Joined September 2014
14 Photos and videos
🚨 Breaking: AI agents aren’t “productivity tools.” Individuals pushing massive amounts of code. This isn’t just automation. It’s leverage.
Absolutely insane week for agentic engineering 37K LOC per day across 5 projects Still speeding up
1
118
johannes retweeted
Working on the new simulator. I just wanted to see what Atari2600 fetching data from ROM looks like at CMOS FET level (@tinytapeout TT09 Atari circuit by @__ReJ__)
106
479
4,325
182,388
johannes retweeted
Me: Power corrupts @wiknerj: Rowhammer is a good example of that
2
11
1,947
4 Aug 2025
Great selection - in particular nr 6 😎 Excited for #blackhat2025. Hope to see many new and familiar faces in Vegas in the upcoming days :)
Blackhat USA 2025 will happen soon, this is my personal top 12 master selection: 1. HTTP/1.1 Must Die! The Desync Endgame Speaker: James Kettle Tracks: Application Security: Offense, Application Security: Defense Format: 40-Minute Briefings Location: Oceanside A, Level 2 2. Invitation Is All You Need! Invoking Gemini for Workspace Agents with a Simple Google Calendar Invite Speaker: Ben Nassi, Speaker: Or Yair, Speaker: Stav Cohen Track: AI, ML, & Data Science Format: 40-Minute Briefings Location: Oceanside A, Level 2 3. Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications Speaker: Fengyu Liu, Speaker: YouKun Shi, Contributor: Tian Chen, Contributor: Bocheng Xiang, Contributor: Junyao He, Contributor: Qi Li, Contributor: Guangliang Yang, Contributor: Yuan Zhang, Contributor: Min Yang Tracks: Application Security: Offense, Exploit Development & Vulnerability Discovery Format: 30-Minute Briefings Location: Jasmine A & E, Level 3 4. Protecting Small Organizations in the Era of AI Bots Speaker: Rama Hoetzlein Tracks: Defense & Resilience, AI, ML, & Data Science Format: 40-Minute Briefings Location: Islander F & G, Level 0 - North Convention Center 5. Keynote: Chasing Shadows: Chronicles of Counter-Intelligence from the Citizen Lab Speaker: Ron Deibert Track: Keynote Format: 40-Minute Keynote Location: Oceanside A, Level 2 6. Racing for Privilege: Leaking Privileged Memory From Any Intel System Using a Microarchitectural Race Condition Speaker: Sandro Rüegge, Speaker: Johannes Wikner Tracks: Platform Security, Exploit Development & Vulnerability Discovery Format: 30-Minute Briefings Location: Mandalay Bay H, Level 7. Hackers Dropping Mid-Heist Selfies: LLM Identifies Information Stealer Infection Vector and Extracts IoCs Estelle Ruellan | Threat Intelligence Researcher, Flare Olivier Bilodeau | Principal Security Researcher, Flare Date: Wednesday, August 6 | 3:20pm-4:00pm ( Oceanside C, Level 2 ) Format: 40-Minute Briefings Tracks: Malware, AI, ML, & Data Science 8. Keynote: Three Decades in Cybersecurity: Lessons Learned and What Comes Next Speaker: Mikko Hypponen Track: Keynote Format: 40-Minute Keynote Location: Michelob ULTRA Arena, Concourse Level 9. Breaking Out of The AI Cage: Pwning AI Providers with NVIDIA Vulnerabilities Andres Riancho | Security Researcher, Wiz Hillai Ben-Sasson | Security Researcher, Wiz Ronen Shustin | Security Researcher, Wiz Date: Wednesday, August 6 | 11:20am-12:00pm ( Mandalay Bay H, Level 2 ) Format: 40-Minute Briefings Tracks: Cloud Security, AI, ML, & Data Science 10. Booting into Breaches: Hunting Windows SecureBoot's Remote Attack Surfaces Speaker: Jietao Yang Tracks: Exploit Development & Vulnerability Discovery, Platform Security Format: 40-Minute Briefings Location: Islander E & I, Level 0 - North Convention Center 11. Burning, Trashing, Spacecraft Crashing: A Collection of Vulnerabilities That Will End Your Space Mission Andrzej Olchawa | Offensive Security Researcher, VisionSpace Technologies GmbH Milenko Starcik | Head of Cyber Security, VisionSpace Technologies GmbH Ricardo Fradique | Cybersecurity Engineer, VisionSpace Technologies GmbH Ayman Boulaich | Cybersecurity Intern, VisionSpace Technologies GmbH Date: Wednesday, August 6 | 2:30pm-3:00pm ( Mandalay Bay H, Level 2 ) Format: 30-Minute Briefings Tracks: Exploit Development & Vulnerability Discovery, Application Security: Offense 12. Dark Corners: How a Failed Patch Left VMware ESXi VM Escapes Open for Two Years Speaker: Yuhao Jiang, Contributor: Xinlei Ying, Speaker: Ziming Zhang Tracks: Exploit Development & Vulnerability Discovery, Cloud Security Format: 40-Minute Briefings Location: Jasmine A & E, Level 3 @BlackHatEvents blackhat.com/us-25/briefings…
1
1
298
johannes retweeted
Huh, I didn't realize that the vibe-coded vulns inserted into 5 LTS kernels that still aren't fixed 22 days later haven't been fixed because the person who inserted them is busy telling everyone at a conference how great the AI he used to insert the vulns (that he didn't find) is
4
92
626
56,465
johannes retweeted
14 May 2025
Happy to announce that the paper about IBPB problems that included the first real cross-process Spectre exploit just got a distinguished paper award at @IEEESSP! Dr. @wiknerj now has two of these awards in his thesis. What will he do next?!
18 Oct 2024
HW defenses against Spectre are tricky: they need to be applied correctly by the SW, and we need to trust that the HW does what its supposed to. Our latest work "Breaking the Barrier" exploits loopholes in both of these issues on Intel and AMD parts. comsec.ethz.ch/breaking-the-…
2
8
762
13 May 2025
Branch Race Conditions Predictor causes recent predictions to be added after more recent privilege switches (→ wrong privilege, eIBRS💥) prediction flushes (→ retained valid, IBPB💥) finish. @sparchatus eventually figured it out 🙌
13 May 2025
Disclosing Branch Predictor Race Conditions (BPRC), a new class of vulnerabilities where asynchronous branch predictor operations violate hardware-enforced privilege and context separation in virtually all recent Intel CPUs. @wiknerj @kavehrazavi : comsec.ethz.ch/bprc
2
21
16,627
johannes retweeted
12 May 2025
Spectre v2 is back again! Disclosing "Training Solo": 3 new self-training attack classes, 2 end-to-end exploits, and 2 new hardware issues that break domain isolation even when implemented perfectly. Joint work by @SanWieb @c_giuffrida: vusec.net/projects/training-…
28
83
5,553
johannes retweeted
15 Apr 2025
🔨 Posthammer (USENIX Sec '25) brings Rowhammer back in the browser! What if visiting a website was enough to trigger a Rowhammer attack? Posthammer shows how to bring non-uniform Rowhammer patterns into the browser. More information: 📄comsec.ethz.ch/posthammer

