Claudiu Teodorescu (@cteo13) 's Twitter Profile
Claudiu Teodorescu

@cteo13

Co-founder @Binarly_io

Previously worked at Cylance, FireEye, EnCase, eEye Digital Security

ID: 3256013564

linkhttps://binarly.io calendar_today25-06-2015 22:33:12

242 Tweet

362 Followers

66 Following

USC ISI (@usc_isi) 's Twitter Profile Photo

Come join us at our #cybersecurity seminar next Thursday! ⁠ ⁠ As the Founder and CEO of BINARLY🔬, Alex Matrosov will discuss #research areas of interest to help the industry recover from repeatable failures in firmware #security. ⁠ Tune in on zoom: bit.ly/3V8Snby

Come join us at our #cybersecurity seminar next Thursday! ⁠
⁠
As the Founder and CEO of <a href="/binarly_io/">BINARLY🔬</a>, <a href="/matrosov/">Alex Matrosov</a> will discuss #research areas of interest to help the industry recover from repeatable failures in firmware #security.
⁠
Tune in on zoom: bit.ly/3V8Snby
Alex Matrosov (@matrosov) 's Twitter Profile Photo

⛓️Recently, MSI Gaming USA announced a significant data breach. The data has now been made public, revealing a vast number of private keys that could affect numerous devices. 🔥FW Image Signing Keys: 57 products 🔥Intel BootGuard BPM/KM Keys: 166 products 🔬github.com/binarly-io/Sup…

BINARLY🔬 (@binarly_io) 's Twitter Profile Photo

⛓️Digging deeper into the aftermath of the MSI Gaming USA data breach and its impact on the industry. 🔥Leaked Intel BootGuard keys from MSI are affecting many different device vendors, including @Intel , Lenovo, @Supermicro_SMCI, and many others industry-wide. 🔬#FwHunt is on!

⛓️Digging deeper into the aftermath of the <a href="/msiUSA/">MSI Gaming USA</a> data breach and its impact on the industry. 

🔥Leaked Intel BootGuard keys from MSI are affecting many different device vendors, including @Intel , <a href="/Lenovo/">Lenovo</a>, @Supermicro_SMCI, and many others industry-wide.

🔬#FwHunt is on!
Alex Matrosov (@matrosov) 's Twitter Profile Photo

⛓️Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem. It appears that Intel BootGuard may not be effective on certain devices based on the 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake. Our investigation is ongoing, stay tuned for updates.

⛓️Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem. It appears that Intel BootGuard may not be effective on certain devices based on the 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake. Our investigation is ongoing, stay tuned for updates.
STH (@servethehome) 's Twitter Profile Photo

Security researchers on claiming on Twitter that an Intel Boot Guard OEM Private Key was leaked as part of the MSI data breach servethehome.com/intel-boot-gua… Alex Matrosov Intel BINARLY🔬

Security researchers on claiming on Twitter that an Intel Boot Guard OEM Private Key was leaked as part of the MSI data breach servethehome.com/intel-boot-gua… <a href="/matrosov/">Alex Matrosov</a> <a href="/intel/">Intel</a> <a href="/binarly_io/">BINARLY🔬</a>
Alex Matrosov (@matrosov) 's Twitter Profile Photo

⛓️Diving deeper into MSI leak, it has been discovered that one of the leaked keys (bxt_dbg_priv_key.pem) is associated with Intel Orange or OEM Unlocked. 🔥Based on Intel documentation, it appears to be more powerful in comparison to Boot Guard keys. intel.com/content/www/us…

⛓️Diving deeper into MSI leak, it has been discovered that one of the leaked keys (bxt_dbg_priv_key.pem) is associated with Intel Orange or OEM Unlocked.

🔥Based on Intel documentation, it appears to be more powerful in comparison to Boot Guard keys.

intel.com/content/www/us…
BINARLY🔬 (@binarly_io) 's Twitter Profile Photo

🔥The bxt_dbg_priv_key.pem, which is the Intel OEM Platform Key (Orange Unlock) obtained from an MSI leak, has been detected on devices from HP, Lenovo, AOPEN, CompuLab, and Star Labs. 🔬Stay tuned for more updates as the investigation continues. github.com/binarly-io/Sup…

🔥The bxt_dbg_priv_key.pem, which is the Intel OEM Platform Key (Orange Unlock) obtained from an MSI leak, has been detected on devices from HP, Lenovo, AOPEN, CompuLab, and Star Labs. 

