Sign in

aurelsec

@aurelsec.bsky.social
327 followers 642 following 23 posts

Hackademic at S3@eurecom

PostsRepliesMedia
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 04/09/2026
"Au cœur d’une cyberattaque sans précédent qui a ébranlé le notariat français" www.lemonde.fr/pixels/artic...
lemonde.fr
Au cœur d’une cyberattaque sans précédent qui a ébranlé le notariat français
Des pirates ont détourné au moins 35 millions d’euros au sein de centaines d’offices notariaux pendant deux ans. Les hackeurs étaient si prolifiques que les autorités ont craint l’émission de faux act...
111
aurelsec @aurelsec.bsky.social · 17/08/2026
Bon peut etre que a force d'etre victime on va finir par renoncer a mettre des backdoors dans les trucs qui marchent et sont sécurisée (messageries, etc), on a pas besoin de vulnérabilités en plus, mais de se concentrer a durcir les systèmes d’information, ceux de l’etat en premier!
011
Reposted by aurelsec
henri2h.bsky.social @henri2h.bsky.social · 15/08/2026
Happy to have presented our paper with @aurelsec.bsky.social "SoK: Insecurity of Cellular Basebands" at USENIX WOOT'26. Paper: www.usenix.org/conference/w... #WOOT26
031
Reposted by aurelsec
Matt Blaze @mattblaze.org · 23/07/2026
This is a wonderful documentary that you should see whether you'd heard of Joybubbles or not and whether you identify as a, um, phone enthusiast, or not.
1296
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 02/07/2026
Ce que nous enseigne la première attaque (expérimentale) d’un ver informatique mû par l’IA www.lemonde.fr/sciences/art...
lemonde.fr
Ce que nous enseigne la première attaque (expérimentale) d’un ver informatique mû par l’IA
Une équipe canadienne a développé un programme utilisant un grand modèle de langage pour orchestrer des attaques et repérer des failles de façon autonome. Si cette démonstration ne surprend pas les sp...
121
aurelsec @aurelsec.bsky.social · 29/06/2026
Interesting, spam email using LLM for generating content, LLM saying "nope" :)
031
Reposted by aurelsec
Julien Gossa @juliengossa.cpesr.fr · 27/06/2026
[ #VeilleESR #Parcoursup ] Enseignement supérieur privé lucratif : 32 propositions pour réguler le secteur « une qualité pédagogique inégale, des pratiques commerciales trompeuses et un manque de transparence sur les diplômes, dans un contexte de risque de défaillance de certains acteurs »
igas.gouv.fr
Enseignement supérieur privé lucratif : 32 propositions pour réguler le secteur | Igas
Le rapport dresse un état des lieux du secteur, en forte expansion depuis la réforme de l'apprentissage de 2018 et largement soutenu, en France, par des financements publics.
10152137
Reposted by aurelsec
Julien Gossa @juliengossa.cpesr.fr · 27/06/2026
Le rapport enquête notamment Galileo Global Education. Le groupe qui rémunère Muriel Pénicaud. La même Muriel Pénicaud qui a fait la LCAP qui permet au groupe Galileo Global Education de s'enrichir au détriment de tout notre système national d'enseignement supérieur.
14022
Reposted by aurelsec
The Conversation France @france.theconversation.com · 18/06/2026
Une étude des discours de politique générale depuis 1959 montre que les premiers ministres du centristes ont contribué à accélérer le glissement vers les idées d’extrême droite.
9192134
Reposted by aurelsec
Phrack Zine @phrack.org · 28/05/2026
Submissions are still open! If you've been sitting on a bug, technique, war story, weird research rabbit hole, or beautifully cursed idea: now is the time. Write something worth archiving. Phrack CFP closes June 30. More details on how to submit at phrack.org/news
02119
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 18/05/2026
La réponse, agacée, de Vincent Strubel sur les rumeurs de tensions entre Matignon et l'Anssi
182
Reposted by aurelsec
0xor0ne @0xor0ne.bsky.social · 14/05/2026
HDD firmware hacking: dumping/analyzing/modifying the drive firmware and debugging via JTAG icode4.coffee?p=1465 Credits Ryan Miceli #infosec
icode4.coffee
HDD Firmware Hacking Part 1
Do you know how a hard drive works? Come find out with me as I dump, reverse engineer, and modify the firmware on various HDDs and SSDs.
