Sign in

Mathy Vanhoef

@vanhoefm.bsky.social
822 followers 370 following 49 posts

Prof. @KU_Leuven | Research in Network & Software Security | Known for WPA2 KRACK attack, Dragonblood, and FragAttacks | Open to consultancy | Ex-Postdoc NYU

PostsRepliesMedia
Mathy Vanhoef @vanhoefm.bsky.social · 11/09/2026
Interview with SecureW2, where we look back on various Wi-Fi attacks and give network security advice to handle future attacks, especially in the age of AI securew2.com/signal/sneak... tl;dr: ensure a layered defense
securew2.com
'Always Have a Layered Defense': KRACK Attack Researcher Keeps Finding New Wi-Fi Hacks
Cybersecurity researcher Mathy Vanhoef knows hackers don’t often break cryptography. Instead, they find ways to sneak around it.
030
Reposted by Mathy Vanhoef
Kenny Paterson @kennyog.bsky.social · 15/08/2026
Signal is the gold standard for secure messengers. We broke Signal’s integrity (twice) in this paper via message injection attacks. @kientuong114.bsky.social presented this week at #USENIX and he and Noemi will present it again at #WAC (Crypto workshop) this weekend. Catch their talk if you can!
02911
Reposted by Mathy Vanhoef
vincentholst.bsky.social @vincentholst.bsky.social · 13/08/2026
In 2023, @nature.com published 'Papers and patents are becoming less disruptive over time', receiving world-wide media attention. Our Matters Arising, published after a 32 month delay (more on that soon), shows that the reported decline can largely be attributed to dataset artefacts. 🧵
The average CD_5 index per year for Web of Science. The original Park et al. decline (top curve) becomes essentially flat (bottom curve) when removing papers with CD_5=1. Those papers largely correspond to dataset artefacts.
9351173
Reposted by Mathy Vanhoef
Courtney Milan @courtneymilan.com · 26/07/2026
I have run into situations where people want to set duress passwords on things and there are really three possibilities.
2355114
Reposted by Mathy Vanhoef
Steven Van de Walle @stevenvdwalle.bsky.social · 19/06/2026
Dus je kunt flexijobben bij je eigen werkgever mits 5/5 Dan is het echt totaal onbegrijpelijk dat een klein bijberoep zo disproportioneel wordt belast.
5182
Reposted by Mathy Vanhoef
Matthew Green @matthewdgreen.bsky.social · 04/06/2026
Where these tools shine is literature searches. I’m increasingly of the opinion that we need to write papers for LLMs to read. It’s frustrating that many ePrint sites actually block these tools. This is the first tool that can find the “small result” you left as a footnote in Appendix B that I need.
3296
Mathy Vanhoef @vanhoefm.bsky.social · 19/05/2026
Nominate yourself to help review papers for USENIX Security 2027! sec-rms.com/submit-appli... (or rms.swag.cispa.de/submit-appli... ). Deadline: May 28, 2026. We're looking for both senior and junior people. See Andrei Sabelfeld's LinkedIn post for more info: www.linkedin.com/feed/update/...
sec-rms.com
Signal PC interest - USENIX Security Symposium
025
Mathy Vanhoef @vanhoefm.bsky.social · 26/02/2026
We found that Wi-Fi client isolation can often be bypassed. This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others. NDSS'26 paper: www.ndss-symposium.org/wp-content/u... GitHub: github.com/vanhoefm/air...
3158
Reposted by Mathy Vanhoef
Rabbi Danya Ruttenberg @theradr.bsky.social · 20/02/2026
In addition to being absolutely brilliant, amazing & charming in her own right, we all know she was raised by a single dad w/4 siblings and that he came to the US bc of persecution bc of his participation in the ‘89 Tiananmen democracy uprising, right?
504022768
Reposted by Mathy Vanhoef
Ed @ed3d.net · 17/02/2026
this is one of the most amazing papers I have ever read eprint.iacr.org/2026/058.pdf
eprint.iacr.org
082
Reposted by Mathy Vanhoef
Joseph Lorenzo Hall, PhD @josephhall.org · 15/02/2026
The NDSS Symposium 2026 program is live. With 265 accepted papers and 8 workshops, the quality of security research this year is staggering. It is a testament to the community's dedication to keeping the digital world safe. www.ndss-symposium.org/ndss2026/pro... 1/4
152
Reposted by Mathy Vanhoef
Michael Clemens @mclem.org · 14/11/2025
The US government is considering punishing American scientists who worked with Chinese researchers *years ago, retroactively*.
18944
Mathy Vanhoef @vanhoefm.bsky.social · 12/11/2025
I've found AI tools to be quite useful too look for related work. And apparently so do others, searching Google Scholar for "utm_source=chatgpt.com" gives 13,900+ hits ;) scholar.google.com/scholar?star...
scholar.google.com
010
Mathy Vanhoef @vanhoefm.bsky.social · 12/11/2025
Russia is blocking mobile phones being brought back into the country from abroad for 24 hours, in an attempt to mitigate drone attacks. Seems like this can probably be bypassed using relay "worm hole" attacks, though it adds some complexity. novayagazeta.eu/articles/202...
novayagazeta.eu
One-day data block introduced on Russian SIM cards being brought back into country — Novaya Gazeta Europe
The Russian authorities have begun blocking mobile phones being brought back into the country from abroad for 24 hours in an attempt to undermine Ukrainian drone strikes, the Ministry of Digital Devel...
020
Reposted by Mathy Vanhoef
Joseph Lorenzo Hall, PhD @josephhall.org · 28/10/2025
woo! $10 MM USD in grants from ICANN... amazing. And great grantees here! "ICANN Announces First Cohort of Grant Program Recipients" www.icann.org/en/announcem...
icann.org
ICANN Announces First Cohort of Grant Program Recipients
Following an extensive applicant review period, ICANN has announced some of the projects that will receive funding in the ICANN Grant Program’s first cycle.
042
Reposted by Mathy Vanhoef
Aurore Fass @aurore-fass.bsky.social · 16/10/2025
Last chance to (self-) nominate for USENIX Security'26 Artifact Evaluation Committee! You should expect a low load of ~1 artifact for functionality/reproducibility assessments per cycle (max 3 for the whole year). Please support Open Science and fill the form by Oct 17: forms.gle/WoYRX4govNY1... 🚀
forms.gle
(Self-)Nomination for the USENIX Security '26 Artifact Evaluation Committee (AEC)
For the seventh year, USENIX Security allows the evaluation of artifacts that support a paper: software, hardware, evaluation data and documentation, raw measurement data, raw survey results, mechaniz...
087
Reposted by Mathy Vanhoef
Matthew Garrett @mjg59.eicar-test-file.zip · 24/09/2025
I have been learning more about PDFs than I really wanted to for maybe the absolutely most funny reason possible - letting agency forgery: mjg59.dreamwidth.org/73317.html
612433
Reposted by Mathy Vanhoef
LaurieWired @lauriewired.bsky.social · 19/08/2025
The West has a blindspot when it comes to alternative CPU designs.

 We’re so entrenched in the usual x86, ARM, RISC-V world, that most people have no idea what’s happening over in China.

 LoongArch is a fully independent ISA that’s sorta MIPS…sorta RISC-V…and sorta x87!
14311
Mathy Vanhoef @vanhoefm.bsky.social · 13/08/2025
At USENIX Security? Then check out: Studying the Use of CVEs in Academia, won distinguished paper award www.usenix.org/conference/u... Discovering and Exploiting Vulnerable Tunnelling Hosts, won most innovative research Pwnie @ DEFCON www.usenix.org/conference/u... Big thanks to all co-authors!!
0157
Reposted by Mathy Vanhoef
Nadim Kobeissi @nadim.computer · 06/08/2025
I'm thrilled to announce that after months of intensive work, the complete materials for my Applied Cryptography course at the American University of Beirut are now finished: both Part 1 (Provable Security) and Part 2 (Real-World Cryptography)!
4329
Reposted by Mathy Vanhoef
Dan Garisto @dangaristo.bsky.social · 31/07/2025
Breaking: NSF is suspending roughly 300 grants with UCLA, following a DOJ finding on Tuesday that the university violated Title VI by "creating a hostile educational environment for Jewish and Israeli students."
22351219
Mathy Vanhoef @vanhoefm.bsky.social · 12/07/2025
Our research on open tunneling servers got nominated for the Most Innovative Research award :) The work will be presented by Angelos Beitis at Black Hat and also at USENIX Security Brief summary and code: github.com/vanhoefm/tun... Paper: papers.mathyvanhoef.com/usenix2025-t...
076
Reposted by Mathy Vanhoef
Martin Laurent @malauren.be · 12/07/2025
Also in Poland. It was used by Russia in 2023 to stop about 20 trains.
railtarget.eu
Suspicious Train Disruptions in Poland: Is Russia Pulling the Levers? | RAILTARGET
Over the past weekend, Poland experienced an unusual series of train stoppages that have raised serious national security concerns.
