Alexander Ermolov

617 posts

Alexander Ermolov

Alexander Ermolov

@flothrone

Security researcher, team lead & speaker. Low-level design, firmware and system software. Fuzzing & testing automation for CI/CD pipelines.

Katılım Temmuz 2017
130 Takip Edilen1.3K Takipçiler
Alexander Ermolov retweetledi
Paolo Stagno (VoidSec)
Paolo Stagno (VoidSec)@Void_Sec·
Bug count != exploitable bug. Finding != chaining. LLMs are exceptional at pattern recognition on known bug classes. They are not reasoning about novel failure modes in complex multi-component systems. The hard bugs still require humans. voidsec.com/ai-vulnerabili…
English
4
19
76
8.2K
Alexander Ermolov retweetledi
FuzzingLabs
FuzzingLabs@FuzzingLabs·
New blog post: exploring NVIDIA’s open-source GPU drivers. Kernel modules, IOCTL attack surface, mmap primitives, UVM internals, and CPU↔GPU interactions (pushbuffers → firmware). Not just graphics: a large, exposed kernel surface. fuzzinglabs.com/exploring-nvid…
FuzzingLabs tweet media
English
0
31
98
5.7K
Alexander Ermolov retweetledi
Nikolaj Schlej
Nikolaj Schlej@NikolajSchlej·
Don't want to cry wolf just yet, but this magenta-boxed part of LOTS of Insyde H2O-based UEFI FWs is highly suspicious, even if they are currently empty. Neither BootGuard nor FlashDeviceMap covers those volumes, and presence of PEI deps section suggests they are processed.
Nikolaj Schlej tweet media
English
1
7
20
2.2K
Alexander Ermolov retweetledi
Mark Ermolov
Mark Ermolov@_markel___·
Intel SGX has fallen! Its most important key is in our hands: we extracted the Global Wrapping Key from an instance of the Intel Gemini Lake platform
Mark Ermolov tweet mediaMark Ermolov tweet media
English
34
354
2K
220.9K
Alexander Ermolov retweetledi
Sam Thomas
Sam Thomas@xorpse·
I'm pleased to announce a new release of the Rust bindings for @HexRaysSA IDA SDK! This release includes v9.3 compatibility. Code: git.idalib.rs Docs: docs.idalib.rs Thank you to @yeggorv who contributed to this release, and to @HexRaysSA for their support.
English
0
20
75
5.2K
Alexander Ermolov retweetledi
Nikolaj Schlej
Nikolaj Schlej@NikolajSchlej·
Published my OFFZONE 2025 presentation slides (in Russian) on GitHub: github.com/NikolajSchlej/… Had a great time at the conf, kudos to Bi.Zone and other sponsors and crew members for organizing and running it.
English
1
5
18
2.7K
Alexander Ermolov retweetledi
ZeroNights
ZeroNights@ZeroNights·
ZeroNights CFP is open 🔥 Long time no see. ZN will take place on Nov 26, 2025 zeronights.ru The program committee is accepting talks in Offensive and SecOps tracks, rewarding exclusive in-person presentations Submit cfp.zeronights.ru/zeronights-202… @cfptime
ZeroNights tweet media
English
2
4
9
2.1K
Alexander Ermolov retweetledi
Nikolaj Schlej
Nikolaj Schlej@NikolajSchlej·
Published the third part of my blog series about Hydroph0bia (CVE-2025-4275) vulnerability, this one is about the fix as Insyde applied it, and my thoughts on improvements for it. coderush.me/hydroph0bia-pa…
English
3
35
74
9.2K
Alexander Ermolov retweetledi
Nikolaj Schlej
Nikolaj Schlej@NikolajSchlej·
Preliminary analysis shows that Insyde fixed Hydroph0bia (CVE-2025-4275) by forcefully removing the NVRAM vars that lead to exploitation during SecureFlashDxe driver startup, and setting a restrictive variable policy for them, so such vars can't be set from the OS anymore.
Nikolaj Schlej tweet media
English
1
17
79
7.7K
Alexander Ermolov retweetledi
Alexander Ermolov retweetledi
BINARLY🔬
BINARLY🔬@binarly_io·
🚨Binarly is documenting the discovery of CVE-2025-3052, a memory-corruption flaw in a Microsoft-signed UEFI module that lets attackers bypass Secure Boot and run unsigned code before the OS starts. 🔗 Full details: binarly.io/blog/another-c… 🛡️ Advisory: binarly.io/advisories/brl…
BINARLY🔬 tweet media
English
3
69
115
34.4K
Alexander Ermolov retweetledi
Nikolaj Schlej
Nikolaj Schlej@NikolajSchlej·
The embargo (12:00 UTC 2025-06-10) is over, let's start a thread on Hydroph0bia (CVE-2025-4275), a trivial SecureBoot and FW updater signature bypass in almost any Insyde H2O-based UEFI firmware used since 2012 and still in use today. English writeup: coderush.me/hydroph0bia-pa…
English
3
92
200
20.1K
Alexander Ermolov retweetledi
Adam 'pi3' Zabrocki
Adam 'pi3' Zabrocki@Adam_pi3·
Together with @AlexTereshkin we managed to summarize NVIDIA Offensive Security Research (OSR) work on breaking BMC (reference to our DefCon talk youtube.com/watch?v=dbJQIQ…). This blog post also includes a link to the full paper.
YouTube video
YouTube
NVIDIA AI Infrastructure@NVIDIAAIInfra

Baseboard Management Controllers (BMCs) are vital for remote server management, but they can also be a significant security risk. Explore findings and recommendations to safeguard your #datacenter infrastructure from NVIDIA's Offensive Security Research team. ➡️ nvda.ws/3HsQOme

English
0
13
28
6.3K
Alexander Ermolov retweetledi
raptor
raptor@0xdea·
If for some reason #semgrep doesn’t fit your use case, here’s a port of my C vulnerability research ruleset to #weggli: github.com/0xdea/weggli-p… Read the linked blog post and check it out!
English
1
21
78
5.8K
Alexander Ermolov retweetledi
Andrey Konovalov
Andrey Konovalov@andreyknvl·
Gave a talk on external fuzzing of Linux kernel USB drivers with syzkaller at SAFACon by @SAFATeamGmbH. Includes a demonstration of how to rediscover CVE-2024-53104, an out-of-bounds bug in the USB Video Class driver. Slides: docs.google.com/presentation/d…
Andrey Konovalov tweet mediaAndrey Konovalov tweet mediaAndrey Konovalov tweet media
English
3
55
220
19.4K