Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems

DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems

Posted on September 15, 2026 By CWS

Confidential cloud computing systems are designed to shield user data from server operators. However, a new method known as DDRop reveals potential failures in this promise by exploiting vulnerabilities in the DDR5 memory path.

Understanding the DDRop Attack

This innovative attack is a hardware manipulation technique rather than malware, and it poses a significant threat to tasks safeguarded by Intel TDX and AMD SEV-SNP. It targets the physical components of memory communication, rather than software applications.

Previous research has already questioned the security boundaries within confidential virtual machines. Earlier findings on TDX isolation demonstrated how a malicious virtual-machine manager could monitor activities within a secure domain. DDRop extends these concerns to the hardware level, focusing on memory command transit between processors and server memory.

Technical Insights into DDRop

The researchers behind DDRop, who shared their findings with Cyber Security News, detailed how the attack operates using a custom DDR5 registered DIMM interposer. This device disrupts memory writes at standard operating speeds, utilizing hardware designs, controller firmware, host tools, and proof-of-concept codes.

For the attack to succeed, it requires privileged access to the target machine and brief physical interaction to set up the device. While this limits its impact on typical endpoint users, it raises severe concerns for cloud infrastructure and environments where physical access to servers is possible during maintenance or supply-chain processes.

Impact on Intel and AMD Security

The DDRop interposer, constructed at a modest cost of $159, intervenes between the CPU and DDR5 RDIMM, manipulating command signals without intercepting normal application data. It can induce parity errors, prompting the memory module to dismiss certain write commands without alerting the system.

This results in protected virtual machines potentially reading outdated data, as discarded writes are not replaced with the latest information. The attack affects Intel TDX, Intel Scalable SGX, and AMD SEV-SNP due to incomplete verification of encrypted memory cache lines.

Researchers highlight that while encryption prevents an attacker from reading memory values, it does not guarantee that the data is current. Comparable risks have been noted in DRAM scrambling analyses, emphasizing vulnerabilities in memory address stability assumptions.

Mitigation Strategies and Future Outlook

DDRop’s danger amplifies when malicious hosts exploit trusted memory-management interfaces, enabling interference with page relocation and causing destination pages to hold stale data. This vulnerability allows for deterministic plaintext copying within the same confidential virtual machine’s pages.

The researchers demonstrated that attackers could gain control over address translations, leading to potential ciphertext access, replay attacks, and corruption of critical control structures. They suggest that robust hardware designs implementing cryptographic integrity and freshness checks are essential long-term solutions.

In the interim, organizations should restrict physical server access, monitor firmware and memory configuration changes, cautiously use attestation, and disable unnecessary memory-management features. Additionally, strengthening AI data center practices, including firmware baselines and hardware inventory controls, can mitigate exposure to physical platform attacks.

Cyber Security News Tags:AMD SEV-SNP, cloud infrastructure, cloud security, Cybersecurity, data protection, DDRop attack, hardware attack, Intel TDX, malware prevention, memory encryption, memory path, physical attack, server security, Vulnerabilities

Post navigation

Previous Post: Massive Data Breach Impacts 240,000 at Japan’s Digital Agency

Related Posts

New TEE.fail Attack Breaks Trusted Environments to Exfiltrate Secrets from Intel and AMD DDR5 Environments New TEE.fail Attack Breaks Trusted Environments to Exfiltrate Secrets from Intel and AMD DDR5 Environments Cyber Security News
Anthropic Launches Claude Opus 4.7 with Enhanced Security Features Anthropic Launches Claude Opus 4.7 with Enhanced Security Features Cyber Security News
Sendmarc Appoints Dan Levinson as Customer Success Director in North America Sendmarc Appoints Dan Levinson as Customer Success Director in North America Cyber Security News
Fraudulent AI Token Sales Exploit Free Cloud Accounts Fraudulent AI Token Sales Exploit Free Cloud Accounts Cyber Security News
Analog Devices Reports Cyber Intrusion and Data Breach Analog Devices Reports Cyber Intrusion and Data Breach Cyber Security News
Microsoft Enhances NuGet Security with API Key Changes Microsoft Enhances NuGet Security with API Key Changes Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems
  • Massive Data Breach Impacts 240,000 at Japan’s Digital Agency
  • Human Hacker Swiftly Exploits Marimo RCE in Record Time
  • Hackers Target Gitea RCE Flaw to Hijack Servers
  • Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems
  • Massive Data Breach Impacts 240,000 at Japan’s Digital Agency
  • Human Hacker Swiftly Exploits Marimo RCE in Record Time
  • Hackers Target Gitea RCE Flaw to Hijack Servers
  • Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark