Very quick blog post to start the week: "enhanced session" shares your host clipboard with virtual machines, even if you didn't copy/paste anything from the VM itself. Might be common knowledge but it surprised me so I'm sharing it here windows-internals.com/random-windo...
Yarden Shafir
@yardenshafir.bsky.social
A circus artist with a visual studio license
I checked and it's been 2 years since my last blog post??? So anyway, here's a quick blog post about KDP pool - the latest KDP feature that will replace the secure pool in future Windows versions: windows-internals.com/goodbye-secu...
Registration is open to all RECon classes! As usual, I’ll be teaching Windows Internals. This is the only time this year that the class is offered in North America 😊 And if windows isn’t your thing, there are lots of other great classes! recon.cx/2026/en/trai...
Looks like BlueHatIL talks are online now, so here’s my talk for anyone who wanted to learn about the latest episode of KASLR and couldn’t make it: www.youtube.com/watch?v=Dk2r...
BlueHat IL 2025 - Yarden Shafir - Look, Ma—No Privileges! How Windows Gives You Kernel Pointers...
YouTube video by Microsoft Israel R&D Center
youtube.com
For about a year now, WdBoot.sys essentially does nothing. Microsoft installs 2 versions: - \System32\drivers\wdboot.sys is the “full”, functional version - \System32\drivers\wd\wdboot.sys is the “empty” version, which is the one being updated and loaded. Does anyone know the reason behind this?
Oh look they’re going to vibe program the SSA systems. I’m sure this will be perfectly fine and will cause no issues.
SCOOP: DOGE wants to rebuild SSA's codebase in months, risking benefits and system collapse, sources tell me. The plan is to migrate all systems off COBOL quickly which would likely require the use of generative AI. www.wired.com/story/doge-r...
This cute little thing sounds like a witch laughing in a dark forest and has tried to kill me twice so far
I was told Australia is scary but didn’t expect to land and immediately get threatened by a public bus
"Zen and the Art of Microcode Hacking" Tragic signature bypass enables custom microcode loading on AMD processors, and a tool to do it. The blog is extremely well written and provides concise explanations of topics mentioned + plenty of resources! A must read. bughunters.google.com/blog/5424842...
Blog: Zen and the Art of Microcode Hacking
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
bughunters.google.com
Small anecdote about thread priorities and throttling on Windows 11: I’m downloading a large file. Estimated time left: 28 minutes. Open notepad, put it as the front window. Download time left: 57 minutes. Close notepad, browser back in front. Time left: 27 minutes.
I’m not saying you definitely have to go to @BlueHatIL this year, I’m just letting you know it’s free, by the beach and I’ll be there dropping kernel pointers to anyone who asks nicely
I work with cool people who do cool things: www.eff.org/deeplinks/20...
Meet Rayhunter: A New Open Source Tool from EFF to Detect Cellular Spying
Rayhunter is a new open source tool we’ve created that runs off an affordable mobile hotspot that we hope empowers everyone, regardless of technical skill, to help search out cell-site simulators (CSS...
eff.org
Going to a Rocky Horror show in a quiet UK town and the crowd is almost entirely old British people so I’m expecting an incredible time
Every single Canadian stereotype is correct. It is -4c (24f) today and I've seen one people walking around in shorts and another one in a short-sleeved t-shirt. Not a single person is wearing a hat.
Does anyone know companies hiring for entry level roles (in Canada/remote)? And I mean *real* entry level, not degree + 2 certs + 3 years experience “entry level”. Not just cybersecurity, any entry level roles at all, in any area.
Yesterday Microsoft fixed 6 kernel address leaks that I reported CVE-2025-21316 CVE-2025-21317 CVE-2025-21318 CVE-2025-21319 CVE-2025-21320 CVE-2025-21321
The fact those toggles have a different design is driving me crazy
You should all see this photo that my phone just reminded me of
Important news: Microsoft is working to bring SMAP into Windows www.youtube.com/watch?v=-3jx... Great talk by Joe Bialek from MORSE team
BlueHat 2024: S09: Pointer Problems – Why We’re Refactoring the Windows Kernel
YouTube video by Microsoft Security Response Center (MSRC)
youtube.com
Sudden eye infection and doctor visit is not how I planned to spend my Sunday morning. But it does mean I can spoil myself with the world’s largest pizza slice and not feel guilty about it.
My summer associate Michael Lin wrote a powershell script to help you find out which vulnerable/malicious drivers from loldrivers.io will successfully load on your HVCI-enabled system: github.com/trailofbits/...
GitHub - trailofbits/HVCI-loldrivers-check
Contribute to trailofbits/HVCI-loldrivers-check development by creating an account on GitHub.
github.com