084
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 14/05/2026
"Pourquoi il faut sauver le soldat Anssi" www.lemagit.fr/tribune/Pour...
lemagit.fr
Pourquoi il faut sauver le soldat Anssi | LeMagIT
L'Agence nationale de la sécurité des systèmes d'information apparaît comme le parfait fusible de l'échec de l'administration française en matière de cybersécurité, après des dizaines de brèches de do...
152
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 12/05/2026
« L’allégation selon laquelle Europol aurait “caché” des informations concernant les environnements ou les systèmes de traitement constitue une déformation des faits », a répondu l'agence.
011
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 12/05/2026
« Ils protègent la loi tout en l’enfreignant » : dans les coulisses du SI parallèle d’Europol: Computer Weekly dénonce les méthodes de l'agence européenne www.lemagit.fr/actualites/3...
lemagit.fr
« Ils protègent la loi tout en l’enfreignant » : dans les coulisses du SI parallèle d’Europol | LeMagIT
Sous la pression de devoir produire des résultats dans la lutte contre la criminalité transfrontalière, Europol a construit et exploité une plateforme d’analyse de données parallèle, contenant de gran...
143
Reposted by aurelsec
Yiorgos Vassalos @yiorgosvassalos.bsky.social · 13/11/2025
Hungry for data: Inside Europol’s secretive AI programme www.computerweekly.com/news/3666344...
computerweekly.com
Hungry for data: Inside Europol’s secretive AI programme | Computer Weekly
The EU’s law enforcement agency has been quietly amassing data to feed an ambitious but secretive artificial intelligence development programme that could have far-reaching privacy implications for pe...
001
Reposted by aurelsec
Léαlinux 🐧 @lea-linux.org · 07/05/2026
github.com/V4bel/dirtyf... Faille Kernel Linux, va falloir blacklister de nouveau certains kmodules.
media.tenor.com
a man stands in front of a crowd with the words " are you not entertained " below him
Alt: a man stands in front of a crowd with the words " are you not entertained " below him
51912
Reposted by aurelsec
404 Media @404media.co · 02/04/2026
NEW: TeleGuard has been downloaded more than a million times and markets itself as a secure way to chat. But the app, which has been repeatedly been linked to child abusers, has such bad encryption, experts say its claims are "meaningless."
404media.co
A Secure Chat App’s Encryption Is So Bad It Is ‘Meaningless’
TeleGuard is an app downloaded more a million times that markets itself as a secure way to chat. The app uploads users’ private keys to the company’s server, and makes decryption of messages trivial.
112339
Reposted by aurelsec
Léαlinux 🐧 @lea-linux.org · 01/04/2026
lkml.org/lkml/2026/4/... Le patch que tout le monde veut !
lkml.org
LKML: Christian Brauner: [PATCH] vfs: require verified birth date for file creation
053
Reposted by aurelsec
Hervé Schauer @herve-schauer.bsky.social · 23/03/2026
Le #SSTIC ne semble toujours pas sur BlueSky 😢 Programme en ligne : www.sstic.org/2026/program...
sstic.org
SSTIC2026 » Programme du 3 au 5 juin 2026
088
Reposted by aurelsec
Matthew Green @matthewdgreen.bsky.social · 21/03/2026
Here’s a good article about Meta’s very frustrating decision to pull encryption out of Instagram. www.wired.com/story/the-da...
wired.com
The Danger Behind Meta Killing End-to-End Encryption for Instagram DMs
Meta blamed users for not opting into the privacy-protecting feature. Experts fear the move could be the first major domino to fall for end-to-end encryption tech worldwide.
211967
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 19/03/2026
"Règlement Chat Control : L’Europe maintient la détection ciblée des contenus pédocriminels mais refuse le contrôle massif des communications privées" www.usine-digitale.fr/cybersecurit...
usine-digitale.fr
111
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 13/03/2026
Affaire de l'IMSI-catcher: le tribunal judiciaire de Paris rend son délibéré.
173
Reposted by aurelsec
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 05/03/2026
NEW: The FBI said it is investigating a hack on its networks. The breach affected the FBI's systems to manage wiretaps and surveillace requests, according to CNN. techcrunch.com/2026/03/05/f...
techcrunch.com
FBI investigating hack on its wiretap and surveillance systems: report | TechCrunch
Hackers allegedly broke into the FBI’s networks, according to a report by CNN.
02411
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 26/02/2026
Et de requérir huit ans d’emprisonnement et une peine d’amende de 200 000 euros. "C’est une peine qui aura valeur d’avertissement pour tous ceux qui seraient tentés d’introduire en France des IMSI ou toutes sortes de produits réglementés dangereux", conclut Johanne Brousse.
121
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 26/02/2026
Pour Sammy N., l'un des acheteurs d'un IMSI Catcher, utilisé disait-il pour faire des SMS promotionnels pour un fast-food: quatre ans de prison, dont deux avec sursis.
122
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 26/02/2026
Contre Mohamed A., celui qui a recruté des conducteurs - il a “exploité des femmes” pour “pas se fatiguer” et faire circuler un IMSI. “Il refuse de parler”, une "règle tactile du milieu”. “Compte tenu de son palmarès judiciaire”, elle demande quatre ans d’emprisonnement avec mandat de dépôt.
122
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 26/02/2026
Le cas d'Abdoulaye K., Mohamed M. et leur société Scion Data Agency est traité d'un bloc, car "tout découpage serait artificiel". "Ils pourraient assumer, mais on préfère enfoncer les autres plutôt que d’assumer leurs responsabilités", tance-t-elle.
121
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 26/02/2026
Ce sont "des escrocs chevronnés", "malins", note-t-elle, capables d'aller à la Cnil pour se “préconstituer une preuve”. Une peine de 5 ans de prison et une amende de 50 000 euros contre chacun des prévenus est requise, ainsi qu'une amende de 300 000 euros contre leur société.
122
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 26/02/2026
Bonjour, l'audience de l'affaire "IMSI-Catcher" va reprendre cet après-midi au tribunal judiciaire de Paris. Thread👇.
155
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 20/02/2026
Bonjour, L'audience de l'examen de l'affaire dite de l'IMSI catcher va bientôt reprendre au tribunal judiciaire de Paris. Thread👇.
184
Reposted by aurelsec
Gabriel Thierry @gabrielthierry.eurosky.social · 19/02/2026
Bonjour, Reprise de ce live-skeet avec le deuxième jour d'audience de l'affaire dite de l'IMSI Catcher qui va bientôt débuter.
154
Reposted by aurelsec
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/11/2025
USENIX WOOT Conference 2026: two submission deadlines this year! - Cycle 1: December 12, 2025 *only one month away* ! - Cycle 2: March 3, 2026 WOOT still has a SoK track and an "Up-and-coming track" (~Industry), CFP for details: www.usenix.org/conference/w...
056
Reposted by aurelsec
Edwy Plenel @edwyplenel.bsky.social · 05/11/2025
C'est un document sans précédent : les caméras-piétons des gendarmes mobiles engagés à Sainte-Soline en 2023 dévoilent un maintien de l'ordre fascisant où tous les excès sont permis avec les encouragements de la hiérarchie. À partager. www.mediapart.fr/journal/fran...
mediapart.fr
« Faut leur tirer dans la gueule ! » : la manifestation de Sainte-Soline vue par les gendarmes
Mediapart et « Libération » révèlent des images inédites du 25 mars 2023, filmées par les caméras-piétons des gendarmes. Elles montrent des consignes prohibées et dangereuses données par la hiérarchi…
12385212
Reposted by aurelsec
Aurore Fass @aurore-fass.bsky.social · 16/10/2025
Last chance to (self-) nominate for USENIX Security'26 Artifact Evaluation Committee! You should expect a low load of ~1 artifact for functionality/reproducibility assessments per cycle (max 3 for the whole year). Please support Open Science and fill the form by Oct 17: forms.gle/WoYRX4govNY1... 🚀
forms.gle
(Self-)Nomination for the USENIX Security '26 Artifact Evaluation Committee (AEC)
For the seventh year, USENIX Security allows the evaluation of artifacts that support a paper: software, hardware, evaluation data and documentation, raw measurement data, raw survey results, mechaniz...
087
Reposted by aurelsec
Hervé Schauer @herve-schauer.bsky.social · 10/10/2025
À #SecSea2k5 Aurélien Francillon d'Eurecom relate les expériences hallucinantes d'écoutes en reconnectant avec les documents NSA déclassifiés en parallèle 😁 ✅ Bluetooth 😧 ✅ JTAG fait tout fuiter "quand le 𝑗𝑖𝑡𝑡𝑒𝑟 révèle le calcul de la puce" 👏🏻 Génial 👍🏻
183
Reposted by aurelsec
Electronic Frontier Foundation @eff.org · 06/10/2025
The Danish Presidency is pushing a dangerous proposal in the EU that would allow the government to scan all our private communications. www.eff.org/deeplinks/2...
eff.org
Chat Control Is Back on the Menu in the EU. It Still Must Be Stopped
The European Union Council is once again debating its controversial message scanning proposal, aka “Chat Control,” that would lead to the scanning of private conversations of billions of people. Chat
011772
Reposted by aurelsec
Suzanne Smalley @suzannesmalley.bsky.social · 06/10/2025
Signal to leave EU rather than comply w/ Chat Control, which would scan all messages sent over end-to-end encrypted platforms. Vote on Chat Control's future Oct 14. Germany is the swing vote. Officials there opposed the measure in past but new govt silent re position therecord.media/signal-calls...
therecord.media
Signal calls on Germany to vote against ‘Chat Control,’ saying it would leave EU market
The head of the Signal Foundation raised concerns around Germany now refusing to say whether it will support Chat Control in an upcoming vote.
02113
aurelsec @aurelsec.bsky.social · 06/10/2025
Interesting story how DES 56 became a 56-bit key algorithm (while having a 64-bit block size): "NSA tried to convince IBM to reduce the length of the key from 64 to 48 bits. Ultimately, they compromised on a 56-bit key."
162
Reposted by aurelsec
Nicolas Hénin @nicolashenin.net · 06/10/2025
Archives du 26 juillet 2024 : Emmanuel Macron écarte l'option d'un gouvernement mené par @luciecastets.bsky.social au nom de "la stabilité institutionnelle".
tf1info.fr
Emmanuel Macron écarte l'option d'un gouvernement de gauche au nom de "la stabilité institutionnelle" | TF1 INFO
[VIDÉO] Emmanuel Macron a exclu lundi soir l'idée de nommer un Premier ministre issu du Nouveau Front populaire. Les représentants de l'alliance de gauche dénoncent "un coup de force" et appellent à u...
511437699
aurelsec @aurelsec.bsky.social · 29/09/2025
Tomorrow at 6:30 PM the EU Green Parliament group holds a webinar on #ChatControl act.greens-efa.eu/chatcontrol
act.greens-efa.eu
Stop Chat Control: Why scanning all our private messages is a very bad idea
🔴 Webinar - Tue 30 Sep 18.30h CEST
064
Reposted by aurelsec
Natanael, Tech janitor @natanael.bsky.social · 23/09/2025
"Bad news: The proposal is going forward to be voted on on October 14th, and there's still no blocking minority achieved, as Germany reverted its position to undecided. Good news: There is still time to fight back!" Shut this monstrosity down NOW
privacyguides.org
The battle to stop Chat Control continues, act now!
Unfortunately, the battle against Chat Control continues this month. For human rights, for civil liberties, for safety, and for democracy, this privacy-wrecking proposal must be stopped. We need your ...
01010
Reposted by aurelsec
EURECOM Library @eurecom-library.bsky.social · 16/09/2025
Le projet de loi pour espionner vos conversations privées #WhatsApp revient sur la table, l’opposition se mobilise 01net.com/actualites/l... via @01net.com #EURECOM @aurelsec.bsky.social
01net.com
Le projet de loi pour espionner vos conversations privées WhatsApp revient sur la table, l'opposition se mobilise
Le projet de règlement européen CSAR (appelé « chatcontrol » par ses opposants, pour « contrôle des conversations ») revient sur le devant de la scène, et les scientifiques tirent (à nouveau) la sonne...
021
Reposted by aurelsec
Phrack Zine @phrack.org · 18/08/2025
At long last - Phrack 72 has been released online for your reading pleasure! Check it out: phrack.org
The table of contents for Phrack 72 from phrack.org
012061
Reposted by aurelsec
Travis Campbell @hcoyote.bsky.social · 18/08/2025
Phrack 72 released today. phrack.org/issues/72/1 It got me thinking. I first read Phrack back in the 90's as I started hanging out on IRC (maybe '93 or '94?), as I was learning about FreeBSD and later, Linux. It must have been Phrack 43-45 where I started. What a wild ride on the Internet.
phrack.org
.:: Phrack Magazine ::.
Phrack staff website.
155
Reposted by aurelsec
pinkflawd.bsky.social @pinkflawd.bsky.social · 18/08/2025
I reverse engineered Lockbit's Linux ESXi variant, also explaining how I did some of the steps! For the fun of it, cause reverse engineering is lots of fun. Enjoy! hackandcheese.com/posts/blog1_...
1115
Reposted by aurelsec
pinkflawd.bsky.social @pinkflawd.bsky.social · 14/08/2025
@blackhoodie.bsky.social will be at @sec-t.bsky.social on September 10th with a training on Linux Malware Reverse Engineering, for women by women! We have very few seats left 😁 blackhoodie.re/SecT2025/
0129
Reposted by aurelsec
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 17/07/2025
Discounted early bird registration for WOOT '25 is still open until Monday - www.usenix.org/conference/w... - join us in Seattle on Aug 11/12 (right before USENIX Security) for talks and discussions on great cutting-edge offensive security research. Full program at www.usenix.org/conference/w...
usenix.org
WOOT '25 Technical Sessions
135
Reposted by aurelsec
Mathy Vanhoef @vanhoefm.bsky.social · 12/07/2025
Our research on open tunneling servers got nominated for the Most Innovative Research award :) The work will be presented by Angelos Beitis at Black Hat and also at USENIX Security Brief summary and code: github.com/vanhoefm/tun... Paper: papers.mathyvanhoef.com/usenix2025-t...
076
Reposted by aurelsec
Nain Portekoi @nainportekoi.bsky.social · 09/07/2025
Une pétition vient d'être lancée sur le site de l'AN pour demander au gouvernement français d'arrêter d'utiliser X pour ses communications officielles. Je l'ai évidemment signée. Avec toi ? (Et on fait tourner l'info) petitions.assemblee-nationale.fr/initiatives/...
petitions.assemblee-nationale.fr
Cesser d'utiliser X (anciennement Twitter) pour les communications officielles du gouvernement - Cesser d'utiliser X (anciennement Twitter) pour les communications officielles du gouvernement - Platef...
Cessez d'utiliser cette plateforme comme l'un des principaux porte-parole des communications officielles en France. Il existe des alternatives bien mieux modérées et régulées, et il est même possible ...
1213678