0155
Mathy Vanhoef @vanhoefm.bsky.social · 12/07/2025
Yikes. Turns out you can send a plaintext radio signal to cause any train in the USA to do an emergency break. The original 'security' was just a checksum, no encryption or authentication. Reporting this took them 12 years (!) because the vendor dismissed it initially www.cisa.gov/news-events/...
cisa.gov
End-of-Train and Head-of-Train Remote Linking Protocol | CISA
1118164
Reposted by Mathy Vanhoef
David Picard @davidpicard.eurosky.social · 06/06/2025
Reminder that the MSCA postdoctoral program exists. If you have a PhD and want to work in a European lab, you have until September to apply. Just contact them now. ec.europa.eu/info/funding...
ec.europa.eu
03024
Mathy Vanhoef @vanhoefm.bsky.social · 03/07/2025
Senate GOP budget bill has little-noticed provision that could hurt your Wi-Fi arstechnica.com/tech-policy/... ==> Possibly no 6GHz for Wi-Fi 7
arstechnica.com
Senate GOP budget bill has little-noticed provision that could hurt your Wi-Fi
Cruz bill could take 6 GHz spectrum away from Wi-Fi, give it to mobile carriers.
001
Mathy Vanhoef @vanhoefm.bsky.social · 10/06/2025
Reminder to apply to be part of the artifact evaluation committee of NDSS'26! And share with your colleagues :) We'll likely close this form around the end of next week.
014
Reposted by Mathy Vanhoef
Mathy Vanhoef @vanhoefm.bsky.social · 25/05/2025
All papers should publish their code. Help realize this by becoming an artifact reviewer at NDSS'26, apply here: docs.google.com/forms/d/e/1F... You'll review artifacts of accepted papers. We especially encourage junior/senior PhD students & PostDocs to help. Distinguished reviews will get awards!
docs.google.com
Self-nomination for the Artifact Evaluation Committee of NDSS 2026
We are looking for members of the Artifact Evaluation Committee (AEC) of NDSS 2026. The Network and Distributed System Security symposium adopts an Artifact Evaluation (AE) process allowing authors t...
01210
Reposted by Mathy Vanhoef
Thor Benson @thorbenson.bsky.social · 04/06/2025
Lee Jae-myung, the South Korean politician who climbed the fence of the parliament to get inside and vote against martial law, has been elected president. Pretty cooool
Lee Jae-myung going beast mode
205246134211
Mathy Vanhoef @vanhoefm.bsky.social · 25/05/2025
All papers should publish their code. Help realize this by becoming an artifact reviewer at NDSS'26, apply here: docs.google.com/forms/d/e/1F... You'll review artifacts of accepted papers. We especially encourage junior/senior PhD students & PostDocs to help. Distinguished reviews will get awards!
docs.google.com
Self-nomination for the Artifact Evaluation Committee of NDSS 2026
We are looking for members of the Artifact Evaluation Committee (AEC) of NDSS 2026. The Network and Distributed System Security symposium adopts an Artifact Evaluation (AE) process allowing authors t...
01210
Reposted by Mathy Vanhoef
Kasper Nollet @kaspernollet.bsky.social · 13/05/2025
Calling researchers: EU #grantconsultancy 🚨 Have you worked with private grant consultants for EU research funding (Horizon, EIC, etc.)—Have you had positive or negative experiences? 📩 Share your story: kaspernollet@gmail.com / thordeyaert@hotmail.be (@thordeyaert.bsky.social) 🔁 RT appreciated!
075
Reposted by Mathy Vanhoef
Clémentine Maurice @bloody-tangerine.bsky.social · 14/05/2025
Haven't seen this on Bluesky yet: S&P 2027 will take place in Montreal, Canada!
