Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New DRAM Attack Threatens CPU Security Measures

New DRAM Attack Threatens CPU Security Measures

Posted on August 14, 2026 By CWS

A novel attack strategy has emerged, targeting the very heart of modern computer security by manipulating a computer’s memory controller. This technique can circumvent robust hardware security measures within current processors, including System Management Mode, Platform Security Processor, and CPU microcode protections.

The research, made public on GitHub under the project name skitter-creek-bath-salts, was spearheaded by security expert Christopher Domas. It highlights a vulnerability within the DRAM controller’s address-translation logic, a crucial layer often overlooked by existing defenses.

Understanding the DRAM Controller’s Role

Every physical address a CPU generates is processed by the memory controller, which translates it into specific memory locations within the DIMM’s architecture. The security features such as SEV, SGX, TDX, TrustZone, and firmware memory carveouts depend on these addresses remaining constant once they are out of the CPU core. Domas’s findings disrupt this assumption with a single instruction.

By altering certain configuration bits in the memory controller, attackers can manipulate how physical addresses correlate with actual DRAM cells. This process, described as ‘spaghettifying’ memory, enables different addresses to point to the same previously restricted memory cell, compromising access-control mechanisms.

Implications of the DRAM Scrambling Attack

This vulnerability isn’t due to a single flaw that can be easily fixed. It stems from the linear operations within the memory controller’s address transformation over GF(2), which can be reconstructed using linear algebra and tools like the SMT solver Z3, even if manufacturers keep the remapping details confidential.

Domas demonstrated the attack on AMD Family 16h processors, extracting sensitive data like the fTPM’s RSA signing routine from supposedly isolated Platform Security Processor memory. The attack also revealed secure data from the System Management Mode and exposed the CPU’s microcode patches during idle states.

Future Outlook and Industry Response

This research, targeting an older AMD platform, has broader implications as similar architectural patterns are prevalent across various modern memory controllers, including those by AMD, Intel, ARM, and RISC-V. Domas plans to present these findings at Black Hat 2026, urging the industry to respond to this security threat that traditional CPU models cannot address.

The ongoing developments in this area will be closely watched by researchers and chipmakers alike, as they seek strategies to mitigate this significant vulnerability class and reinforce CPU security models against such sophisticated attacks.

Cyber Security News Tags:Black Hat 2026, Christopher Domas, CPU security, DRAM attack, GitHub research, hardware security, memory vulnerability

Post navigation

Previous Post: Top Microsegmentation Tools for 2026: A Comprehensive Guide
Next Post: AmnesiaStealer Malware Targets macOS Users

Related Posts

Threat Actors Could Misuse Code Assistant To Inject Backdoors and Generating Harmful Content Threat Actors Could Misuse Code Assistant To Inject Backdoors and Generating Harmful Content Cyber Security News
CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks Cyber Security News
PoC Released for Linux Privilege Escalation Vulnerability via udisksd and libblockdev PoC Released for Linux Privilege Escalation Vulnerability via udisksd and libblockdev Cyber Security News
Emerging Malware Threatens Network Devices with DDoS and Crypto-Mining Emerging Malware Threatens Network Devices with DDoS and Crypto-Mining Cyber Security News
Urgent Alert: Craft CMS Vulnerability Under Attack Urgent Alert: Craft CMS Vulnerability Under Attack Cyber Security News
Apple Warns iPhone Users of Spyware Threats in 110 Countries Apple Warns iPhone Users of Spyware Threats in 110 Countries Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Aeternum Botnet’s Blockchain Strategy Challenges Security
  • Hackers Target GeoServer’s Unpatched Vulnerability
  • AmnesiaStealer Malware Targets macOS Users
  • New DRAM Attack Threatens CPU Security Measures
  • Top Microsegmentation Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Aeternum Botnet’s Blockchain Strategy Challenges Security
  • Hackers Target GeoServer’s Unpatched Vulnerability
  • AmnesiaStealer Malware Targets macOS Users
  • New DRAM Attack Threatens CPU Security Measures
  • Top Microsegmentation Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark