@_markel___i
iAccount based inSweden!
About this account
- Account based in
- Sweden
- Connected via
- Russian Federation Android App
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
I research security of Intel platforms. I don't work for Intel
Москва, Россия
Joined September 2014
- Tweets1.6K
- Following132
- Followers12.2K
- Likes2.3K
Pinned Tweet
Finally, the casket is opened: we (+@h0t_max and @_Dmit) have extracted Intel x86 microcode! One more Intel "top secret" information gets revealed...
github.com/chip-red-pill/glm…
I’m so happy for our hardware Positive Labs (@ivannikovp and others), who are helping me with my Intel research. Together, we’re going to break Intel desktop CPUs!
Missed one more from the drop lol
CVE-2026-43783 - macOS LPE via DesktopServicesHelper. One XPC request -> arbitrary chown -> root.
PT SWARM writeup:
ptswarm.com/blog/cve-2026-43…
My blog:
andrd3v.github.io/cve-2026-4…
PoC:
github.com/andrd3v/CVE-2026-…
Mark Ermolov retweeted
After 4 years of effort, I'm happy to announce that one of the final secrets of the PS2 has been broken wide open!
It's been a long process of decapping, optical dumping, and now at last a software solution.
Thank you Libby for finding the exploit from our dirty optical dumps!
Anyone who has carefully read the Intel article on XuCode (intel.com/content/www/us/en/…) might well wonder: where (from which memory) MCHECK executes? (1/x)
It's not L2 or C6SRAM of CPU module, it's a completely different memory outside of CPU core used also to cache requests to memory controller (D-unit) from all agents including iGPU (5/x)
Mark Ermolov retweeted
Looks like AMD supports "Red Unlock" too! I wonder how HSP_DEBUG_UNLOCK syscall really works ;)
It turns out that Intel Gemini Lake Refresh platforms were supported by the new Intel SGX PCS (Provisioning Certification Service) remote attestation mechanism based on DCAP/ECDSA
This means we have compromised the actual Intel SGX 2.0, and anyone who hoped that only the older SGX was vulnerable was sorely mistaken...
intel.com/content/www/us/en/…
Mark Ermolov retweeted
New exploit: “xor dword [0xf80c2094], 1<<22”
Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.
github.com/xoreaxeaxeax/skit…
Mark Ermolov retweeted
⭐️My PoC exploit for CVE-2026-31695 in the Linux kernel is ready
🏁I managed to make it absolutely stable on Fedora 44 Server despite an elusive race condition during the exploitation
🛠This vuln existed for ≈5 years before I fixed it upstream
⚡️Gonna publish a detailed article!
I guess the TSE stores the encryption keys in the "Secure" Key Storage inside CSME...
Data-at-rest protection, lower CPU overhead. Intel Total Storage Encryption (Intel® TSE) strengthens protection with AES-256 encryption, hardware-protected keys and 70% average CPU cycle savings vs. software-based BitLocker. #IntelSecurity
🎥Learn more: youtu.be/owRK0Dm6Uh4?si=W3xC…
Mark Ermolov retweeted
BTW I still keep updating the VMX capabilities table at pulsedbg.com/vmx.html
Check out new features for Panther Lake CPUs.