Jonathan Lusky (@luskyyehonatan) 's Twitter Profile
Jonathan Lusky

@luskyyehonatan

Security research team lead at Cellebrite. I love anything related with low-level security research, poking CPUs, hopping between rings and destroying hardware

ID: 1526912886399975426

calendar_today18-05-2022 13:09:47

26 Tweet

63 Followers

87 Following

Jonathan Lusky (@luskyyehonatan) 's Twitter Profile Photo

I guess now would be great opportunity for an hello world tweet :) Thank you for hopping in to our talk, we "hopped" you enjoyed it! BlueHat IL Benny Zeltser #RingHopper #UEFI #SMM

Benny Zeltser (@benny_zeltser) 's Twitter Profile Photo

Jonathan Lusky and I submitted our talk "The #RingHopper Journey: Hopping through the maze of SMM exploitation" where we delve into the realm of SMM exploitation and talk extensively about the journey, rather than only the destination. Fingers crossed we get to deliver this talk

Jonathan Lusky (@luskyyehonatan) 's Twitter Profile Photo

Our talk from BlueHat IL is live! youtube.com/watch?v=CJDv_b… In our live demo on stage, we hopped from user-space to SMM modifying the BIOS logo 😎 Benny Zeltser #RingHopper #UEFI

Xeno Kovah (@xenokovah) 's Twitter Profile Photo

2023-03-29 "RingHopper – Hopping from User-space to God Mode" Slides: msrndcdn360.blob.core.windows.net/bluehat/blueha… Video: youtube.com/embed/CJDv_bcI… By Jonathan Lusky & Benny Zeltser Added to darkmentor.com/timeline.html

Alex Matrosov (@matrosov) 's Twitter Profile Photo

Great summary of the recent BitLocker attacks. In many cases, these attacks can bypass Secure Boot by design. As #BlackLotus just did with BatonDrop exploit recently. github.com/Wack0/bitlocke…

Adam 'pi3' Zabrocki (@adam_pi3) 's Twitter Profile Photo

Bug bounties are broken - the story of "i915" bug, ChromeOS + Intel bounty programs, and beyond Google VRP (Google Bug Hunters) Intel Security How the unspoken problems of bug bounties can be addressed? "Imbalance of Power" is a real problem and it should be changed. blog.pi3.com.pl/?p=931

Xeno Kovah (@xenokovah) 's Twitter Profile Photo

The “Architecture 4021: Introductory UEFI” ost2.fyi/Arch4021 #OST2 class videos are now publicly available via a YouTube playlist for those interested in downloading for offline viewing in the future. But as always, the best experience is in-class. youtube.com/playlist?list=…

Jonathan Lusky (@luskyyehonatan) 's Twitter Profile Photo

I’m glad to share that I’ll be presenting with Benny Zeltser at DEF CON. Come visit our talk “The RingHopper Journey or How We Almost Zero-day’d the 🌎”, Friday at 10am. #RingHopper

I’m glad to share that I’ll be presenting with <a href="/benny_zeltser/">Benny Zeltser</a> at <a href="/defcon/">DEF CON</a>. 
Come visit our talk “The RingHopper Journey or How We Almost Zero-day’d the 🌎”, Friday at 10am.
#RingHopper
Benny Zeltser (@benny_zeltser) 's Twitter Profile Photo

It was an incredible experience presenting our #ringhopper talk at #DEFCON31 Our slides are available at media.defcon.org/DEF%20CON%2031… Many thanks to everyone who came to our talk and to DEF CON for having us! Jonathan Lusky

It was an incredible experience presenting our #ringhopper talk at #DEFCON31

Our slides are available at 
media.defcon.org/DEF%20CON%2031…

Many thanks to everyone who came to our talk and to <a href="/defcon/">DEF CON</a> for having us!

<a href="/LuskyYehonatan/">Jonathan Lusky</a>
Benny Zeltser (@benny_zeltser) 's Twitter Profile Photo

📢 Super thrilled to announce that our #RingHopper talk presented @ #DefCon31 is now LIVE on YouTube! 🎉📺 If you want to dive even deeper into the details of our research, check out our awesome blog post series too! medium.com/@RingHopper/em… 📚🔍 Jonathan Lusky

shayb (@0f1f0f1f) 's Twitter Profile Photo

Extremely excited to be speaking in the first edition of #NoOffense! Seats are limited, make sure to register while you can.

Benny Zeltser (@benny_zeltser) 's Twitter Profile Photo

Just dropped the second blog in our #RingHopper series! Join us on our mission to acquire write-primitives within the tightly secured SMRAM medium.com/@RingHopper/th…

Just dropped the second blog in our #RingHopper series! Join us on our mission to acquire write-primitives within the tightly secured SMRAM
medium.com/@RingHopper/th…
Benny Zeltser (@benny_zeltser) 's Twitter Profile Photo

Just released the third blog in our #RingHopper series! 📝 Dive in as we showcase the transformation of a seemingly weak write primitive into unauthorized code execution in SMM 💻🔒 medium.com/@RingHopper/br… Jonathan Lusky

Just released the third blog in our #RingHopper series! 📝 Dive in as we showcase the transformation of a seemingly weak write primitive into unauthorized code execution in SMM 💻🔒
medium.com/@RingHopper/br…

<a href="/LuskyYehonatan/">Jonathan Lusky</a>
Benny Zeltser (@benny_zeltser) 's Twitter Profile Photo

📢 Just dropped the fourth and final blog post in the #RingHopper saga! In this post, we elevated the attack to operate from user-land and thus, managed to hop from Ring 3 to SMM. Explore the details in our latest post here: medium.com/@RingHopper/co… ⭕🦗 Jonathan Lusky

shayb (@0f1f0f1f) 's Twitter Profile Photo

If you're interested in doing Android vulnerability research, exploit engineering or low level dev, we're also expanding and recruiting, both remote and local. We have immensely talented folks and top notch memes, and are looking for experienced researchers and developers.

quarkslab (@quarkslab) 's Twitter Profile Photo

Is remote code execution in UEFI firmware possible? Yes it is. Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers. Full details by Francisco Falcon and iarce in our new blog post: blog.quarkslab.com/pixiefail-nine…

Is remote code execution in UEFI firmware possible?
Yes it is. 
Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
Full details by <a href="/fdfalcon/">Francisco Falcon</a> and <a href="/4Dgifts/">iarce</a> in our new blog post:
blog.quarkslab.com/pixiefail-nine…
NoOFFENSE (@nooffense_il) 's Twitter Profile Photo

Breaking News: Registration is now open! nooffensecon.org/registration We're proud to announce our top lectures for NoOFFENSE 2024, featuring exclusive content never seen before. See you there, NoOFFENSE team *Participation depends on registration and seat availability.

Breaking News: Registration is now open!
nooffensecon.org/registration

We're proud to announce our top lectures for NoOFFENSE 2024, featuring exclusive content never seen before. 

See you there, 
NoOFFENSE team

*Participation depends on registration and seat availability.
NoOFFENSE (@nooffense_il) 's Twitter Profile Photo

Yesterday was a hit! Huge thanks to shayb and Aviel Warschawski, who shared insights with 150 of Israel's top researchers. We appreciate everyone who participated and apologize to those who couldn’t get in due to high demand. This is the beginning of an exciting legacy.

Yesterday was a hit! Huge thanks to <a href="/0F1F0F1F/">shayb</a> and <a href="/PastaFork/">Aviel Warschawski</a>, who shared insights with 150 of Israel's top researchers. We appreciate everyone who participated and apologize to those who couldn’t get in due to high demand. This is the beginning of an exciting legacy.