1. X
  2. Alex Ionescu
Log inSign up
Alex Ionescu
8,449 posts
Alex Ionescu profile banner
user avatar

Alex Ionescu

@aionescu
Chief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
Montréal, Québec
windows-internals.com
Joined April 2008
2,052
Following
47.1K
Followers
RepliesRepliesMediaMedia
  • user avatar
    Alex Ionescu
    @aionescu
    Aug 4
    When you forgot to tell Claude about C̵a̵l̵l̵b̵a̵c̵k̵ ̵O̵b̵j̵e̵c̵t̵s̵.̵ ̵W̵i̵n̵3̵2̵ ̵C̵a̵l̵l̵o̵u̵t̵s̵.̵ ̵E̵x̵t̵e̵n̵s̵i̵o̵n̵ ̵H̵o̵s̵t̵s̵.̵ ̵A̵P̵I̵ ̵S̵e̵t̵s̵.̵ Build a 8th mechanism to pass pointers between the kernel and Win32k.sys.
  • user avatar
    Alex Ionescu
    @aionescu
    Jul 18
    I have literally two CVEs over the last decade with the same bug, in the same place, again, and again (and ten other researchers have ten more). It’s insane. When I still taught seminars I used to tell my classes “just scan memory for kernel pointers each build”.
    user avatar
    karollol
    @karollooool
    Jul 17
    Wrote up CVE-2026-50416. win32k maps the desktop heap into every process. Offset 0x100 hands out a raw kernel session pool pointer. Readable from Low IL, AppContainer, even a zero capability LPAC. github.com/karollooool/CV…
  • user avatar
    Alex Ionescu
    @aionescu
    Jun 15
    Very excited to see the talent we continue to bring together working on the next generation of our products.
    user avatar
    Tony Meehan
    @snowboardvstree
    Jun 15
    I'm thrilled to share that I am joining @CrowdStrike, along with a few of my colleagues I’ve most loved building with. When we founded @prequel_dev in 2023, we set out to change how teams find and fix security and reliability problems. Joining @CrowdStrike, a company I’ve long
  • user avatar
    Alex Ionescu
    @aionescu
    May 21
    This information class was added only a few years ago. In the age of trillion dollar spending on AI code reviews and security, codeQL, KASAN and more, the world’s leading operating system kernel still added code to increment an arbitrary user controlled pointer in a system call
    user avatar
    Clandestine
    @akaclandestine
    May 18
    GitHub - orinimron123/CVE-2026-40369-EXPLOIT: Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox · GitHub github.com/orinimron123/C…
  • user avatar
    Alex Ionescu
    @aionescu
    Apr 10
    You can’t have #loldrivers if you stop signing everyone’s drivers
    GIF

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.