@_markel___

I research security of Intel platforms. I don't work for Intel

Москва, Россия
Joined September 2014
Finally, the casket is opened: we (+@h0t_max and @_Dmit) have extracted Intel x86 microcode! One more Intel "top secret" information gets revealed... github.com/chip-red-pill/glm…
19
368
25
963
Here is what the differential clock signaling actually looks like for Intel CPUs...
12
3
1
159
7,510
I’m so happy for our hardware Positive Labs (@ivannikovp and others), who are helping me with my Intel research. Together, we’re going to break Intel desktop CPUs!
3
5
74
3,599
Mark Ermolov retweeted
Missed one more from the drop lol CVE-2026-43783 - macOS LPE via DesktopServicesHelper. One XPC request -> arbitrary chown -> root. PT SWARM writeup: ptswarm.com/blog/cve-2026-43… My blog: andrd3v.github.io/cve-2026-4… PoC: github.com/andrd3v/CVE-2026-…
2
8
50
4,007
After 4 years of effort, I'm happy to announce that one of the final secrets of the PS2 has been broken wide open! It's been a long process of decapping, optical dumping, and now at last a software solution. Thank you Libby for finding the exploit from our dirty optical dumps!
109
682
19
7,657
365,679
Here is how the EREPORT SGX leaf signs the report
1
5
57
2,761
Anyone who has carefully read the Intel article on XuCode (intel.com/content/www/us/en/…) might well wonder: where (from which memory) MCHECK executes? (1/x)
2
1
22
2,155
It's not L2 or C6SRAM of CPU module, it's a completely different memory outside of CPU core used also to cache requests to memory controller (D-unit) from all agents including iGPU (5/x)
1
1
4
481
We think that desktop/server CPUs also have this 'February' memory and really want to read it )) (6/6)
5
392
Mark Ermolov retweeted
Looks like AMD supports "Red Unlock" too! I wonder how HSP_DEBUG_UNLOCK syscall really works ;)
3
7
102
7,631
Intel SGX total hack paper is in progress and I don't think Intel will like it ))
10
69
6
505
35,809
It turns out that Intel Gemini Lake Refresh platforms were supported by the new Intel SGX PCS (Provisioning Certification Service) remote attestation mechanism based on DCAP/ECDSA
1
2
1
28
2,565
This means we have compromised the actual Intel SGX 2.0, and anyone who hoped that only the older SGX was vulnerable was sorely mistaken... intel.com/content/www/us/en/…
3
12
1,003
Mark Ermolov retweeted
New exploit: “xor dword [0xf80c2094], 1<<22” Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed. github.com/xoreaxeaxeax/skit…
168
1,068
184
8,207
1,096,564
Mark Ermolov retweeted
⭐️My PoC exploit for CVE-2026-31695 in the Linux kernel is ready 🏁I managed to make it absolutely stable on Fedora 44 Server despite an elusive race condition during the exploitation 🛠This vuln existed for ≈5 years before I fixed it upstream ⚡️Gonna publish a detailed article!
4
19
1
178
11,202
Hacking into an Intel desktop platform...
8
5
156
8,253
I guess the TSE stores the encryption keys in the "Secure" Key Storage inside CSME...
Data-at-rest protection, lower CPU overhead. Intel Total Storage Encryption (Intel® TSE) strengthens protection with AES-256 encryption, hardware-protected keys and 70% average CPU cycle savings vs. software-based BitLocker. #IntelSecurity 🎥Learn more: youtu.be/owRK0Dm6Uh4?si=W3xC…
1
9
2,304
Mark Ermolov retweeted
BTW I still keep updating the VMX capabilities table at pulsedbg.com/vmx.html Check out new features for Panther Lake CPUs.
1
5
18
2,509