Sign in

Laurent Clévy

@lorenzo2472.bsky.social
230 followers 585 following 168 posts

Reverse engineering, files formats and crypto. github.com/lclevy

PostsRepliesMedia
Reposted by Laurent Clévy
Brandon Sheffield @brandon.insertcredit.com · 01/10/2026
Several weeks ago, Phil Tippett's legendary animation studio in Berkeley, CA closed. An anonymous hero noticed a folder of CDs. This turned out to be hundreds of unseen hi-res images and videos from Star Wars, Robocop, Jurassic Park, etc. ~90 isos for you to browse: archive.org/details/tipp...
A casual Star Wars alien fella at the cantina, in a sun faded, reddish photo. Someone will be mad at me for not knowing who this is. Phil, a balding Caucasian man, poses a model of the garthok, an antagonist from the Coneheads movie.Phil, a balding caucasian man, points at some CG on a CRT computer monitor, as a younger man looks on. The screen shows a model of a dinosaur attacking a jeep, while there's an actual physical model of that event in the foreground for reference.an isolated shot of a star wars vehicle. Sorry, I don't know star wars lol
5152972341
Reposted by Laurent Clévy
Nicolas Hénin @nicolashenin.net · 01/10/2026
Depuis 2020, le @fondspresselibre.org a soutenu 58 médias indépendants grâce à 1,46 million d'euros de dons 🧡 Nouvel objectif : réunir 100.000 € avant le 29 octobre pour financer six mois d'enquêtes sur l'ED avant la présidentielle. Merci de votre contribution, à la hauteur de vos moyens 🫶
fondspresselibre.org
Soutenir le Fonds pour une presse libre
Le 18 avril 2027, la France vote. D’ici là, finançons celles et ceux qui enquêtent pour nous informer. Le Fonds pour une presse libre lance son dixième appel à projets.
13833
Reposted by Laurent Clévy
Synacktiv @synacktiv.com · 01/10/2026
Our CEO Renaud Feil shared his insights on how AI is shaping cybersecurity at @bsidescbr.bsky.social 🇦🇺 While we wait for the official video, check out and download the slides here: www.synacktiv.com/sites/defaul... Thanks to the organizers and everyone who attended!
synacktiv.com
011
Reposted by Laurent Clévy
InfoSec @infosec.skyfleet.blue · 01/10/2026
New PS5 Relapse Exploit Breaks Into the Kernel Across Years of Firmware Releases
cybersecuritynews.com
New PS5 Relapse Exploit Breaks Into the Kernel Across Years of Firmware Releases
Researchers have released a new PlayStation 5 jailbreak , Relapse, that public reports say reaches firmware 7.00 through 13.60 on both the standard PS5 and the PS5 Pro. Coverage has treated the drop as a broad jump for consoles that have not installed Sony’s newer update. It does not crack every firmware ever shipped. Relapse is a two-stage exploit chain. The first stage runs in the console’s built-in browser and abuses a weakness in WebKit . A kernel stage then follows and is reported to establish kernel read and write access, the control needed to run unsigned code. After a successful run, the project starts an ELF loader so compatible payloads, including homebrew tools, can be sent to the console. Developers warn that the browser stage can stall, while the kernel stage can hang or crash the console. The limit is Sony’s update line. Firmware 14.00, released in mid-September 2026, sits outside the stated range, and reporting says that release closes the hole used here. Consoles already on 14.00, or shipped with it, are not supported. System software cannot be officially downgraded, so owners who installed that update cannot roll back. Builds older than 7.00 also fall outside this chain. PS5 Relapse Exploit According to project details published on GitHub , the jailbreak is tethered. It does not survive a restart, so the chain has to be run again after every reboot. That makes Relapse useful for research and homebrew experiments, but unreliable as a permanent change. Some newer games already demand firmware this chain does not support. Credit is split across familiar console researchers. Sonic_Iso is credited for the kernel exploit , Jordy for the WebKit exploit and the kernel bug, and ntfargo and ufm42 for development, with testing by Dr. Yenyen. Further help is attributed to TheFlow, SlidyBat, Flatz, and other contributors. Nathan Fargo published the project on GitHub as Relapse-Exploit around September 29, 2026. For players, the risk is concrete. Unofficial code can cause crashes, data loss, or a PlayStation Network ban. For researchers, the disclosure shows that a reachable browser flaw on a locked console still matters when it is chained with a memory bug the vendor has not yet patched. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post New PS5 Relapse Exploit Breaks Into the Kernel Across Years of Firmware Releases appeared first on Cyber Security News .
