Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems

DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems

Posted on September 15, 2026 By CWS

Confidential cloud computing systems are designed to shield user data from server operators. However, a new method known as DDRop reveals potential failures in this promise by exploiting vulnerabilities in the DDR5 memory path.

Understanding the DDRop Attack

This innovative attack is a hardware manipulation technique rather than malware, and it poses a significant threat to tasks safeguarded by Intel TDX and AMD SEV-SNP. It targets the physical components of memory communication, rather than software applications.

Previous research has already questioned the security boundaries within confidential virtual machines. Earlier findings on TDX isolation demonstrated how a malicious virtual-machine manager could monitor activities within a secure domain. DDRop extends these concerns to the hardware level, focusing on memory command transit between processors and server memory.

Technical Insights into DDRop

The researchers behind DDRop, who shared their findings with Cyber Security News, detailed how the attack operates using a custom DDR5 registered DIMM interposer. This device disrupts memory writes at standard operating speeds, utilizing hardware designs, controller firmware, host tools, and proof-of-concept codes.

For the attack to succeed, it requires privileged access to the target machine and brief physical interaction to set up the device. While this limits its impact on typical endpoint users, it raises severe concerns for cloud infrastructure and environments where physical access to servers is possible during maintenance or supply-chain processes.

Impact on Intel and AMD Security

The DDRop interposer, constructed at a modest cost of $159, intervenes between the CPU and DDR5 RDIMM, manipulating command signals without intercepting normal application data. It can induce parity errors, prompting the memory module to dismiss certain write commands without alerting the system.

This results in protected virtual machines potentially reading outdated data, as discarded writes are not replaced with the latest information. The attack affects Intel TDX, Intel Scalable SGX, and AMD SEV-SNP due to incomplete verification of encrypted memory cache lines.

Researchers highlight that while encryption prevents an attacker from reading memory values, it does not guarantee that the data is current. Comparable risks have been noted in DRAM scrambling analyses, emphasizing vulnerabilities in memory address stability assumptions.

Mitigation Strategies and Future Outlook

DDRop’s danger amplifies when malicious hosts exploit trusted memory-management interfaces, enabling interference with page relocation and causing destination pages to hold stale data. This vulnerability allows for deterministic plaintext copying within the same confidential virtual machine’s pages.

The researchers demonstrated that attackers could gain control over address translations, leading to potential ciphertext access, replay attacks, and corruption of critical control structures. They suggest that robust hardware designs implementing cryptographic integrity and freshness checks are essential long-term solutions.

In the interim, organizations should restrict physical server access, monitor firmware and memory configuration changes, cautiously use attestation, and disable unnecessary memory-management features. Additionally, strengthening AI data center practices, including firmware baselines and hardware inventory controls, can mitigate exposure to physical platform attacks.

Cyber Security News Tags:AMD SEV-SNP, cloud infrastructure, cloud security, Cybersecurity, data protection, DDRop attack, hardware attack, Intel TDX, malware prevention, memory encryption, memory path, physical attack, server security, Vulnerabilities

Post navigation

Previous Post: Massive Data Breach Impacts 240,000 at Japan’s Digital Agency
Next Post: Optimize Security by Testing Attack Chains Holistically

Related Posts

U.S. Treasury Warns of Crypto ATMs Fueling Criminal Activity U.S. Treasury Warns of Crypto ATMs Fueling Criminal Activity Cyber Security News
Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data Cyber Security News
Resilient Tycoon2FA Phishing Platform Bounces Back Rapidly Resilient Tycoon2FA Phishing Platform Bounces Back Rapidly Cyber Security News
Microsoft October 2025 Security Update Causes Active Directory Sync Issues on Windows Server 2025 Microsoft October 2025 Security Update Causes Active Directory Sync Issues on Windows Server 2025 Cyber Security News
Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum Cyber Security News
Akira Ransomware Targets Over 250 Organizations, Extracts  Million in Ransom Payments – New CISA Report Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Alters Link Previews in Search Results
  • Thai ISP Breach Exploited Fortinet Flaws
  • Optimize Security by Testing Attack Chains Holistically
  • DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems
  • Massive Data Breach Impacts 240,000 at Japan’s Digital Agency

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Alters Link Previews in Search Results
  • Thai ISP Breach Exploited Fortinet Flaws
  • Optimize Security by Testing Attack Chains Holistically
  • DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems
  • Massive Data Breach Impacts 240,000 at Japan’s Digital Agency

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark