Sign in

Aska

@flutsunami-is-aska.bsky.social
114 followers 118 following 4 posts

Former RE team lead @synacktiv - Former @AirbusSecLab lead Collector of Quote

PostsRepliesMedia
Reposted by Aska
InfoSecSherpa 🏔️ Lake Ontario 🚣‍♀️ @infosecsherpa.bsky.social · 01/02/2026
If you appreciate the under-reported #InfoSec & #DataPrivacy news content I share every week, please support what I do by signing up for my newsletter. sherpaintelligence.substack.com I'm really proud of the content I provide and subscribers make my work possible. Repost & share with your network!
055
Reposted by Aska
Synacktiv @synacktiv.com · 23/01/2026
On the podium at #Pwn2Own Automotive 2026 🥉 Synacktiv ranked 3rd in Tokyo 🇯🇵 after successful attacks on #Tesla Infotainment (USB), #Sony XAV-9500ES (USB) and #Autel MaxiCharger (NFC). 📍 Next stop: Berlin!
054
Reposted by Aska
Matthew Green @matthewdgreen.bsky.social · 22/11/2025
Trying to think of something serious to say about the “cryptographers lose the key for the cryptographer election” story and, mostly, hey: I just love that cryptographers are actually using the weird cryptography! www.nytimes.com/2025/11/21/w...
nytimes.com
Cryptographers Held an Election. They Can’t Decrypt the Results.
810011
Reposted by Aska
Synacktiv @synacktiv.com · 31/10/2025
A big shout-out to the #Synacktiv team for their strong performance at the latest #Pwn2Own competition in Cork! They proudly secured third place overall 👏 Next stop: Tokyo for the upcoming edition 🇯🇵 👀 More details on the targets and participants here ℹ️ www.zerodayinitiative.com/blog/2025/20...
033
Reposted by Aska
Synacktiv @synacktiv.com · 23/10/2025
🎉 Big win at #Pwn2Own Cork! @pol-y.bsky.social of #Synacktiv successfully breached the @Ubiquiti AI Pro surveillance system 🦈🎶 What a way to wrap up the challenge - congrats, @pol-y.bsky.social 💪
076
Reposted by Aska
Synacktiv @synacktiv.com · 22/10/2025
Impressive work from our team today at #Pwn2Own! @mtalbi.bsky.social and Matthieu just pulled off an exploit on the Philips Hue Bridge without laying a finger on the device! Great demonstration of Synacktiv’s offensive expertise 👏 Come on 🔥
0137
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/10/2025
Confirmed! The team from @synacktiv.com used a buffer overflow to exploit the Phillips Hue Bridge. Their unique bug earns them $20,000 and 4 Master of Pwn points. #Pwn2Own
084
Reposted by Aska
Hexacon @hexacon.bsky.social · 13/10/2025
That's a wrap for Hexacon 2025! We hope that you've enjoyed the event at least as much as we did 🤩 Please take a moment to fill out our satisfaction survey and help us make Hexacon 2026 even better 🔥 Thank you for trusting us year after year 🙏
053
Reposted by Aska
Sil D. @silo-moussu.bsky.social · 27/08/2025
Parce qu'il serait trop dommage de passer à côté, voici la source: www.7joursaclermont.fr/wp-content/u...
341
Reposted by Aska
Jen @jensebalade.bsky.social · 27/08/2025
En cliquant sur la version "à écouter" fou rire garanti ! J'en pleure encore...
3018889
Reposted by Aska
Wolfmanning Skull 🎃 @manningkrull.bsky.social · 14/08/2025
Mafia guy 1: He's wearing a wire! Mafia guy 2: More importantly, with a microphone, and a recording device on it! Those are a lot more alarming than the wire itself, honestly. Way to bury the lede, Vinnie. Just a wire, I ain't worryin' about.
1349
Reposted by Aska
Synacktiv @synacktiv.com · 31/07/2025
The latest Synacktiv Summer Challenge was in 2019, and after 6 years, it's back! Send us your solution before the end of August, there are skills to learn and prizes to win 🎁 www.synacktiv.com/en/publicati...
synacktiv.com
2025 Summer Challenge: OCInception
🏆 Prizes Here are the prizes for the top three participants:
053
Reposted by Aska
Synacktiv @synacktiv.com · 11/08/2025
🔥 A few hours ago our experts took the stage at #DEFCON33, sharing cutting-edge research on SCCM exploitation and modern GPO attacks in Active Directory. Proud of the team! 🙌 cc @kalimer0x00.bsky.social @quent0x1.bsky.social @wilfri3d.bsky.social
073
Aska @flutsunami-is-aska.bsky.social · 20/04/2025
10 days ago, I left @synacktiv.com to discover new challenges. It was a bittersweet day as I loved my years there and I will miss my team, co-leaders and all ninjas. “Mersynacktiv !”
141
Reposted by Aska
Hexacon @hexacon.bsky.social · 16/04/2025
iOS for Security Engineers by Quentin Meffre (@0xdagger.bsky.social) & Etienne Helluy-Lafont www.hexacon.fr/trainer/meff...
076
Reposted by Aska
Synacktiv @synacktiv.com · 09/04/2025
From firmware dumps to wireless exploration — check out our latest dive into DVB receiver analysis and the hidden attack surface it exposes! www.synacktiv.com/en/publicati...
synacktiv.com
Hack the channel: A Deep Dive into DVB Receiver Security
Introduction During a garage cleaning, we found a DVB receiver and thought it would be a great target for vulnerability research.
01211
Reposted by Aska
Synacktiv @synacktiv.com · 10/04/2025
In iOS 18.4, Apple introduced a bug in dynamic symbol resolutions for some specific exports. @0xf4b.bsky.social took a long journey down a rabbit hole to understand its root cause. www.synacktiv.com/en/publicati...
synacktiv.com
iOS 18.4 - dlsym considered harmful
Observations We first observed the bug in a custom iOS application compiled for the arm64e architecture (thus supporting PAC instructions).
0159
Reposted by Aska
Katie Mack @astrokatie.com · 09/04/2025
The problem with most machine-based random number generators is that they’re not TRULY random, so if you need genuine randomness it is sometimes necessary to link your code to an external random process like a physical noise source or the current rate of US tariffs on a given country.
374189843607
Reposted by Aska
DanHELL M. Ford @soundingline.bsky.social · 08/04/2025
ADVOCATE, Book 3 of THE WARDEN is out in 2 weeks! Preorders are love. bookshop.org/p/books/advo...
bookshop.org
Advocate: Book Three of The Warden Series
Book Three of The Warden Series
12516
Reposted by Aska
robert j bennett, ceo, results omega @robertjbennett.bsky.social · 07/04/2025
“where were you when your Hugo nomination was announced?” “well I was at a laundromat trying to wash dog piss out of a set of curtains”
5442
Reposted by Aska
0xor0ne @0xor0ne.bsky.social · 01/04/2025
Embedded devices reverse engineering. Beginners intro. Ghidra setup: voidstarsec.com/blog/ghidra-... Tools: voidstarsec.com/blog/intro-t... Firmware extraction: voidstarsec.com/blog/uart-ub... #cybersecurity
0206
Reposted by Aska
DanHELL M. Ford @soundingline.bsky.social · 01/04/2025
Listen, I know the Brands got all in on April Fool's Day back on the hell site. But credit where it's due, this was the funniest one ever www.youtube.com/watch?v=BpXt...
youtube.com
Quilted Northern Rustic Weave | Artisanal Toilet Paper
YouTube video by marmosetmusic
053
Reposted by Aska
Synacktiv @synacktiv.com · 01/04/2025
Our ninjas are attending SO-CON! Come and say hi 👋
072
Reposted by Aska
depths of wikipedia @depthsofwikipedia.bsky.social · 28/03/2025
Llandegley International Airport is a spoof located in the village of Llandegley (Welsh: Llandeglau), near Llandrindod Wells, in mid Wales. No such airport exists, but a sign, erected as a practical joke, announces a forthcoming turn off to it
19101795
Reposted by Aska
Synacktiv @synacktiv.com · 28/03/2025
Synacktiv is looking for an additional team leader in Paris for its Reverse-Engineering Team! Find out if you are a good candidate by reading our offer (🇫🇷). www.synacktiv.com/responsable-...
synacktiv.com
Responsable équipe reverse engineering
076
Reposted by Aska
Gints Zilbalodis @gintszilbalodis.bsky.social · 20/03/2025
Flow global box office is over $36 Million and still going strong! Not bad for a $3.7 million budget! Exciting times for independent animation! variety.com/2025/film/bo...
