Researchers introduced SessionLatch, a session-attestation mechanism that binds confidential-VM remote-attestation evidence to individual TLS connections without modifying applications, TLS libraries, certificates, or accessing TLS session secrets. It observes a server-generated ephemeral public key at the operating-system layer, holds encrypted client records while evidence is exchanged alongside the TLS handshake, and releases traffic only after the server’s expected platform and software state is verified; an optional mutual mode also attests the client environment.
The prototype integrates with Linux and Windows and, on Linux, uses nftables, NFQUEUE, conntrack, libpcap, and SOCK_DIAG/Netlink to authorize a specific connection rather than a host or IP address. Tests using Hygon CSV attestation reported lower mean short-upload latency than TNG in interleaved Linux/Windows experiments, but SessionLatch remains a preprint research system: source code has not yet been published, certificate validation was disabled during performance testing, and independent compatibility, resilience, and deployment validation is still required.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Qi Gu and Sheng Ma submitted the paper "Session Attestation for Unmodified TLS Services in Confidential Virtual Machines," presenting SessionLatch for binding confidential-VM attestation to individual TLS sessions without changing applications, TLS implementations, or certificates.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.