In between Physics & Computing. Fault Injection, TEEs, IoT & anything else challenging my curiosity. Founder at Raelize (@raelizecom)

Science.Art.Life.Universe
Humbled to share I will be keynoting at LangSec 2025. I am thankful for such a unique honor, at one of the most prestigious security venues in the world.
11th LangSec IEEE Security & Privacy workshop is happy to announce its preliminary program: langsec.org/spw25/program.ht… Abstracts are posted at langsec.org/spw25/abstracts.… Join us on May 15 in San Francisco!
2
14
3,529
Cristofaro Mune retweeted
huge news, dream job unlocked: I started my PhD in CS at @dartmouth last week, where I’m working with @sergeybratus & Christophe Hauser in the Trust Lab. happy&proud to step into this new era, work on my most ambitious UEFI research projects yet, collab w my incredible lab cohort
8
3
75
2,288
Just do it. Ask for it. It just works. Beautifully. As usual, the difference lies in if you're looking for a result or an understanding. And that difference only matters when you're failing at glitching your target :)
We let Claude reproduce our EM fault injection attack on Google's TV Streamer 4K — from restricted adb shell to root — using only our presentation slides and the tool manuals as input. Time to root in <15 minutes. 🤯 Full write-up 👇 raelize.com/blog/ai-fi-repro…
3
440
Cristofaro Mune retweeted
For over three years, @LennertWo and I have worked on improving fault injection attacks against STM32F2 and STM32F4 devices to make them more repeatable and reliable. It's been a roller coaster of late nights, bricked chips, and questioning our life choices, resulting in over 100 million total glitches, a new attack strategy, and flash memory recovery from dozens of locked targets with a 100% success rate. I'm super proud of what we've done and happy to officially share it with the world! grandideastudio.com/portfoli… github.com/joegrand/stm32-fa… piped.video/watch?v=4LahQG09…
6
58
237
12,813
Cristofaro Mune retweeted
In Richard Feynman's words: "I often liked to play tricks on people when I was at MIT. One time, in mechanical drawing class, some joker picked up a French curve (a piece of plastic for drawing smooth curves - a curly, funny-looking thing) and said, "I wonder if the curves on this things have some special formula?" I thought for a moment and said, "Sure they do. The curves are very special curves. Lemme show ya," and I picked up my French curve and began to turn it slowly. "The French curve is made so that at the lowest point on each curve, no matter how you turn it, the tangent is horizontal." All the guys in the class were holding their French curve up at different angles, holding their pencil up to it at the lowest point and laying it along, and discovering that, sure enough, the tangent is horizontal. They were all excited by this "discovery" - even though they had already gone through a certain amount of calculus and had already "learned" that the derivative (tangent) of the minimum (lowest point) of any curve is zero (horizontal). They didn't put two and two together. They didn't even know what they "knew". I don't know what's the matter with people: they don't learn by understanding; they learn by some other way - by rote, or something. Their knowledge is so fragile!"
58
214
2,009
107,460
Cristofaro Mune retweeted
Exploiting QSEE Vulnerabilities in Google's Wifi Pro (slide deck) raelize.com/upload/research/… Credits @tieknimmers and @pulsoid #infosec
1
26
224
14,046
Cristofaro Mune retweeted
1
2
2
664
Cristofaro Mune retweeted
That class I can highly recommend. One of the best I took!
The next opportunity to master TEE exploitation is with our upcoming TEEPwn training at CanSecWest 2026 (September 26-29 in Vancouver): secwest.net/csw26-dojos/teep… Our TEEPwn is back.. and it now also covers Google devices ;)
1
1
6
1,246
Slides from #Offensivecon2026 have been released! You may want to peek into our use of secure ranges and XPUs to pwn QSEE on Google Wifi Pro. EL3 privesc with 2 single writes. --> TEE writable from NS-EL0. Writing TEE memory with bash scripts...is quite cool ;)
Our @offensive_con 2026 slides are now publicly available: raelize.com/upload/research/… We got the highest privileges (EL3) on QSEE's Google's Wifi Pro, dumped the ROM and broke the /data partition encryption. Our technique may be applicable to other TrustZone TEEs as well. Enjoy!
