Tal Lossos (@tallossos) 's Twitter Profile
Tal Lossos

@tallossos

Security Researcher

ID: 1539256900251963394

calendar_today21-06-2022 14:40:34

31 Tweet

142 Followers

59 Following

EranShimony (@eranshimony) 's Twitter Profile Photo

Omer Tsarfati and I harnessed ChatGPT to create a #polymorphic #malware, which uses ChatGPT on runtime to load and mutate new code that easily bypasses the content-filter. We are looking forward to continuing and research the topic -:) cyberark.com/resources/threโ€ฆ

CyberArk Labs (@cyberarklabs) 's Twitter Profile Photo

The #NTFS3 driver for #Linux is not without its flaws. I #bug has been found by Alon Zahavi that could lead to a denial-of-serveice attack. #DoS cyberark.com/resources/threโ€ฆ

Tal Lossos (@tallossos) 's Twitter Profile Photo

Had a blast. You should definitely check it out if you wanna see how I've exploited it to a LPE, in a colorful way of course ๐Ÿ”ด๐Ÿ”ต๐ŸŸข๐ŸŸก

CyberArk Labs (@cyberarklabs) 's Twitter Profile Photo

.Tal Lossos explaining how he's exploiting 3rd party kernel modules. In this case, OpenRazer... #RSAC2023 #opensource #bufferoverlow #fuzzing

.<a href="/TalLossos/">Tal Lossos</a> explaining how he's exploiting 3rd party kernel modules. 
In this case, OpenRazer...

#RSAC2023 #opensource #bufferoverlow #fuzzing
REcon (@reconmtl) 's Twitter Profile Photo

Recon 2023 Talk selection has been released, cfp.recon.cx/2023/featured/ The Conference schedule will be published soon. Register here: recon.cx/2023/index.html See you in June! #cybersecurite #REcon2023 #ReverseEngineering

Tal Lossos (@tallossos) 's Twitter Profile Photo

A deep dive into how we've found some cool low-hanging-fruits in the Linux kernel ๐Ÿž๐Ÿ”cyberark.com/resources/threโ€ฆ

LaurieWired (@lauriewired) 's Twitter Profile Photo

Did you know that NVMe over TCP exists? I sure didn't, but it's a super interesting attack vector. Tal Lossos just put out an excellent blogpost of using CppCheck to find a null pointer deference in the Linux kernelโ€™s NVMe driver. Check it out! cyberark.com/resources/threโ€ฆ

awxylitol (@awxylitol) 's Twitter Profile Photo

#HITB2023HKT The blog post version of this talk is now available vul.360.net/archives/699 and the slides are here conference.hitb.org/hitbsecconf202โ€ฆ

CyberArk Labs (@cyberarklabs) 's Twitter Profile Photo

Check it out! Our resident expert reverse engineer Tal Lossos giving his talk on at REcon Montreal. Topic: Vulnerabilities in the NVMe (Non-Volatile Memory Express) protocol and its extension, NVMeoF (NVMe over Fabrics).

0xor0ne (@0xor0ne) 's Twitter Profile Photo

Interesting reading on how to use Static Code Analysis tools for finding vulnerabilities (with a NULL Pointer Dereference in the NVMe driver of the Linux kernel as practical example) Credits Tal Lossos (Tal Lossos) cyberark.com/resources/all-โ€ฆ #Linux #kernel #infosec

Interesting reading on how to use Static Code Analysis tools for finding vulnerabilities (with a NULL Pointer Dereference in the NVMe driver of the Linux kernel as practical example)
Credits <a href="/TalLossos/">Tal Lossos</a> (<a href="/TalLossos/">Tal Lossos</a>)

cyberark.com/resources/all-โ€ฆ

#Linux #kernel #infosec
Shak Reiner ๐Ÿ (@shakreiner) 's Twitter Profile Photo

Finally got around to publishing this post on a ๐™˜๐™ง๐™ž๐™ฉ๐™ž๐™˜๐™–๐™ก ๐™ซ๐™ช๐™ก๐™ฃ๐™š๐™ง๐™–๐™—๐™ž๐™ก๐™ž๐™ฉ๐™ฎ ๐™ž๐™ฃ ๐™– #๐—–๐—ผ๐˜€๐—บ๐—ผ๐˜€๐—ฆ๐——๐—ž ๐™˜๐™๐™–๐™ž๐™ฃ! Dive in if you're interested in the security of the #IBC protocol and the Cosmos in general ๐Ÿชโœจ cyberark.com/resources/threโ€ฆ

Tal Lossos (@tallossos) 's Twitter Profile Photo

Quite a few people asked me if weโ€™ve found more vulnerabilities in the NVMe Linux kernel driver. So, here is my answer! Check out the blog post of my colleague Alon on his journey of fuzzing the driver with some lovely findings!

Alon Zahavi (@alon_z4) 's Twitter Profile Photo

Had an amazing experience at Insomni'hack this year, talking about adding NVMe-of/TCP to syzkaller. In case you want to check it out: Hereโ€™s the recording - m.youtube.com/watch?v=Jc25CMโ€ฆ And the slides - download.scrt.ch/insomnihack/inโ€ฆ