Matthias Deeg (@matthiasdeeg) 's Twitter Profile
Matthias Deeg

@matthiasdeeg

Interested in IT and likes to see whether security assumptions in soft-, firm-, or hardware hold true when taking a closer look. 📚author // books.deeg.xyz

ID: 1126745886715891713

calendar_today10-05-2019 07:08:48

272 Tweet

549 Followers

162 Following

Matthias Deeg (@matthiasdeeg) 's Twitter Profile Photo

Yesterday, my colleague Andreas Grasser published a tech blog article titled "Windows local privilege escalation through the bitpixie vulnerability". I can highly recommend this article to learn more about this boot vulnerability and its mitigations. blog.syss.com/posts/bitpixie/

Gerhard Klostermeier (@iiiikarus) 's Twitter Profile Photo

I was giving a talk at BalCCon about breaking out of kiosk mode environments. The conference was an fantastic experience! You can find the full write-up with tips & tricks, slides, etc. here: github.com/ikarus23/kiosk…

No Hat Con (@nohatcon) 's Twitter Profile Photo

Information security may seem chaotic, but within that chaos lies opportunity, the spark of discovery that leads to groundbreaking findings. Join our Research Track to find out some incredible talks! 🧃 Matthias Deeg kangel Will Huang Guillaume André Wil Ignacio Navarro

Information security may seem chaotic, but within that chaos lies opportunity, the spark of discovery that leads to groundbreaking findings.
Join our Research Track to find out some incredible talks!

<a href="/vesnafvr/">🧃</a> <a href="/matthiasdeeg/">Matthias Deeg</a> <a href="/J_kangel/">kangel</a> <a href="/In0de_16/">Will Huang</a> <a href="/yaumn_/">Guillaume André</a> <a href="/wil_fri3d/">Wil</a> <a href="/IgNavarro1/">Ignacio Navarro</a>
No Hat Con (@nohatcon) 's Twitter Profile Photo

Less than two weeks to go! Are you ready to experience some mind-blowing talks with our Technical Track? Ken Munro Nino 🧃 Find out more nohat.it/agenda

Less than two weeks to go! Are you ready to experience some mind-blowing talks with our Technical Track?

<a href="/TheKenMunroShow/">Ken Munro</a> <a href="/gibbersen/">Nino</a> <a href="/vesnafvr/">🧃</a> 

Find out more
nohat.it/agenda
Matthias Deeg (@matthiasdeeg) 's Twitter Profile Photo

I‘m on my way to No Hat Con - just across the street. 😄 My first day in Bergamo was already great, and I hope that the weekend will also be an awesome experience.

Simone (@simo_m2001) 's Twitter Profile Photo

Before lunch at No Hat Con: Ken Munro “All at sea. Thought your OT/IT was complex? Try doing it on a cruise ship.” 🚢 + Matthias Deeg “Your Security Update is Not Secure Enough — Hacking Portable Storage Devices Again.” 💻 #nohat2025 #cybersecurity

Before lunch at <a href="/nohatcon/">No Hat Con</a>: <a href="/TheKenMunroShow/">Ken Munro</a> “All at sea. Thought your OT/IT was complex? Try doing it on a cruise ship.” 🚢 + <a href="/matthiasdeeg/">Matthias Deeg</a> “Your Security Update is Not Secure Enough — Hacking Portable Storage Devices Again.” 💻

#nohat2025 #cybersecurity
Matthias Deeg (@matthiasdeeg) 's Twitter Profile Photo

I've also learned last weekend that concerning insecure encrypted USB flash drives I'm a "bug cousin" to Katie🌻Moussouris (she/her/she-ra/she-hulk) 🪷. And another "bug cousin" has already reached out to me after my talk via email. 😀 Insecure portable storage devices are definitely not only a thing of the past.

Matthias Deeg (@matthiasdeeg) 's Twitter Profile Photo

Today, we have published two security advisories by my colleague Florian Holley concerning the IBM TS4500 Tape Library WebUI (CVE-2021-23450 and CVE-2025-36088). You can find more information in the SySS Pentest Blog: syss.de/pentest-blog/s…

Matthias Kesenheimer (@bartimaeusvuruk) 's Twitter Profile Photo

Glitching the Trezor One crypto wallet with the #PicoGlitcher and #findus: mkesenheimer.github.io/blog/trezor-wa… It's now possible to recover lost #Bitcoin with relatively low effort.

Matthias Kesenheimer (@bartimaeusvuruk) 's Twitter Profile Photo

Another blog post about attacking the Trezor One #Bitcoin wallet with the #PicoGlitcher and #findus: mkesenheimer.github.io/blog/trezor-wa… This time, a fully locked down device is attacked via a double glitching attack.

Matthias Deeg (@matthiasdeeg) 's Twitter Profile Photo

You can find the recording of my No Hat 2025 talk titled "Your Security Update is not Secure Enough" here: youtube.com/watch?v=WSJyZc… Thanks again to the whole No Hat Con team for inviting me to Bergamo.

Matthias Deeg (@matthiasdeeg) 's Twitter Profile Photo

If you have a short attention span or not much time right now, I recommend the following YouTube short demonstrating a successful brute-force attack against a vulnerable Verbatim Keypad Secure: youtube.com/shorts/wUXupV7…

No Hat Con (@nohatcon) 's Twitter Profile Photo

Photos from 2025 No Hat Computer Security Conference are online! You can find them here photos.app.goo.gl/9TLiUNXYPFLzGZ…

No Hat Con (@nohatcon) 's Twitter Profile Photo

📣 No Hat 2026 is coming back on Oct 17, 2026! Another day of computer security, hacking, learning, and awesome people coming together. Interested in sponsoring the event? Get in touch! nohat.it #nohat #nohat2026 #computer #security #conference #community #cyber