15
64
7,065
Happy to share that #TEEPwn is back! We will be touching upon those software/hardware boundaries that make TEE exploitation unique. See you in Canada!
The next opportunity to master TEE exploitation is with our upcoming TEEPwn training at CanSecWest 2026 (September 26-29 in Vancouver): secwest.net/csw26-dojos/teep… Our TEEPwn is back.. and it now also covers Google devices ;)
5
17
2,294
Cristofaro Mune retweeted
Our @offensive_con 2026 slides are now publicly available: raelize.com/upload/research/… We got the highest privileges (EL3) on QSEE's Google's Wifi Pro, dumped the ROM and broke the /data partition encryption. Our technique may be applicable to other TrustZone TEEs as well. Enjoy!
Back from an amazing @offensive_con 2026! It's been an honor to be on stage and present our Google WiFi Pro/QSEE research. Thanks everyone at @Binary_Gecko for making it awesome.
14
66
14,733
Cristofaro Mune retweeted
Hall of shame: mtkclient.com/ and mtkclient.org/ claim to be developers of mtkclient. They are not and are also not authorized to use my software or my logo. Always get my software from github.com/bkerler/mtkclient. Such guys are the reason why I do not push regular updates anymore.
4
7
36
3,602
Cristofaro Mune retweeted
Secure Boot is designed to keep attackers out. This training shows you how attackers get in. 👀 Learn to identify weaknesses in Secure Boot implementations with @pulsoid at Hardwear.io Netherlands 2026. 🎟️ Register now: hardwear.io/trainings/nl-202… #HardwearNL2026
4
4
653
Cristofaro Mune retweeted
Sometimes, all it takes is a perfectly timed glitch. ⚡ Join @tieknimmers at Hardwear.io Netherlands 2026 to learn advanced fault injection techniques through hands-on labs and real-world attack scenarios. 🎟️ Register now: hardwear.io/trainings/nl-202… #HardwearNL2026
3
5
540
Cristofaro Mune retweeted
Submit your research to the room that actually knows what an EMFI probe is-before the CFP window slams shut on 22nd July. 🛠️Submit here: hardwear.io/nl-2026/cfp/ @hardwear_io #Hardweario #HardwareHacking #ReverseEngineering #InfoSec #FaultInjection #SideChannel
1
1
2
188
Cristofaro Mune retweeted
Massive respect to our @hardwear_io review panel @aseemjakhar, @pulsoid, @yossioren, @jzvw, @LennertWo, @XenoKovah who officially starts evaluating incoming research in a few days. Make their jobs harder with your best research.
1
4
168
Cristofaro Mune retweeted
Great bit of research this. Well done
1
2
259
Cristofaro Mune retweeted
One EM pulse flips a single instruction inside __sys_setresuid, and an unprivileged adb shell becomes uid 0 on Google's TV Streamer 4K (@raelizecom) raelize.com/blog/setresuid-g… #infosec
26
121
10,614
Cristofaro Mune retweeted
Slides for our OffensiveCon talk (by me and @jmartijnb) androidoffsec.withgoogle.com…: A tiny mistake in a render config ➡️ corrupt a special GPU stack pointer register ➡️ GPU hardware “renders” pixels to the AP kernel directly ➡️ pwned More presentations: androidoffsec.withgoogle.com… :)
1
43
188
13,856
Cristofaro Mune retweeted
Oh boy, it's been a while. Now with AI all the exploiteers are half-a-sleep as AI is doing all the work. But wait ! Here's some food for your brain: github.com/bkerler/exploit_m… I've added a bit more vulnerabilities (29 in total). Have fun !
3
70
362
18,355