Cybersecurity | Product Security Expert | Founder of intwave.com

Proxima Centauri
"From SSRF to sustained server engagement" slides and tools are now available here: github.com/dglynos/mustaine Use this to turn low-value SSRFs to MEDIUM risk issues! #appsec #infosec #cybersecurity #productsecurity
3
3
567
Dimitris Glynos retweeted
Today, Project Zero is releasing MAccConc, a tool by @tehjh that enables deterministic testing of race conditions on Linux. It can be used for fuzzing, ad-hoc exploration, regression tests and more! projectzero.google/2026/09/m…
3
114
447
40,241
Dimitris Glynos retweeted
Delete the file - the data's still there. 🔍️ Great write-up from our partners at intWave on secure deletion in littlefs. Deleting a file, or even formatting the filesystem, can leave sensitive data behind in flash. The reference disappears - the bytes don't. For products entering the EU market, that falls short of the Cyber Resilience Act's requirements for permanently removing sensitive data. intWave's recommendation is cryptographic erase and it only holds if you can truly destroy the key. That's the case for a secure element. 🛡️ With TROPIC01, keys live in tamper-resistant memory, and you erase the data by destroying the key inside the chip. That gives manufacturers a verifiable way to actually meet the bar, not just hope the flash block was clean. 🔗 Well worth a read bit.ly/4wNdwK6
2
6
629
Dimitris Glynos retweeted
Unhappy with NSA's SIGINT Enabling Project sabotaging cryptographic standards? This week you can take action to register an objection with IETF regarding an NSA-funded project to standardize ietf-tls-mlkem, a weakened version of ietf-tls-ecdhe-mlkem: nsa.2026.action.cr.yp.to/
3
27
74
8,354
#RED and #CRA require a secure data wiping mechanism in #IoT to protect the previous device owner's sensitive data. Our new post explores what works as secure wiping and what does not, when #littlefs is used in on-chip flash to store sensitive data: intwave.com/blog/2026/06/29/…
3
416
Dimitris Glynos retweeted
a new paper on efficient firmware fuzzing has arrived! Khost uses near-native execution and rehosts ARM firmware inside KVM on an ARM host, dropping overhead by over 90% when compared to QEMU-based frameworks.
1
34
206
12,381
Dimitris Glynos retweeted
Some notes on Copy Fail or CVE-2026-31431, found by Xint Code (xint.io/blog/copy-fail-linux…). This is a very stable and very straightforward exploit. It worked almost on anything I tested and in some cases, there are no Kernel patches available in stable distributions (eg. Debian 13). Debian has not yet released a patched kernel for Trixie. The upstream fix landed in mainline 6.18.22 / 6.19.12, but the backport to Debian’s 6.12 kernel series for Trixie is not available yet. The available mitigation is pretty much the only option at the moment.
1
10
37
4,553
Dimitris Glynos retweeted
I'm hiring a research intern for summer 2026 to work with me on applied cryptography research projects. This is a paid, three-month, fully remote position. Check it out, and please spread the word! symbolic.software/blog/2026-…
17
55
494
31,331
Arriving in Nuremberg for Embedded World 2026. See you at the intWave booth 5-474 intwave.com/company%20news/2…
98
intWave intern Sifis Bampionitakis found that Portainer came with default settings allowing regular users to perform a host takeover. If you're sharing your #Portainer installation with other users it's best to update to 2.39.0 LTS. For the details see: intwave.com/blog/2026/02/26/…
1
3
215
Dimitris Glynos retweeted
My CISO called me at 3 AM last Tuesday. "We caught someone." I asked, "Caught them doing what?" He said, "Typing." Let me explain. We have an employee in IT. Great worker. Always online. Never complained. Perfect Slack etiquette. One problem. His keystrokes were arriving 110 milliseconds late. One hundred and ten milliseconds. That's 0.11 seconds. The average American remote worker has 20-40ms of latency. This guy? 110ms. Every. Single. Keystroke. My security team ran the numbers. That latency doesn't come from a bad router in Ohio. That latency comes from Pyongyang. Our "Senior DevOps Engineer" was a North Korean operative. Running his work laptop through a laptop farm. In America. While he worked from a government building. In North Korea. He passed the interview. He passed the background check. He passed the vibe check. He did not pass the speed of light. Here's what people don't understand about physics: Light travels 186,000 miles per second. But it still has to go through China. And China adds latency. Since April, Amazon has caught 1,800 of these attempts. Eighteen hundred. I called an emergency meeting with my board. I said, "We need to implement Keystroke Velocity Auditing across all remote employees." They said, "That sounds invasive." I said, "You know what else is invasive? The Democratic People's Republic of Korea in your Jira tickets." They approved the budget. We now monitor keystroke timing to the microsecond. If your latency exceeds 60ms, you get a call from HR. If it exceeds 100ms, you get a call from the FBI. We've already flagged 47 employees. Turns out 44 of them just have bad Wi-Fi. 3 of them are "still under investigation." The lesson? You can fake a resume. You can fake a background check. You can fake an American accent on Zoom. But you cannot fake the speed of light. Physics is the ultimate background check. Hire accordingly.
620
3,372
18,681
1,452,573
Dimitris Glynos retweeted
Top researchers do their best to exploit bugs. "Something from Nothing - Exploiting Memory Zeroing in XNU": objectivebythesea.org/v8/tal…
17
85
8,053
Off to #hw_ioNL2025 in Amsterdam if you're around catch me in the hallways. Happy to exchange notes on CRA, supplier/vendor conformance and everything product security!
127
We've opened a position for an Application Security Engineer @ intWave. For more information see: intwave.com/careers.html#pos… #cybersecurity #appsec #hiring
219
Dimitris Glynos retweeted
Apparently the maintainer ~qix has been compromised affecting billions of installations on @npmjs Here are the top 20 packages that qix contributed to with the number of installations per months: 1.6B --> ansi-styles 1.5B --> debug 1.3B --> chalk 1.2B --> supports-color 1.1B --> strip-ansi 1.0B --> ansi-regex 828.4M --> color-convert 823.1M --> wrap-ansi 820.8M --> color-name 310.9M --> is-arrayish 245.6M --> slice-ansi 202.5M --> error-ex 133.7M --> color 118.9M --> color-string 111.5M --> simple-swizzle 50.9M --> has-ansi 17.2M --> chalk-template 1.1M --> backslash 408.2K --> handler-agent 25.1K --> strip-ansi-stream Source of claim: github.com/Qix-/node-error-e…
9
70
237
44,161
Dimitris Glynos retweeted
1/N I’m excited to share that our latest @OpenAI experimental reasoning LLM has achieved a longstanding grand challenge in AI: gold medal-level performance on the world’s most prestigious math competition—the International Math Olympiad (IMO).
393
1,283
7,237
5,730,773
Dimitris Glynos retweeted
We have @dfunc From SSRF to sustained server engagement @BSidesAth
3
5
413
Dimitris Glynos retweeted
I had a lot of fun making this challenge. I wanted to do a cloud security challenge where the cloud infrastructure is secure (IMDSv2, data perimeters), but something still allows it to be hackable and you need to know some advanced AWS security tricks to abuse it. 🤫 Try it out!
🚨THE ULTIMATE CLOUD SECURITY CHAMPIONSHIP begins today! 🥊 12 monthly challenges. One leaderboard. Challenge #1 is LIVE now, created by @0xdabbad00. Think you've got what it takes? → cloudsecuritychampionship.co…
1
9
49
4,909
On Saturday I'll be at BSides Athens, presenting "From SSRF to sustained server engagement". Don't be shy, come and say hi. Happy to discuss anything related to product security. #infosec #appsec #productsecurity
2
1
7
659