Opens profile photo
Follow
Click to Follow matteyeux
matteyeux
@matteyeux
Display Secure (TZ2)Joined April 2011

matteyeux’s Tweets

Disk encryption is critical in securing your data when you lose your device or an attacker gets physical access. But we found that if you don't use a BitLocker passphrase on an AMD system (before Windows even comes up), your data is not adequately secured:
4
153
Show this thread
Two years ago the SolarWinds hack made history as the boldest, most sophisticated supply chain hack ever pulled off. I dug into the detailed story about the ingenious way the hackers pulled it off - and then got caught - in this tale for WIRED magazine
9
630
Show this thread
Put out a blog post on some reversing I've been doing on the side of the AMD Platform Security Processor / PSP. Part 1 is an overview of the design and memory-mapped I/O (MMIO), part 2 will be on the Crypto Co-Processor MMIO.
11
319
Worth stressing, as LockBit macOS sample though *compiled* for macOS really isn't (yet) designed for macOS. 1. Unsigned (won't easily run on macOS) 2. Doesn't appear to take into account TCC/SIP, so won't be able to encrypt much of anything So (in current form) macOS impact: ~0
Quote Tweet
“Cisco Talos researcher Azim Khodjibaev told BleepingComputer that based on their research, the encryptors were meant as a test and were never intended for deployment in live cyberattacks.” twitter.com/BleepinCompute…
2
122
Show this thread
Looks like my plugin is in the top 5 this month 👀
Quote Tweet
It looks like #Gepetto, developed by @JusticeRage is taking the lead for downloads in March! Publish your plugin in our Repository, and let’s see if it will make it to the top 🌐 plugins.hex-rays.com//?utm_source=S #IDAPlugin #PluginRoundup #IDAPro #IDAPython
Plugin Repository Monthly Roundup: March 2023
1
7
Our team published a post about the #3cx supply chain attack. We describe the Windows & the MacOS backdoors. The timeline: the GitHub repo on December 7 & the infrastructure in November... Few months later a malicious update was sent to the customers :
2
121
New blogpost by and I! Patch Tuesday -> Exploit Wednesday: Pwning Windows afd.sys in 24 Hours. We reverse engineer a bug + write an exploit using a cool new primitive. We also find out that it's been exploited in the wild (previously unknown).
10
664