Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors

New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors

Posted on October 1, 2025October 1, 2025 By CWS

Confidential computing promised to guard delicate workloads within the public cloud. But a brand new low-cost {hardware} assault, Battering RAM, demonstrates that even up-to-date memory-encryption schemes on Intel and AMD processors might be defeated with a easy interposer costing underneath 50 {dollars}.

Fashionable servers use DDR4 DRAM with hardware-backed encryption, akin to Intel SGX’s Complete Reminiscence Encryption (TME) and AMD SEV-SNP, to protect non-public information. 

Earlier analysis on “BadRAM” exploited false SPD metadata at boot time; in response, distributors carried out stricter boot-time alias checks. 

Constructing Battering RAM on $50 Price range

Battering RAM Assault

Battering RAM operates dynamically, the place a customized interposer sits between the CPU and DIMM, clear throughout POST, and evades SPD spoofing checks.

As soon as the system is on-line, an analog change flips, redirecting encrypted site visitors from sufferer addresses to an attacker-controlled alias buffer.

Captured ciphertext is then replayed right into a managed enclave, yielding arbitrary plaintext entry. This assault totally compromises each SGX and SEV-SNP attestation on patched cloud platforms, enabling learn/write of enclave reminiscence. 

The interposer design, shared on GitHub, makes use of two SPDT analog switches and a microcontroller to toggle aliasing at runtime.

This code fragment illustrates the two-phase capture-and-replay course of that yields decrypted enclave information.

Battering RAM Assault

Implications for Cloud Safety

Battering RAM exposes elementary flaws in static memory-encryption engines, which lack cryptographic freshness checks. 

As a result of TME and SEV-SNP derive ciphertext solely from a set key and bodily tackle, replayed information decrypts predictably, nullifying passive-attack defenses like cold-boot mitigation.

Key implications embrace:

Bodily-layer adversaries rogue cloud employees or supply-chain attackers require solely transient entry to put in the interposer.

Software program or firmware patches can not detect on-the-fly tackle remapping. True mitigation calls for per-page nonce or integrity checks built-in into the DRAM encryption engine.

At underneath $50, Battering RAM democratizes a category of assaults previously restricted to high-end DRAM interposers (> $100,000).

Tutorial groups at KU Leuven, College of Birmingham, and Durham College carried out the analysis and have printed schematics, firmware, and proof-of-concept code underneath CC0. 

Each Intel and AMD have issued safety advisories acknowledging the findings, however notice that bodily interposer assaults are past the present product scope.

As public cloud adoption of SGX and SEV-SNP grows, overlaying providers on AWS, Azure, Google Cloud, and IBM Cloud, organizations should reassess the bodily safety of datacenter infrastructure. 

With out vital enhancements to reminiscence encryption protocols, Battling RAM underscores that confidential computing isn’t indestructible.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:AMD, Attack, Battering, Bypasses, Cloud, Defenses, Intel, Latest, Processors, RAM

Post navigation

Previous Post: New Chinese Nexus APT Hackers Attacking Organizations to Deliver NET-STAR Malware Suite
Next Post: Red Hat Openshift AI Service Vulnerability Allow Attackers to Take Control of the Infrastructure

Related Posts

Hackers Delivering Cobalt Strike Beacon Leveraging GitHub and Social Media Hackers Delivering Cobalt Strike Beacon Leveraging GitHub and Social Media Cyber Security News
New Tool Exploits Windows Service Recovery for Cyber Attacks New Tool Exploits Windows Service Recovery for Cyber Attacks Cyber Security News
AI Pentest Tool Enhances Security Testing with New Features AI Pentest Tool Enhances Security Testing with New Features Cyber Security News
Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Cyber Security News
Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack Cyber Security News
New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark