safe RET Interrupt Vulnerability affects Zen 1 through Zen 4 processors, where a local attacker can time an interrupt injection to weaken Safe RET and expose kerne...
AMD Zen 1 through Zen 4 Safe RET Interrupt security flaw
VulnerabilityAbout this happening: Safe RET Interrupt Vulnerability affects Zen 1 through Zen 4 processors, where a local attacker can time an interrupt injection to weaken Safe RET and expose kerne...
Timeline
-
14.09.2026 19:58 2 articles · 2h ago
DDRop disclosure exposes a write-dropping interposer attack on Intel TDX and AMD SEV-SNP
Initial DisclosureResearchers disclosed DDRop, a hardware interposer attack that silently drops writes on DDR5 server memory so stale encrypted data is reused as current, undermining Intel TDX, Intel Scalable SGX, and AMD SEV-SNP on cloud servers. The disclosure also says Intel and AMD were notified through coordinated disclosure, with vendor security bulletins expected on the disclosure date.
Show sources
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing — thehackernews.com — 14.09.2026 19:58
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing — thehackernews.com — 14.09.2026 19:58