We sent one of us to scout the grounds of this year's @1ns0mn1h4ck.
From Android rollback attacks to AI-driven malware, here’s what stood out to us: https://t.co/vJ3DMiS2s4
We are excited to announce Mathias Payer as the Keynote Speaker for the first day of Talks at Insomni'hack 2025!
🎟️ Register now and secure your spot: https://t.co/xi526GC3Aq
#INSO25#Cybersecurity#EthicalHacking#Switzerland
🚨 The Insomni’hack 2025 Conferences Programme is LIVE!
📅 2 days, top experts, & cutting-edge cybersecurity talks.
Get your tickets now: https://t.co/TwPCSb646c
#INSO25#Cybersecurity#EthicalHacking#Switzerland
💡 ARM TrustZone-based TEEs secure devices like smartphones; drones, but they have critical vulnerabilities
Join @0ddc0de at #hw_ioUSA2025 to analyze system designs, spot security flaws & explore isolation and confidentiality techniques
👉 https://t.co/s5G5Sjpg7u
#TrustZoneTEE
🚨 At #hw_ioNL2024, Marcel Busch and @_chli_ introduced EL3XIR, a powerful framework designed to rehost and fuzz the secure monitor firmware layer of TrustZone-based TEEs.
YouTube Link: https://t.co/Q2gZ31gLub
#fuzzing#securemonitor#EL3XIR
📢 SPEAKERS ANNOUNCEMENT 📢
On Wednesday Nov. 6th, Marcel Busch @0ddc0de and Philippe Mao 🙋♂️, Postdoc and PhD at @EPFL HexHive lab, will propose a fascinating talk
🔥 GlobalConfusion: Trustzone Trusted Application 0-Days by Design 🔥
Abstract 👉 https://t.co/yN4d03PjP0
🥁🥁🥁...Uncovering Security Vulnerabilities at #hw_ioNL2024!
Marcel; @_chli_ reported 34 bugs in secure monitors, with 17 classified as security critical. Affected vendors confirmed 14, leading to 6 CVEs for EL3XIR
👉 https://t.co/j6gb3T9Zpq
#fuzzing #EL#XIR #monitorsecurity
🔒 ARM TrustZone is the backbone of mobile devices 📱, and EL3XIR provides an effective framework for rehosting and fuzzing the secure monitor firmware of proprietary TrustZone-based TEEs
Join Marcel & @_chli_ at #hw_ioNL2024
👉 https://t.co/j6gb3T9Zpq
#fuzzing#mobilesecurity
Coming up at @USENIXSecurity, we have three exciting papers on Android security across all layers of the stack. Learn about fuzzing trusted components, type confusion in trusted APIs and a study on how trusted apps are updated. @EPFL_en@ICepfl
https://t.co/vrKBAgBeG3
Downgrading trusted apps allows attackers to use N-days for attacking the trusted world. Sadly, @0ddc0de@USENIXSecurity discovered that rollback prevention is lacking on Android. Paper: https://t.co/o0RsI4kl0A
Do you want 0days in Android Trusted Applications using the Global Platform API? Use @0ddc0de's binary static analysis @USENIXSecurity to find type confusions resulting in arbitrary writes. Paper: https://t.co/lvH4aB8szX
As it turns out, the secure monitor, Android's most trusted component is full of bugs. @_chli_ and @0ddc0de discovered lots of serious issues @USENIXSecurity though fuzzing. Paper: https://t.co/LBiJF2FXno