About
Over the past decade, I turned my hacking hobby into a career. My interests and experience span reverse engineering, malware analysis, embedded and mobile security, web hacking, cryptography, and computational complexity. I also teach a biannual workshop on assembly, x86/x64 reverse engineering, and black-box research.
I hold an M.Sc. in Theoretical Computer Science from the Weizmann Institute, and presented my thesis at the 14th ITCS conference at MIT.
Today I’m the Head of Research at Astrix Security (acquired by Cisco), where I research how the world implements connectivity between (and by) non-human identities and AI Agents, and specifically when it breaks. That line of work led to GhostToken, a 0-day in Google Cloud Platform that let a malicious app hide itself as an invisible, unremovable trojan on any Google account. I presented it at DEF CON 31. I presented my professional and personal cyber research at DEFCON, RSAC, Reversim Summit, fwd:cloudsec, BSides, and various OWASP chapters.
I was part of the 2016 “Unknown6” group that broke its anti-cheating system, by reverse-engineering its anti-cheat and network protocol from scratch. I presented this journey at DEF CON 33 as Breakin’ ‘Em All and wrote up here in Part 1 and Part 2.
A few other side treks along the way I wrote about or will in the future:
- I hacked vehicle infotainment systems at a previous job.
- I turned a OnePlus 5T with a broken screen into an ad blocker for my home network, alongside a privacy-focused meta search engine.
- I performed open-heart surgery on my (one month out-of-warranty) Nintendo Switch to replace its fan — a small nod to the “Right to Repair” movement.
- After the LLM boom started, I created a set of LLM-based automations: a personal discovery playlist in Spotify, personal Spanish teacher that adapts to me, an RSS-filter mechanism that learns using my feedback and a personal file-manager and investments assistant.
This blog is where I practice writing about things I love: reverse engineering, security research, CTFs, and other assorted technological side treks.