Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New TEE.fail Exploit Steals Secrets from Intel & AMD DDR5 Trusted Environments

Researchers have unveiled a groundbreaking attack dubbed “TEE.fail” that fundamentally compromises the security guarantees of Trusted Execution Environments (TEEs) from Intel and AMD by exploiting DDR5 memory architecture.The attack demonstrates how even…

Researchers have unveiled a groundbreaking attack dubbed “TEE.fail” that fundamentally compromises the security guarantees of Trusted Execution Environments (TEEs) from Intel and AMD by exploiting DDR5 memory architecture.The attack demonstrates how even the most advanced hardware-backed security features can be defeated using surprisingly accessible electronic equipment, raising critical questions about the future of confidential computing.The TEE.fail attack centers on a memory interposition device that physically intercepts DDR5 memory traffic in server environments.Despite DDR5’s increased complexity and higher operational speeds, researchers proved that such interception devices can be constructed using only off-the-shelf electronic components, making the attack both economical and practical for determined adversaries.The attack leverages a critical weakness in how Intel TDX and AMD SEV-SNP implement encryption. While these TEE technologies do encrypt data in memory, they employ deterministic encryption schemes that produce identical ciphertext for identical plaintext blocks.This predictable pattern allows attackers to perform comparison attacks, identifying when the same data appears in different memory locations even without decrypting the actual content.The researchers demonstrated their findings using a DDR5 DRAM bus interposer that captures memory transactions in real-time.In their proof-of-concept, they showed how three write operations—writing zeros, then ones, then zeros again—produced identical encrypted values for the matching operations, creating a fingerprint that attackers can exploit to extract sensitive information.Datacenter Security ConcernsPerhaps most concerning is the attack’s portability. While initial demonstrations used bulky laboratory equipment, researchers developed a compact version housed in a standard 17-inch briefcase.This portable attack platform can operate covertly without being opened, complete with a coffee cup holder to maintain an innocuous appearance during infiltration attempts.The briefcase-mounted system includes all necessary components for signal capture and analysis, fitting airline carry-on requirements and raising serious questions about physical security protocols in datacenter environments.The researchers specifically addressed concerns about gaining datacenter access, noting that the compact nature of their device makes covert deployment significantly more feasible than traditional laboratory setups.The attack’s effectiveness extends beyond theoretical vulnerabilities to practical key extraction.Researchers successfully recovered ECDSA attestation keys from Intel’s Provisioning Certification Enclave (PCE), completely breaking SGX and TDX attestation mechanisms.The extraction process operates automatically from a single signing operation, demonstrating the attack’s efficiency against real-world implementations.Using extracted keys, the team generated forged TDX quotes that pass verification through Intel’s DCAP Quote Verification Library at the highest “UpToDate” trust level.These forged attestations contain invalid measurements that would be impossible in authentic TDX reports, proving complete compromise of the attestation chain.Cross-Platform Impact The attack’s implications extend beyond CPU-based TEEs to affect Nvidia’s GPU Confidential Computing implementations.Extracted attestation keys enable attackers to bypass GPU TEE protections entirely, allowing unauthorized execution of AI workloads without any security guarantees.The researchers estimate that compromised attestation keys could potentially generate millions of dollars in unauthorized profits through cryptocurrency mining services and cloud computing platforms that rely on TEE attestations for security validation.This financial incentive significantly amplifies the threat landscape for organizations deploying confidential computing solutions.The TEE.fail attack fundamentally challenges assumptions about hardware-based security in modern computing environments, demonstrating that even sophisticated TEE implementations remain vulnerable to determined attackers with physical access and relatively inexpensive equipment.Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories