MonstreamSign in
Discover
RadarPrivacyby Gurgen Arakelov · Daily batch, 08:00 UTC

TEE Radar

Everything in trusted execution environments and confidential computing: Intel SGX and TDX, AMD SEV-SNP, Arm CCA, confidential GPUs, attestation, TEEs in blockchains and private AI, new attacks and side channels, releases, products and funding.

Explore streams
80Subscribers
1Results so far
Oct 2026Created
1h agoLast update

Latest

Oct 7 · 3 of 21 shown
DDRop hardware attack breaks Intel TDX and AMD SEV-SNP memory freshness for about $200
  • DDRop uses an interposer to drop memory writes, so TDX and SEV-SNP VMs process stale data; vendors reportedly call it out of scope.
  • An IETF draft cites CVEs rated up to CVSS 9.1 showing early attestation fails; most implementations are withdrawn or moved.
  • Attested private AI is shipping: NEAR AI on TDX and H200, dstack 0.6.0, Phala's proxy, OpenStack TDX support.
PRA-TLS protocol attests client applications that invoke TEE enclaves

An arXiv paper proposes Portable Remote Attestation TLS (PRA-TLS), where an Attester Daemon measures the host environment and application code at runtime for a remote Verifier. The authors checked its security with the Tamarin Prover and built an Intel SGX prototype; it addresses tampering at the boundary between an attested enclave and its untrusted application.

DDRop attack uses $200 board to break Intel TDX and AMD SEV-SNP

DDRop is a hardware attack that uses an interposer to drop memory write commands, so Intel TDX and AMD SEV-SNP VMs process stale but validly encrypted data. It needs brief physical access and about $200 in hardware, and exploits the lack of memory freshness guarantees; a blog post says vendors treat it as out of scope, and the post is a secondary write-up that names no original researchers or date.

Also in news.google.com, tech-insider.org
IETF draft details CVEs showing early attestation fails in practice

An IETF SEAT draft dated 2 October 2026 gives technical details of CVE-2026-92701 and CVE-2026-92702 (both CVSS 9.1) and CVE-2026-33697 (CVSS 7.5), plus several GitHub advisories, as evidence that early attestation fails even without physical access. The authors say all but two early-attestation implementations have been archived, withdrawn or moved to post-handshake attestation, which matters for remote attestation design in TEEs.

Also in GitHub · muhammad-usama-sardar
🔒18 more in this resultSubscribe to see everything this stream finds, in your feed and by email. It’s free; one run serves every subscriber.

More in Privacy

Streams that already watch this field. Follow one as it is — it costs nothing extra.

See all in Privacy →
RadarPrivacyDaily batch, 09:00 UTC

Everything around FHERMA, the FHE challenge platform by Fair Math: new challenges and prize pools, results and winners, solution write-ups, Polycircuit and OpenFHE-rs releases, partnerships and mentions.

80 subscribers
View
Can’t find what you need? Describe it in a sentence and Monstream builds the stream for you.Create your own →