Sign in

Erwan Grelet

@ergrelet.bsky.social
45 followers 104 following 5 posts

Fond of reverse engineering and software development. Doing security engineering at some company.

PostsRepliesMedia
Erwan Grelet @ergrelet.bsky.social · 04/06/2026
Took some time to improve a few things on WinDiff (added permalinks, filtered out empty results) and added a Claude skill to easily use WinDiff to produce quick security-oriented diff analyses between binary/OS versions. Feel free to try! github.com/ergrelet/win...
022
Reposted by Erwan Grelet
Zion Leonahenahe Basque @mahal0z.bsky.social · 03/06/2026
Agents need better tools for reversing! I'm releasing declib (previously libbs), with a new CLI today that gives agents CLI access to 4 decompilers (IDA, Ghidra, Binja, angr), parity feature support to most MCP (12 features), and the ability to sync those changes across decs!
asciinema.org
libbs decompiler: cross-decompiler type sync (IDA -> Ghidra)
Recorded by mahaloz
111
Reposted by Erwan Grelet
hasherezade.bsky.social @hasherezade.bsky.social · 28/05/2026
New #TinyTracer (4.0) is ready: github.com/hasherezade/... - refactored for compatibility with the latest PIN - and with some new features!
094
Reposted by Erwan Grelet
pinkflawd.bsky.social @pinkflawd.bsky.social · 21/05/2026
I'll be back at @reconmtl.bsky.social teaching a training with Keith Ramphal, we'll be bringing our combined malware reverse engineering experience to the masses! Whatever runs, wherever it runs, cause the days of your boring ol' Windows C bot are over. recon.cx/2026/en/trai...
recon.cx
Advanced Malware Reverse Engineering - REcon 2026 Training
4-day hands-on malware analysis training by Marion Marschalek and Keith Ramphal. Master Windows, Linux & macOS malware reverse engineering at REcon Montreal.
073
Reposted by Erwan Grelet
OffensiveCon @offensivecon.bsky.social · 16/05/2026
Offensivecon is coming to Tokyo! 🔗 www.offensivecon.jp Ticket shop, sponsorships and CFP are already open...
111
Reposted by Erwan Grelet
Natalie Silvanovich @natashenka.bsky.social · 13/05/2026
Seth Jenkins updated our 0-click exploit chain to work on a Pixel 10 with an eye-popping driver bug! We’ll be presenting this work Saturday @offensivecon.bsky.social projectzero.google/2026/05/pixe...
projectzero.google
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible t...
095
Reposted by Erwan Grelet
Science Magazine @science.org · 05/05/2026
Deepfakes are everywhere, but digital forensics investigators are fighting back. Learn more: scim.ag/42dMPBg
To verify images, digital forensics investigators will often check whether the geometry of the scene is realistic. In a real photo, lines that run parallel in reality—like floor tiles—should meet at a single vanishing point. In this image, however, the dotted lines do not meet in a single point, indicating it is a fake.
Image: an AI-generated image of soldiers marching down a hallway in three lines, wearing fatigues and carrying rifles. Four dotted white lines have been added over the image, running along the floor tiles visible in the foreground and extending back to where the vanishing point should be, behind the soldiers. Instead of meeting in a single point, the lines all cross at different points.Investigators also examine reflections. The lines connecting points on an object to matching points in its mirror image run parallel in reality, so similarly should meet at a vanishing point. In this image, the lines again do not converge on one point, revealing it to be a fake.
Image: An AI-generated image of a plastic cartoon dinosaur toy with its reflection visible in a small mirror. Four dotted white lines are layered over the image, connecting points on the toy with the same points on its reflection: the top of its eye, the end of its jaw, its hand, and its foot. The lines extend out to the side of the image, where they all cross at different points rather than meeting at a single point.Shadows can be a giveaway, too. Because the Sun is so far away, its rays are essentially parallel when they reach Earth's surface. That means that the lines connecting points on an object to the shadows they cast in sunlight should also intersect at a vanishing point. In this Al-generated image, that is clearly not the case.
Image: An AI-generated image of colorful, semi-transparent plastic cubes arranged in a group in a city plaza. Six dotted white lines are layered over the image, connecting corners of several cubes with the corresponding corners in their shadows. The lines extend upward off the edge of the image, toward where a vanishing point should be. Three of them converge on roughly the same point, but two extend further, and one cuts across all the others at an angle.
