BINARLY🔬 Profile Banner
BINARLY🔬 Profile
BINARLY🔬

@binarly_io

Followers
3,694
Following
366
Media
180
Statuses
1,318

⛓️Binarly is the world’s most advanced automated software supply chain security platform.

Santa Monica, CA
Joined May 2019
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@binarly_io
BINARLY🔬
2 months
🚨New! "PKFail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem." #PKfail is a supply-chain issue affecting x86/ARM devices around the globe. Blog: Full report: A free scanning tool:
4
67
92
@binarly_io
BINARLY🔬
2 days
🏆Our REsearch team is proud to have stepped onto the @LABScon_io keynote stage for the third year! 🔐Huge shoutout to our speakers, @pagabuc and @matrosov , who presented “ #PKFAIL : Supply-Chain Failures in Secure Boot Key Management.” 🔥slides:
Tweet media one
Tweet media two
0
6
10
BINARLY🔬 Retweeted
@matrosov
Alex Matrosov
2 days
Traditional static analysis tools will not help beyond simple SDLC cases. The CodeQL datalog approach is cool, but only a few people can develop valuable rules on it. Semgrep isn't very helpful beyond simple cases with its taint analysis limitations on C/C++ & performance issues.
2
5
10
BINARLY🔬 Retweeted
@matrosov
Alex Matrosov
4 days
IDAlib is the first idiomatic Rust bindings library for @HexRaysSA IDA SDK, helping go beyond C/C++ or Python in RE automation. Huge thanks to @xorpse for making it happen! Binarly team ❤️ Rust 🙌 🛠️use idalib::idb::*; 🦀
1
19
60
@binarly_io
BINARLY🔬
4 days
Our REsearch team is thrilled about the new IDA v9.0! #efiXplorer is fully compatible with v9.0 and still supports IDA v8.4🚀 🔬 We are thrilled to announce IDAlib — idiomatic Rust bindings for the IDA SDK 🎉 Kudos to @xorpse ! ⚙️
Tweet media one
0
13
59
@binarly_io
BINARLY🔬
5 days
🔐Update on #PKfail ! Our detection service has scanned over 10,336 unique firmware images and detected 869 impacted instances — that’s 8.4%! All detected unique keys are now showcased on the service👇
Tweet media one
0
6
10
BINARLY🔬 Retweeted
@dinodaizovi
Dino A. Dai Zovi
8 days
Good example of why your OOB management network that these BMC and IPMI interfaces are attached to is extremely security sensitive
3
11
30
BINARLY🔬 Retweeted
@matrosov
Alex Matrosov
8 days
💥PoC is now public! target = " https://{ip_address}/cgi/login.cgi" command = "touch /tmp/BRLY" libc = 0x76283000 # we try to guess gadget1 = 0x000D8874 # pop {r0, r1, r2, r3, fp, pc}; gadget2 = 0x001026D4 # mov r0, sp; blx r3; system = 0x0003C4D4
2
86
248
@binarly_io
BINARLY🔬
9 days
🚨New! "CVE-2024-36435 Deep-Dive: The Year’s Most Critical BMC Security Flaw." 🔥Classic buffer overflow vulnerabilities resurface in BMCs, remotely opening the gates from the castle. 🏆Kudos to @AlexTereshkin for the initial discovery and disclosure!
1
36
90
BINARLY🔬 Retweeted
@Cisco_Invests
Cisco Investments
11 days
We're always on the hunt for innovative startups with game-changing solutions. Check out the companies w/cutting-edge tech, making sure @Cisco customers have the best tools to stay ahead and discover new business opportunities.👇 🔗 #CiscoInvests
Tweet media one
0
3
8
BINARLY🔬 Retweeted
@matrosov
Alex Matrosov
13 days
Don’t miss your chance to be a part of such an amazing event focused on program analysis 🔬
0
7
17
BINARLY🔬 Retweeted
@SentinelOne
SentinelOne
15 days
⛓️ @binarly_io 's @matrosov and @pagabuc unveiled PKFAIL, a critical firmware supply-chain issue affecting hundreds of devices due to vendors shipping default test keys. #LABScon24 📄 Read more about their research in a blog post published the same day:
Tweet media one
1
5
12
BINARLY🔬 Retweeted
@labscon_io
LABScon
16 days
Binarly researchers Alex Matrosov and Fabio Pagani with some fresh details on the PKfail supply chain exposure @binarly_io @matrosov @pagabuc
Tweet media one
Tweet media two
0
8
30
@binarly_io
BINARLY🔬
16 days
NEW! Repeatable Failures: Test Keys Used to Sign Production Software…Again? 🔥Full details:
@matrosov
Alex Matrosov
16 days
🚨In just a few hours at #LABScon , we’ll be unveiling a high-impact vulnerability and a critical security discovery affecting platform trust on Supermicro servers. Stay tuned and watch our REsearch blog!
Tweet media one
2
17
41
0
18
23
BINARLY🔬 Retweeted
@matrosov
Alex Matrosov
16 days
🚨In just a few hours at #LABScon , we’ll be unveiling a high-impact vulnerability and a critical security discovery affecting platform trust on Supermicro servers. Stay tuned and watch our REsearch blog!
Tweet media one
2
17
41
BINARLY🔬 Retweeted
@binarly_io
BINARLY🔬
1 month
We believe in giving back to the research community that drives progress! We are proud to support OpenSecurityTraining2 in advancing security education and knowledge sharing.
0
10
28
BINARLY🔬 Retweeted
@binarly_io
BINARLY🔬
18 days
📰 #PKfail making more industry-wide impact and news
0
3
6
BINARLY🔬 Retweeted
@matrosov
Alex Matrosov
17 days
More updates will be coming tomorrow at the #LABScon stage. The problems related to the test and non-production keys are much bigger than we initially thought.
0
11
13
BINARLY🔬 Retweeted
@binarly_io
BINARLY🔬
19 days
🚨NEW: "PKfail Two Months Later: Reflecting on the Impact." by @pagabuc Based on data 📈 🖥️10,095 unique firmware images uploaded 🔥791 of which contained an untrusted PK 🛟9304 is safe 💥8.5% vulnerable rate 🔬Full report:
Tweet media one
1
8
16
BINARLY🔬 Retweeted
@matrosov
Alex Matrosov
19 days
Heading to #LABScon to present our latest REsearch with @pagabuc on #PKfail new data points and discoveries!
0
7
26