064
Reposted by Laurent Clévy
Mickaël Newton @mickaelnewton.bsky.social · 27/09/2026
Mon appel aux créateurs JV français : je dois sauver la Bourse Jeux Vidéo d’ici la fin de l’année. Pour cela, je veux monter en 1 mois, un bundle de jeux vidéo dont les fonds iront à la BJV. Le plus de jeux possibles et trouver comment mettre en place cela de façon optimale. Pouvez-vous RT svp ?
13159324
Reposted by Laurent Clévy
Pierre Haski @pierrehaski.bsky.social · 01/10/2026
La Russie joue avec nos nerfs, cette fois en menaçant -une fois de plus- l’Otan d’une guerre nucléaire. C’est un des instruments de la boîte à outils de la guerre hybride de Vladimir Poutine. Ma chronique géopolitique du 7/10 @franceinter www.radiofrance.fr/franceinter/...
radiofrance.fr
La guerre psychologique de Moscou : la Russie menace l’OTAN d’une guerre nucléaire
La Russie menace l’OTAN d’une guerre nucléaire si elle s’en prend au territoire russe de Kaliningrad. Une manœuvre de guerre psychologique qui cherche à déstabiliser les opinions publiques et les gouv...
53112
Reposted by Laurent Clévy
Nicolas Seriot @nst021.bsky.social · 30/09/2026
That's clearer with a diagram. Give this post a heart if you'd like more of "anatomy of a bug" soon!
021
Reposted by Laurent Clévy
Science Étonnante @scienceetonnante.com · 27/09/2026
Le 3 et 4 octobre, rendez-vous au Palais de la Découverte dans son nouvel écrin ! La réouverture approche, alors on va fêter la science là-bas. J'y serai notamment dimanche 4 après-midi pour une table ronde animée par @marietreibert.bsky.social et un podcast de @patrickbaud.bsky.social !
13713
Reposted by Laurent Clévy
Alexis Brignoni🪫 @abrignoni.com · 26/09/2026
New LEAPP in the family: GLEAPP 🖼️🎞️ Image and video triage. Hashing, visual de-dup, EXIF and GPS, video key frames, known-hash matching and a review gallery. By Heather Charpentier. Free and open source. www.leapps.org/releases#sec... #DigitalForensics #DFIR
041
Reposted by Laurent Clévy
Alexandre Borges @alexandreborges.bsky.social · 25/09/2026
VM guest escape via 9p filesystem exploit: gitlab.com/qemu-project... #qemu #exploitation #vulnerability #informationsecurity #infosec #cybersecurity
VM guest escape via 9p filesystem exploit:

https://gitlab.com/qemu-project/qemu/-/work_items/4491

#qemu #exploitation #vulnerability #informationsecurity #infosec #cybersecurity
031
Reposted by Laurent Clévy
Ryan Benson @hindsig.ht · 25/09/2026
The Unfurl v2026.09 release adds parsers for Gmail, Safe Links, Facebook, Instagram, and GitHub, decodes more timestamps in tokens and IDs, and gives the web UI new Tree and Text views. hindsig.ht/blog/unfurl-... Check it out!
011
Reposted by Laurent Clévy
Natalia Krapiva 🕊️👩🏻‍💻 @natynettle.bsky.social · 24/09/2026
🚨 BREAKING: U.S. DOJ arrested the CEO of Oxygen Forensics, Lee Reiber, for concealing the company's Russian ownership. Civil society, including First Department, @olgalautman.bsky.social, & myself, have been sounding alarms for years about this company! 1/ www.justice.gov/usao-cdca/pr...
195
Reposted by Laurent Clévy
La Science, CQFD @sciencecqfd.bsky.social · 24/09/2026
C'est le 1er octobre ! ( @astropierre.com n'est pas réveillé ce matin !)
4101
Reposted by Laurent Clévy
Thaís @barbieauglend.bsky.social · 23/09/2026
You’ve got security research, tooling, findings, or a project you want to share? Submit it to @bsidespdx.bsky.social 2026: cfp.bsidespdx.org/bsidespdx-20... CFP closes Sept 25 — we’re at day-2. I’m looking forward to seeing the cool work and ideas y’all bring to the community. Submit yours now!
cfp.bsidespdx.org
BSidesPDX-2026
Schedule, talks and talk submissions for BSidesPDX-2026
013
Reposted by Laurent Clévy
Legrugru @legrugru.fr · 22/09/2026
Si votre entreprise procède à un renouvellement de véhicules, engins de chantier ou de manutention, groupe électrogène, n'hésitez pas à suggérer un DON ! reçu fiscal possible aussi pour les entreprises - Chaque don matériel c'est énormément d'argent économisé pour d'autres achats !
