Sign in

F4b

@0xf4b.bsky.social
138 followers 100 following 1 posts

VR team tech lead @synacktiv.com

PostsRepliesMedia
Reposted by F4b
Entrypoint @entrypoint-fr.bsky.social · 04/09/2026
Our website is now live! Everything you need to know about Entrypoint 2027 is now in one place. 📅 19-20 March 2027 📍 Paris, France 🎤 CFP is open Explore the event and submit your talk ⬇️ www.entrypoint.fr
entrypoint.fr
Entrypoint 2027 — Offensive Security Conference in Paris
Entrypoint is an offensive security conference in Paris on 19 & 20 March 2027: two days of talks and four days of hands-on trainings on Red Teaming, initial access, Active Directory compromise, supply...
043
Reposted by F4b
Synacktiv @synacktiv.com · 31/08/2026
In our latest article, Quentin presents new scripts allowing to simulate legitimate AD services in a flexible manner, and demonstrates their use through GPO exploitation ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Simulating legitimate Active Directory services on the network: the
Simulating legitimate Active Directory services on the network: the
032
Reposted by F4b
Entrypoint @entrypoint-fr.bsky.social · 23/07/2026
The Review Board for Entrypoint 2027 is complete 🔒 10 security experts from around the world will be reading your submissions this year Reminder: CFP closes on September 20, 2026 at 23:59 UTC Submit your paper now at entrypoint.fr Meet the team below (A-Z) 👇
123
Reposted by F4b
Synacktiv @synacktiv.com · 10/07/2026
After MySQL, it's now SQL Server's turn. noraj takes a deep dive into Unicode-related security issues. 📚 Read the full article: www.synacktiv.com/en/publicati...
synacktiv.com
The SQL Server Unicode problem: why your data might not be what you
The SQL Server Unicode problem: why your data might not be what you
022
Reposted by F4b
Synacktiv @synacktiv.com · 09/07/2026
During an internal assessment, our expert found several vulnerabilities in #Xpra (Screen for X11) which, chained together, allow a malicious server to gain RCE on the client. Update your packages! ⬇️ www.synacktiv.com/en/advisorie...
synacktiv.com
Multiple vulnerabilities in the Xpra client
Multiple vulnerabilities in the Xpra client
021
Reposted by F4b
Synacktiv @synacktiv.com · 07/07/2026
Who said KYC is not fun? Discover how @kevintell.bsky.social and @log-s.bsky.social exploited new #AI techniques to bypass Age Verification and how this technology reshuffles the deck ⬇️ www.synacktiv.com/en/publicati...
023
Reposted by F4b
Synacktiv @synacktiv.com · 06/07/2026
Back from @passthesaltcon.bsky.social 🧂 Our team presented: 💥 Livewire RCE (CVE-2025-54068) – @remsio.bsky.social, alongside Worty 🔍 Dicozorus for smarter web fuzzing – us3r777 💥 BadUSB Forensics – acervoise Tools 👇 github.com/synacktiv/Li... github.com/synacktiv/di...
112
Reposted by F4b
Synacktiv @synacktiv.com · 10/07/2026
🔒 #Recrutement | @synacktiv.com recherche un(e) Officier de Sécurité à Paris. Vous souhaitez contribuer à la protection de l'information au sein d'une société d'expertise en cybersécurité ? 👉 Postulez dès maintenant : www.synacktiv.com/officier-sec...
022
Reposted by F4b
Synacktiv @synacktiv.com · 08/07/2026
🚀 Le pôle Reverse de @synacktiv.com recrute ! Vous poncez les CTF ? Vous aimez la R&D et vous souhaitez évoluer aux côtés d'experts reconnus dans le domaine ? Rejoignez-nous ! 📍 Paris, Rennes, Toulouse, Lille, Bordeaux, Lyon ou full remote (France). 👉 www.synacktiv.com/recherche-et...
022
Reposted by F4b
Entrypoint @entrypoint-fr.bsky.social · 29/06/2026
🚨 The #Entrypoint2027 Call For Papers is now open! Have original offensive security research to share? New techniques, tools, or attack stories ? We want to hear from you. 📅 CFP closes: Sept 20, 2026. Our review board will be revealed soon. 👉 cfp.entrypoint.fr/entrypoint-2...
0109
Reposted by F4b
Entrypoint @entrypoint-fr.bsky.social · 18/06/2026
We've been working on something for a while. The talks your blue team doesn't want you to see. 🔴 Red Teaming. Initial Access. AD. Cloud & Web exploitation. 📍 Paris - Le Dernier Étage 📅 March 19–20, 2027 entrypoint.fr CFP and additional details coming soon.
