Sign in

eShard

@eshard.bsky.social
39 followers 8 following 140 posts

Beyond testing tools, solutions that deliver expertise. 🌐 Chip & binary security testing www.eshard.com

PostsRepliesMedia
eShard @eshard.bsky.social · 2h
We're here at NextApp devcon in Berlin 💙 Find us at our booth, and at lightning talk this Friday at 11h20 local time.
000
eShard @eshard.bsky.social · 22h
In the next chapter of our series on implementation security for autonomous systems, we raise awareness of one point: 𝗽𝗵𝘆𝘀𝗶𝗰𝗮𝗹 𝗰𝗮𝗽𝘁𝘂𝗿𝗲. A risk that traditional security programs don't fully address. www.eshard.com/blog/designi... #drones #drone #embedded #embeddedsystems #cybersecurity #hardware
eshard.com
‍Designing autonomous systems for the reality of physical capture | #2 | eShard
Drones get captured, and zeroization can fail. How to design autonomous systems for physical capture, from side-channel analysis to fault injection.
010
eShard @eshard.bsky.social · 05/10/2026
Record first. Ask questions afterwards. We used Epoch to record an Android app's full-system execution, then asked an AI agent to test it against OWASP MASVS. The trace stays as evidence. www.eshard.com/blog/ai-mobi... #cybersecurity #mobileappsec
eshard.com
Can AI bring Mobile Application Security Analysis in-house? | eShard
Can AI bring mobile app security analysis in-house? See how Epoch's time travel traces and an AI agent test an Android app against OWASP MASVS.
100
eShard @eshard.bsky.social · 02/10/2026
📍 Next. app DevCon, Berlin: introducing our new time travel debugger for AI investigations. 💬 Talk: "Reconstructing Telegram: Time Travel Debugging Meets AI on Android" 📍 UAV Show, Bordeaux: diving into the world of drones, with a first blog post: www.eshard.com/blog/autonom...
000
eShard @eshard.bsky.social · 02/10/2026
New series: implementation security for autonomous defense systems. Their intelligence runs on embedded hardware in the field, where an adversary can recover a device and study it with no time limit. What happens if someone can study it without constraints? 🔗Part 1: www.eshard.com/blog/autonom...
eshard.com
Autonomous Systems are changing the Defence Threat Model | #1 | eShard
Why rapid autonomy, embedded AI and battlefield scale make implementation security a strategic engineering issue.
000
eShard @eshard.bsky.social · 30/09/2026
At next.app devCon in Berlin, eShard security analyst Pierre-François will present “Reconstructing Telegram: Time Travel Debugging Meets AI on Android”, exploring how advanced debugging techniques and AI can help investigate complex Android applications. 📍 Berlin, Germany 📅 07–09 October 2026
000
eShard @eshard.bsky.social · 29/09/2026
Live from ICCC! Our booth is up and running in Rome. Come find Fabien and Julien to discover our offerings for hardware security testing.
001
eShard @eshard.bsky.social · 29/09/2026
We're kicking off a busy event quarter with two stops this week. 📍 ICCC, Rome (Sep 29 – Oct 1) 📍 JAIF, Montpellier (Oct 1) Come find us!
000
eShard @eshard.bsky.social · 24/09/2026
Our PQC training teaches you to attack ML-KEM and ML-DSA yourself with side-channel and fault injection, then assess your own implementation's exposure. First session wrapped, spots open for October and November. Tickets → www.eventbrite.fr/e/post-quant... #pqc #postquantum #cybersecurity
010
eShard @eshard.bsky.social · 22/09/2026
A first public side-channel attack on the Arm CryptoCell-310. Our latest blog post walks through the full methodology: EM signal analysis, a collision-correlation attack, and full AES key recovery. Read it here: www.eshard.com/blog/side-ch...
000
eShard @eshard.bsky.social · 07/09/2026
Epoch is live! ⚡ Time Travel Debugging built for the agentic era. Record full-system execution from Kernel to userland, then let your #AI agents investigate the trace: instructions, registers, memory, all replayable forward and backward. Discover Epoch: www.eshard.com/blog/introdu...
010
eShard @eshard.bsky.social · 03/09/2026
We’ll be presenting at the HS3 workshop during #ESORICS2026 in Rome, sharing our research on Botan’s ECC implementation against physical attacks. The study shows how side-channel leakage can persist despite existing countermeasures, from emulation to real hardware.
