Skip to content
New hardware device can RAM into encrypted memory, expose your data

New hardware device can RAM into encrypted memory, expose your data

Theregister September 14, 2026

AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets 9 days ago

AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets

VMware uses Nvidia-favored 'AI factory' brand to build something with rival AMD 13 days ago

VMware uses Nvidia-favored 'AI factory' brand to build something with rival AMD

Intel's 256-core Xeon 7 CPUs are a Diamond in the rough 19 days ago

Intel's 256-core Xeon 7 CPUs are a Diamond in the rough

OpenAI's upcoming Jalapeño chip looks like it'll be an inference beast 20 days ago

OpenAI's upcoming Jalapeño chip looks like it'll be an inference beast

AMD grabs more CPU while pricier PCs punish desktop demand 24 days ago

AMD grabs more CPU while pricier PCs punish desktop demand

Computer security researchers have identified a design flaw in modern encryption hardware that allows access to protected memory in notionally confidential computing environments. But the attacker would need physical access to the victim system.

Boffins affiliated with KU Leuven, ETH Zurich, Durham University, and Google have found that scalable memory encryption hardware fails to check whether the data in memory is fresh.

As a result, they've been able to devise a small hardware interposer, dubbed DDRop , that when wired to an appropriate circuit board, interferes with DDR5 write operations. Unable to tell that memory isn't fresh, a protected VM becomes vulnerable to a replay attack that uses stale, attacker-selected data.

They describe their work in a paper titled, "DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes." Their attack requires physical access and so it is relevant mainly in scenarios where confidential computing guarantees have been made to tenants by cloud service providers.

"DDRop uses a custom-built 'interposer': a small, custom-designed circuit board, costing under $200, that sits between the processor and a memory module," explained Jo Van Bulck, a professor in the DistriNet lab at KU Leuven, Belgium, in an email to The Register . "It corrupts commands on the high-speed DDR5 memory bus to silently drop writes to encrypted memory. The protected VM keeps computing on old data that still decrypts perfectly. We are releasing the complete interposer design as open-source hardware."

The attack breaks the integrity of Intel TDX, Scalable SGX, and AMD SEV-SNP, used in trusted execution environments (TEEs).

Van Bulck and colleagues Jesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi, David Oswald, Martin Thompson, Kaveh Razavi, and Ingrid Verbauwhede developed a proof-of-concept attack on a current Intel TDX server.

"By injecting maliciously crafted secure page-table entries, we can force any protected VM into debug mode and read out its private memory in plaintext," said Van Bulck. "Furthermore, writing to critical TDX metadata structures enables forged attestation reports, so that a backdoored VM appears trusted to the remote user."

Both attacks, said Van Bulck, succeed deterministically in under two minutes without crashing the machine.

Several of these researchers developed a similar attack on DDR4 . But Van Bulck said this is the first active interposer attack on DDR5.

"DDR5’s redesigned command bus prevents the address-aliasing tricks used by Battering RAM, and until now, only considerably weaker passive attacks had been demonstrated on DDR5: TEE.fail monitors the data bus using bulky, second-hand logic analyzers that are easier to detect and require slowing the memory bus to its lowest speed to observe ciphertext patterns, which can be masked in software," he explained.

DDRop differs in that it alters DDR5 bus traffic at full speed. According to Van Bulck, it's the first attack to subvert TDX's trusted management interface without exploiting a software bug. It also reduces the cost of prior interposition attacks that took an estimated $170,000 in lab equipment to perform.

There's no easy fix for Intel's and AMD's current scalable memory-encryption designs, said Van Bulck, and no simple software or hardware patch that can address the root cause.

"Scalable memory encryption deliberately trades cryptographic freshness (e.g., available in early Intel SGX offerings supporting only 128/256 MB of protected memory) for the ability to protect large amounts of memory in cloud systems," he said.

Noting that Intel's Simon Johnson recently discussed memory-interposer attacks at an industry conference, Van Bulck said that planned mitigations like "cache line versioning" still appear to be vulnerable to DDRop.

In a security bulletin released on Monday, Intel acknowledged the DDRop disclosure and said the attack is out of scope for its cloud computing threat model. The company said it is "evaluating additional architectural hardening options and detection mechanisms as part of ongoing platform security improvements…"

AMD also said the attack is out of scope and no mitigation is planned. ®

New hardware device can RAM into encrypted memory, expose your data

Attackers would need physical access to the server to pull off the DDR5 trick

OpenAI's malicious bot swarm attacked RubyGems

Ruby are you ok? Ruby are you ok? Are you ok Ruby?

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

Datacenter developers want your backyard. FAS says negotiate harder

Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

Europe's right-to-repair rules are broken, not beaten

Patchy compliance is an argument for stronger enforcement, not abandoning the project

Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent

There are plenty of laws on the books to hold companies, and potentially their execs, accountable

PERSONAL TECH Smartphone makers don't bother to comply with EU repairability requirements

Smartphone makers don't bother to comply with EU repairability requirements

NETWORKS Virgin Media offloads email services to third-party provider

Virgin Media offloads email services to third-party provider

offbeat Retired man turns spare room into Soviet-era supercomputer

Retired man turns spare room into Soviet-era supercomputer

CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

software Another Microsoft team admits it’s struggling to handle flood of AI-generated code

Another Microsoft team admits it’s struggling to handle flood of AI-generated code

virtualization VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

on-prem Datacenter developers want your backyard. FAS says negotiate harder Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

Datacenter developers want your backyard. FAS says negotiate harder

Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

LEGAL Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late

Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

SECURITY Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent War is peace. Freedom is slavery. Privacy is surveillance

Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent

War is peace. Freedom is slavery. Privacy is surveillance

SYSTEMS d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers

d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs

AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers

ai and ml Anthropic reveals fourth likely crime committed by its AI Claude's Felony Bench rap sheet is now as long as OpenAI's

Anthropic reveals fourth likely crime committed by its AI

Claude's Felony Bench rap sheet is now as long as OpenAI's

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

A real alternative to running some kind of FOSS Unix clone

Extracted Entities

Attack Types (1)

Companies (2)

Countries (1)

Ransomware Groups (1)

Tools (1)

Vulnerabilities (1)