6975102934
Reposted by Erwan Grelet
pinkflawd.bsky.social @pinkflawd.bsky.social · 07/05/2026
@blackhoodie.bsky.social will be back at @reconmtl.bsky.social this year 😱😻✨ Jane Tangen and Amna K Moon will be teaching an Introduction to x86 Reverse Engineering! We're delighted to be hosted at the Montreal Google offices! blackhoodie.re/Recon2026/
blackhoodie.re
Blackhoodie at Recon 2026
We are looking forward to hosting another Blackhoodie training at Recon for 2026! We will be hosting a free, one day training for women, by women.Join us for an introduction to Ghidra and static analy...
0147
Reposted by Erwan Grelet
Natalie Silvanovich @natashenka.bsky.social · 30/04/2026
Big changes to Android and Chrome VRP: - focus on high-impact, reproducible bugs with low/no reward for lower impact - big prizes for full chains with some annual limits - PoCs required It’s the end of an era, but the start of a new one. bughunters.google.com/blog/evolvin...
bughunters.google.com
Blog: Evolving the Android & Chrome VRPs for the AI Era
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of ...
074
Reposted by Erwan Grelet
Nicolò Altamura @nicolo.dev · 30/04/2026
Join us at REcon 2026 for a deep dive into deobfuscation! @mrphrazer.bsky.social and I will share some insights on the evolving landscape. Stay tuned!
011
Reposted by Erwan Grelet
HyperDbg @hyperdbg.bsky.social · 29/04/2026
Major milestone forward for HyperDbg supporting #Linux. We've made a major progress on porting HyperDbg to Linux (still a long road ahead). Now the HyperDbg SDK can be compiled with GCC for both user/kernel modes on Linux. More updates coming soon...👀 github.com/HyperDbg/Hyp...
github.com
HyperDbg/hyperdbg/linux at dev · HyperDbg/HyperDbg
State-of-the-art native debugging tools. Contribute to HyperDbg/HyperDbg development by creating an account on GitHub.
011
Reposted by Erwan Grelet
Recon @reconmtl.bsky.social · 28/04/2026
We have started announcing Recon 2026 Presentations recon.cx/2026/en/spea... More talks to be announced soon once we have confirmations #REcon2026 #ReverseEngineering #InfoSec #cybersecurity
031
Reposted by Erwan Grelet
0xor0ne @0xor0ne.bsky.social · 26/04/2026
Trailmark: parse source code into a Claude queryable call graph Blog post: blog.trailofbits.com/2026/04/23/t... Repository: github.com/trailofbits/... #infosec #llm
011
Reposted by Erwan Grelet
xarkes @xark.es · 23/04/2026
Mozilla says Mythos helped identify 271 vulnerabilities in Firefox 150. I went through the commits, CVEs, and bug links to see what that number really means. My takeaway: relax folks. xark.es/b/mythos-fir...
xark.es
A quick look at Mythos run on Firefox: too much hype?
A closer look at Mozilla's Firefox 150
199
Reposted by Erwan Grelet
buherator @buherator.bsky.social · 23/04/2026
OffensiveCon'26 agenda is out www.offensivecon.org -> Original->
011
Reposted by Erwan Grelet
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/04/2026
NEW: Apple fixed the bug that law enforcement, like the FBI, were taking advantage of to extract chat messages that had been deleted or disappeared automatically. Until now the iPhone stored deleted or disappered messages in a database, allowing authorities to access them with forensic tools.
techcrunch.com
Apple fixes bug that cops used to extract deleted chat messages from iPhones | TechCrunch
The iPhone and iPad bug allowed law enforcement using forensic tools to read messages that had long been deleted by the Signal app.
24817305
Reposted by Erwan Grelet
Binary Ninja @binary.ninja · 14/04/2026
Binary Ninja 5.3 (Jotunheim) is released: binary.ninja/2026/04/13/b... Major updates: NDS32 support, AArch64 ILP32 ABI, new Universal MachO UI, way more containers, command palette upgrade, type library helpers, ghidra gzf export, updated IDB import, HW and conditional breakpoints, and much more!
binary.ninja
Binary Ninja - Binary Ninja 5.3 (Jotunheim)
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
066
Reposted by Erwan Grelet
Binary Ninja @binary.ninja · 20/04/2026
Binary Ninja 5.3 (Jotunheim) adds new architecture APIs for full function level lifting. We are already using them for upcoming TMS320C6x work, and plugin authors should be able to put them to good use too.
