Mathias Payer

@gannimo@infosec.exchange
1.2K Followers
232 Following
259 Posts
Securitatis inquisitor and professor at EPFL leading the HexHive 🐝 group, focusing on system/software security (he/him).
Homepagehttps://nebelwelt.net
Grouphttps://hexhive.epfl.ch
My #Fandango team at #FSE2025 / #ISSTA2025: Alexi Turcotte, Marius Smytzek, me, Pepe Zamudio, and Laura Plein. What is #Fandango? Watch this space on Thursday for our big 1.0 release announcement and/or attend Pepe‘s presentation on Friday 16:00!
Well, the proposal has nothing to do with lasers "a priori" but I'm sure some cool laser-related research would fit. A 100W laser is a great place to start, right? 🔦🔦🔦
A knockout blow for LLMs?

LLM “reasoning” is so cooked they turned my name into a verb

Marcus on AI
The slides for my OffensiveCon talk "Finding and Exploiting 20-year-old bugs in Web Browsers" https://docs.google.com/presentation/d/1pAosPlKUw4uI5lfg7FVheTZAtI5mUy8iDeE4znprV34/edit?usp=sharing
Finding and Exploiting 20-year-old bugs in Web Browsers

Finding and Exploiting 20-year-old bugs in Web Browsers Ivan Fratric, Google Project Zero OffensiveCon 2025 Thank the audience for having the patience for another talk

Google Docs
Last week, @EPFL hosted LakeCTF, a major academic capture-the-flag competition with amazing challenges. Congrats to @polygl0ts for the flawless organization! I especially enjoyed the retro-challenges on real devices, especially hacking old basic interpreters! 👾👾👾 https://actu.epfl.ch/news/zer0rocketwrecks-has-won-lakectf-switzerland-s-top/
Zer0RocketWrecks has won LakeCTF, Switzerland's top Capture the Flag

Ten teams have taken part in the third edition of this security hacking contest organized by EPFL’s Capture the Flag team, the polygl0ts and the School of Computer and Communication Sciences.

So many amazing papers at #IEEESSP Oakland'25 this year. Congratulations to all authors on your accepted papers and an amazing program overall.

This year, we had one paper "SoK: Challenges and Paths Toward Memory Safety for eBPF" where Kaiming Huang explores challenges in protecting the Linux kernel against bugs in the eBPF verifier. As it turns out, securing even a simple language is challenging and we need to carefully consider how optimizations are implemented. Check out the full paper for details: https://nebelwelt.net/files/25Oakland.pdf

Sadly, I could not make it to San Francisco this year. Luckily my alternative program to go hike with the kids was not too bad either!

Today I received my first spear phishing attempt with a great context and reasonable request. 🤩🤩🤩 Does that mean I'm important now?
These two selfies are less than 24hrs and less than 50km apart from each other. One of the reasons why I love #EPFL and Switzerland
The universe is sending a very clear signal that I should stay TF out of France. Flight cancelled after 3hr delay and we ended up driving all night because no flights or trains were available the next three days. Thanks #easyjet
The #THcon organizers suggested that I take a hotel in the city center and commute to the conference. In spite of bad past experiences in every major city in France, I took their advice and learned why Toulouse does not have a problem with transport strikes: they got rid of the conductors!