7
25
1,870
johannes retweeted
The @phrack 72 CFP horny emojipasta has hit the chats
16 Dec 2024
We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org/
4
12
41
10,340
17 Dec 2024
Thanks for the 21st @h2hconference! Always a joy to meet the mix of researchers, enthusiasts, academics, hackers. Special thanks to the organizers and yes the 🚌 trip to Rio went smoothly @bsdaemon @gabrielnb 😄 has a moment to enjoy this very special zine on the journey..
3
15
522
18 Oct 2024
The first ever end-to-end cross-process Spectre exploit? I worked on this during an internship with @grsecurity! An in-depth write-up here: grsecurity.net/cross_process…

54
124
17,752
18 Oct 2024
HW defenses against Spectre are tricky: they need to be applied correctly by the SW, and we need to trust that the HW does what its supposed to. Our latest work "Breaking the Barrier" exploits loopholes in both of these issues on Intel and AMD parts. comsec.ethz.ch/breaking-the-…

2
33
116
32,549
18 Oct 2024
And of course we fix the problems we cause (unless they're in microcode..). github.com/torvalds/linux/co…

1
11
1,262
18 Oct 2024
My and @kavehrazavi's paper has been accepted for S&P 2025.
1
3
1,326
14 Oct 2024
Curious about this...
I've just presented at IEEE SecDev our work on reversing the eIBRS HW mitigation. TLDR: use retpoline or stibp ibpb ;) The mitigation relies on an automatic flush of the predictor to prevent brute-force. But it is not frequent enough (thus, it relies on obscurity really). Recommendation for Intel: 1-) add a tunable for it 2-) disclose the details so customers can understand risk.
3
368
johannes retweeted
Call for Papers officially open! 21 years of @h2hconference #H2HC2024
21 Jun 2024
#H2HC2024 Inscricoes abertas e chamada de trabalhos tambem! @h2hcon
19
47
8,760
johannes retweeted
With RISC-H, we demonstrate the first Rowhammer bit flips on a high-end RISC-V CPU! We had to devise a novel method to order memory requests and carefully characterize the system to avoid bottlenecks comsec.ethz.ch/wp-content/fi… presented @ DRAMSec (ISCA) with @kavehrazavi :)
25
55
5,157