13330
Reposted by Laurent Clévy
Alexandre Borges @alexandreborges.bsky.social · 20/09/2026
Qualcomm’s Adreno X2 GPU: chipsandcheese.com/p/qualcomms-... #gpu #infosec #qualcomm #engineering
chipsandcheese.com
Qualcomm’s Adreno X2 GPU
Integrated GPUs have become a crucial component in recent laptop chips, thanks to a push for better graphics performance in ultraportable devices.
011
Reposted by Laurent Clévy
Stephen Moran. @moranstephen1000.bsky.social · 17/09/2026
1832995
Reposted by Laurent Clévy
Quarkslab @quarkslab.bsky.social · 16/09/2026
Optical network security often sounds like an obscure incantation: PON, ONU, OLT, PLOAM, OMCI, GEM, GPON, XG-PON, 50G-PON, T-CON.. To conjure the right knowledge read Thiébaud Fuchs' overview of Passive Optical Networks and their security features blog.quarkslab.com/overview-of-...
VSOL ONT OLT PON PING PONG
012
Reposted by Laurent Clévy
Brian Stelter @brianstelter.bsky.social · 15/09/2026
This jaw-dropping story has become ProPublica's most-read article of 2026, with more than 2.2 million views in the first day, a spokesperson tells me
321280333
Reposted by Laurent Clévy
Julien Briault 🩷💿💜 @juhnny5.bsky.social · 15/09/2026
Pour la rentrée, nous aurions besoin d'aide pour le Cloud du Coeur. Nous recherchons de l'emplacement en DC en région Parisienne pour notre région "Paris" et du transit IP sur Marseille. 💕 Merci pour votre aide ! 💪🏼
11538
Reposted by Laurent Clévy
Ben Houston @ben3d.ca · 14/09/2026
I want developers to be able to write performant #WebGPU code. To do that, they need to know what different operations, code patterns, and optional features actually cost on the devices people use. ben3d.ca/blog/introdu...
ben3d.ca
Introducing WebGPU-Bench: A WebGPU Microbenchmark
Introducing webgpu-bench, the micro-benchmark suite behind Web3D Survey’s GPU benchmark, with measurements of shader operations and code patterns available through a webpage and CLI.
1152
Reposted by Laurent Clévy
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 14/09/2026
hack.lu 2026 agenda is live! (the 20th Edition) including more details about the keynote. 🔗 2026.hack.lu/blog/hack.lu-2026-agen… #conference #hacklu #cybersecurity
2026.hack.lu
hack.lu 2026 agenda is live! (the 20th Edition)
We are happy to announce that the hack.lu 2026 agenda is now published!
013
Reposted by Laurent Clévy
Legrugru @legrugru.fr · 12/09/2026
Désolé de relancer encore et toujours... Activement recherché : véhicules, remorques, générateurs, éco flow, chauffages autonomes type chantier, citernes de carburants / eau potable... L'hiver approche !
11619
Reposted by Laurent Clévy
Terence Tao @teorth.bsky.social · 11/09/2026
A group of 25 Fields Medalists, including myself, have made a joint declaration on Math and AI: mathandai.org . We welcome additional signatories. See also this article in the Economist announcing the declaration: www.economist.com/science-and-...
mathandai.org
Declaration — Math and AI
Read the declaration and add your name.
422054930
Reposted by Laurent Clévy
Marcus Brinkmann @lambdafu.bsky.social · 10/09/2026
We found a new compression side-channel attack against SSH: if you use port forwarding with terminal sessions, a web attacker+eavesdropper can recover a sudo pwd in a few hundred trials. There is only one compression context for all channels. Accepted at CCS 26, preprint: arxiv.org/abs/2609.07709
arxiv.org
Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels
SSH is the standard protocol for secure remote administration of servers. At the transport layer, SSH uses the Binary Packet Protocol (BPP) for encrypted and authenticated communication. Above this, t...
15219
Reposted by Laurent Clévy
Andrey Konovalov @andreyknvl.bsky.social · 10/09/2026
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
July/August updates · xairy/linux-kernel-exploitation@281f69d
011
Reposted by Laurent Clévy
Cindʎ Xiao 🍉 @cxiao.net · 10/09/2026
Slides for my #RustConf 2026 talk are now up! A recording will be posted some time after the conference as well, I'll post it when it's up.