085
Reposted by F4b
Synacktiv @synacktiv.com · 07/05/2026
Back from #THCON 2026 🔥 Proud to see our teams share their latest offensive security research once again this year: 📡 Wi-Fi pentesting in 2025 & WPA3 bypasses - Quentin 🛡️ Cross-domain & cross-forest RBCD - Simon 🏴 THCON pre-challenge write-up - @0xf4b.bsky.social Great work everyone 👏
141
Reposted by F4b
Synacktiv @synacktiv.com · 14/04/2026
Double trouble at #SOCON2026! Our ninja @kalimer0x00.bsky.social was busy breaking down Microsoft SCCM (once again!), while @quent0x1.bsky.social unveiled new GPO-based attack paths & his latest Bloodhound contributions targeting OUs & AD Sites. Awesome job! 👏
022
Reposted by F4b
Synacktiv @synacktiv.com · 10/02/2026
#IT evolves… and so do attacks. 🛡️ Sharpen your skills in March-April 2026 with our #cybersecurity courses: Forensic, Cloud, Active Directory & Malware Analysis. 📅 Limited spots: www.synacktiv.com/en/offers/tr...
012
Reposted by F4b
Synacktiv @synacktiv.com · 26/01/2026
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 www.synacktiv.com/en/publicati...
synacktiv.com
On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025
On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025
061
Reposted by F4b
Synacktiv @synacktiv.com · 23/01/2026
On the podium at #Pwn2Own Automotive 2026 🥉 Synacktiv ranked 3rd in Tokyo 🇯🇵 after successful attacks on #Tesla Infotainment (USB), #Sony XAV-9500ES (USB) and #Autel MaxiCharger (NFC). 📍 Next stop: Berlin!
054
Reposted by F4b
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2026
In a highlight from Day One of #Pwn2Own Automotive 2026, @synacktiv.com targets the #Tesla infotainment system. #P2OAuto youtube.com/shorts/DKYT-...
youtube.com
From Pwn2Own Automotive 2026 Day 1: Synacktiv vs. Tesla
YouTube video by TrendAI Zero Day Initiative
063
Reposted by F4b
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/01/2026
Confirmed! Synacktiv (@synacktiv) chained three vulnerabilities to gain root-level code execution on the Sony XAV-9500ES, earning a full win of $20,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
021
Reposted by F4b
Synacktiv @synacktiv.com · 14/01/2026
From legacy WEP to WPA3-Enterprise: sharing our recent #WiFi field experiences. 📡 We detail various scenarios to better understand the risks, including WPA3 PEAP relaying & optimized online PSK brute-forcing. ⤵️ www.synacktiv.com/en/publicati...
synacktiv.com
Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025
Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025
033
Reposted by F4b
REVEL·IO @revel-io.bsky.social · 05/01/2026
✨ Happy New Year 2026 ✨ Everyone at REVEL·IO wishes you a successful year ahead. As digital investigation challenges continue to grow, we remain committed to contributing to a safer future. Thank you for your trust!
021
Reposted by F4b
Synacktiv @synacktiv.com · 16/12/2025
[New blog post] As part of an R&D project, @tomtombinary.bsky.social identified several critical vulnerabilities in the LAN multiplayer mode of the game Anno 1404 (released in 2009) 🔍 Want to know more? Read the full article on our blog 👇 www.synacktiv.com/en/publicati...
synacktiv.com
Exploiting Anno 1404
Exploiting Anno 1404
033
Reposted by F4b
Synacktiv @synacktiv.com · 12/12/2025
HID recently disclosed HID-PSA-2025-002, a critical flaw in the #ActivID Authentication Appliance 8.7. In our new blog post, @us3r777.bsky.social and @pierregg.bsky.social break down exactly how they uncovered it, from methodology to exploitation 💡 Read it here ⬇️ synacktiv.com/en/publicati...
synacktiv.com
ActivID administrator account takeover : the story behind
ActivID administrator account takeover : the story behind
032
Reposted by F4b
Synacktiv @synacktiv.com · 01/12/2025
Missed @hexacon.bsky.social 2025? 🤯 Good news, all #Synacktiv’s deep-dive talks on offensive research & reverse engineering are now online! 🎥 Watch the full playlist: www.youtube.com/playlist?lis... #cybersecurity
082
Reposted by F4b
Synacktiv @synacktiv.com · 27/11/2025
At #Pwn2Own2025, our experts Tek & @anyfun.bsky.social remotely compromised a Synology Beestation Plus via a pre-auth exploit, leading to full system takeover. The vuln is now tracked as CVE-2025-12686 🔍 🔗 Full write-up: www.synacktiv.com/en/publicati...
