Researchers have demonstrated a hardware interposer that sits on the DDR5 bus and extracts data from memory that is supposed to be encrypted, though the attack requires physical access to the machine. That caveat matters, but it does not neutralize the finding. The entire value proposition of confidential computing — Intel TDX/SGX, AMD SEV-SNP — rests on the claim that data-in-use stays protected even from a compromised host or a curious operator. A working physical read against DDR5 chips at the memory-controller layer chips away at that guarantee for anyone who cannot fully vouch for who touches the hardware.

Globally, the threat model shifts most for shared and distributed infrastructure. Hyperscalers with tightly controlled cages can argue physical access is implausible, but the fast-growing edge, telco, and colocation footprint is a different story. Regulated workloads pushed to the edge for latency, sovereign-cloud deployments in leased facilities, and confidential-VM offerings sold as a compliance shortcut all inherit new exposure. Expect this to feed procurement questions: attestation logs, tamper-evident chassis, supply-chain custody, and memory-encryption schemes with stronger integrity and anti-replay properties rather than raw confidentiality alone.

For Japanese enterprises and SIers, the practical impact lands in two places. First, finance and healthcare clients have been steered toward confidential computing as a way to run sensitive data on public or hybrid cloud while satisfying FISC-style guidance and personal-data rules. Integrators who positioned encrypted memory as a clean compliance answer now need a more honest layered story — physical security, operational controls, and attestation — rather than leaning on a single hardware feature.

Second, the on-premises and colocation base that still dominates Japanese enterprise IT is exactly where physical-access attacks are most credible. SIers running data centers for banks, government, and manufacturers should treat physical custody, rack-level tamper detection, and hardware refresh planning as part of the security posture, not facilities overhead. RPA and automation platforms that cache credentials or PII in memory on shared hosts deserve the same scrutiny.

The near-term reality is measured: this is a targeted, access-gated attack, not a remote worm. But it resets the marketing. Confidential computing remains useful; it is not a substitute for controlling who can physically reach the box. The winners will be vendors and integrators who fold that nuance into architecture reviews before clients discover it the hard way.