112
Reposted by Erwan Grelet
Samuel Groß @saelo.bsky.social · 20/04/2026
The fuzzer that found project-zero.issues.chromium.org/issues?q=com... (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844 It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
project-zero.issues.chromium.org
Project Zero
0135
Reposted by Erwan Grelet
dmnk @dmnk.bsky.social · 11/04/2026
2 years ago I did a PoC to run #rust 🦀 in the #pixel modem Today it shipped in millions of devices! They grow up to fast! 🥲 security.googleblog.com/2026/04/brin... #rust #security #smartphone #baseband
security.googleblog.com
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been f...
49917
Reposted by Erwan Grelet
Quarkslab @quarkslab.bsky.social · 03/04/2026
Tired of reversing the same libc for the 100th time? 👀 Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries. High-confidence function mapping. Works with any disassembler. By @Mad5quirrel & Sami. 🔗 blog.quarkslab.com/sighthouse-a...
032
Reposted by Erwan Grelet
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 23/03/2026
SCOOP: Someone has found new samples of the iPhone spyware DarkSword and published them on GitHub, putting millions of iOS users at risk. A cybersecurity researcher told us that the leaked spyware is "way too easy to repurpose" and "we need to expect criminals and others to start deploying this."
techcrunch.com
Someone has publicly leaked an exploit kit that can hack millions of iPhones | TechCrunch
Leaked "DarkSword" exploits published to GitHub allow hackers and cybercriminals to target iPhone users running old versions of iOS with spyware, according to cybersecurity researchers.
710179
Reposted by Erwan Grelet
404 Media @404media.co · 16/03/2026
The CEO of Krafton used ChatGPT to push out the head of the studio developing Subnautica 2 against the advice of his own legal team and failed miserably.
404media.co
CEO Ignores Lawyers, Asks ChatGPT How to Void $250 Million Contract, Loses Terribly in Court
The CEO of Krafton used ChatGPT to push out the head of the studio developing Subnautica 2 against the advice of his own legal team and failed miserably.
15594228
Reposted by Erwan Grelet
RE//verse @re-verse.io · 16/03/2026
RE//verse 2026 talks are live on YouTube! Want to revisit a talk or catch the ones you missed? The full playlist is now available: youtube.com/playlist?lis...
084
Reposted by Erwan Grelet
Nicolò Altamura @nicolo.dev · 16/03/2026
The recording of my talk "Challenges in Decompilation and Reverse Engineering of CUDA-based Kernels" at @re-verse.io is now online! Recording: www.youtube.com/watch?v=ns5j... Slides: nicolo.dev/files/pdf/re... Binary Ninja plugin: github.com/seekbytes/pt...
github.com
GitHub - seekbytes/ptxNinja: Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs.
Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs. - seekbytes/ptxNinja
003
Reposted by Erwan Grelet
buherator @buherator.bsky.social · 16/03/2026
RE//verse 2026 videos are online www.youtube.com -> Original->
023
Reposted by Erwan Grelet
Nicolò Altamura @nicolo.dev · 08/03/2026
The slides from my @re-verse.io talk, "Challenges in Decompilation and Reverse Engineering of CUDA-based Kernels", are now online! Slides: nicolo.dev/files/pdf/re... Plugin: github.com/seekbytes/pt...
Diagram titled “Transformer attention.” It shows three steps of the attention computation with code snippets beside each step. The first step is “Scale factor 1/√dₖ,” highlighting code that computes the reciprocal square root. The second step is “Dot product Q · K,” showing code performing a dot-product accumulation. The third step is “Scaling + max tracking,” highlighting code that multiplies by the scale factor, stores the value, and updates a running maximum. The phrase “Transformer attention” appears prominently in the center.
162
Reposted by Erwan Grelet
Decoder Loop @decoderloop.com · 07/03/2026
Last day before prices go up for Deconstructing Rust Binaries at Ringzer0, March 23-26! If you've been thinking about this fully remote, 16-hour Rust reverse engineering training: now is the time to book! ringzer0.training/countermeasu... #infosec #ReverseEngineering #rustlang #MalwareAnalysis
ringzer0.training
Deconstructing Rust Binaries
Deconstructing Rust Binaries is the first comprehensive training course focused solely on reverse engineering Rust binaries. This course is for any reverse engineer who needs a rapid, practical…
043
Reposted by Erwan Grelet
Natalie Silvanovich @natashenka.bsky.social · 26/02/2026
In the final part of his blog series, @tiraniddo.dev tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphf...
projectzero.google
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...
