Alon Leviev

92 posts

Alon Leviev banner
Alon Leviev

Alon Leviev

@alon_leviev

Senior Vulnerability Researcher at @Microsoft | Brazilian Jiu Jitsu athlete turned cyber security researcher

Katılım Haziran 2022
200 Takip Edilen1.5K Takipçiler
Sabitlenmiş Tweet
Alon Leviev
Alon Leviev@alon_leviev·
What an amazing week we’ve had presenting our latest research at Black Hat USA and DEFCON 33! We shared our security research on BitLocker and WinRE - highlighting new vulnerabilities, exploits and fixes! The slides are now live at: i.blackhat.com/BH-USA-25/Pres…
Alon Leviev tweet mediaAlon Leviev tweet media
English
1
21
98
13.9K
Alon Leviev
Alon Leviev@alon_leviev·
Our DEFCON 33 talk “BitUnlocker: Leveraging Windows Recovery to Extract BItLocker Secrets” is now live on YouTube! youtu.be/Cc6vrQSVMII?si…
YouTube video
YouTube
English
2
0
5
1.4K
Alon Leviev
Alon Leviev@alon_leviev·
Today's Patch Tuesday includes 6 CVEs for vulnerabilities that I found in BitLocker - CVE-2025-55330, CVE-2025-55332, CVE-2025-55333, CVE-2025-55337, CVE-2025-55338 and CVE-2025-55682. You can check them out here 👉 msrc.microsoft.com/update-guide/r…
Alon Leviev tweet media
English
3
46
197
22.3K
Alon Leviev retweetledi
David Weston (DWIZZZLE)
David Weston (DWIZZZLE)@dwizzzleMSFT·
Microsoft just open sourced a Rust implementation of UEFI boot firmware called "Patina" this is a MASSIVE step forward in improving boot security for all. Exciting!!! github.com/openDevicePart…
English
8
79
271
29.4K
Alon Leviev retweetledi
Or Yair
Or Yair@oryair1999·
So @ShahakMo and I just dropped our Win-DoS research + tools at @defcon and on GitHub!💥 Win-DoS repo: * 4 new remote DoS exploits for Domain Controllers and Win11 (3 pre-auth!) * TorpeDoS technique - exhausting resources via RPC * DCs DDoS botnet attack github.com/SafeBreach-Lab…
English
0
15
42
3.1K
Alon Leviev
Alon Leviev@alon_leviev·
3x Pwnie-nominated, 0x Pwnie-winner At this rate I’m on track to win the “Most Nominated Without Winning” award 🦄 Huge thanks to @PwnieAwards and congrats to the very well deserved winners!
English
3
2
31
3.6K
Mickey
Mickey@HackingThings·
Here’s a video of an exploited Lenovo 510 FHD Webcam downloading a meterpreter payload from the internet and executing it, letting us send keystrokes to the computer it’s connected to, then return to being a regular unsuspecting webcam 😄 (Top left: webcam serial port output Bottom left: kali instance in the cloud Right: victim laptop view)
English
2
6
17
10.9K
Alon Leviev retweetledi
Or Yair
Or Yair@oryair1999·
The blog post of our "Invitation Is All You Need" research is now live! Don't skip it if you want to learn how Stav Cohen, @ben_nassi, and I took over Gemini agents of remote users to control their smart home, video stream them via zoom, exfiltrate emails, and more safebreach.com/blog/invitatio… @safebreach
English
0
3
10
2K
Alon Leviev retweetledi
Danis Jiang
Danis Jiang@danis_jiang·
Our “Dark Corners: How a Failed Patch Left VMware ESXi VM Escapes Open for Two Years” slides are now available! This research was a collaborative effort with @0x140ce, @ezrak1e and myself. In this talk, we introduce the ESXi virtual machine escape and sandbox escape vulnerabilities we discovered, along with the stories behind them. At the same time, this is also the first talk to systematically introduce the ESXi sandbox. We hope you can gain useful content from it. i.blackhat.com/BH-USA-25/Pres…
English
4
42
157
14.3K
Alon Leviev retweetledi
Microsoft Threat Intelligence
Microsoft Threat Intelligence@MsftSecIntel·
In the briefing “BitUnlocker: Leveraging Windows Recovery to Extract BitLocker Secrets” Microsoft security researchers share how their research into attack surfaces led to hardening and further securing Windows Recovery Environment (WinRE). msft.it/6018syn7Q
English
1
1
6
972
Alon Leviev retweetledi
Pwnie Awards
Pwnie Awards@PwnieAwards·
We are very happy to announce the nominees for the 2025 Pwnie Awards! As a reminder, we will be presenting the winners at DEF CON this year. Saturday the 9th, 10:00AM Main Stage. Hope to see you there! docs.google.com/document/d/1fy…
English
0
47
140
47.9K
Alon Leviev
Alon Leviev@alon_leviev·
Our research on BitLocker got nominated for not one but TWO Pwnie Awards - “Best Desktop Bug” and “Most Innovative Research”! Happy for the 3rd Pwnie Award nomination in two consecutive years @PwnieAwards !
Alon Leviev tweet mediaAlon Leviev tweet media
English
3
6
27
3.5K
Alon Leviev
Alon Leviev@alon_leviev·
This Patch Tuesday includes 5 CVEs for vulnerabilities that @NetanelBenSimon and I found in BitLocker! We've recently been focusing on BitLocker research and it's great seeing fixes released. If you're interested in learning more about this work, join our talks at BH US and DC!
Alon Leviev tweet media
English
0
6
46
3.1K
Alon Leviev retweetledi
Jeremiah Grossman
Jeremiah Grossman@jeremiahg·
Registration for the Cyber-Security Brazilian Jiu-Jitsu Smackdown (2025) is open! Held between @BlackHatEvents and @defcon (Thur, Aug 7), 60 of us step onto the mat for the most fun and epic experience. Former UFC Champion @ForrestGriffin is our head instructor, accompanied by several more elite pros. First-timers always welcomed! Reg: eventbrite.com/e/cyber-securi… 2024 Video: youtube.com/watch?v=vT5WMp… Sponsored by: @nucleussec and @wirespeed_
YouTube video
YouTube
English
0
5
10
2.2K
Alon Leviev
Alon Leviev@alon_leviev·
You know what’s even more exciting than being accepted to Black Hat USA? Getting accepted to DEFCON too!   I'm happy to share that my and @NetanelBenSimon‘s WinRE VR project “BitUnlocker: Leveraging Windows Recovery to Extract BitLocker Secrets” is coming to @defcon!   #DEFCON33
Alon Leviev tweet media
English
2
1
17
1.5K
Alon Leviev
Alon Leviev@alon_leviev·
I am beyond thrilled to share that @NetanelBenSimon and I have been accepted to present at @BlackHatEvents USA 2025! We will present our talk "BitUnlocker: Leveraging Windows Recovery to Extract BitLocker Secrets", where we share our VR journey of WinRE! See you there! #BHUSA
Alon Leviev tweet media
English
2
2
13
4.2K