Daniel Gruss's Avatar

Daniel Gruss

@gruss.cc

Aka @lavados #InfoSec University Professor @ #TUGraz. #meltdown, #spectre, #rowhammer, cache attacks, sustainable security. Produced a side channel security sitcom. https://gruss.cc https://x.com/lavados https://infosec.exchange/@lavados

460
Followers
289
Following
28
Posts
17.11.2024
Joined
Posts Following

Latest posts by Daniel Gruss @gruss.cc

I'm looking forward to presenting my paper, "Continuous User Behavior Monitoring using DNS Cache Timing Attacks" at NDSS next week!
We mount an Evict+Reload-style attack on the local DNS cache, detecting recently accessed domains and evicting to continuously monitor new accesses.

22.02.2026 06:37 πŸ‘ 6 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Preview
Eviction Notice: Reviving and Advancing Page Cache Attacks Foreword This blog post is a summarized and introductory write up of our paper recently accepted at NDSS 2026, β€œEviction Notice: Reviving and Advancing Page Cache Attacks”. Read the full paper here. A...

I'm excited to announce that my first first-author paper is accepted at NDSS 2026 πŸ₯³.

Eviction Notice: Reviving and Advancing Page Cache Attacks

Check it out at: snee.la/posts/evicti...

@snee.la, @notimaginary.bsky.social, Lukas Maar, @gruss.cc

from @isec-tugraz.bsky.social, @tugraz.bsky.social

16.01.2026 16:12 πŸ‘ 10 πŸ” 4 πŸ’¬ 1 πŸ“Œ 1
Video thumbnail

Today we reveal StackWarp: a new CPU vulnerability exploiting a synchronization bug in AMD’s stack engine across Zen 1–5 CPUs. It enables deterministic manipulation of Confidential VM's stack pointer, allowing RCE and privilege escalation via both control- and data-flow hijacking.

15.01.2026 18:27 πŸ‘ 32 πŸ” 13 πŸ’¬ 1 πŸ“Œ 0
2nd Microarchitecture Security Conference (uASC '26)

I just registered for uasc.cc -- uASC (the Microarchitecture Security Conference) is on February 3rd, in Leuven, Belgium.

**Registration is free but mandatory!**

I would be happy to see all of you there :)

Especially from the Cologne and Ruhr area, it's just a train ride to Leuven -> join us!

07.01.2026 11:23 πŸ‘ 6 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I'll arrive at the #39c3 tomorrow evening, see you there!

26.12.2025 20:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

DIMVA is looking for PC nominations! Feel free to nominate yourself or your peers! πŸ’―
[mark your calendar] DIMVA 2026 will be held in Chania, Greece, July 1 - 3, 2026 πŸ–οΈπŸŒž
Daniele Cono D'Elia and I look forward to your submissions!πŸ₯³

15.09.2025 17:32 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

Later in the morning, Jo van Bulck gave an insightful talk about attacking and defending Trusted Execution Environments (TEEs) and the evolution of confidential computing.

#GSW25 #TEE

04.09.2025 15:28 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image Post image

Thursday evening, @gruss.cc hosted a city tour, showing off the best spots in the inner city, climbing the "Schlossberg," and surprising first-time visitors and locals alike with many fun facts!

#GSW25 #Graz

05.09.2025 19:35 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

This morning, David Oswald started our last day at GSW with his talk "Breaching the Gates: Uncovering Hardware Weaknesses in Confidential Computing", giving an overview of power side-channels and fault attacks in confidential computing scenario.

#GSW25 #sidechannels

05.09.2025 20:07 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image

In our second morning session, Stefan Mangard and @gruss.cc spoke about side-channel attacks in various settings - from phones to computers to networks - showing that side channels really are everywhere.

#GSW25 #SideChannels

03.09.2025 15:13 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image Post image

Social Event Part 1: Trip to the @zotterchocolates.bsky.social chocolate factory! We tasted our way through the factory with over 40 chocolate stations, experiencing the whole production process from the cocoa bean to the delicious end product! πŸ˜‹πŸ«

#GSW25 #chocolate

03.09.2025 19:10 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Social Event Part 2: Our culinary adventure continues! For dinner we went to a traditional Styrian "Buschenschank", a restaurant serving cold spreads made of local foods and their own wine and juices. 😍

#GSW25 #buschenschank

03.09.2025 20:02 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image

For our first session today, Fabio Pierazzi talked about trends and challenges in AI for systems security. What an exciting start to Day 2 of GSW'25!

#GSW25 #AI #SystemSecurity

02.09.2025 09:39 πŸ‘ 7 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

In our second session, Christian Rossow shared an overview of CFI techniques and developments and showed which areas still need further research to improve the guarantees CFI can provide and the compatibility with language constructs.

#GSW25 #CFI #Cybersecurity

02.09.2025 13:07 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
A room full of people doing CTF challenges

A room full of people doing CTF challenges

The winners of the CTF

The winners of the CTF

Tech support by LosFuzzys

Tech support by LosFuzzys

Thumbs up!

Thumbs up!

This afternoon, our student team LosFuzzys hosted the Graz Security Week CTF! To keep the spirits high and minds sharp, we provided some pizza. βœ¨πŸ•

Congratulations to all winners! πŸ₯³
1st place: "Computerclub St. PΓΆlten (not)"
2nd place: "Zotter Fanclub"
3rd place: "Polund"

#GSW25 #CTF

02.09.2025 18:41 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

In the afternoon, we continued with "Advanced Branch Target Injection Attacks" by Kaveh Razavi: An awesome talk about how branch target injection aka spectre v2 attacks evolved since 2018!

#GSW25 #spectre

01.09.2025 14:33 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Our last session of the day: The PhD Forumβ€”here our participants got the chance to share their research in short 5-min presentations!Β 

Hopefully, this will help them to get connected with others working on similar topics and spark some interesting discussions this week!

#GSW25 #PhD #research

01.09.2025 16:15 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Here we go!
Graz Security Week is starting any minute now! πŸ₯³

01.09.2025 08:53 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Welcome to Graz!
We wish you a great week. 😎

01.09.2025 09:19 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

We're kicking-off our summer school Graz Security Week with a short introduction and our first talk by Maria Eichlseder about Lightweight Cryptography and its challenges.

#GSW25 #lightweight #cryptography

01.09.2025 11:41 πŸ‘ 6 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Congrats!

28.07.2025 14:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Congratulations Dr. @giner.cc! It was great to have you in our team and I am proud of you that you have completed this journey with an excellent PhD thesis. Your works will have lasting impact on the community and I wish you the best for your next endeavors!

23.07.2025 10:46 πŸ‘ 20 πŸ” 2 πŸ’¬ 1 πŸ“Œ 1
Post image

πŸŽ‰ Congratulations to @notimaginary.bsky.social! πŸŽ‰

This week, he defended his PhD thesis β€œAttacking and Securing Leaky Systems at the Hardware-Software Boundary.”!

We’re so excited for you and wish you all the best for the future!🌟

Check out the thesis here πŸ‘‡
www.jonasjuffinger.com/phd-thesis.pdf

12.07.2025 14:14 πŸ‘ 6 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Congratulations Dr. @notimaginary.bsky.social! Was a pleasure to take part in your journey and I am really proud of you! Outstanding thesis and defense - you absolutely deserve the PhD! All the best for your future!

You can all check out Jonas' PhD thesis here: www.jonasjuffinger.com/phd-thesis.pdf

08.07.2025 19:31 πŸ‘ 9 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

If you're looking for something to do before or after #dimva25 in #graz, maybe hike up the SchΓΆckl (1445m) www.bergfex.at/sommer/steie...

07.07.2025 23:59 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

uASC 2026 will take place on February 3, 2026, in Leuven, Belgium, hosted by KU Leuven. We can't wait to see you next year!

Cycle 1 Paper Submission Deadline is July 15, 2025!
πŸ‘‰ uasc.cc #uasc26

19.05.2025 15:58 πŸ‘ 10 πŸ” 9 πŸ’¬ 0 πŸ“Œ 0
Post image

Only one month left to submit your paper for the first submission cycle at uASC 2026!

πŸ“… Submission Deadline: July 15, 2025
πŸ‘‰ uasc.cc

#microarchitecture #security #conference #uasc26

17.06.2025 17:20 πŸ‘ 4 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0
Security Week Graz 2025 – Summer School for Cybersecurity

Join the Graz Security Week from Sep 1 to 5! with @sahar-abdelnabi.bsky.social, Jo Van Bulck, Maria Eichlseder, Georg Fuchsbauer, @sublevado.bsky.social, @fbpierazzi.bsky.social, Kaveh Razavi, Christian Rossow, Yang Zhang securityweek.at (system security, side channels, AI security, & cryptography)

16.06.2025 09:51 πŸ‘ 10 πŸ” 5 πŸ’¬ 2 πŸ“Œ 0

I am happy to announce that my first paper has been accepted at USENIX Security!

We propose TEEcorrelate, a mitigation that statistically decorrelates reported performance counters from real ones during TEE execution.

13.06.2025 13:47 πŸ‘ 22 πŸ” 8 πŸ’¬ 3 πŸ“Œ 0

Congrats!

13.06.2025 13:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0