064
Reposted by Erwan Grelet
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 18/02/2026
NEW: Def Con banned hackers Pablos Holmes and Vincenzo Iozzo, as well as former MIT Media Lab director Joichi Ito, from attending the conference based on their links to Jeffrey Epstein. Holmes and Iozzo exchanged emails with Epstein for several years.
techcrunch.com
Hacking conference Def Con bans three people linked to Epstein | TechCrunch
The Def Con hacking conference banned hackers Pablos Holman and Vincenzo Iozzo, as well as former MIT Media Lab director Joichi Ito, from attending the annual conference after their reported connectio...
311236
Reposted by Erwan Grelet
Lukasz Olejnik @lukaszolejnik.bsky.social · 14/02/2026
Meta is putting a "Name Tag" feature in Ray-Bans - facial recognition through the glasses' camera. You look at someone, AI tells you who they are. In an internal document, the company wrote that the timing is good because civil society groups are busy with politics and won't cause problems.
341212749
Reposted by Erwan Grelet
Joanna Rutkowska @rootkovska.bsky.social · 01/02/2026
Hello, World! Welcome back! I have new blog :-) tracesofhumanity.org/hello-world/
5286
Reposted by Erwan Grelet
Matthew Garrett @mjg59.eicar-test-file.zip · 28/01/2026
Hadn't realised that the third party review of Twitter's chat protocol had been published and wow github.com/trailofbits/...
github.com
211634
Reposted by Erwan Grelet
Natalie Silvanovich @natashenka.bsky.social · 26/01/2026
No security feature is perfect. @tiraniddo.dev reviewed Windows’ new Administrator Protection and found several bypasses. projectzero.google/2026/26/wind...
projectzero.google
Bypassing Windows Administrator Protection - Project Zero
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Cont...
065
Reposted by Erwan Grelet
RE//verse @re-verse.io · 16/01/2026
The RE//verse 2026 schedule is live and the lineup is stacked! Check it out: reverse-2026.sessionize.com/schedule
reverse-2026.sessionize.com
RE//verse 2026
Schedule
043
Reposted by Erwan Grelet
Natalie Silvanovich @natashenka.bsky.social · 15/01/2026
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/pixe...
projectzero.google
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
15733
Reposted by Erwan Grelet
Recon @reconmtl.bsky.social · 13/01/2026
🚨 REcon 2026 is LIVE! 🚀 Call for papers and registration are now open! Join the world's top reverse engineers & exploit devs in Montreal: 🛠 Trainings: June 15-18 📅 Conference: June 19-21 Tickets & early bird now open → recon.cx Limited spots – see you in MTL! #REcon2026 #ReverseEngineering
recon.cx
REcon 2026 - Premier Reverse Engineering Conference
REcon 2026 - Premier reverse engineering and cybersecurity conference in Montreal
083
Reposted by Erwan Grelet
RE//verse @re-verse.io · 12/01/2026
Nicolò Altamura digs into decompiling CUDA kernels at RE//verse 2026! He takes a look at how GPU execution and NVIDIA’s IRs change the usual assumptions for decompilers and shows early work on a Binary Ninja PTX plugin aimed at real CUDA reversing. Don't miss out: shop.binary.ninja/collections/...
031
Reposted by Erwan Grelet
Romain Thomas (@rh0main) @rh0main.bsky.social · 05/01/2026
I reverse engineered DexProtector, the security solution protecting applications like Revolut and other banking apps. From custom ELF loaders to vtable hooking, here is an insight into how these protections work and their limitations. www.romainthomas.fr/post/26-01-d...
romainthomas.fr
A Glimpse Into DexProtector | Romain Thomas
This blog post provides a high-level overview of DexProtector's security features and their limitations
13412
Reposted by Erwan Grelet
Cindʎ Xiao 🍉 @cxiao.net · 18/12/2025
Excited to bring Deconstructing Rust Binaries to NorthSec in March! Chat with me here or at @decoderloop.com if you have questions about the training. Take advantage of the early bird rate for the onsite option! Pricing is in CAD, take advantage of the exchange rate (: nsec.io/training/202...