000
eShard @eshard.bsky.social · 10/08/2026
We had a great time at Black Hat USA in Las Vegas 📍🇺🇸
000
eShard @eshard.bsky.social · 27/07/2026
We're on our way to Black Hat USA 2026! Stop by Booth #5645 to see how our Time Travel Debugging tool keeps an eye 👁‍🗨 on the truth. ➡ eshard.com/time-travel-...
000
eShard @eshard.bsky.social · 22/07/2026
New Expert Review: "Mind the Faulty Keccak" shows a loop-abort fault injection attack hijacking Keccak's sponge construction to force a known output, cascading into a full break of both NIST-standardized PQC algorithms. Read the full review here: www.eshard.com/blog/the-rot...
000
eShard @eshard.bsky.social · 20/07/2026
Join our intensive, hands-on 2-day online training to break ML-KEM and ML-DSA implementations under real-world hardware attack conditions: 🗓️ September 22 & 23 • October 27 & 28 ⚠️ Seats are limited. 👉 Link to register: u.eshard.com/training-pqc
u.eshard.com
Post-Quantum Cryptography (PQC) Physical Threats: 2-Day Training Program
2 days of hands-on SCA and FI against ML-KEM and ML-DSA, from attack theory to live key recovery.
000
eShard @eshard.bsky.social · 16/07/2026
It's a wrap for CODE-Jahrestagung 2026! At the FORTRESS booth, we delivered a live demonstration showing how side-channel leakage can threaten an ML-KEM implementation.
000
eShard @eshard.bsky.social · 15/07/2026
We're running a 2-day remote training on SCA and fault injection against ML-KEM and ML-DSA. Early bird pricing still live. 👉 u.eshard.com/training-pqc #PQC #postquantum #postquantumcryptography #hardwarehacking #cybersecurity
000
eShard @eshard.bsky.social · 10/07/2026
The biggest event of the summer for reverse engineers is just around the corner. We'll be at #BlackHat USA 2026 🇺🇸
000
eShard @eshard.bsky.social · 07/07/2026
🔴 Second session starting now! Join here: zoom.us/meeting/regi... #webinar #pqc #postquantum #postquantumcryptography #nist
000
eShard @eshard.bsky.social · 07/07/2026
🔴 We're starting! Join us here: zoom.us/meeting/regi...
000
eShard @eshard.bsky.social · 06/07/2026
Save your spot for our next webinar. 🔵 10 am CEST | 4 pm SGT: zoom.us/meeting/regi... 🔵 5 pm CEST | 11 pm SGT: zoom.us/meeting/regi... #cybersecurity #postquantum #postquantumcryptography #webinar #sidechannel #nist #algorithms
000
eShard @eshard.bsky.social · 03/07/2026
On July 7th, join us to learn about the physical blind spots in Post-Quantum Cryptography, and why the math behind ML-KEM and ML-DSA won't stop a hardware glitch. 📌 Two sessions available: 🕙 10:00 CEST | 04:00 EDT | 16:00 SGT: lnkd.in/dSF4pzk9 🕔 17:00 CEST | 11:00 EDT | 23:00 SGT: lnkd.in/dDVi_w6w
000
eShard @eshard.bsky.social · 03/07/2026
Heading to Munich for CODE 2026 at the @UniBw Campus! 🇩🇪 Catch us at the @FORTRESS booth for live SCA demos on #PQC algorithms. 🎙️ Plus: We'll be giving a talk on PQC security validation & joining a panel on hybrid secure boot challenges.
000
Reposted by eShard
eShard @eshard.bsky.social · 09/06/2026
Keccak is at the core of ML-KEM and ML-DSA. One fault and your entire PQC stack is compromised. On July 7th, we show exactly how. Live demos, real targets. 🕙 10:00 CEST: zoom.us/meeting/regi... 🕔 17:00 CEST: zoom.us/meeting/regi... #PQC #HardwareSecurity
001
eShard @eshard.bsky.social · 30/06/2026
Sneak peek of what we're preparing for our webinar next week: how Keccak's physical vulnerabilities translate into real attacks on #PQC implementations. Register here. 🕙 10:00 CEST: zoom.us/meeting/regi... 🕔 17:00 CEST: zoom.us/meeting/regi...
010
eShard @eshard.bsky.social · 26/06/2026
A 2-day remote training on the physical attack surface of ML-KEM and ML-DSA: SCA, fault injection, and live key recovery on real implementations. Early bird pricing live now. Seats are limited. 👉 www.eventbrite.fr/e/post-quant... #pqc #postquantum
eventbrite.fr
Post-Quantum Cryptography (PQC) Physical Threats: 2-Day Training Program
2 days of hands-on SCA and FI against ML-KEM and ML-DSA, from attack theory to live key recovery.