synacktiv.com
Breaking the BeeStation: Inside Our Pwn2Own 2025 Exploit Journey
Breaking the BeeStation: Inside Our Pwn2Own 2025 Exploit Journey
041
Reposted by F4b
Synacktiv @synacktiv.com · 18/11/2025
Meet our #Synacktiv and @revel-io.bsky.social experts at #Milipol, from Tuesday 18 to Friday 21 November 2025! 📍 Visit us at Stand H063 (Hall 4 – Forensic Zone). ℹ️ www.milipol.com/fr-FR
011
Reposted by F4b
Synacktiv @synacktiv.com · 07/11/2025
[Blogpost] @croco_byte presents how to exploit attack paths related to Active Directory sites' ACLs. As the latter often constitute a blind spot for AD enumeration tools, the article also describes a pull request aiming to integrate them into the BloodHound project:
synacktiv.com
Site Unseen: Enumerating and Attacking Active Directory Sites
Site Unseen: Enumerating and Attacking Active Directory Sites
021
Reposted by F4b
REVEL·IO @revel-io.bsky.social · 04/11/2025
See you at #MilipolParis 2025 👋 📅 November 18-21, 2025 📍 Paris Nord Villepinte - Hall 4, Stand H063 (Forensic Zone) Meet our experts on site and discover how #REVEL·IO improves the efficiency and reliability of digital investigations 🔗 www.milipol.com/en
051
Reposted by F4b
Synacktiv @synacktiv.com · 31/10/2025
A big shout-out to the #Synacktiv team for their strong performance at the latest #Pwn2Own competition in Cork! They proudly secured third place overall 👏 Next stop: Tokyo for the upcoming edition 🇯🇵 👀 More details on the targets and participants here ℹ️ www.zerodayinitiative.com/blog/2025/20...
033
Reposted by F4b
Synacktiv @synacktiv.com · 31/10/2025
#REVEL·IO will be exhibiting at #MilipolParis 2025 📢 Developed by @synacktiv.com, REVEL·IO is the first French digital forensics solution designed to help investigators. 📍 Hall 4 - Forensic zone - Stand H063 💡 Learn more about Milipol: www.milipol.com/en 💡 Discover REVEL·IO: revelio.eu
021
Reposted by F4b
Synacktiv @synacktiv.com · 30/10/2025
Another busy month with many technical talks from the team! 💪 Links and more details below 👇️
611
Reposted by F4b
Synacktiv @synacktiv.com · 27/10/2025
Following their presentation at @hexacon.bsky.social, @mtalbi.bsky.social & Etienne detail how they exploited CVE-2023-40129, a critical vulnerability affecting the Bluetooth stack in Android ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Paint it blue: Attacking the bluetooth stack
Paint it blue: Attacking the bluetooth stack
065
Reposted by F4b
Synacktiv @synacktiv.com · 23/10/2025
🎉 Big win at #Pwn2Own Cork! @pol-y.bsky.social of #Synacktiv successfully breached the @Ubiquiti AI Pro surveillance system 🦈🎶 What a way to wrap up the challenge - congrats, @pol-y.bsky.social 💪
076
Reposted by F4b
Synacktiv @synacktiv.com · 22/10/2025
Impressive work from our team today at #Pwn2Own! @mtalbi.bsky.social and Matthieu just pulled off an exploit on the Philips Hue Bridge without laying a finger on the device! Great demonstration of Synacktiv’s offensive expertise 👏 Come on 🔥
0137
Reposted by F4b
Synacktiv @synacktiv.com · 21/10/2025
Congrats to tek and anyfun for landing the first successful entry at #Pwn2OwnCork - exploiting a stack overflow on Synology BeeStation Plus for $40,000 and 4 Master of Pwn points in the process 💥 Let’s keep pushing 💪 #P2OIreland #Synacktiv
044
Reposted by F4b
Synacktiv @synacktiv.com · 16/10/2025
Our post-quantum cryptography series continues! This new article by @bluesheeet.bsky.social unpacks the hybridization of key exchanges, covering theory and implementations. Read all about why it matters, how to approach it safely, and some misconceptions here 👇 www.synacktiv.com/en/publicati...
synacktiv.com
Quantum readiness: Hybridizing key exchanges
Quantum readiness: Hybridizing key exchanges
111
Reposted by F4b
Synacktiv @synacktiv.com · 14/10/2025
LinkPro: new stealthy #Linux rootkit based on eBPF 🔍️ Our #CSIRT team discovered and named LinkPro, a new Linux rootkit, during an incident response. It exploits eBPF for evasion and persistence. Here are the four key technical points in the image below. 💡 🔗 www.synacktiv.com/en/publicati...
044
Reposted by F4b
Hexacon @hexacon.bsky.social · 13/10/2025
That's a wrap for Hexacon 2025! We hope that you've enjoyed the event at least as much as we did 🤩 Please take a moment to fill out our satisfaction survey and help us make Hexacon 2026 even better 🔥 Thank you for trusting us year after year 🙏
053
Reposted by F4b
Synacktiv @synacktiv.com · 13/10/2025
🎯 New training session: #ActiveDirectory Intrusion Tactics – Advanced Level 5 intense days diving into advanced AD intrusion techniques. Don’t miss our upcoming offensive #cybersecurity courses! 🔗 www.synacktiv.com/en/offers/tr...
021
Reposted by F4b
Synacktiv @synacktiv.com · 08/10/2025
LLM Poisoning [1/3]: Local LLMs are vulnerable to supply chain attacks. Inject a trigger-activated Trojan in a LLM. First step, build a probe to read a transformer's pre-down MLP activations to detect your chosen trojan trigger. 🔗 Full article www.synacktiv.com/en/publicati...
synacktiv.com
LLM Poisoning [1/3] - Reading the Transformer's Thoughts
LLM Poisoning [1/3] - Reading the Transformer's Thoughts
011
Reposted by F4b
Synacktiv @synacktiv.com · 08/10/2025
#LesAssises2025, here we go 🚀 Come and meet us at 𝘀𝘁𝗮𝗻𝗱 𝗙𝟮𝟴 to discuss your challenges and find out how we can strengthen your #cyber posture. Adrien, Augustin and Neder will be on hand to answer all your questions and share their insights. Seeing you there 🤝
011
Reposted by F4b
Synacktiv @synacktiv.com · 07/10/2025
A look back at our ninjas' first day at @hexacon.bsky.social ! We are proud of our experts Quentin and Etienne, who are leading the ‘iOS for Security Engineers’ training course. At the same time, Matthieu and Paul are hard at work on the ‘Azure intrusion for red teamers’ training course 🚀
021
Reposted by F4b
Hexacon @hexacon.bsky.social · 03/10/2025
📢"Paint it Blue: Attacking the Bluetooth stack" by Mehdi Talbi and Etienne Helluy-Lafont
022
Reposted by F4b
Synacktiv @synacktiv.com · 03/10/2025
Tick tock... 7 days to go until #Hexacon2025 kicks off ⏳ The @synacktiv.com team can't wait to see you at this crucial event for the #cyber ecosystem. Our experts will be on hand to discuss the latest innovations in pentesting and reverse engineering with you ! ℹ️ www.hexacon.fr
011
Reposted by F4b
Synacktiv @synacktiv.com · 03/10/2025
In our new blogpost, Alexandre Z. shows how one can abuse Unicode characters to bypass filters and abuse shell globbing, regexp, HTTP query parameters or WAFs when #MySQL strict SQL mode is off 👇 www.synacktiv.com/en/publicati...
synacktiv.com
What could go wrong when MySQL strict SQL mode is off?
What could go wrong when MySQL strict SQL mode is off?
011
Reposted by F4b
Synacktiv @synacktiv.com · 03/10/2025
Join us on 24 November for the Azure Intrusion Tactics training course 🛡️ Learn offensive techniques for compromising Azure environments. Realistic scenarios, stealthy approaches and cutting-edge expertise. Information & registration 👇 www.synacktiv.com/en/offers/tr...
021
Reposted by F4b
Hexacon @hexacon.bsky.social · 03/10/2025
Last sponsor to announce: Synacktiv! 🥷 @synacktiv.com strives to help firms evaluate and improve their IT security, everybody there is working to make it the 🇫🇷 standard in offensive security. There will a be a lot of ninjas lurking around, feel free to reach them out!
032
Reposted by F4b
Hexacon @hexacon.bsky.social · 02/10/2025
📢"Inside Apple Secure Enclave Processor in 2025" by Quentin Salingue
011