Return to Threats

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

thehackernews.com 2026-09-14 AI supply chain Critical

What Happened

Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit

Why It Matters

Fact: Researchers disclosed a new hardware attack named DDRop that can break memory protection in Intel TDX and AMD SEV-SNP confidential computing by silently dropping memory writes, causing processors to keep reading stale encrypted data while the attacker must already control the server software and briefly access the machine to add a small circuit. Fact: This undermines the integrity guarantees of confidential computing environments that many AI workloads rely on, even though the attacker prerequisites are non-trivial. RealGround analysis: Organizations using confidential computing for AI models and data should treat DDRop as a supply chain and infrastructure integrity risk, ensuring hardware security assumptions are revisited and threat models account for physical and privileged attackers. RealGround analysis: Security teams should incorporate hardware-level attack scenarios into AI readiness assessments and SBOM-style inventories, verifying where confidential computing is used for AI and planning compensating controls such as tamper-resistant hosting, tighter access controls, and continuous integrity monitoring.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html

Talk to AI CISO