
Matthias Deeg
@matthiasdeeg
Followers
555
Following
889
Media
65
Statuses
289
Interested in IT and likes to see whether security assumptions in soft-, firm-, or hardware hold true when taking a closer look. 📚author // https://t.co/0pUoUrDxIV
Germany
Joined May 2019
RT @iiiikarus: Colleague of mine just released a cool tool to make #EMBA installations a breeze. It will setup a clean #Kali VM (qemu/Virtu….
github.com
Automatable setup of EMBA installations. Contribute to SySS-Research/emba-builder development by creating an account on GitHub.
0
1
0
RT @dcrainmakerblog: COROS has confirmed a substantial set of security vulnerabilities, impacting not just the watch, but COROS online acco….
0
20
0
RT @BartimaeusvUruk: Two blog articles about fault injection vulnerabilities of the nRF54L15 and the stm32l051 released:. .
blog.syss.com
The term “fault injection” refers to a class of vulnerabilities in which attackers deliberately attempt to create error states in systems. These error states lead to abnormal system behavior and can...
0
14
0
A new tech blog article by my colleague @BartimaeusvUruk about an electromagnetic fault injection attack against an nRF54L15 by Nordic Semiconductor is now also online. If you want to know more about EMFI or the security issue SYSS-2025-022 have a look:.
blog.syss.com
Electromagnetic fault injection, or EMFI for short, is a technique used to intentionally introduce faults into electronic systems. By directing high-intensity electromagnetic pulses (EMPs) at a...
0
8
14
RT @moritz_abrell: Today we published the blog post about the BLE analysis of a COROS PACE3 sports watch:. #CVE #V….
blog.syss.com
In this blog post, we describe the Bluetooth analysis of the COROS PACE 3 sports watch and the security vulnerabilities we found during this research.
0
6
0
I'm looking forward to attending No Hat Con for the first time this October and also visiting the beautiful city of Bergamo. Thank you for the invitation and for giving me the opportunity to present my research.
<CFP Update> Our first speaker is @matthiasdeeg with "Your Security Update is Not Secure Enough - Hacking Portable Storage Devices Again'. Welcome on board!.
0
0
4
RT @moritz_abrell: Check out the discovery and analysis of CVE-2025-33073 by my colleagues. A vulnerability with real-world impact. https:….
blog.syss.com
In this blog article, further technical details concerning the Microsoft Windows SMB security vulnerability CVE-2025-33073 are presented.
0
2
0
As announced yesterday, the blog article by my colleagues Stefan Walter and Daniel Isern with further technical details concerning the Windows SMB security vulnerability CVE-2025-33073 is now published.
blog.syss.com
In this blog article, further technical details concerning the Microsoft Windows SMB security vulnerability CVE-2025-33073 are presented.
0
3
5
You can find their SySS security advisory here:. They have also written a blog article with more technical details that will be published on the SySS Tech Blog ( soon.
blog.syss.com
SySS Tech Blog
0
0
6
RT @iiiikarus: Finally! A solid automotive Ethernet adapter that is build with Linux in mind. No weird drivers and tools required. https:/….
crowdsupply.com
An easy-to-use Automotive Ethernet interface for engineers, researchers, and enthusiasts
0
1
0
RT @BartimaeusvUruk: #findus 1.11.0 released:.- Added a function to generate two fully configurable pulses with the crowbar stage (arm_doub….
github.com
Added a function to generate two fully configurable pulses with the crowbar stage (arm_double) This could be used to double-glitch a target configuration is similar as for the multiplexing method ...
0
2
0
My colleague @BartimaeusvUruk was successful with some more voltage glitching and electromagnetic fault injection attacks and published one security advisory for the STM32L051 and one for the nRF54L15 today. You can find a short German blog article here:.
syss.de
Fault Injection dient dazu, Fehlerzustände in Systemen zu erzeugen. Die Fehlerzustände können ausgenutzt werden, um Sicherheitsbeschränkungen zu umgehen.
1
3
9
My crosshairs for Windows was updated today.
github.com
Simple free and lightweight open-source crosshairs application for Windows - mdeeg/Fadenkreuz
0
0
1
I've also published a new SySS PoC Video demonstrating a voltage glitching attack using the open-source tool chain consisting of the glitching device Pico Glitcher and the fault-injection library findus, both developed by my colleague @BartimaeusvUruk .
0
3
7
Today, my new blog article titled "Voltage Glitching with the Pico Glitcher and Findus" was published. You can find it on the SySS Tech Blog:.
blog.syss.com
Fault injection attacks against microcontrollers can be very rewarding for attackers, if they are successful. In this article, a new hardware device for performing voltage glitching attacks, the Pico...
0
3
7
RT @BartimaeusvUruk: New blog post about voltage glitching the Raspberry Pico v2 with a Raspberry Pico v1. How hard could it be?. https://t….
0
4
0
RT @moritz_abrell: Check out our today published CVEs on @AudioCodes Session Border Controller and One Voice Operation Center. Unauthentic….
syss.de
AudioCodes Mediant SBC und das One Voice Operation Center (OVOC) beinhalten Schwachstellen, über welche u. a. Passwörter entschlüsselt werden können.
0
1
0
The shown voltage glitching attack is not new and has been demonstrated many times in the last few years by different researchers using different voltage glitching setups. Thanks to @ghidraninja, @colinoflynn, @adamcatley, and many others for sharing their knowledge and tools.
2
1
2