191088136
Reposted by Aska
Game of Rôles @gameofroles.bsky.social · 19/03/2025
Bon, @fibretigre.com, ce n'est pas que le scénario ne nous intéresse pas, mais là, il y a des potits chats... Signé : la régie.
229022
Reposted by Aska
Hexacon @hexacon.bsky.social · 18/03/2025
Excited to announce two updates to our program committee! 🎉 We welcome @naehrdine.bsky.social to the team and are thrilled to have @perrib.us back with us. Looking forward to Hexacon 2025! www.hexacon.fr/about/commit...
hexacon.fr
Hexacon - Committee
Handpicked from the best our community has to offer
093
Reposted by Aska
robert j bennett, ceo, results omega @robertjbennett.bsky.social · 19/03/2025
neat!
121258
Reposted by Aska
clhwindsor @clhwindsor.bsky.social · 12/03/2025
If you want/need to have a laugh please check out Josh Johnson @joshjohnsoncomedy.bsky.social It's like chilling with that friend who is funny AF and never shuts up, but you don't want them to. A new set every week & no crowd work? 🤯 #havealaugh #joyisanactofresistance youtu.be/_-BuK8RimV4?...
youtu.be
The Saga of the Body Buried in the Backyard
YouTube video by Josh Johnson
27412
Reposted by Aska
Kumail Nanjiani @kumail.bsky.social · 26/02/2025
Movie night with Bagel. Trying not to interrupt whatever’s going on here. #Flow
631234761608
Reposted by Aska
Gints Zilbalodis @gintszilbalodis.bsky.social · 11/03/2025
Ok, this is the last one
8966972124
Reposted by Aska
Lincoln Michel @thelincoln.bsky.social · 25/02/2025
Don't let anyone tell you that you can't live your dreams
News article with this passage highlighted: "who asked not to be identified because she has always wanted to be an anonymous source"
11640288
Reposted by Aska
Synacktiv @synacktiv.com · 10/03/2025
Interested in vulnerabilities in video games? 🎮 @tomtombinary.bsky.social presented critical flaws in Neverwinter Nights Enhanced Edition at #Hexacon, which could allow attackers to take control of players' computers. 🛡️ Check out the full details of these bugs!👇 www.synacktiv.com/en/publicati...
synacktiv.com
Exploiting Neverwinter Nights
Introduction Neverwinter Nights is an RPG based video game developed by BioWare and Obsidian Entertainment in 2002.
088
Reposted by Aska
Synacktiv @synacktiv.com · 07/03/2025
Hunters International RaaS group has claimed 280+ victims since Oct 2023. Check out our latest blog post on the TTPs they use, including SMOKEDHAM malvertising & ESXi ransomware with advanced obfuscation. #RaaS #CyberSecurity #ThreatAnalysis www.synacktiv.com/en/publicati...
synacktiv.com
Case Study: How Hunters International and friends target your hypervisors
Introduction First, a bit of history.
0104
Reposted by Aska
Mike Bithell @mikebithell.bsky.social · 27/01/2025
Hard Sci Fi is when you only break 10 basic laws of physics, rather than 11.
2251225
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 24/01/2025
And that’s a wrap! #Pwn2Own Automotive 2025 is complete. In total, we awarded $886,250 for 49 0-days over the three day competition. With 30.5 points and $222,250 awarded, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) is our Master of Pwn. #P2OAuto
192
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 24/01/2025
Confirmed! The @Synacktiv team used a single buffer overflow to exploit the Autel MaxiCharger. They were also able to demonstrate signals being transmitted via the Charging Connector for the add on. This work earns them $35,000 and 6 Master of Pwn points. #P2OAuto #Pwn2Own
0105
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 23/01/2025
Confirmed! @Synacktiv used a logic bug as a part of their chain to exploit the Tesla Wall Connector via the Charging Connector. Their outstanding (and inventive) research earns them $45,000 and 7 Master of Pwn points. #P2OAuto #Pwn2Own
1104
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 23/01/2025
Wow. Just wow. The @synacktiv team was able to take over the #Tesla Wall Connector while having their exploit originate from the Charging Connector. To our knowledge, that's never been demonstrated publicly before. They head to the disclosure room with details. #P2OAuto #Pwn2Own
11813
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2025
Well that's awkward. @EQSTLab used a OS command injection bug, but it was one used last year. Alpine chose not to patch it since "in accordance with ISO21434...the vulnerability is classified as 'Sharing the Risk'." Yikes. The @EQSTLab team earns $5,000 and 1 Master of Pwn point.
