{
  "id": 7401506,
  "title": "New hardware device can RAM into encrypted memory, expose your data",
  "url": "https://urgent.news/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data-7401506",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-14T18:31:33.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377"
  },
  "original_language": "en",
  "account": "A new hardware device has been discovered that can bypass encrypted memory, exposing sensitive data. The flaw lies in modern encryption hardware, which fails to verify if the data in memory is fresh. Researchers affiliated with KU Leuven, ETH Zurich, Durham University, and Google have developed a small hardware interposer called DDRop that interferes with DDR5 write operations. When wired to a circuit board, DDRop can cause a protected VM to become vulnerable to replay attacks using stale data.\n\nThe attack requires physical access to the victim system and can exploit scalable memory encryption hardware, including Intel TDX, Scalable SGX, and AMD SEV-SNP. By injecting maliciously crafted secure page-table entries, the researchers were able to force protected VMs into debug mode and read out their private memory in plaintext. The attack can also enable forged attestation reports, making a backdoored VM appear trusted to remote users.\n\nDDR5's redesigned command bus prevents the address-aliasing tricks used in previous attacks, but DDRop can still alter DDR5 bus traffic at full speed. This is the first active interposer attack on DDR5, and it differs from previous DDR4 attacks. Unlike previous passive attacks, DDRop can subvert TDX's trusted management interface without exploiting a software bug.\n\nThe researchers released the complete interposer design as open-source hardware, and the cost of the device is under $200. There is no easy fix for the current scalable memory-encryption designs, and Intel and AMD have neither acknowledged the vulnerability nor planned any mitigation.",
  "summary": "Attackers would need physical access to the server to pull off the DDR5 trick",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "New hardware device can RAM into encrypted memory, expose your data",
        "url": "https://urgent.news/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data",
        "published": "2026-09-14T18:31:33.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}