Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New DRAM Attack Threatens CPU Security Measures

New DRAM Attack Threatens CPU Security Measures

Posted on August 14, 2026 By CWS

A novel attack strategy has emerged, targeting the very heart of modern computer security by manipulating a computer’s memory controller. This technique can circumvent robust hardware security measures within current processors, including System Management Mode, Platform Security Processor, and CPU microcode protections.

The research, made public on GitHub under the project name skitter-creek-bath-salts, was spearheaded by security expert Christopher Domas. It highlights a vulnerability within the DRAM controller’s address-translation logic, a crucial layer often overlooked by existing defenses.

Understanding the DRAM Controller’s Role

Every physical address a CPU generates is processed by the memory controller, which translates it into specific memory locations within the DIMM’s architecture. The security features such as SEV, SGX, TDX, TrustZone, and firmware memory carveouts depend on these addresses remaining constant once they are out of the CPU core. Domas’s findings disrupt this assumption with a single instruction.

By altering certain configuration bits in the memory controller, attackers can manipulate how physical addresses correlate with actual DRAM cells. This process, described as ‘spaghettifying’ memory, enables different addresses to point to the same previously restricted memory cell, compromising access-control mechanisms.

Implications of the DRAM Scrambling Attack

This vulnerability isn’t due to a single flaw that can be easily fixed. It stems from the linear operations within the memory controller’s address transformation over GF(2), which can be reconstructed using linear algebra and tools like the SMT solver Z3, even if manufacturers keep the remapping details confidential.

Domas demonstrated the attack on AMD Family 16h processors, extracting sensitive data like the fTPM’s RSA signing routine from supposedly isolated Platform Security Processor memory. The attack also revealed secure data from the System Management Mode and exposed the CPU’s microcode patches during idle states.

Future Outlook and Industry Response

This research, targeting an older AMD platform, has broader implications as similar architectural patterns are prevalent across various modern memory controllers, including those by AMD, Intel, ARM, and RISC-V. Domas plans to present these findings at Black Hat 2026, urging the industry to respond to this security threat that traditional CPU models cannot address.

The ongoing developments in this area will be closely watched by researchers and chipmakers alike, as they seek strategies to mitigate this significant vulnerability class and reinforce CPU security models against such sophisticated attacks.

Cyber Security News Tags:Black Hat 2026, Christopher Domas, CPU security, DRAM attack, GitHub research, hardware security, memory vulnerability

Post navigation

Previous Post: Top Microsegmentation Tools for 2026: A Comprehensive Guide
Next Post: AmnesiaStealer Malware Targets macOS Users

Related Posts

LinkedIn Social Engineering Targets Cryptocurrency Firms LinkedIn Social Engineering Targets Cryptocurrency Firms Cyber Security News
North Korean IT Workers Exploit AI in Job Scams North Korean IT Workers Exploit AI in Job Scams Cyber Security News
HackerOne Employee Data Breach Exposes Sensitive Information HackerOne Employee Data Breach Exposes Sensitive Information Cyber Security News
BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year Cyber Security News
Cybersecurity Newsletter Weekly – AWS Outage, WSUS Exploitation, Chrome Flaws, and RDP Attacks Cybersecurity Newsletter Weekly – AWS Outage, WSUS Exploitation, Chrome Flaws, and RDP Attacks Cyber Security News
Oyster Malware as PuTTY, KeyPass Attacking IT Admins by Poisoning SEO Results Oyster Malware as PuTTY, KeyPass Attacking IT Admins by Poisoning SEO Results Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bitget Security Breach Results in $387 Million Loss
  • Nvidia Launches AI Safety Platform with Hardware Watchdog
  • Major Cybersecurity Incidents: Crypto Heist and Citrix Flaws
  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bitget Security Breach Results in $387 Million Loss
  • Nvidia Launches AI Safety Platform with Hardware Watchdog
  • Major Cybersecurity Incidents: Crypto Heist and Citrix Flaws
  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark