New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
thehackernews.compreview
Requires physical access:
The attack requires an attacker who already controls the server’s software and can briefly access the machine to insert a small circuit board, called an interposer, between the processor and a memory module.
So not like Spectre or Meltdown. I suspect we’ll only see more and more vulnerabilities like this exposed as LLMs are used by capable security researchers and computer criminals to reduce the amount of work required to explore concepts that wouldn’t have been worthwhile in the past.
Nerds missed old google five to ten years ago. It was crap way before the AI garbage, but agreed that they’re shoving bs on us.