Shmuel Cohen

81 posts

Shmuel Cohen banner
Shmuel Cohen

Shmuel Cohen

@_BinWalker_

Former Security researcher @SafeBreach | Former malware researcher @_CPResearch_ | 3x BlackHat speaker | DEFCON speaker | SecTor speaker

Katılım Eylül 2018
246 Takip Edilen259 Takipçiler
Sabitlenmiş Tweet
Shmuel Cohen
Shmuel Cohen@_BinWalker_·
If you heard about my research "The Dark Side of EDR: Repurpose EDR as Offensive tool" Make sure you also check out my tool :) github.com/SafeBreach-Lab…
English
5
50
162
17.7K
Shmuel Cohen retweetledi
Alon Leviev
Alon Leviev@alon_leviev·
Our research on BitLocker got nominated for not one but TWO Pwnie Awards - “Best Desktop Bug” and “Most Innovative Research”! Happy for the 3rd Pwnie Award nomination in two consecutive years @PwnieAwards !
Alon Leviev tweet mediaAlon Leviev tweet media
English
3
6
27
3.5K
Alon Leviev
Alon Leviev@alon_leviev·
I am beyond thrilled to share that @NetanelBenSimon and I have been accepted to present at @BlackHatEvents USA 2025! We will present our talk "BitUnlocker: Leveraging Windows Recovery to Extract BitLocker Secrets", where we share our VR journey of WinRE! See you there! #BHUSA
Alon Leviev tweet media
English
2
2
13
4.2K
Shmuel Cohen
Shmuel Cohen@_BinWalker_·
@PsExec64 How the hell PaloAlto is rated as A? You can literally change your ransom binary to be something like “explorer.exe” and it will bypass Cortex completely (You can read more about it with my CortexVortex research)
English
0
1
3
1.1K
Xappy
Xappy@theXappy·
"Mark of the Web" sounds way too cool for what it really is
English
1
0
0
52
Shmuel Cohen
Shmuel Cohen@_BinWalker_·
@nirohfeld As always, great findings, and a super cool blogpost! keep up the good work ;)
English
0
0
1
114
Nir Ohfeld
Nir Ohfeld@nirohfeld·
Thrilled to finally share this—one of the coolest container escapes I’ve seen! 🔥 wiz.io/blog/nvidia-ai… A subtle logic bug that lets you break out to the host on ANY NVIDIA GPU-supported container 🤯 Can’t believe we had to sit on the technical details for so long! Incredible research by @shirtamari @ronenshh @AndresRiancho
GIF
Ronen Shustin@ronenshh

A couple of months ago, we at @wiz_io discovered a container escape vulnerability in the NVIDIA Container Toolkit, which impacts many cloud and AI SaaS providers. We're finally able to share the technical details. wiz.io/blog/nvidia-ai…

English
1
10
47
5K
Shmuel Cohen
Shmuel Cohen@_BinWalker_·
@theXappy The official name of this behavior is RVO (Return Value Optimization)
English
0
0
1
46
Xappy
Xappy@theXappy·
TIL: If you "return a struct" from a C/++ function, and it's larger then 8 bytes, it becomes a by-ref argument. Caller created an empty struct -> Passes pointer to the func, as the last arg -> func populated the pointed struct. * at least for MSVC for x64
Xappy tweet media
English
2
0
3
211
Shmuel Cohen retweetledi
Alon Leviev
Alon Leviev@alon_leviev·
My DEF CON 32 talk “Windows Downdate: Downgrade Attacks Using Windows Updates” is live on YouTube! youtu.be/HHmxuxQ7bE8?si…
YouTube video
YouTube
English
3
88
287
24.4K
Shmuel Cohen retweetledi
Or Yair
Or Yair@oryair1999·
If you're into researching Google's Quick Share, don't forget to check out QuickShell! It implements the RCE chain we found and tools allowing to sniff, receive and send the protocol's packets, fuzz the protocol, exploit vulnerabilities we found and more! github.com/SafeBreach-Lab…
English
1
24
83
12.2K
Shmuel Cohen retweetledi
Alon Leviev
Alon Leviev@alon_leviev·
Reminder: tomorrow at @BlackHatEvents 10:20 AM in Oceanside A - I will be sharing my journey of researching downgrade attacks on Windows and their severe implications on Windows’s platform security. Join my talk “Windows Downdate: Downgrade Attacks Using Windows Updates” #BHUSA
English
1
3
9
2.1K
chompie
chompie@chompie1337·
since MS doesn’t consider Admin to Kernel a boundary then is it chill to publish about one without telling them? i know one of you has done this so just give me the tea before I get in trouble
English
35
18
345
71K
Alon Leviev
Alon Leviev@alon_leviev·
Just hit the 5-hour work mark and explorer.exe hasn’t crashed even once. Wondering if I should report this bug to MSRC
English
3
0
3
700
Shmuel Cohen
Shmuel Cohen@_BinWalker_·
It's my honor to present alongside Or. This talk is going to be amazing, I promise ;) See you at #DC32
Or Yair@oryair1999

Honored to announce that @_BinWalker_ and I were accepted to speak at @defcon ! Our research - "QuickShell: Sharing is caring about an RCE attack chain on Quick Share" showcases 10 vulns in Google's Quick Share, chained to a creative RCE attack chain on Quick Share for Windows

English
0
0
3
229
Shmuel Cohen
Shmuel Cohen@_BinWalker_·
ProcessHacker is now called SystemInformer, and it looks just amazing with lots of new features. Make sure you check it out if you use the old ProcessHacker: github.com/winsiderss/sys…
English
0
2
0
217