22817
Mathy Vanhoef @vanhoefm.bsky.social · 07/05/2025
New version of the IEEE 802.11 standard that underpins Wi-Fi was has been released. A total of 5969 pages! The number of pages clearly keeps increasing. That includes more features to defend networks, but also more features to potentially abuse 👀
0105
Reposted by Mathy Vanhoef
LOEWE emergenCITY @emergencity.de · 06/03/2025
In two weeks, @vanhoefm.bsky.social , professor at DistriNet at KU Leuven, takes the stage for our next #DistinguishedLecture. He will present current strategies to strengthen Wi-Fi #security based on recent attacks on networks and previously detected design flaws. All information: buff.ly/gslCMCB
051
Reposted by Mathy Vanhoef
GrapheneOS @grapheneos.org · 04/02/2025
February 2025 Android Security Bulletin includes a heap buffer overflow in a Linux kernel USB peripheral driver (CVE-2024-53104) marked exploited in the wild. It's likely one of the USB bugs exploited by forensic data extraction tools. We block them using these. source.android.com/docs/securit...
source.android.com
Android Security Bulletin February 2025  |  Android Open Source Project
14411
Reposted by Mathy Vanhoef
Dorsa Amir @dorsaamir.bsky.social · 25/01/2025
Does the culture you grow up in shape the way you see the world? In a new Psych Review paper, @chazfirestone.bsky.social & I tackle this centuries-old question using the Müller-Lyer illusion as a case study. Come think through one of history's mysteries with us🧵(1/13):
331093423
Reposted by Mathy Vanhoef
Jeroen Baert @jbaert.bsky.social · 21/01/2025
The PC is Dead: It’s Time to Make Computing Personal Again
vintagecomputing.com
The PC is Dead: It’s Time to Make Computing Personal Again
How surveillance capitalism and DRM turned home tech from friend to foe. For a while—in the '80s, '90s, and early 2000s—it felt like nerds were [...]
2146
Mathy Vanhoef @vanhoefm.bsky.social · 14/01/2025
After an embargo of 8 months, we are glad to finally share our USENIX Security '25 paper! We found more than 4 MILLION vulnerable tunneling servers by scanning the Internet. These vulnerable servers can be abused as proxies to launch DDoS attacks and possibly to access internal networks.
25725
Reposted by Mathy Vanhoef
Max Hils @hi.ls · 12/01/2025
mitmproxy 11.1 is out! 🥳 We now support *Local Capture Mode* on Windows, macOS, and - new - Linux! This allows users to intercept local applications even if they don't have proxy settings. More details are at mitmproxy.org/posts/local-.... Super proud of this team effort. 😃
mitmproxy.org
Intercepting Linux Applications
27522
Reposted by Mathy Vanhoef
GrapheneOS @grapheneos.org · 10/01/2025
Using Play Integrity API is an incredibly anti-privacy and anti-security practice despite being wrongly portrayed as a security feature. The notification will include a link for leaving a rating and review for the app via sandboxed Play Store to make it very convenient for people to send complaints.
1536
Reposted by Mathy Vanhoef
Doll @dollspace.gay · 23/12/2024
15518
Reposted by Mathy Vanhoef
Phrack Zine @phrack.org · 16/12/2024
We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org
screenshot of the CFP on phrack.org
411658
Reposted by Mathy Vanhoef
Ciaran Martin @ciaranm.bsky.social · 12/12/2024
I don’t normally get worked up about the naming threat actors thing. But the Volt & Salt Typhoon is a disaster as it’s so hard for non-specialists to tell them apart: - Salt is Snowden style espionage by China against US - Volt is a direct 🇨🇳 military threat to degrade western infrastructure 1/2
712938
Reposted by Mathy Vanhoef
Dan Goodin @dangoodin.bsky.social · 10/12/2024
Researchers unveiled an attack that completely undermines security assurances AMD makes to customers using one of its most expensive microprocessor product lines in the cloud. BadRAM takes minutes to bypass SEV-SNP protections that warn when the VM is compromised arstechnica.com/information-...
arstechnica.com
AMD’s trusted execution environment blown wide open by new BadRAM attack
Attack bypasses AMD protection promising security, even when a server is compromised.
0177
Reposted by Mathy Vanhoef
Mathy Vanhoef @vanhoefm.bsky.social · 10/12/2024
Yes WPA2 loops through all passwords until the MIC of Msg2 is valid. With WPA3 this is not possible and you either need to have unique passwords tied to MAC addresses (annoying due to MAC randomization) or use password identifiers (requires extra user input).
121
Mathy Vanhoef @vanhoefm.bsky.social · 23/11/2024
Wow, an adversary first compromised a neighbor of the target, and then attacked the target over Wi-Fi (with stolen password). This is the first observed case of the #AntennaForHire attack that AirEye hypothesized. Any Wi-Fi attack is now a remote attack! www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
0197
Reposted by Mathy Vanhoef
ShmooCon @shmoocon.bsky.social · 22/11/2024
Just a reminder that the CFP closes in a few days. If you've got something to submit... www.shmoocon.org/call-for-pap...
shmoocon.org
Call for Papers – ShmooCon
02817