Security researchers have demonstrated new hardware-based techniques to extract sensitive data from devices previously considered secure, including smartwatches and confidential computing servers. In one case, analysts revived the 'Blinkenlights' technique, adapting it to modern TFT screens to extract firmware from a budget smartwatch by exploiting a dial parser vulnerability. This allowed arbitrary memory content to be displayed on the device's screen, which was then captured using a high-speed Raspberry Pi Pico setup. The smartwatch, which contained fake health sensors and used a JieLi AC6958C6 system-on-chip, was found to have weak authentication and a flawed firmware parser, enabling the out-of-bounds read attack.
Separately, researchers from KU Leuven University presented a low-cost hardware attack called 'Battering RAM' at Black Hat Europe 2025, which targets secure CPU enclaves such as Intel SGX and AMD SEV. By using a $50 DDR4 interposer, the researchers manipulated memory address mapping at runtime, bypassing firmware mitigations and gaining unauthorized access to encrypted memory. This allowed them to extract platform provisioning keys, forge attestation reports, and implant persistent backdoors on protected virtual machines, raising concerns about the security of cloud infrastructures relying on these technologies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers at Quarkslab adapted the historic Blinkenlights technique to dump firmware from a low-cost smartwatch built on a JieLi AC6958C6 chip. They exploited a dial parser out-of-bounds read flaw to force arbitrary memory contents onto the display, then captured and reconstructed the firmware using inexpensive hardware and Python tooling.
Following disclosure of the Battering RAM findings, Intel and AMD stated that the attack falls outside their security scope because it depends on physical hardware manipulation. The response underscored that current software and firmware defenses do not detect this class of attack.
Security researchers from KU Leuven University showed that a custom $50 DDR4 interposer can manipulate memory address mapping at runtime and break confidential-computing protections in systems using Intel SGX and AMD SEV. The attack enabled plaintext memory read/write access, SGX provisioning key extraction, forged attestation reports, and persistent backdoors on AMD SEV virtual machines while bypassing existing firmware mitigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.