Skip to content
DDRop Attack Exposes Vulnerabilities in Intel and AMD Confidential Computing

DDRop Attack Exposes Vulnerabilities in Intel and AMD Confidential Computing

First seen 14 Sep 2026, 18:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 19:54 UTC
  • DDRop attack targets Intel TDX and AMD SEV systems, requiring physical access.
  • The attack exploits a design flaw in memory encryption that lacks freshness checks.
  • Researchers will release the interposer design and attack code as open-source.

Researchers have unveiled a hardware attack named DDRop that compromises memory protection in Intel TDX and AMD SEV systems. This attack allows an attacker with physical access to a server to insert a low-cost interposer, which drops write commands to memory, enabling the processor to read outdated encrypted data. The attack exploits a design flaw that omits a freshness guarantee in scalable memory encryption hardware. The interposer, costing under $200, can be built and deployed to manipulate memory operations in real-time. Affected systems include cloud services that rely on these technologies for confidential computing. The research team, comprising members from KU Leuven, ETH Zurich, Durham University, and Google, plans to present their findings at the ACM CCS 2026 conference in November and will release the interposer's design as open-source hardware. The attack poses a significant risk to data integrity in cloud environments, particularly for organizations relying on these trusted execution environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-14
DDRop attack disclosed
Researchers announced the DDRop attack, which compromises Intel TDX and AMD SEV memory protection.
The Register
2026-09-14
Research team details attack method
The team explained how the DDRop interposer drops writes to memory, allowing access to stale data.
The Hacker News
2026-11-01
ACM CCS 2026 conference presentation
The research team is scheduled to present their findings and the DDRop attack at the ACM CCS 2026 conference.
Date unknown

More articles in this cluster (6)

Following this threat?

Track Conti and AMD in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed