"Screaming Channels" paper #CCS18/@BlackHatEvents is online https://t.co/q8Eep9Dl5c
Electromagnetic side channels from a CPU can leak to a radio transmitter. CPU and radio transmitters are often integrated (think WiFi, BlueTooth)
We recover an AES key from 10 meters on a BT chip
For 19 years, GPS satellites have secretly broadcast a “numbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now. https://t.co/xz3svmqiDa
We are starting to upload the videos of this year's talks.
And nothing better to start with than our two keynotes :
https://t.co/3jINfjcwNO and https://t.co/zSf5iRYoBF from @misc0110 and @aurelsec
Our paper "CFIghter: Automated Control-Flow Integrity Enablement and Evaluation for Legacy C/C++ Systems" will be presented at the 2026 ACM Secure Development Conference (SecDev '26) in July.
@OwenBrakes Let us (with @nSinusR@GioCamurati@poeplau ...) know if you have questions.
Follow up work, improved attack:
https://t.co/uPyHTEcaNW
on actual bluetooth protocol :
https://t.co/3HhXgbZBJg
@pwalshbuilds@OwenBrakes Because the key is used by the processor, a side channel (power consumption) couples to the radio transmitter. And then you can find the key (after a lot of packet collection and statistics) in the noise of the transmission.
@the_void_is_nil@OwenBrakes@kmcnam1 All those are related indeed. The difference with screaming channels is we show that these get amplified and transmitted further by a nearby (or integrated) radio transmitter. Rebroadcasting the side channel in a way.
The RF world is insane.
Researchers recovered AES-128 keys from a Bluetooth chip by listening to its own antenna from 10 meters away.
Crypto-engine switching noise couples into the RF chain, rides the 2.4 GHz carrier, and leaks out as radio.
THCON 2026 Poster Reveal
It’s here !
👀 Full program on the website : https://t.co/PQy8q1IJMk
🎟️ Tickets are live : https://t.co/rXzBIHdVTl
See you there !
🇫🇷Ils ont obtenu un nouveau vote : RN, PS, LR, RE, MoDem, ils impose un nouveau vote sur #ChatControl demain à 11h. https://t.co/QQ2rro19Eb
Un appel demain peut encore faire changer d’avis des eurodéputés. Dernière chance d’appeler leur bureau :
👉 https://t.co/qnKyyls0uG
“Backdoors in your smartphones? Why? How? Not?” by @aurelsec
This talk examines what backdoors really mean from a systems and protocols perspective, and discusses concrete technical proposals
📅 May 5th & 6th, 2026 🔗 Tickets: https://t.co/rXzBIHdVTl
Details 👇🏻
Hello security researchers! Like it or not, agentic AI is here. It’s time to explore its impact on novel, academic research in cybersecurity. To this end, we’re launching the Conference for Synthetic Security Research (https://t.co/uvE3Fp12L7). Researchers, start your agents!
Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k. The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage. Let's buy it back ! Please donate/spread/tag/RT 🙏
https://t.co/TLbddlhsFB
The European Commission is pushing hard to extend #ChatControl 1.0 - allowing mass scanning of private messages without court orders for another two years. Contact your MEPs TODAY via https://
https://t.co/q0TINAXE2P to defend your privacy and digital rights!
Okay so, we just found that over 50 papers published at @Neurips 2025 have AI hallucinations
I don't think people realize how bad the slop is right now
It's not just that researchers from @GoogleDeepMind, @Meta, @MIT, @Cambridge_Uni are using AI - they allowed LLMs to generate hallucinations in their papers and didn't notice at all.
It's insane that these made it through peer review👇
THC Release 💥: The world’s largest IP<>Domain database: https://t.co/o4F8M1Pqi1
All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free.
Updated monthly.
Try: curl https://t.co/5V2xLadmx5
Raw data (187GB): https://t.co/cBZOSAE89K
(The fine work of messede 👌)
The GrapheneOS team has said that “France isn’t a safe country for open source privacy projects,” pointing to what it describes as the expectations of encryption backdoors.
Last week, it announced it has removed all servers from France.
https://t.co/eLRly3aJes
1/5
France is one of the strongest supporters of Chat Control and law enforcement is acting as if that's already law. We're protecting our users in France and elsewhere against GrapheneOS being treated similarly to SkyECC or Encrochat. We have many users in France and will continue to provide GrapheneOS and our services to people there from servers in Germany, Switzerland, Luxembourg, etc. not at a French hosting provider.
Read what law enforcement has said about it. Here are 2 articles heavily quoting law enforcement:
https://t.co/5TvYFemejg contains many inaccurate claims about GrapheneOS features, marketing, distribution and usage directly quoted from law enforcement. Le Parisien cannot be blamed for what French law enforcement says, only the fact that they presented it as factual information and did not give us the opportunity to review the specific claims and respond to them.
https://t.co/g95DYdYpKe also contains comparisons to SkyECC and Encrochat by law enforcement with a clear threat of similar action if we don't cooperate with providing device access.
https://t.co/j1ubZtBzrd is French state media with more inaccurate claims about it from law enforcement presented as fact.
There's much more than this and we haven't read all of the other coverage ourselves.
None of this is the fault of OVH but we cannot trust France-based providers anymore. OVH was forced to cooperate in actions against SkyECC and Encrochat, both brought up in comparisons by French law enforcement.
Call it fearmongering if you want but that is actually what French police and the national government are doing about encryption and secure devices. It has negative consequences for French businesses like OVH who are subject to their demands.