012
Reposted by Laurent Clévy
Frandroid @frandroid.com · 11/09/2026
Anthropic publie 161 pages sur les détournements de Claude, et ça pique
l.frandroid.com
Anthropic publie 161 pages sur les détournements de Claude, et ça pique
076
Reposted by Laurent Clévy
Xavier "dascritch" Mouton-Dubosc @dascritch.net · 10/09/2026
pendant ce temps, @ponos-job.bsky.social ponos.fr va mourir, la tentative d'alternative européenne et libre de @p4bl0p3rn0t.bsky.social ne decollant ps faute d'utilisateurs. Go ! go ! go !
ponos.fr
Ponos - Alternative européenne open source et IA à LinkedIn
Réseau professionnel minimaliste, sans tracking, respectueux de votre vie privée. Conforme RGPD.
033
Reposted by Laurent Clévy
David Monniaux @monniauxd.bsky.social · 09/09/2026
@philpaj.bsky.social blogs.mediapart.fr/david-monnia...
blogs.mediapart.fr
Un séisme dans le monde mathématique
L'intelligence artificielle dépasse les meilleurs mathématiciens. Et après ?
4176
Reposted by Laurent Clévy
Laurent Cheylus @lcheylus.bsky.social · 08/09/2026
Suite aux fuites de données de l’État (Impôts, ANTS, Éducation nationale..), quelques très bons conseils pour vérifier que vous n'êtes pas la cible d'une usurpation d’identité - Article et Vidéo par IT-Connect #Privacy www.it-connect.fr/usurpation-i...
it-connect.fr
Usurpation d'identité : que vérifier après les fuites de données de l'État ?
Fuites DGFiP, France Titres... Vérifiez si quelqu'un utilise votre identité via FranceConnect, FICOBA, la Banque de France et MonIdenum. Liens officiels et démarches.
033
Reposted by Laurent Clévy
Alexandra Delbot @alexandradelbot.bsky.social · 08/09/2026
À 16h dans @sciencecqfd.bsky.social on parle de la théorie des cordes. Comment propose-t-elle d’unir mécanique quantique et relativité générale ? Mon cerveau fume déjà 🤯
static.klipy.com
Hothead Steaming During Football Game
Alt: Monsieur avec une belle calvitie dont la tête fume au bord d’un terrain de football
68414
Reposted by Laurent Clévy
Laurent Cheylus @lcheylus.bsky.social · 07/09/2026
SRE-Bench: a recent Research Paper introducing a new Benchmark for LLM about Reverse Engineering Binaries #AI #LLM #ReverseEngineering arxiv.org/abs/2608.11469
arxiv.org
The Next Challenge for Agentic Cybersecurity: A Realistic, Contamination-Free Reverse Engineering Benchmark
AI agents are rapidly improving in cybersecurity capabilities when the source code is available for analysis, yet much of the software most consequential to cybersecurity, including malware,…
021
Reposted by Laurent Clévy
Frandroid @frandroid.com · 06/09/2026
RAW, JPEG, HEIF : ce qui se passe vraiment dans votre appareil photo (et votre smartphone) quand vous déclenchez 👉 l.frandroid.com/IbJ
Photo issue d’un capteur Micro 4/3 // Source : Tristan Jacquel
021
Reposted by Laurent Clévy
jiska @naehrdine.bsky.social · 05/09/2026
Did you know macOS binaries can run on iOS? It needs rewriting architecture information and adjusting library paths. I automated this, including DYLD shared cache library extraction and replacement, allowing many macOS command line tools to run on iOS. github.com/mowisec/maco...
github.com
GitHub - mowisec/macos-to-ios
Contribute to mowisec/macos-to-ios development by creating an account on GitHub.
0122
Reposted by Laurent Clévy
Astropierre @astropierre.com · 05/09/2026
Cette année encore s'est tenue la nouvelle édition de la remise des prix humoristico-scientifiques Ig-Nobel, qui récompensent les recherches "qui font rire d'abord et réfléchir ensuite". 🧪 Et cette année encore la cérémonie (et les lauréat·es) ne nous ont pas déçus ! Voici les résultats ⬇️⬇️⬇️ 1/12
Cérémonie des Ig Nobels 2026.
On voit à l'arrière-plan le présentateur historique de la cérémonie Marc Abrahams, épaulé cette année par la médiatrice scientifique et responsable du festival Pint of Science : Elodie Chabrol.
