Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors

## Cybersecurity: Battering RAM Attack Overview

Cybersecurity: Battering RAM Attack Overview

Recent developments in confidential computing have aimed to secure sensitive workloads within public cloud environments. However, a newly identified hardware attack, known as Battering RAM , has revealed vulnerabilities in current memory-encryption methods used in Intel and AMD processors. This attack is facilitated by a low-cost interposer, priced under $50, which can bypass these encryption mechanisms.

Modern servers utilizing DDR4 DRAM employ hardware-backed encryption technologies, such as Intel's Total Memory Encryption (TME) and AMD's SEV-SNP, to protect private data. Despite improvements in boot-time alias checks, Battering RAM achieves full memory access by dynamically manipulating encrypted traffic.

The Battering RAM attack involves an interposer placed between the CPU and DIMM. This interposer remains undetected during the Power-On Self-Test (POST) phase, circumventing existing security checks. Once the system is operational, the interposer redirects encrypted data to an attacker-controlled buffer, allowing arbitrary access to plaintext data. This method fully compromises SGX and SEV-SNP attestations, enabling unauthorized read and write access to enclave memory.

Design details of the interposer, shared on GitHub, include the use of two SPDT analog switches and a microcontroller for runtime aliasing. The attack is executed in a two-phase process, capturing and replaying ciphertext to decrypt enclave data.

The Battering RAM attack highlights significant vulnerabilities in static memory-encryption engines that lack cryptographic freshness checks. Key implications include:

Recent developments in confidential computing have aimed to secure sensitive workloads within public cloud environments.
Noah Redmond · Thehackingpost

Physical-layer adversaries require minimal access to deploy the interposer, posing a risk from rogue cloud personnel or supply-chain attackers. Software or firmware solutions cannot detect the real-time address remapping enabled by the attack. Effective mitigation demands enhancements to DRAM encryption, such as per-page nonce or integrity checks. The affordability of Battering RAM, at less than $50, democratizes a class of attacks previously limited to costly DRAM interposers.

Research conducted by academic teams at KU Leuven, University of Birmingham, and Durham University has been documented, with schematics and proof-of-concept code available under CC0 licensing.

Security advisories have been issued by both Intel and AMD, acknowledging the findings. However, they note that physical interposer attacks are outside the current scope of product defenses.

Advertisement

As public cloud services increasingly adopt Intel SGX and AMD SEV-SNP, organizations using platforms such as AWS, Azure, Google Cloud, and IBM Cloud must reassess the physical security of their datacenter infrastructure to counteract such attacks.

In conclusion, the Battering RAM attack underscores the need for substantial enhancements in memory encryption protocols to ensure robust data security within confidential computing environments.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories