[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH1hjixa5DqXGrW0p1dPkGDvR39TSLRHXr6M3l-7z8nE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"cb5b6415-dbfe-4272-98dc-a8281b2997a6","ddrop-hardware-attack-bypasses-confidential-computing-protections-in-intel-tdx-and-amd-sev-snp","cd9efaee-c462-4c85-b25e-8b6aa1ff5d98","DDRop Hardware Attack Bypasses Confidential Computing Protections in Intel TDX and AMD SEV-SNP","The DDRop attack exploits a physical hardware vulnerability by inserting a custom interposer circuit between the CPU and memory modules, silently dropping memory write operations so the processor reads stale, outdated encrypted data. This undermines the core integrity guarantees that confidential computing technologies like Intel TDX and AMD SEV-SNP are designed to provide, potentially allowing an attacker with physical or supply-chain access to hijack protected virtual machines. The attack is particularly dangerous in cloud and data center environments where tenants rely on hardware-enforced isolation to protect sensitive workloads from even privileged insiders. This highlights that cryptographic and software-layer protections are insufficient when physical hardware integrity cannot be guaranteed, making supply chain security and physical access controls critical.","**Immediate actions:**\n- Audit and restrict physical access to servers hosting confidential computing workloads to authorized personnel only.\n- Review supply chain provenance for all server hardware, memory modules, and peripheral components for signs of tampering or unauthorized modification.\n- Apply any available microcode, firmware, or platform updates from Intel and AMD that address memory integrity enforcement.\n\n**Detection measures:**\n- Deploy tamper-evident seals and hardware attestation checks on critical servers to detect physical interposer-style modifications.\n- Enable continuous platform integrity attestation using Trusted Platform Module (TPM) measurements and remote attestation protocols to identify unexpected state changes.\n- Monitor anomalous memory behavior and VM performance metrics that may indicate stale or inconsistent memory reads.\n\n**Long-term improvements:**\n- Establish a formal hardware supply chain risk management program aligned with NIST SP 800-161 to vet vendors and component integrity.\n- Engage with CPU and platform vendors to advocate for stronger out-of-band memory write-drop detection mechanisms in future hardware generations.\n- Implement defense-in-depth strategies so confidential workloads are not solely dependent on a single hardware isolation boundary.",[12,13,14,15,16,17,18,19,20,21,22],"NIST SP 800-161 (Supply Chain Risk Management)","NIST SP 800-193 (Platform Firmware Resiliency)","NIST CSF PR.DS-6 (Integrity Checking Mechanisms)","NIST CSF ID.SC-4 (Supply Chain Risk Assessment)","CIS Control 3: Data Protection","CIS Control 16: Application Software Security","CIS Control 18: Penetration Testing","ISO\u002FIEC 27001 A.11.2 (Physical Equipment Security)","ISO\u002FIEC 27001 A.15.1 (Supplier Relationships)","NIST SP 800-207 (Zero Trust Architecture — Physical Layer Assumptions)","TCG Trusted Platform Module (TPM) Remote Attestation Standards","published","2026-09-14T18:21:04.788224+00:00","2026-09-14T18:21:04.604+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fnew-ddrop-attack-breaks-intel-tdx-and.html","new-ddrop-attack-breaks-intel-tdx-and-amd-sev-snp-confidential-computing-d1e3ec","New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"2947d027-0aa6-4577-a065-c73bed047da6","2026-09-15","morning","ThreatNoir Morning Brief — September 15","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-15\u002Fthreatnoir-morning-brief-2026-09-15.mp3"]