000
eShard @eshard.bsky.social · 23/06/2026
Last week, we hosted the FORTRESS consortium at our HQ. Two days of solid work on quantum-safe secure boot for critical infrastructure across Europe. 🛡️ Subscribe to the project newsletter: bit.ly/4fVDA0y #pqc #PostQuantumCryptography
000
eShard @eshard.bsky.social · 09/06/2026
Keccak is at the core of ML-KEM and ML-DSA. One fault and your entire PQC stack is compromised. On July 7th, we show exactly how. Live demos, real targets. 🕙 10:00 CEST: zoom.us/meeting/regi... 🕔 17:00 CEST: zoom.us/meeting/regi... #PQC #HardwareSecurity
001
eShard @eshard.bsky.social · 04/06/2026
Join us to exploit Keccak's physical vulnerabilities in ML-KEM and ML-DSA implementations live, via side-channel analysis and fault injection. 🕙 10:00 CEST: zoom.us/meeting/regi... 🕔 17:00 CEST: zoom.us/meeting/regi... #PQC #hardwarehacking #nist
031
eShard @eshard.bsky.social · 02/06/2026
We're starting our webinar on Physical Attacks on PQC Implementations 📢 Join the talk: zoom.us/meeting/regi... #pqc #postquantum #postquantumcryptography
zoom.us
Welcome! You are invited to join a meeting: Securing Post-Quantum Implementations Against Physical Attacks. After registering, you will receive a confirmation email about joining the meeting.
Quantum-resistant algorithms are arriving in real devices;  but physical attacks may already undermine them. eShard and PQShield explore whether side-channel and fault injection attacks pose a real-w...
010
eShard @eshard.bsky.social · 01/06/2026
Last call to join us at our webinar about securing #PQC implementations against physical attacks 📢 🗓 June 2nd, 10 am CEST | 4 pm SGT 🔗 zoom.us/meeting/regi... #postquantum #postquantumcryptography #hardware #hardwarehacking #nist
000
eShard @eshard.bsky.social · 01/06/2026
This weekend we were at Hardwear.io in Santa Clara 🇺🇸 We joined a talk on fault injection and side-channel analysis, while we demonstrated its real-world application at our booth. See you at the next edition in Europe later this year! #hardwarehacking #cybersecurity
000
eShard @eshard.bsky.social · 28/05/2026
We're at TyphoonCon 📍🇰🇷 We're here all week showing everyone how to master Time Travel Debugging. If you're around, stop by our booth to take on the challenge!
000
eShard @eshard.bsky.social · 26/05/2026
We paired time travel debugging with an #AI agent on a noisy 7B-instruction ARM64 Android trace. In ~10 minutes, it traced the MTProto v2 decryption chain down to AES-IGE and correctly described the execution flow. Full write-up 👇 www.eshard.com/blog/telegra...
eshard.com
Navigating a 7-Billion-Instruction Telegram TTD Trace with an AI Agent | eShard
Analyzing a 7-billion-instruction ARM64 execution trace of Telegram for Android using our EPOCH MCP time travel debugging tool.
000
eShard @eshard.bsky.social · 25/05/2026
We're heading to Hardwear.io with our Glitching Fault Injection set up and Pattern Detector demo 🔬 See you there!
000
eShard @eshard.bsky.social · 22/05/2026
If your team is preparing for post-quantum migration, now is the right time to look beyond the algorithm and evaluate the implementation. www.eshard.com/blog/webinar... #pqc #postquantum #postquantumcryptography #nist
eshard.com
Webinar: Securing Post-Quantum Implementations Against Physical Attacks | eShard
Join eShard and PQShield for a technical webinar on post-quantum cryptography, ML-KEM implementations, and how side-channel analysis helps evaluate physical attack resistance.
000
eShard @eshard.bsky.social · 21/05/2026
We replicated the 'Scatter+Moran' attack and looked for ways to push it further with #AI, on a public masked+shuffled AES-128 dataset, in one afternoon. ✔ Replication in 1h ✔ 33% fewer traces ✔ MIA: 50k to 20k ✔ Full Rust in 2.5s 🔗 www.eshard.com/blog/revisit... #hardware #cybersecurity
eshard.com
Revisiting a Masked AES Side-Channel Attack in half a day with AI | eShard
A hands-on experiment: can a large language model meaningfully accelerate side-channel analysis research?