nsec.io
Deconstructing Rust Binaries
053
Reposted by Erwan Grelet
Natalie Silvanovich @natashenka.bsky.social · 17/12/2025
We launched a redesigned Project Zero website today at projectzero.google ! To mark the occasion, we released some older posts that never quite made it out of drafts. Enjoy!
projectzero.google
Google Project Zero
Make zeroday hard
0184
Reposted by Erwan Grelet
Liam @ GamingOnLinux @gamingonlinux.com · 16/12/2025
It just keeps getting worse - Firefox to "evolve into a modern AI browser " #AI #Mozilla #Firefox
gamingonlinux.com
It just keeps getting worse - Firefox to "evolve into a modern AI browser "
Just like Google plan with Chrome, Mozilla aren't sitting still on expanding Firefox into something resembling a web browser but with more AI.
1861530473
Reposted by Erwan Grelet
Synacktiv @synacktiv.com · 16/12/2025
[New blog post] As part of an R&D project, @tomtombinary.bsky.social identified several critical vulnerabilities in the LAN multiplayer mode of the game Anno 1404 (released in 2009) 🔍 Want to know more? Read the full article on our blog 👇 www.synacktiv.com/en/publicati...
synacktiv.com
Exploiting Anno 1404
Exploiting Anno 1404
033
Reposted by Erwan Grelet
Samuel Groß @saelo.bsky.social · 09/12/2025
V8 now has a JS bytecode verifier! IMO a good example for the benefits of the V8 Sandbox architecture: - Hard: verify that bytecode is correct (no memory corruption) - Easier: verify that it is secure (no out-of-sandbox memory corruption) The sandbox basically separates correctness from security.
1204
Reposted by Erwan Grelet
Cindʎ Xiao 🍉 @cxiao.net · 08/12/2025
YARA fans, check out this great new @binary.ninja plugin!!!
031
Reposted by Erwan Grelet
The Register @theregister.com · 28/11/2025
GrapheneOS bails on OVHcloud over France's privacy stance
dlvr.it
GrapheneOS bails on OVHcloud over France's privacy stance
Project cites fears of state access as cloud sovereignty row deepens French cloud outfit OVHcloud took another hit this week after GrapheneOS, a mobile operating system, said it was ditching the company's servers over concerns about France's approach to digital privacy.…
55420
Reposted by Erwan Grelet
Binary Ninja @binary.ninja · 13/11/2025
Binary Ninja 5.2, Io, is live and it's out of this world! binary.ninja/2025/11/13/b... With some of our most requested features of all time including bitfield support, containers, hexagon, Ghidra import, and a huge upgrade to TTD capabilities, plus a ton more, make sure to check out the changelog!
193
Reposted by Erwan Grelet
diversenok @diversenok.bsky.social · 10/11/2025
I wanted to understand what information is available in .pdb files, so I made a tool for it 🔎🐛 Welcome DiaSymbolView - a debug symbol hierarchy and properties viewer based on MSDIA: github.com/diversenok/D...
A screenshot of DiaSymbolView inspecting combase.pdb
1104
Reposted by Erwan Grelet
Natalie Silvanovich @natashenka.bsky.social · 03/11/2025
New Blog Post: Seth Jenkins broke kASLR by doing … nothing 😩 googleprojectzero.blogspot.com/2025/11/defe...
googleprojectzero.blogspot.com
Defeating KASLR by Doing Nothing at All
Posted by Seth Jenkins, Project Zero Introduction I've recently been researching Pixel kernel exploitation and as part of this research I ...
0115
Reposted by Erwan Grelet
Decoder Loop @decoderloop.com · 03/11/2025
Thank you for your interest in Decoder Loop & #rustlang reverse engineering training so far! This Friday, November 7th, join us at Ringzer0 COUNTERMEASURE, in Ottawa, Canada, where @cxiao.net will present the workshop "Reversing a (not-so-) Simple Rust Loader": ringzer0.training/countermeasu...
ringzer0.training
WORKSHOP: Reversing a (not-so-) Simple Rust Loader // Cindy Xiao
Rust can be challenging for even experienced reverse engineers. We will reverse a simple Rust malware loader found in the wild with obfuscated strings and a decoy payload, making it a good example for...
123