New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

A devastating new attack has been discovered that exploits vulnerabilities in Intel’s TDX (Trusted Domain Extensions) and AMD’s SEV-SNP (Secure Encrypted Virtualization-System-wide Network Processor) confidential computing features. Dubbed DDRop, this sophisticated assault bypasses critical security measures designed to safeguard sensitive data, leaving organizations vulnerable to unprecedented breaches.

The DDRop attack targets the memory encryption mechanisms used by TDX and SEV-SNP, which are intended to protect virtual machine (VM) memory from unauthorized access. Confidential computing is a rapidly evolving field that promises to revolutionize data protection, but it appears that Intel and AMD’s solutions have been compromised. By exploiting these vulnerabilities, attackers can gain unfettered access to encrypted VMs, allowing them to steal or manipulate sensitive information.

The attack works by manipulating the way memory encryption keys are generated and managed within the virtualization layer. This enables attackers to intercept and alter the keys used for encrypting data, effectively rendering the security measures useless. According to security researchers who discovered the vulnerability, DDRop can be executed remotely, making it a particularly concerning threat.

Intel’s TDX and AMD’s SEV-SNP solutions have been widely adopted by cloud service providers (CSPs) and enterprise organizations seeking to enhance their data protection capabilities. The DDRop attack poses significant risks for these users, as it could potentially expose sensitive information stored in encrypted VMs. Furthermore, the vulnerability highlights the importance of ensuring that security measures are not only robust but also properly implemented.

The discovery of DDRop has far-reaching implications for the confidential computing ecosystem. As more organizations transition to cloud-based infrastructure, the need for secure data protection has never been more pressing. The fact that Intel and AMD’s solutions have been compromised raises questions about the long-term viability of their offerings. In the short term, users of TDX and SEV-SNP should be on high alert for signs of a potential breach, including unusual system activity or unexpected access attempts.

As a practical takeaway from this story, organizations should consider implementing additional security controls to mitigate the risks associated with DDRop. This may involve using more robust encryption methods, segmenting sensitive data, or implementing regular vulnerability assessments and penetration testing. By staying vigilant and proactive in their approach to cybersecurity, users can minimize their exposure to attacks like DDRop and ensure that their confidential computing initiatives remain secure.


Source: The Hacker News — 2026-09-14