In 2018, Israel presented some materials allegedly intended to demonstrate Iran's capabilities for developing nuclear weapons. During that presentation the Israeli PM showed a video of an implosion simulation generated using the LS-DYNA (ls-prepost) software, the same kind of simulation and software targeted by Fast16. After analyzing the video I found that the uranium core is being compressed to…
In 2024, the focus was on nuclear energy with " A Practical Analysis of Cyber-Physical Attacks Against Nuclear Reactors ", and this year it is the turn of solar photovoltaic generation, completing the coverage of the carbon-free energy sources I consider crucial for Europe's energy sovereignty. I hope it will be useful and interesting, just as the previous one was for some people. The paper is…
Index Introduction PhysicsFiction state_monitor state_physics state_physics #2 — A key part state_physics #3 — The attack What about the target? Conclusions Introduction This past friday Juan Andres Guerrero-Saade and Vitaly Kamluk published an extraordinary piece of research, which uncovered a 20 years old sophisticated malware, plausibly attributed to state actors. What is outstanding about this…
A Swiss E-Voting Mystery: USB Glitch or Sabotage? Imagine that you're a member of an electoral board, and the cryptographic materials required to decrypt votes, coming from an e-voting system, are stored on a USB key that happens to fail. But wait...because another USB key fails, and then another one...That's precisely what happened in the Swiss canton of Basel, now under a criminal investigation…
TL;DR This post describes the conditions and technical details that enable Adversary-in-The-Middle (AiTM) attacks against Signal when Censorship Circumvention is enabled. However, despite the ability to decrypt TLS traffic between the target and the Signal backend, the end-to-end encryption (E2EE) scheme implemented by Signal prevents attackers from accessing user content such as conversations,…
The "mystery" of what happened at the "Núñez de Balboa" photovoltaic power plant is, to this day, one of the most significant unresolved questions of the Iberian blackout. In this post I elaborate on this issue by using open-source intelligence, official reports and a bit of reverse engineering. Introduction In a recent official hearing of the Spanish Senate commission investigating the blackout,…
A couple of months ago I spent some time reading code from Signal (libsignal, Android/iOS apps, server, etc.) and came across some interesting issues, which I reported to @Security. This post describes the case of the UNENCRYPTED_FOR_TESTING hardcoded username in Signal's TLS Proxy implementation, a debugging-only feature that could be 'exploited' (though the impact is very limited) in Signal for…
Just a few days ago, a reliable but anonymous source shared with me telemetry data from the day of the blackout, covering thousands of solar inverters deployed across Spain. Yesterday evening, the Spanish government released its official report on the blackout. In this post I present a detailed analysis of the telemetry data to understand how inverter-based resources may be linked to the voltage…
Introduction Yesterday afternoon, I was writing what should have been the regular newsletter when the power suddenly went out. I wasn’t alarmed at all because I live in a mountain area, and power outages like this happen several times a year. It was a slightly windy day, so I assumed that maybe a tree had cracked and hit a low-voltage line or something similar. But, as it turns out, that wasn't…
Index 1. Introduction 2. Practical Gamma Spectroscopy for Security Researchers 3. SIGMA Network 4. Conclusions Disclaimer To avoid any misunderstandings, I want to clarify that all the information in this post is based on open-source intelligence, publicly available documents, and reverse engineering. I have not attempted to compromise or replicate any potential attacks on internet-facing SIGMA…
The war that began with Russia's full-scale invasion of Ukraine has led to a series of unprecedented nuclear-related situations. During the first 48 hours, Chernobyl—a symbol of the deep-seated fear of nuclear disaster, especially within Europe—was taken by Russian troops. This was accompanied by reports of radiation spikes, various plots involving dirty bombs and nuclear materials, and Russian…
In December 2024, two events —drone sightings in the US and Israel’s strike on Syria’s weapon depots— were followed by orchestrated reports of detected radiation spikes. Some media outlets took these dubious reports (with millions of views) that originated from social media , and published pieces based on them. In one of these cases, the actors behind the disinformation campaign exploited a…
A year ago, shortly after presenting the Chernobyl research , I was kind of surprised to find out that a plethora of brand-new Teleperm XS (2nd generation) components were available on eBay. Framatome’s Teleperm XS (TXS) is a digital Instrumentation & Control platform designed specifically for use in safety systems in Nuclear power plants, as a replacement for, or upgrades to their analog…
First off I would like to provide some context for those readers who are not familiar with this topic. In 2023 I presented at BlackHat USA ' Seeing Through the Invisible: Radiation Spikes Detected in Chernobyl During the Russian Invasion Show Possible Evidence of Fabrication '. Kim Zetter also wrote an investigative piece . The research materials are publicly available. As I casually discovered a…
Exactly two years ago I brought my blog back to life, after many years of hiatus, with " Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1 ". That was the first of a series of blog posts covering that system. During these two years I've been periodically assessing the security posture of this e-voting solution, as part of their Bug Bounty program , which I personally…
This blog post contains the web version of my research paper: " Seeing Through the Invisible: Radiation Spikes Detected in Chernobyl During the Russian Invasion Show Possible Evidence of Fabrication ", which was unveiled at BlackHat USA 2023 . It is intended to ease the indexing and dissemination of the information collected during this research. In a few days, I'll be in Brussels presenting this…
I'm a little bit surprised about today's Schneier blog post " Security Vulnerability of Switzerland’s E-Voting System " Just to add some context before continuing: I've been researching into that specific e-Voting system since 2022. I've reported quite a few vulnerabilities (I hold the 1st place in the 'SwissPost e-Voting' Bug Bounty program), also publishing detailed write-ups for some of these…
-------------- Update from 06/10/2023 : following my publication, I’ve been in contact with France Identité CISO and they could provide more information on the measures they have taken in the light of these findings: We would like to thank you for your in-depth technical research work on “France Identite” app that was launched in beta a year ago and for which you were rewarded. As you know, the…
Seeing Through the Invisible: Radiation Spikes Detected in Chernobyl During the Russian Invasion Show Possible Evidence of Fabrication After many months of intense research, I'm finally releasing the paper that contains full technical details and collected evidence. I presented this research at BlackHat USA 2023 a few days ago. Kim Zetter published on Wired a fascinating story about this research.…
During Q2 2022, in view of the geopolitical situation that unfolded after the Russian invasion of Ukraine, I decided that it wouldn't do any harm to kill some bugs in some of the main players within the ICS arena. I focused in those software frameworks that are running on the engineering workstations so, if compromised, attackers would be in a privileged position to manipulate controllers logic,…
Sometimes there are subtle bugs whose origin can be found in some quirks from the underlying language used to build the software. This blog post describes one of those cases in order to let both fellow security researchers and developers, who didn't know about it, become aware of this potential vulnerable pattern. In fact, I'm pretty sure that similar bugs to the one herein described likely affect…
A recent story has been making the rounds: " Hundreds of Nuclear Radiation Monitors Were Allegedly Hacked by Former Repairmen ". Basically, it seems that more than a year ago two disgruntled employees sabotaged +300 radiation monitoring devices, which were part of a nation-wide civil radiation monitoring network (RAR) in Spain. On top of that, they were apparently using the free WiFi of a…
In November 2021 YesWeHack invited me to participate in a private bug bounty program organized by Bug Bounty Switzerland on behalf of Proton AG. The scope of the program was quite interesting and heterogeneous, as it covered most of the applications and services offered by Proton, such as ProtonMail and ProtonVPN. As a result, multiple technologies and codebases were in scope, ranging from…