🔬Stay tuned for more updates as the investigation continues.

github.com/binarly-io/Sup…
BINARLY🔬 (@binarly_io) 's Twitter Profile Photo

⛓️Thank you Intel Security for fixing the incomplete RSB stuffing SMM mitigation (#FirmwareBleed/CVE-2022-38087). 💥BRLY: binarly.io/advisories/BRL… 💥Intel: intel.com/content/www/us… 💥IBM: ibm.com/support/pages/… 💥Dell: dell.com/support/kbdoc/… 🔬Details: binarly.io/posts/Firmware…

BINARLY🔬 (@binarly_io) 's Twitter Profile Photo

💥HP: support.hp.com/sk-en/document… 💥Lenovo: support.lenovo.com/us/en/product_… 🔥NVD CVSS score: 8.8 High (CWE-78) nvd.nist.gov/vuln/detail/CV…

Alex Matrosov (@matrosov) 's Twitter Profile Photo

🔥New finding! We have confirmed that previously leaked Intel BootGuard private keys from Lenovo/LCFC in September 2022 are still relevant for numerous devices in the field (Lenovo, Supermicro, Intel ...). ⛓️github.com/binarly-io/Sup… 🔬FwHunt: github.com/binarly-io/FwH…

🔥New finding! We have confirmed that previously leaked Intel BootGuard private keys from Lenovo/LCFC in September 2022 are still relevant for numerous devices in the field (Lenovo, Supermicro, Intel ...).

⛓️github.com/binarly-io/Sup…

🔬FwHunt: github.com/binarly-io/FwH…
Alex Matrosov (@matrosov) 's Twitter Profile Photo

🎙️Join us tomorrow for the #BHASIA talk: "The Various Shades of Supply Chain: SBOM, N-Days, and Zero Trust." /cc @hughsient immune ⛓️We have some fascinating data insights regarding firmware supply chain security. blackhat.com/asia-23/briefi…

🎙️Join us tomorrow for the #BHASIA talk: "The Various Shades of Supply Chain: SBOM, N-Days, and Zero Trust."  /cc @hughsient <a href="/immune_gmbh/">immune</a>

⛓️We have some fascinating data insights regarding firmware supply chain security.

blackhat.com/asia-23/briefi…
Alex Matrosov (@matrosov) 's Twitter Profile Photo

⛓️Design issues are the worst! 🔥Given the current revocation architecture, we are facing the serious challenges of accommodating over 2300+ bootmgr binaries within DBX Revocation List (limited space left in EFI Variable storage).

hardwear.io (@hardwear_io) 's Twitter Profile Photo

😎We are excited to Welcome Alex Alex Matrosov BINARLY🔬 for the📡CXO panel! 🧠Learn, network & collaborate with the #hardwaresecurity geniuses➡️bit.ly/3UCENgz #hw_ioUSA2023 #Conference

😎We are excited to Welcome Alex <a href="/matrosov/">Alex Matrosov</a> <a href="/binarly_io/">BINARLY🔬</a> for the📡CXO panel! 

🧠Learn, network &amp; collaborate with the #hardwaresecurity geniuses➡️bit.ly/3UCENgz

#hw_ioUSA2023 #Conference
Alex Matrosov (@matrosov) 's Twitter Profile Photo

Heading to the Qualcomm Product Security Summit and @Offensive_con this week 🔥A Dark Side of UEFI: Cross-Silicon Exploitation @Binarly_io REsearch going to present new ways of exploiting Qualcomm Snapdragon 8 devices with UEFI-specific flavor. Stay tuned! Alexander Ermolov Yegor

Heading to the Qualcomm Product Security Summit and @Offensive_con this week

🔥A Dark Side of UEFI: Cross-Silicon Exploitation

@Binarly_io REsearch going to present new ways of exploiting Qualcomm Snapdragon 8 devices with UEFI-specific flavor. Stay tuned!

<a href="/flothrone/">Alexander Ermolov</a>  <a href="/yeggorv/">Yegor</a>
BINARLY🔬 (@binarly_io) 's Twitter Profile Photo

⛓️The widespread use of UEFI on ARM devices notably expands the attack surfaces within TrustZone and beyond, raising security concerns 💥REsearch: "A Dark Side of UEFI: Cross-Silicon Exploitation" presented the new ARM attacks at offensivecon 🔬Slides: github.com/binarly-io/Res…

⛓️The widespread use of UEFI on ARM devices notably expands the attack surfaces within TrustZone and beyond, raising security concerns

💥REsearch: "A Dark Side of UEFI: Cross-Silicon Exploitation" presented the new ARM attacks at <a href="/offensive_con/">offensivecon</a>

🔬Slides: github.com/binarly-io/Res…
BINARLY🔬 (@binarly_io) 's Twitter Profile Photo

🔥At offensivecon, we showcased three different attack scenarios on ARM UEFI and beyond: 1️⃣CWE-125: OOB (memory leak) with GetVariable/SetVariable pattern. 2️⃣BRLY-2022-033: GetVariable Stack overflow (UsbConfigDxe). 3️⃣LPE to SMM from DXE by design. youtube.com/watch?v=7COjay…