Alon Leviev (@_0xdeku) 's Twitter Profile
Alon Leviev

@_0xdeku

Security Researcher at @safebreach | Hacker, Speaker, BJJ Black Belt, Former BJJ World and Euro Champion

ID: 1539634973866659844

linkhttps://il.linkedin.com/in/alonleviev calendar_today22-06-2022 15:42:52

58 Tweet

928 Followers

114 Following

Alon Leviev (@_0xdeku) 's Twitter Profile Photo

Thrilled to share that my research has been accepted to BOTH Black Hat USA and DEF CON 32! I’ll present my research “Windows Downdate: Downgrade Attacks Using Windows Updates” Abstract is still under embargo, but I promise its worth the wait. Stay tuned! #BHUSA #DEFCON32

Alon Leviev (@_0xdeku) 's Twitter Profile Photo

Just hit the 5-hour work mark and explorer.exe hasn’t crashed even once. Wondering if I should report this bug to MSRC

Alon Leviev (@_0xdeku) 's Twitter Profile Photo

Super excited that my research on Windows downgrade attacks has been nominated for the most epic achievement pwnie award!

BINARLY🔬 (@binarly_io) 's Twitter Profile Photo

🚨New! "PKFail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem." #PKfail is a supply-chain issue affecting x86/ARM devices around the globe. Blog: binarly.io/blog/pkfail-un… Full report: …222483.fs1.hubspotusercontent-na1.net/hubfs/22222483… A free scanning tool: pk.fail

chompie (@chompie1337) 's Twitter Profile Photo

I’m thrilled to share my latest blog post! This one focuses on the bug hunting process: inspiration, approach, and execution. I also provide a retrospective on how the bug was introduced and analyze the insufficient “patch”. Check it out: securityintelligence.com/x-force/little…

Alon Leviev (@_0xdeku) 's Twitter Profile Photo

Reminder: tomorrow at Black Hat 10:20 AM in Oceanside A - I will be sharing my journey of researching downgrade attacks on Windows and their severe implications on Windows’s platform security. Join my talk “Windows Downdate: Downgrade Attacks Using Windows Updates” #BHUSA

Alon Leviev (@_0xdeku) 's Twitter Profile Photo

Proud to have been nominated for the most epic achievement Pwnie Awards, congrats to the winner Andres Freund (Tech) for finding the XZ backdoor, truly an epic achievement! If you want to hear more about my research, join my talk tomorrow at DEF CON 10 am LVCC-L1-HW1-11-03 (Track 3)

Proud to have been nominated for the most epic achievement <a href="/PwnieAwards/">Pwnie Awards</a>, congrats to the winner <a href="/AndresFreundTec/">Andres Freund (Tech)</a> for finding the XZ backdoor, truly an epic achievement!

If you want to hear more about my research, join my talk tomorrow at <a href="/defcon/">DEF CON</a> 10 am LVCC-L1-HW1-11-03 (Track 3)
Or Yair (@oryair1999) 's Twitter Profile Photo

Just had our DEF CON talk and we are thrilled to publish QuickShell - tools for researching Google's Quick Share including a sniffer, a fuzzer, tools that exploit the 10 vulnerabilities Shmuel Cohen and I found, and the RCE attack we chained them into github.com/SafeBreach-Lab…

Mickey (@hackingthings) 's Twitter Profile Photo

For those of you interested in getting started with UEFI vuln research and exploitation, check out the Damn Vulnerable UEFI project on GitHub github.com/hacking-suppor… By Stan Lyakhov and myself. Contributions are welcome!

Alon Leviev (@_0xdeku) 's Twitter Profile Photo

Had the best time presenting Windows Downdate at Black Hat USA and DEF CON 32, thank you all for joining. Windows Downdate is now live! Blog - safebreach.com/blog/downgrade… GitHub repo - github.com/SafeBreach-Lab… #BHUSA #DEFCON32

Had the best time presenting Windows Downdate at <a href="/BlackHatEvents/">Black Hat</a> USA and <a href="/defcon/">DEF CON</a> 32, thank you all for joining. Windows Downdate is now live!

Blog - safebreach.com/blog/downgrade…

GitHub repo - github.com/SafeBreach-Lab…

#BHUSA #DEFCON32
VictorV (@vv474172261) 's Twitter Profile Photo

v-v.space/2024/08/19/CVE… Check my blog about Windows secure channel RCE analysis, though MSRC thought it's a DOS. By the way, I'm not the finder. Share for studying

Or Yair (@oryair1999) 's Twitter Profile Photo

If you're into researching Google's Quick Share, don't forget to check out QuickShell! It implements the RCE chain we found and tools allowing to sniff, receive and send the protocol's packets, fuzz the protocol, exploit vulnerabilities we found and more! github.com/SafeBreach-Lab…

Zero Day Initiative (@thezdi) 's Twitter Profile Photo

We've updated our blog on abusing file deletes to escalate privileges. We've also released PoC to demonstrate this. The exploit offers a high degree of reliability and eliminates all race conditions. It has been tested on the latest Windows 11 Enterprise. zerodayinitiative.com/blog/2022/3/16…