Researchers Created Hardware Device to Exploit Cloud Servers

The DDRop device targets physical memory on Intel and AMD platforms, exposing gaps in current confidential computing models.

Updated on Oct. 11, 2026 in Cybersecurity

Researchers Created Hardware Device to Exploit Cloud Servers

Live Poll

Do you trust that your cloud-based data is secure from physical hardware tampering?

Researchers have developed a hardware device called DDRop that exploits physical memory vulnerabilities in cloud computing environments. The device allows attackers to manipulate memory writes on Intel and AMD platforms, compromising the security of virtual machines.

Why it matters

This research reveals that encryption is insufficient for securing workloads if hardware-level memory operations can be intercepted. It highlights a critical blind spot in confidential computing, where data remains encrypted but can still be manipulated at the physical layer.

The DDRop device requires a single instance of physical access to a server to interfere with memory write operations. Testing confirmed the attack successfully bypassed existing protections on Intel TDX systems by forcing virtual machines to operate on stale, manipulated data.

The players

Durham University

A research institution that contributed to the development of the DDRop hardware.

Intel

A semiconductor manufacturer whose TDX confidential computing platform was tested against the vulnerability.

AMD

A semiconductor company alerted by researchers regarding the security implications for its cloud computing platforms.

The details

The DDRop device functions by physically tapping into a server to intercept or modify memory write operations. Because the data within memory remains encrypted, the underlying virtual machine system fails to detect the external manipulation. This method successfully targets the attestation mechanism—a security process that verifies a virtual machine has not been tampered with—by ensuring the host executes commands using outdated memory states.

Timeline

  1. October 11, 2026: The research findings on the DDRop device were published.

The Tech Race

This research complicates the industry-wide push toward confidential computing, which relies on hardware-level isolation to secure data in the cloud. It highlights a significant challenge for Intel and AMD as they attempt to guarantee security against physical-layer interference.

This vulnerability is limited to environments where an attacker can obtain physical access to server hardware, meaning most remote cloud users remain unaffected. Enterprise data center operators and cloud providers will need to evaluate physical access controls to address this specific attack vector.

The takeaway

The DDRop research confirms that hardware-layer security is as vital as software encryption in cloud environments. Watch for upcoming security advisories from Intel and AMD that detail how they intend to harden attestation mechanisms against physical memory manipulation.

Further reading

For more on evolving threats to data infrastructure, visit our Cybersecurity section.

Source note: This article includes information reported by IHLS.

Live Poll

Do you trust that your cloud-based data is secure from physical hardware tampering?