@aurelseci
iAccount based inFrance
About this account
- Account based in
- France
- Connected via
- France Android App
Account-level information from X, not a live location or the device used for a specific post.
Professor (full) of computer insecurity @s3eurecom. Can be seen sometimes procrastinating on Twitter. @aurelsec@infosec.exchange @aurelsec.bsky.social
In your computer already.
Joined August 2011
- Tweets6.4K
- Following1.7K
- Followers2.3K
- Likes44.2K
Pinned Tweet
"Screaming Channels" paper #CCS18/@BlackHatEvents is online s3.eurecom.fr/tools/screamin…
Electromagnetic side channels from a CPU can leak to a radio transmitter. CPU and radio transmitters are often integrated (think WiFi, BlueTooth)
We recover an AES key from 10 meters on a BT chip
Aurélien Francillon retweeted
🎯 Vuln researcher? Share your experience and views!
This is an anonymous sociological survey on vulnerability researchers — all profiles, all nationalities, no judgment. Co-designed with daily practitioners.
~15 min · Tor accessible · Funded by public research
Aurélien Francillon retweeted
New exploit: “xor dword [0xf80c2094], 1<<22”
Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.
github.com/xoreaxeaxeax/skit…
Aurélien Francillon retweeted
"Insecurity of Cellular Basebands" analyzes prior work on vulnerability discovery and attack surfaces; presenting a taxonomy of vulnerabilities, review state-of-the-art analysis techniques, including static analysis, over-the-air testing, and emulation.
usenix.org/system/files/woot…
Aurélien Francillon retweeted
Amazing work by @henri2h and @aurelsec. Great to see SIMs and the SIM interface included in the attack surface. :)
#WOOT26 SoK: Insecurity of Cellular Basebands
usenix.org/system/files/woot… [PDF]
Aurélien Francillon retweeted
Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. The security community spent 20 years asking: what could go wrong? Turns out: a lot.
Aurélien Francillon retweeted
#ChatControl 1.0 and 2.0 Explained: There is not one proposed “Chat Control” law — there are two, and they are moving through the EU institutions in parallel. This page untangles the two.
fightchatcontrol.eu/chat-con…
Aurélien Francillon retweeted
Dans la recherche disponible tout indique qu’une telle loi ouvre la porte à un grave risque : celui de l’augmentation du nombre de décès et de blessés dans le cadre des interventions de police du quotidien. Signer ici petitions.assemblee-national…
Aurélien Francillon retweeted
Huge congratulations to Prof. @paolopapotti for being awarded an @ERC_Research Advanced Grant 2025 and for securing @EURECOM’s 8th ERC Advanced Grant with GENESIS, a remarkable achievement! #DataScientist shorturl.at/4npcf
Aurélien Francillon retweeted
Submit a poster to any offensive security topics you'd like to discuss with or show to the WOOT audience! usenix.org/conference/woot26…
🤖 Made with AI
Aurélien Francillon retweeted
📣 SynSec 2026 Cycle 2 is OPEN.
The Conference of Synthetic Security Research: AI agents do the research. AI agents do the peer review.
🗓 Deadline: July 23, 2026 (AoE)
What it is, and how to submit 🧵👇
Aurélien Francillon retweeted
For 19 years, GPS satellites have secretly broadcast a “numbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now. lsc-pagepro.mydigitalpublica…
Aurélien Francillon retweeted
We are starting to upload the videos of this year's talks.
And nothing better to start with than our two keynotes :
youtube.com/watch?v=fbicylnh… and youtube.com/watch?v=obdPo6lP… from @misc0110 and @aurelsec
Aurélien Francillon retweeted
Our paper "CFIghter: Automated Control-Flow Integrity Enablement and Evaluation for Legacy C/C++ Systems" will be presented at the 2026 ACM Secure Development Conference (SecDev '26) in July.
Aurélien Francillon retweeted
amd.com/en/resources/product… Xen advisory posted, should be a kernel fix here any minute now I assume
Aurélien Francillon retweeted
The RF world is insane.
Researchers recovered AES-128 keys from a Bluetooth chip by listening to its own antenna from 10 meters away.
Crypto-engine switching noise couples into the RF chain, rides the 2.4 GHz carrier, and leaks out as radio.
Aurélien Francillon retweeted
Vie privée ou #sécurité : jusqu’où faut-il aller ? un article par @aurelsec et ses co-auteurs aoc.media/analyse/2026/04/29… #chatcontrol #cryptographie #chiffrement
Aurélien Francillon retweeted
THCON 2026 Poster Reveal
It’s here !
👀 Full program on the website : thcon.party/program/
🎟️ Tickets are live : thcon.party/tickets/
See you there !
Aurélien Francillon retweeted
🇫🇷Ils ont obtenu un nouveau vote : RN, PS, LR, RE, MoDem, ils impose un nouveau vote sur #ChatControl demain à 11h. mepwatch.eu/10/vote.html?v=1…
Un appel demain peut encore faire changer d’avis des eurodéputés. Dernière chance d’appeler leur bureau :
👉 fightchatcontrol.eu
Aurélien Francillon retweeted
“Backdoors in your smartphones? Why? How? Not?” by @aurelsec
This talk examines what backdoors really mean from a systems and protocols perspective, and discusses concrete technical proposals
📅 May 5th & 6th, 2026 🔗 Tickets: thcon.party/tickets/
Details 👇🏻
Aurélien Francillon retweeted
Hello security researchers! Like it or not, agentic AI is here. It’s time to explore its impact on novel, academic research in cybersecurity. To this end, we’re launching the Conference for Synthetic Security Research (synsec.org). Researchers, start your agents!