Executive Summary
Researchers from KU Leuven, ETH Zurich, Durham University, and Google disclosed the DDRop attack in September 2026, a hardware-based vulnerability that breaks memory protection in Intel TDX and AMD SEV-SNP confidential computing systems. The attack requires physical access to insert a $200 interposer device between the processor and memory module, which silently drops memory writes causing processors to read stale encrypted data. This allows attackers to gain full control of protected virtual machines, read victim memory, manipulate attestation measurements, and bypass confidential computing protections used by major cloud providers including AWS, Microsoft Azure, and Google Cloud.
This attack demonstrates the growing sophistication of hardware-level threats targeting cloud infrastructure's foundational security mechanisms, highlighting critical gaps in confidential computing architectures as organizations increasingly rely on these technologies for sensitive workloads.
Why This Matters Now
DDRop exposes fundamental weaknesses in confidential computing hardware that major cloud providers rely on to protect customer data, with no simple software patch available and requiring future hardware redesigns to fully address.
Attack Path Analysis
The DDRop attack begins with an adversary gaining brief physical access to insert a hardware interposer between processor and memory modules. The attacker then leverages existing software control to manipulate memory writes, escalating privileges by corrupting page tables and TDX firmware structures. Lateral movement occurs through mapping attacker memory onto victim VM addresses, while command and control is maintained through debug mode activation and memory manipulation. Exfiltration happens via direct memory access to protected VM data, with final impact achieved through attestation forgery and complete confidential computing bypass.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker gains brief physical access to cloud server to insert DDRop interposer hardware between processor and DDR5 memory module, requiring supply chain compromise, rogue data center employee, or legal hardware seizure
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
Exploitation for Defense Evasion
Exploitation for Credential Access
Modify Cloud Compute Infrastructure: Create Snapshot
Exploitation for Privilege Escalation
Data from Local System
Impair Defenses: Disable or Modify Tools
Weaken Encryption: Reduce Key Space
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Cryptographic Keys Protection
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Data Encryption
Control ID: 500.15
DORA – ICT Third-Party Risk Management
Control ID: Article 8
CISA ZTMM 2.0 – Hardware Root of Trust
Control ID: Platform Security
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001 – Security of Equipment and Assets Off-Premises
Control ID: A.11.2.6
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
DDRop hardware attacks directly compromise cloud infrastructure foundations, breaking Intel TDX and AMD SEV-SNP confidential computing protections critical for IT service delivery.
Banking/Mortgage
Financial institutions face severe confidential computing breaches exposing encrypted customer data, violating HIPAA and PCI compliance requirements through memory protection failures.
Health Care / Life Sciences
Healthcare cloud deployments using AWS, Azure, Google Cloud vulnerable to patient data exposure through compromised confidential computing memory encryption systems.
Government Administration
Government cloud workloads at risk from physical interposer attacks enabling unauthorized access to classified data through compromised Intel TDX memory protection.
Sources
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computinghttps://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.htmlVerified
- Intel Security Announcement - Physical Interposer Attackshttps://intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.htmlVerified
- AMD Security Bulletin AMD-SB-3048 - DDRop Attack Disclosurehttps://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.htmlVerified
- DDRop Attack Research Paper and Technical Detailshttps://ddropattack.eu/ddrop.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope and impact of DDRop hardware attacks by constraining cross-VM lateral movement and limiting attacker reachability through segmented network enforcement. While physical hardware compromise cannot be prevented, Zero Trust segmentation would likely contain the blast radius of memory-based VM-to-VM access attempts.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust architecture would likely provide enhanced visibility into anomalous VM behavior and communication patterns that could indicate hardware manipulation, though the physical compromise itself may still occur.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely constrain the scope of privilege escalation by limiting which resources and network segments the compromised workload could access, reducing the blast radius of corrupted memory operations.
Control: East-West Traffic Security
Mitigation: Network-level segmentation and east-west traffic inspection would likely limit cross-VM communication pathways, constraining the attacker's ability to establish persistent connections between compromised and target workloads through memory mapping.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and anomaly detection capabilities would likely identify unusual VM behavior patterns or unauthorized debug mode activation, potentially alerting security teams to ongoing command and control activities.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies and data loss prevention controls would likely limit the attacker's ability to exfiltrate extracted memory contents through standard network channels, constraining outbound data flows.
While attestation forgery may still succeed, the constrained network access and limited lateral movement capabilities would likely reduce the scope of workloads that malicious VMs could effectively impersonate or compromise.
Impact at a Glance
Affected Business Functions
- Cloud Computing Services
- Confidential Computing Platforms
- Customer Data Protection
- Trusted Execution Environments
Estimated downtime: N/A
Estimated loss: N/A
Research demonstrates potential for unauthorized access to encrypted memory contents in Intel TDX and AMD SEV-SNP environments, including virtual machine memory, debug mode activation, and attestation forgery. Attack requires physical access and hardware interposer costing under $200.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit blast radius even if confidential computing is compromised through hardware attacks
- • Deploy Multicloud Visibility & Control to detect anomalous memory access patterns and unusual VM behaviors across cloud environments
- • Enable Egress Security & Policy Enforcement to prevent data exfiltration even when memory protections are bypassed
- • Establish Threat Detection & Anomaly Response capabilities to identify unusual hardware behaviors and debug mode activations
- • Implement Encrypted Traffic controls as defense-in-depth since hardware memory encryption alone is insufficient against physical interposer attacks