051
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2025
Confirmed! The @synacktiv team used an OS command injection bug to exploit the #Kenwood IVI and play a video of the original Doom game. Their second round win earns them $10,000 and 2 Master of Pwn points. #P2OAuto
052
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2025
Whew! It took two attempts but the #Synacktiv team successfully exploited the #ChargePoint EV Charger and demonstrated signal manipulation over the connector. They are off to the disclosure room to go over how they did it. #P2OAuto #Pwn2Own
1107
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2025
We're doomed! At least the #Kenwood IVI is since @Synacktiv exploited the system and loaded a video of the classic FPS. They're off to the disclosure room to provide details on the exploit and why Doom isn't playable. #P2OAuto #Pwn2Own
196
Reposted by Aska
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2025
Well that's a first. @ScepticCtf, @diff_fusion), & @SeTcbPrivilege of fuzzware.io used a power drill to gain access to a port and exploit the Autel MaxiCharger. They head off to explain their work - except for the drill - we understand that part. #P2OAuto
fuzzware.io
Fuzzware | Fuzzware
Fuzzware elevates embedded systems security with a hardware-free, full-system firmware fuzzing tool, focusing on thorough, binary-only analysis. It proactively identifies vulnerabilities, securing ent...
182
Reposted by Aska
Synacktiv @synacktiv.com · 20/01/2025
Yay! Our offensive Azure training was accepted at BlackHat USA 2025 🥳 Can't wait to see you there and share cutting-edge techniques for attacking Azure environments!
097
Reposted by Aska
Synacktiv @synacktiv.com · 16/01/2025
A few months ago, Microsoft released a critical patch for CVE-2024-43468, an unauthenticated SQL injection vulnerability in SCCM/ConfigMgr leading to remote code execution, discovered by @kalimer0x00.bsky.social. www.synacktiv.com/advisories/m...
synacktiv.com
Microsoft Configuration Manager (ConfigMgr) 2403 Unauthenticated SQL injections
Microsoft Configuration Manager (ConfigMgr) 2403 Unauthenticated SQL injections
1118
Reposted by Aska
Matthew Reichbach @fbihop.com · 15/01/2025
The New Mexico Department of Transportation released the winners of its annual "name a snowplow contest."
A map of New Mexico split up by DOT regions, with the names of snowplows in each region. 

District 1: Snow Bueno, Snow Way, José!
District 2: Scoop Dogg, Chips & Que Snow. 
District 3: Alice Scooper, Taylor Drift.
District 4: Blizzard of Oz, Red Chilly Brrrr-ito.
District 5: Clear-o-Pathra, Blizzard Wizard.
District 6: Zia Later, Snow, En-CHILL-ada.
820870
Reposted by Aska
cfreal.bsky.social @cfreal.bsky.social · 16/01/2025
This year again, I am lucky enough to get nominated twice for the Top Ten Hacking Techniques, for my research on iconv and PHP, and lightyear. This time feels a bit special however, as these are my last blog posts on ambionics. www.ambionics.io/blog/iconv-c... www.ambionics.io/blog/lightye...
ambionics.io
Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine (part 1)
A few months ago, I stumbled upon a 24 years old buffer overflow in the glibc, the base library for linux programs. Despite being reachable in multiple well-known libraries or executables, it proved r...
0124
Reposted by Aska
Rayna 🤓🇪🇺👩‍💻📚✍️ @maliciarogue.bsky.social · 14/01/2025
La Pologne a pris la présidence tournante de l'UE le 1 janvier, avec de grandes ambitions sur le numérique et, notamment, la cyber. C rare qu'une présidence de l'UE ait autant d'ambitions sur la tech. J'en décrypte les enjeux et le calendrier 👇 tech-est-politique.eu/posts/la-pol... #DigitalEU
tech-est-politique.eu
👓 La Pologne aux commandes du numérique européen et élection du Contrôleur européen de la protection des données
Pour cette édition de début 2025, on décrypte le programme ambitieux de la Présidence polonaise de l'UE et au rôle de Contrôleur européen des données.
2148