Captures flags with @TeamTasteless. Assistant Professor at @unibirmingham and maintainer of FirmWire & avatar2.

Our USENIX Security'26 Paper "Download More RAM" is now available! In this paper, we introduce a new memory aliasing attack, fully from software and completely subverting Windows OS Security. Full paper with more information and case studies at: usenix.org/system/files/usen…
1
8
40
3,044
Our @wootsecurity'26 paper "CATana" is now available: usenix.org/system/files/woot…! In the paper, we find that some phones and many IoT devices execute AT commands sent by the SIM, leading to a wide range of consequences from DoS over 2G downgrade to device compromise.
2
8
20
4,058
Amazing work by @henri2h and @aurelsec. Great to see SIMs and the SIM interface included in the attack surface. :)
#WOOT26 SoK: Insecurity of Cellular Basebands usenix.org/system/files/woot… [PDF]
2
6
413
Together with @ScepticCtf, we are running our baseband reversing and fuzzing training again at @hardwear_io NL'26! Details below:
Learn how to reverse engineer cellular firmware, build emulation environments, and fuzz real-world protocol parsers with Marius Muench and Tobias Scharnowski at Hardwear.io Netherlands 2026. 🎟️ Register now: hardwear.io/trainings/nl-202… #HardwearNL2026 #HardwearTrainings
3
250
The recording of our @WEareTROOPERS'26 talk is online! In "A SIM Hacking Odyssey: Can a SIM hack YOU", Tomasz and I describe our journey in SIM-originating attacks, which started more than 4 years ago! Video: piped.video/Rysq35GUumY Slides: troopers.de/downloads/troope…
2
2
20
1,839
nSinus-R (@nsr@infosec.exchange) retweeted
Overcoming State: Finding Baseband Vulnerabilities by Fuzzing Layer-2 【PDF】 i.blackhat.com/BH-US-24/Pres…
1
16
101
7,105
Great summary of the work we recently shared at @WEareTROOPERS. For everyone interested in this, stay tuned for our upcoming @wootsecurity paper "CATana: On the Dangers of SIM-Originating AT Commands": usenix.org/conference/woot26…
How a SIM can (and will) hack you: Security analysis of SIMs, attacks, and tools for research. 👨🏻‍💻🎫📱🩻👾 More details on: LinkedIn: linkedin.com/posts/dlaskov_c… Substack: it4sec.substack.com/p/how-a-…
5
22
4,383
nSinus-R (@nsr@infosec.exchange) retweeted
A virtual iteration of our training on fuzzing custom embedded systems is coming up end of March. One cool story about this: The participants of our training in 2024 exploited a bunch of devices at Pwn2Own Tokyo 2026!🔥 Details: ringzer0.training/countermea…
1
1
10
1,383
In case you missed the live version, the recording of our talk is now available: media.ccc.de/v/39c3-of-boot-…!
En route to #39c3 - come to our talk at 4pm! I will only be there today and tomorrow, but happy to meet-up & chat. Also, if you are at #39c3 and often dump SPI flash-chips please let me know, I might have something for you that I'm looking for feedback on 🙂
1
10
1,173
nSinus-R (@nsr@infosec.exchange) retweeted
En route to #39c3 - come to our talk at 4pm! I will only be there today and tomorrow, but happy to meet-up & chat. Also, if you are at #39c3 and often dump SPI flash-chips please let me know, I might have something for you that I'm looking for feedback on 🙂
2
7
54
11,878
nSinus-R (@nsr@infosec.exchange) retweeted
🤩A hush settles as the RP2350’s challengers—Marius Muench and Thomas Roth—begin their story What started as a public hacking challenge became a trail of breakthroughs, from unverified vector boots to secrets pulled straight out of OTP memory. 👉hardwear.io/netherlands-2025… #RP2350
1
4
628
nSinus-R (@nsr@infosec.exchange) retweeted
🔍 It’s reverse engineering mayhem as participants trace how basebands whisper to each other inside the Shannon modem, mapping flows that feel straight out of a sci-fi network core. In action Marius Muench; Tobias Scharnowski at #hw_ioNL2025 👉hardwear.io/netherlands-2025… #fuzzing
4
10
1,239
Our @defcon'33 talk is online: piped.video/FXIScbxJTZw! Ever wondered how to get banned from online games without cheating? We've got you covered! Check out this talk for fun hacks tripping off modern anticheats. Joined work with @Cowtickle & @TomChothia.
1
5
12
3,048
More information about our research, slides, and additional resources are available at: game-research.github.io
224
nSinus-R (@nsr@infosec.exchange) retweeted
I absolutely love this paper, so much reverse engineering alpha the researchers who won the rpi hacking challenge came together to describe in detail how they overcame the defenses of a secure-by-design chip, incl. custom laser fault injection and single instruction skips
4
49
192
16,016
nSinus-R (@nsr@infosec.exchange) retweeted
We have an exciting piece of vulnerability research 🕵️‍♂️ to share, conducted in collaboration with external researchers from VU Amsterdam. Find out more about the L1TF vulnerability, a CPU vulnerability on some Intel CPUs (Skylake and older). goo.gle/3I69VDv
4
41
146
16,059
nSinus-R (@nsr@infosec.exchange) retweeted
#SecureBoot is the clubs bouncer🕺🚫—but a double glitch is like sneaking past while he blinks That’s the magic (and mischief) in the #RP2350. @nSinusR & @ghidraninja will show you how it happened at #hw_ioNL2025 and why fixing it makes chips stronger 👉hardwear.io/netherlands-2025…
3
10
1,023
nSinus-R (@nsr@infosec.exchange) retweeted
📶 Ever wondered how your phone seamlessly switches between 2G, 3G, 4G and 5G? Join Marius Muench & @ScepticCtf at #hw_ioNL2025 to peel back the layers of #basebandfirmware to show how your device talks to the world—from older 2G networks to modern 5G 👉hardwear.io/netherlands-2025…
3
9
1,215
Our work on solving @Raspberry_Pi's RP2350 Hacking Challenge is now online! 5 different attacks and lots of lessons learned. Joint work with Aedan Cullen, Kévin Courdesses, @ghidraninja and @azonenberg! Full paper: usenix.org/system/files/woot… Source code: github.com/bhamsec/woot25-rp…
1
37
135
20,448
nSinus-R (@nsr@infosec.exchange) retweeted
new baseband rehosting research just dropped! BaseBridge dynamically identifies relevant regions from a memory dump which are then loaded into the FirmWire emulator to enrich global state. this leads to way higher fidelity, more coverage during fuzzing, and finally more bugs.
1
22
100
8,502