7451223
Reposted by Laurent Clévy
Frandroid @frandroid.com · 04/09/2026
Fnac et Darty vont adopter Wero, le paiement souverain européen
l.frandroid.com
Fnac et Darty vont adopter Wero, l'alternative européenne à Visa et Mastercard
063
Reposted by Laurent Clévy
ESA Operations @operations.esa.int · 03/09/2026
ACQUISITION OF SIGNAL CONFIRMED! 🎉🛰️ #BepiColombo telemetry shows the Mercury Transfer Module has successfully separated from the spacecraft stack! ✅ First step of Mercury arrival phase - complete! 👏 Next stop: Mercury orbit insertion for MPO and Mio in November! @esa.int #JAXA #Mercury
First signal after seperation from BepiColombo
528075
Reposted by Laurent Clévy
Etienne Jacob @bleuje.com · 01/09/2026
A little “Brick Territories” experiment. → bleuje.com/js_sketches/...
1127954
Reposted by Laurent Clévy
Women In Cybersecurity Community Association @womenofwicca.bsky.social · 01/09/2026
First pulse, first success. ⚡ @g0mb4ck (Milena) shows a triggerless EM fault injection attack on Nordic Semi's nRF52810 SoC (CVE-2025-9709) - the first of its kind ever reported and remarkably reproducible. 👉 Program & tickets: wiccon.nl
022
Reposted by Laurent Clévy
Xavier "dascritch" Mouton-Dubosc @dascritch.net · 01/09/2026
Blague à part, ce matin à 9h sur Radio FMR, rediff d'un @cpu.pm sur les jeux de stratégie. Écoutable gratuitement, sans pub, ni tracking, ni app : bsky.app/profile/cpu....
042
Reposted by Laurent Clévy
csharp83.bsky.social @csharp83.bsky.social · 31/08/2026
🤭
static.klipy.com
Godiche
ALT: Godiche
011
Reposted by Laurent Clévy
jiska @naehrdine.bsky.social · 31/08/2026
Google: "We shipped MTE hardware for 3 years and only academics enabled this optional feature to demonstrate practical attacks against it, so we decided to no longer ship it on the latest Pixels."
051
Reposted by Laurent Clévy
Mehul @technoiruk.bsky.social · 29/08/2026
Happy Birthday #Skynet #Terminator
01713
Reposted by Laurent Clévy
Hervé Schauer @herve-schauer.bsky.social · 29/08/2026
Attaques par injection de fautes par P.Azalbert à #BARBHACK2, sur microcontrôleurs Renesas RH850 & Infineon Tricore TC275 utilisés dans l'automobile. "Le pic de consommation électrique est lors de la vérification du mot de passe" Réactivation du mode débogage ! 👏🏻 pour la démo en direct
031
Reposted by Laurent Clévy
Kate @katef.bsky.social · 28/08/2026
that's my jam
a shell pipeline in a terminal compiling a regex, where the regex was written with syntax that would be pathological when executed backtracking style. stages of the pipeline show:
1. constructing an NFA from the regex (it goes through an AST first of course, but we don't see that). the NFA here contains loops within loops, where the exit from the loop is ambiguous: given an input of 'b' we could be iterating around an inner or an outer loop, but we don't know which until there's a following character 'a' or not.
2. NFA -> minimal DFA. this is where the ambiguity is resolved, and every state has outgoing edges that are deterministic
3. the same DFA output to a text format
4. the text format piped into the same tool, a command line interface for libfsm, showing a constructed AST
5. the AST rendered out to pcre regex syntax. the end result here now contains just one loop, with the contents rearranged such that it wouldn't be pathological given a backtracking implementation
712614
Reposted by Laurent Clévy
Volatility @volatilityfoundation.org · 13/08/2026
The 14th annual #Volatility #PluginContest is officially OPEN! This is your chance to contribute to open source forensics, gain community-wide visibility for your work, and win a cash prize! See our blog post for details! Submission Deadline: 31 December 2026 #dfir #memoryforensics
volatilityfoundation.org
The 14th Annual Volatility Plugin Contest is Open!
We are excited to announce that the 14th Annual Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open sourc…
045
Reposted by Laurent Clévy
Catherine @whitequark.org · 28/08/2026
ever wondered how USB devices negotiate Power Delivery (PD) with each other? ordinarily, you'd need a specialized USB PD analyzer. the upcoming #GlasgowInterfaceExplorer revD has I/O drivers that natively support USB PD voltage levels, enabling you to directly observe USB PD communication!
SOURCE CAP message:
[1] [Fixed] 5V 3A (15W) [unconstrained] 
[2] [Fixed] 9V 3A (27W)
[3] [Fixed] 12V 3A (36W)
[4] [Fixed] 15V 3A (45W)
[5] [Fixed] 20V 5A (100W)
[6] [Programmable|PPS] 5/21V 5A
2685