Alon Leviev
@_0xdeku
Security Researcher at @safebreach | Hacker, Speaker, BJJ Black Belt, Former BJJ World and Euro Champion
ID: 1539634973866659844
https://il.linkedin.com/in/alonleviev 22-06-2022 15:42:52
58 Tweet
928 Followers
114 Following
🚨New! "PKFail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem." #PKfail is a supply-chain issue affecting x86/ARM devices around the globe. Blog: binarly.io/blog/pkfail-un… Full report: …222483.fs1.hubspotusercontent-na1.net/hubfs/22222483… A free scanning tool: pk.fail
Proud to have been nominated for the most epic achievement Pwnie Awards, congrats to the winner Andres Freund (Tech) for finding the XZ backdoor, truly an epic achievement! If you want to hear more about my research, join my talk tomorrow at DEF CON 10 am LVCC-L1-HW1-11-03 (Track 3)
For those of you interested in getting started with UEFI vuln research and exploitation, check out the Damn Vulnerable UEFI project on GitHub github.com/hacking-suppor… By Stan Lyakhov and myself. Contributions are welcome!
We've updated our blog on abusing file deletes to escalate privileges. We've also released PoC to demonstrate this. The exploit offers a high degree of reliability and eliminates all race conditions. It has been tested on the latest Windows 11 Enterprise. zerodayinitiative.com/blog/2022/3/16…