Confidential computing's trust mechanism is broken. The fix may not exist
ID: e6ea1617-dd34-55be-ba3b-3be47b40c899
STIX ID: report--e6ea1617-dd34-55be-ba3b-3be47b40c899
Feed Name: The Register (Security)
New formal verification research demonstrates that current attested-TLS (intra-handshake attestation) designs can be abused in relay/diversion attacks that let clients unknowingly encrypt traffic to a malicious host; the flaw (CVE-2026-33697, score 7.5) affects multiple production implementations, was responsibly disclosed, and the authors recommend abandoning intra-handshake attestation in favor of post-handshake approaches that can cryptographically bind attestation to application traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
