7 May 2024

Multiple vulnerabilities in RIOT OS

“Where there is parsing, there are […]

26 March 2024

Frida on Java applications and applets in 2024

As explained in Federico‘s latest article, […]

5 March 2024

Multiple vulnerabilities in RT-Thread RTOS

“Security is in the mind of […]

14 February 2024

Seemposium Podcast interview

The fine folks at Seemposium Sicuranext […]

8 February 2024

Java applet + serialization in 2024! What could go wrong?

Recently, during a red team engagement […]

11 January 2024

A collection of weggli patterns for C/C++ vulnerability research

“No one cares about the old […]

30 November 2023

DevSecCon Italy video

Hi! Yesterday I spoke at DevSecCon […]

28 November 2023

Big update to my Semgrep C/C++ ruleset

“The attack surface is the vulnerability. […]

7 November 2023

OST2, Zephyr RTOS, and a bunch of CVEs

“When hackers tell me it’s so […]

24 October 2023

Customizing Sliver – Part 3

In this third and final post […]

24 October 2023

Customizing Sliver – Part 2

Hello! This is the second part […]

24 October 2023

Customizing Sliver – Part 1

Lately I’ve been conducting research into […]