Sign in

Alexandre Cheron

@axcheron.bsky.social
34 followers 49 following 167 posts

Hacker. Security Researcher. Bytes Addict. Became self-aware at 5:32 a.m. Almost Human. Shall we play a game?

PostsRepliesMedia
Alexandre Cheron @axcheron.bsky.social · 02/06/2026
Critical Windows Netlogon RCE flaw now exploited in attacks #RCE #Windows (CVE-2026-41089) www.bleepingcomputer.com/news/microso...
bleepingcomputer.com
Critical Windows Netlogon RCE flaw now exploited in attacks
The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon vuln...
000
Alexandre Cheron @axcheron.bsky.social · 04/02/2026
EDR killer tool uses signed kernel driver from forensic software #EDR www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
EDR killer tool uses signed kernel driver from forensic software
Hackers are abusing a legitimate but long-revoked EnCase kernel driver in an EDR killer that can detect 59 security tools in attempts to deactivate them.
000
Alexandre Cheron @axcheron.bsky.social · 02/02/2026
Notepad++ update feature hijacked by Chinese state hackers for months www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Notepad++ update feature hijacked by Chinese state hackers for months
Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year, the developer states in an official announcement today.
000
Alexandre Cheron @axcheron.bsky.social · 23/01/2026
Overrun with AI slop, cURL scraps bug bounties to ensure “intact mental health” #Curl arstechnica.com/security/202...
arstechnica.com
Overrun with AI slop, cURL scraps bug bounties to ensure "intact mental health"
The onslaught includes LLMs finding bogus vulnerabilities and code that won't compile.
010
Alexandre Cheron @axcheron.bsky.social · 20/01/2026
Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers thehackernews.com/2026/01/clou... #Cloudflare
thehackernews.com
Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers
Cloudflare patched an ACME HTTP-01 validation flaw that disabled WAF protections and let unauthorized requests reach origin servers.
000
Alexandre Cheron @axcheron.bsky.social · 09/01/2026
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions thehackernews.com/2026/01/tren...
thehackernews.com
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions
Trend Micro patched a critical Apex Central on-prem Windows flaw (CVE-2025-69258) with CVSS 9.8 that allows remote code execution if access exists.
000
Alexandre Cheron @axcheron.bsky.social · 05/01/2026
NordVPN denies breach claims, says attackers have "dummy data" www.bleepingcomputer.com/news/securit... #NordVPN
bleepingcomputer.com
NordVPN denies breach claims, says attackers have "dummy data"
NordVPN denied allegations that its internal Salesforce development servers were breached, saying that cybercriminals obtained "dummy data" from a trial account on a third-party automated testing plat...
000
Alexandre Cheron @axcheron.bsky.social · 28/12/2025
Massive Rainbow Six Siege breach gives players billions of credits www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Massive Rainbow Six Siege breach gives players billions of credits
Ubisoft's Rainbow Six Siege (R6) suffered a breach that allowed hackers to abuse internal systems to ban and unban players, manipulate in-game moderation feeds, and grant massive amounts of in-game cu...
000
Alexandre Cheron @axcheron.bsky.social · 20/12/2025
TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering www.evilsocket.net/2025/12/18/T...
evilsocket.net
TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering
010
Alexandre Cheron @axcheron.bsky.social · 11/12/2025
Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks thehackernews.com/2025/12/unpa... #Gogs #0day
thehackernews.com
Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks
Unpatched Gogs flaw CVE-2025-8110 enables file overwrite and code execution, driving over 700 confirmed compromises.
000
Alexandre Cheron @axcheron.bsky.social · 19/11/2025
Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001) thehackernews.com/2025/11/hack...
thehackernews.com
Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)
Active exploitation targets 7-Zip CVE-2025-11001; patch 25.00 fixes symbolic link RCE flaws.
010
Alexandre Cheron @axcheron.bsky.social · 23/10/2025
Catching Credential Guard Off Guard specterops.io/blog/2025/10...
specterops.io
Catching Credential Guard Off Guard - SpecterOps
Uncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping.
000
Alexandre Cheron @axcheron.bsky.social · 23/10/2025
Bypass AMSI in 2025 #AMSI www.r-tec.net/r-tec-blog-b...
r-tec.net
r-tec Blog | Bypass AMSI in 2025
This blog post will shed some light on what's behind AMSI (roughly, but hopefully easy to understand) and how you can still effectively bypass it - more than four years later.
000
Alexandre Cheron @axcheron.bsky.social · 07/10/2025
13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely #Redis #RCE thehackernews.com/2025/10/13-y...
thehackernews.com
13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely
Redis fixes 13-year CVSS 10 flaw allowing Lua script-based remote code execution in all versions.
000
Alexandre Cheron @axcheron.bsky.social · 18/09/2025
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens #Microsoft #EntraID dirkjanm.io/obtaining-gl...
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
010
Alexandre Cheron @axcheron.bsky.social · 04/09/2025
ksmbd - Fuzzing Improvements and Vulnerability Discovery (2/3) #Fuzzing blog.doyensec.com/2025/09/02/k...
blog.doyensec.com
ksmbd - Fuzzing Improvements and Vulnerability Discovery (2/3) · Doyensec's Blog
ksmbd - Fuzzing Improvements and Vulnerability Discovery (2/3)
000
Alexandre Cheron @axcheron.bsky.social · 04/09/2025
Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel #Linux #Kernel a13xp0p0v.github.io/2025/09/02/k...
a13xp0p0v.github.io
Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel
Some memory corruption bugs are much harder to exploit than others. They can involve race conditions, crash the system, and impose limitations that make a researcher's life difficult. Working with suc...
011
Alexandre Cheron @axcheron.bsky.social · 11/08/2025
WinRAR zero-day exploited to plant malware on archive extraction. #WinRAR #0day www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
WinRAR zero-day exploited to plant malware on archive extraction
A recently fixed WinRAR vulnerability tracked as CVE-2025-8088 was exploited as a zero-day in phishing attacks to install the RomCom malware.
000
Alexandre Cheron @axcheron.bsky.social · 08/08/2025
Project Zero: From Chrome renderer code exec to kernel with MSG_OOB googleprojectzero.blogspot.com/2025/08/from...
googleprojectzero.blogspot.com
From Chrome renderer code exec to kernel with MSG_OOB
Posted by Jann Horn, Google Project Zero Introduction In early June, I was reviewing a new Linux kernel feature when I learned about the...
000
Alexandre Cheron @axcheron.bsky.social · 06/08/2025
ReVault flaws let hackers bypass Windows login on Dell laptops www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
ReVault flaws let hackers bypass Windows login on Dell laptops
ControlVault3 firmware vulnerabilities impacting over 100 Dell laptop models can allow attackers to bypass Windows login and install malware that persists across system reinstalls.
000
Alexandre Cheron @axcheron.bsky.social · 05/08/2025
SonicWall urges admins to disable SSLVPN amid rising attacks #SonicWall www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
SonicWall urges admins to disable SSLVPN amid rising attacks
SonicWall has warned customers to disable SSLVPN services due to ransomware gangs potentially exploiting an unknown security vulnerability in SonicWall Gen 7 firewalls to breach networks over the past...
000
Alexandre Cheron @axcheron.bsky.social · 22/07/2025
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access #0day thehackernews.com/2025/07/hack...
thehackernews.com
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access
Active SharePoint exploits since July 7 target governments and tech firms globally, risking key theft and persistent access.
000
Alexandre Cheron @axcheron.bsky.social · 09/07/2025
CVE-2025-1729 - Privilege Escalation Using TPQMAssistant.exe trustedsec.com/blog/cve-202...
trustedsec.com
CVE-2025-1729 - Privilege Escalation Using TPQMAssistant.exe
000
Alexandre Cheron @axcheron.bsky.social · 04/07/2025
Applocker bypass on Lenovo machines – The curious case of MFGSTAT.zip oddvar.moe/2025/07/03/a...
oddvar.moe
Applocker bypass on Lenovo machines – The curious case of MFGSTAT.zip
This blogpost is about a minor discovery I made regarding a writeable file inside the Windows folder that is present on Lenovo machines. Initially when I found it I thought it was only a handful of…
000
Alexandre Cheron @axcheron.bsky.social · 03/07/2025
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms thehackernews.com/2025/07/chin... #Ivanti #0day
thehackernews.com
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms
Chinese hackers exploited Ivanti CSA zero-days, targeting French government, media, and telecom sectors in September 2024.
000
Alexandre Cheron @axcheron.bsky.social · 30/06/2025
Over 1,200 Citrix servers unpatched against critical auth bypass flaw #Citrix www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Over 1,200 Citrix servers unpatched against critical auth bypass flaw
Over 1,200 Citrix NetScaler ADC and NetScaler Gateway appliances exposed online are unpatched against a critical vulnerability believed to be actively exploited, allowing threat actors to bypass authe...
000
Alexandre Cheron @axcheron.bsky.social · 18/06/2025
Instagram ads mimicking BMO, EQ Bank are finance scams www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Instagram ads mimicking BMO, EQ Bank are finance scams
Instagram ads impersonating financial institutions like Bank of Montreal (BMO) and EQ Bank (Equitable Bank) are being used to target Canadian consumers with phishing scams and investment fraud. Some ...
000
Alexandre Cheron @axcheron.bsky.social · 18/06/2025
CISA Warns of Active Exploitation of Linux Kernel Privilege Escalation Vulnerability thehackernews.com/2025/06/cisa... #Linux
thehackernews.com
CISA Warns of Active Exploitation of Linux Kernel Privilege Escalation Vulnerability
CISA warns CVE-2023-0386 is being actively exploited, impacting Linux systems via OverlayFS. Patching is urgent.
010
Alexandre Cheron @axcheron.bsky.social · 13/06/2025
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware thehackernews.com/2025/06/appl... #Apple
thehackernews.com
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware
Apple patched zero-day flaws exploited to deploy Paragon’s Graphite spyware targeting journalists and civil society, raising global spyware concerns.
000
Alexandre Cheron @axcheron.bsky.social · 11/06/2025
Streaming Zero-Fi Shells to Your Smart Speaker | Exploiting the Sonos Era 300 with a Malicious HLS Playlist blog.ret2.io/2025/06/11/p...
blog.ret2.io
Streaming Zero-Fi Shells to Your Smart Speaker
In October 2024, RET2 participated in the “Small Office / Home Office” (SOHO) flavor of Pwn2Own, a competition which challenges top security researchers to c...
011
Alexandre Cheron @axcheron.bsky.social · 10/06/2025
Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them arstechnica.com/security/202...
arstechnica.com
Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.
The publicly available exploits provide a near-universal way to bypass key protections.
000
Alexandre Cheron @axcheron.bsky.social · 28/05/2025
Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File thehackernews.com/2025/05/micr...
thehackernews.com
Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File
OneDrive’s OAuth flaw grants full cloud access via vague prompts + insecure tokens = user data risk.
000
Alexandre Cheron @axcheron.bsky.social · 09/05/2025
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages googleprojectzero.blogspot.com/2025/05/brea...
googleprojectzero.blogspot.com
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages
Guest post by Dillon Franke, Senior Security Engineer ,  20% time on Project Zero Every second, highly-privileged MacOS system daemons...
000
Alexandre Cheron @axcheron.bsky.social · 30/04/2025
Supercharging Ghidra: Using Local LLMs with GhidraMCP via Ollama and OpenWeb-UI medium.com/@clearblueja...
medium.com
Supercharging Ghidra: Using Local LLMs with GhidraMCP via Ollama and OpenWeb-UI
Reverse engineering binaries often resembles digital archaeology: excavating layers of compiled code, interpreting obscured logic, and…
000
Alexandre Cheron @axcheron.bsky.social · 29/04/2025
Apple 'AirBorne' flaws can lead to zero-click AirPlay RCE attacks www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Apple 'AirBorne' flaws can lead to zero-click AirPlay RCE attacks
​A set of security vulnerabilities in Apple's AirPlay Protocol and AirPlay Software Development Kit (SDK) exposed unpatched third-party and Apple devices to various attacks, including remote code exec...
000
Alexandre Cheron @axcheron.bsky.social · 28/04/2025
iOS and Android juice jacking defenses have been trivial to bypass for years arstechnica.com/security/202...
arstechnica.com
iOS and Android juice jacking defenses have been trivial to bypass for years
New ChoiceJacking attack allows malicious chargers to steal data from phones.
000
Alexandre Cheron @axcheron.bsky.social · 25/04/2025
Ghosting AMSI: Cutting RPC to disarm AV medium.com/@andreabocch...
medium.com
Ghosting AMSI: Cutting RPC to disarm AV
In this post, we explore how to bypass AMSI’s scanning logic by hijacking the RPC layer it depends on — specifically the NdrClientCall3…
000
Alexandre Cheron @axcheron.bsky.social · 24/04/2025
Linux io_uring PoC Rootkit Bypasses System Call-Based Threat Detection Tools thehackernews.com/2025/04/linu...
thehackernews.com
Linux io_uring PoC Rootkit Bypasses System Call-Based Threat Detection Tools
ARMO shows io_uring-based rootkits evade Falco, Tetragon, and Defender, risking Linux runtime security.
000
Alexandre Cheron @axcheron.bsky.social · 18/04/2025
CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download thehackernews.com/2025/04/cve-...
thehackernews.com
CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download
Windows flaw CVE-2025-24054 actively exploited since March 19 to leak NTLM hashes via phishing attacks.
000
Alexandre Cheron @axcheron.bsky.social · 16/04/2025
Task Scheduler– New Vulnerabilities for schtasks.exe cymulate.com/blog/task-sc...
cymulate.com
Task Scheduler– New Vulnerabilities for schtasks.exe
UAC bypass, metadata poisoning, and log overflow vulnerabilities in Windows Task Scheduler reveal new tactics for defense evasion and privilege escalation
001
Alexandre Cheron @axcheron.bsky.social · 15/04/2025
Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence thehackernews.com/2025/04/crit...
thehackernews.com
Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence
Apache Roller flaw CVE-2025-24859 keeps sessions active after password changes, risking persistent access.
000
Alexandre Cheron @axcheron.bsky.social · 15/04/2025
Aiding reverse engineering with Rust and a local LLM security.humanativaspa.it/aiding-rever...
security.humanativaspa.it
Aiding reverse engineering with Rust and a local LLM - hn security
“A large fraction of the flaws […]
000
Alexandre Cheron @axcheron.bsky.social · 08/04/2025
Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal thehackernews.com/2025/04/amaz...
thehackernews.com
Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal
AWS patched an EC2 SSM Agent flaw on March 5, 2025, preventing privilege escalation via plugin ID path traversal.
000
Alexandre Cheron @axcheron.bsky.social · 04/04/2025
Troy Hunt: A Sneaky Phish Just Grabbed my Mailchimp Mailing List www.troyhunt.com/a-sneaky-phi...
troyhunt.com
A Sneaky Phish Just Grabbed my Mailchimp Mailing List
You know when you're really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That's me right now, and the penny has just dropped that a Mailchimp phish h...
000
Alexandre Cheron @axcheron.bsky.social · 01/04/2025
Harnessing the power of Named Pipes cybercx.co.nz/blog/harness...
cybercx.co.nz
Harnessing the power of Named Pipes
This Technical Blog provides a simple methodology for identifying, monitoring, and exploiting named pipes.
000
Alexandre Cheron @axcheron.bsky.social · 01/04/2025
Reforging Sliver: How Simple Code Edits Can Outmaneuver EDR fortbridge.co.uk/research/ref...
fortbridge.co.uk
Reforging Sliver: How Simple Code Edits Can Outmaneuver EDR
Learn how sliver can help you bypass EDR with tailored adaptations and discover the benefits of open source security tools.
000
Alexandre Cheron @axcheron.bsky.social · 31/03/2025
Blasting Past Webp - An analysis of the NSO BLASTPASS iMessage exploit googleprojectzero.blogspot.com/2025/03/blas...
googleprojectzero.blogspot.com
Blasting Past Webp
An analysis of the NSO BLASTPASS iMessage exploit Posted by Ian Beer, Google Project Zero On September 7, 2023 Apple issued  an out-...
000
Alexandre Cheron @axcheron.bsky.social · 25/03/2025
Remote Code Execution Vulnerabilities in Ingress NGINX www.wiz.io/blog/ingress...
wiz.io
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog
Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.
000
Alexandre Cheron @axcheron.bsky.social · 22/03/2025
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns www.trendmicro.com/en_us/resear...
trendmicro.com
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns
Trend Zero Day Initiative™ (ZDI) uncovered both state-sponsored and cybercriminal groups extensively exploiting ZDI-CAN-25373, a Windows .lnk file vulnerability that enables hidden command execution.
000
Alexandre Cheron @axcheron.bsky.social · 18/03/2025
Arbitrary File Write CVE-2024-0402 in GitLab blog.doyensec.com/2025/03/18/e...
blog.doyensec.com
!exploitable Episode Three - Devfile Adventures · Doyensec's Blog
!exploitable Episode Three - Devfile Adventures
000