000
eShard @eshard.bsky.social · 20/05/2026
Quantum-resistant algorithms are only as strong as their implementation. Join us to see how CPA attacks apply to ML-KEM, and how to actually defend against them. 🔗 zoom.us/meeting/regi... #NIST #PQC
010
eShard @eshard.bsky.social · 19/05/2026
Fresh out the oven ♨️ esDynamic 2026.4 includes: ✅ a new trace visualizer, ✅ 20+ PQC notebooks, ✅expanded SCA & FI knowledge, ✅support for Thorlabs & Rohde & Schwarz instruments, ... and more! www.eshard.com/blog/release...
eshard.com
esDynamic 2026.4: Moving side-channel and fault-injection analysis to the next step | eShard
A reworked trace visualizer, an expanded knowledge catalogue, a major upgrade to post-quantum cryptography content, and a sharper, more modern platform. Here is what 2026.4 brings.
000
eShard @eshard.bsky.social · 18/05/2026
TyphoonCon, we're on our way! ✈️ Stop by our booth for a talk about Time Travel Debugging (TTD) through our CTF challenge: ttd.eshard.com
000
eShard @eshard.bsky.social · 15/05/2026
We're at Offensivecon 🏴‍☠️ in Berlin! We're doing demos of our Time Travel Debugging tool, so stop by our booth to catch some "bugs" 👀
000
eShard @eshard.bsky.social · 13/05/2026
Missing peripheral in QEMU? We hit a wall analyzing CVE-2019-14192 on real Raspberry Pi 3B+ firmware, so we added the missing driver to QEMU. Register by register, using U-Boot's own source as the spec. 🔗 www.eshard.com/blog/u-boot-... #QEMU #Cybersecurity #firmware #uboot
eshard.com
Time Travel Analysis with QEMU on IoT Targets: Not Always That Hard - Part II | eShard
Adding a missing USB Ethernet peripheral to QEMU to unlock Time Travel Debugging on unmodified Raspberry Pi 3B+ firmware.
011
eShard @eshard.bsky.social · 11/05/2026
A malicious MKV opens in VLC. A fake calc.exe pops up: "We've got you." An AI agent made an MCP trace-driven analysis and reconstructed the full exploit chain, use-after-free, heap spray, ROP chain, ... from a single CPU trace. www.eshard.com/blog/vlc-med... #AI #Exploit
eshard.com
VLC Media Player MKV Exploit Analysis | eShard
We reconstructed a full VLC Media Player exploit chain from a 4.78-billion-instruction CPU trace using MCP-based time-travel debugging.
000
eShard @eshard.bsky.social · 07/05/2026
Live session with PQShield: physical attacks on post-quantum crypto, a CPA attack on ML-KEM, and how to harden your defenses. Limited seats 👇 zoom.us/meeting/regi... #pqc #hardware
010
eShard @eshard.bsky.social · 06/05/2026
Thanks for joining our live! Recording is up at the same link. Just reply here or comment there if you have any questions.
000
eShard @eshard.bsky.social · 06/05/2026
🔴 We're starting our live! www.youtube.com/watch?v=RaZr... #reverseengineering #cybersecurity
youtube.com
🔴 LIVE: Give Your AI Agent a Time Machine | Reverse Engineering
YouTube video by eShard
000
eShard @eshard.bsky.social · 05/05/2026
Join us tomorrow! We'll go live to talk about AI, reverse engineering, time travel debugging, and more: youtube.com/live/RaZrX0P... 🔔 Click the bell so you don't miss it! #ai #reverseengineering #cybersecurity
youtube.com
🔴 LIVE: Give Your AI Agent a Time Machine | Reverse Engineering
YouTube video by eShard
000
eShard @eshard.bsky.social · 04/05/2026
Copy.fail is a new Linux kernel privilege escalation vulnerability sitting undetected since 2017, and it has been discovered using AI. We analyzed it the same way. Locally. 🔗 www.eshard.com/blog/copy-fa... #Linux #CVE #AI
eshard.com
Copy.fail: Why Internal LLMs Are Non-Negotiable for Security | eShard
We break down the Copy.fail exploit and explain why on-premise AI models are non-negotiable for security teams.
000
eShard @eshard.bsky.social · 30/04/2026
Join us next week for an open conversation about the role of AI in reverse engineering: 🔴 www.youtube.com/live/RaZrX0P... 🔔 Click the bell so you don't miss it! #ai #reverseengineering #cybersecurity
youtube.com
🔴 LIVE: Give Your AI Agent a Time Machine | Reverse Engineering
YouTube video by eShard
000