Sign in

Mehdi Talbi

@mtalbi.bsky.social
86 followers 122 following 9 posts
PostsRepliesMedia
Reposted by Mehdi Talbi
Entrypoint @entrypoint-fr.bsky.social · 23/07/2026
The Review Board for Entrypoint 2027 is complete 🔒 10 security experts from around the world will be reading your submissions this year Reminder: CFP closes on September 20, 2026 at 23:59 UTC Submit your paper now at entrypoint.fr Meet the team below (A-Z) 👇
123
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 02/07/2026
A month ago we pointed our local LLM at #FreeBSD and it helped us find a local root exploit plus an ASLR bypass on SUID binaries to go with it 🚨 Both now patched (CVE-2026-49415 & CVE-2026-49414). Update your boxes! ➡️ www.freebsd.org/security/adv... ➡️ www.freebsd.org/security/adv...
033
Mehdi Talbi @mtalbi.bsky.social · 06/05/2026
Messing with Zigbee at Pwn2Own
022
Reposted by Mehdi Talbi
Fabrice Riceputi @campvolant.bsky.social · 14/02/2026
2399184
Reposted by Mehdi Talbi
buherator @buherator.bsky.social · 24/01/2026
[RSS] On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025 www.synacktiv.com -> Original->
021
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 16/01/2026
Our experts will be at #Pwn2Own Automotive in Tokyo 🇯🇵 After taking 1st place in 2024 by uncovering #Tesla and automotive vulnerabilities, they’re back to explore new attack entry points! Stay tuned 🔍
011
Reposted by Mehdi Talbi
0xor0ne @0xor0ne.bsky.social · 28/11/2025
Synology Beestation Plus pre-auth exploitation and full system takeover www.synacktiv.com/en/publicati... Write up Arnaud Gatignol and Théo Fauché #infosec
042
Mehdi Talbi @mtalbi.bsky.social · 24/11/2025
My #Hexacon talk with Etienne on exploiting the Bluetooth stack (fluoride) is now available on YouTube youtu.be/wYulofbUDqY?...
youtu.be
HEXACON 2025 - Paint it Blue: Attacking the Bluetooth stack by Mehdi Talbi & Etienne Helluy-Lafont
YouTube video by Hexacon
042
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 31/10/2025
A big shout-out to the #Synacktiv team for their strong performance at the latest #Pwn2Own competition in Cork! They proudly secured third place overall 👏 Next stop: Tokyo for the upcoming edition 🇯🇵 👀 More details on the targets and participants here ℹ️ www.zerodayinitiative.com/blog/2025/20...
033
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 27/10/2025
Following their presentation at @hexacon.bsky.social, @mtalbi.bsky.social & Etienne detail how they exploited CVE-2023-40129, a critical vulnerability affecting the Bluetooth stack in Android ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Paint it blue: Attacking the bluetooth stack
Paint it blue: Attacking the bluetooth stack
065
Mehdi Talbi @mtalbi.bsky.social · 23/10/2025
Impressive exploitation strategy!! bsky.app/profile/thez...
030
Reposted by Mehdi Talbi
TrendAI Zero Day Initiative @thezdi.bsky.social · 23/10/2025
Confirmed! David Berard of @synacktiv.com used a pair of bugs to exploit the Ubiquiti AI Pro in the Surveillance Systems category. The impressive display (incl. a round of Baby Shark) earns him $30,000 and 3 Master of Pwn Points. #Pwn2Own
011
Reposted by Mehdi Talbi
TrendAI Zero Day Initiative @thezdi.bsky.social · 23/10/2025
🎥 Eyes wide shut! David Berard of @synacktiv.com just breached the @Ubiquiti AI Pro surveillance system at #Pwn2Own. He also serenaded us with round of "Baby Shark" played through the speaker. He's off to the disclosure room with an ear worm and the details.
034
Reposted by Mehdi Talbi
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/10/2025
Confirmed! The team from @synacktiv.com used a buffer overflow to exploit the Phillips Hue Bridge. Their unique bug earns them $20,000 and 4 Master of Pwn points. #Pwn2Own
084
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 21/10/2025
Congrats to tek and anyfun for landing the first successful entry at #Pwn2OwnCork - exploiting a stack overflow on Synology BeeStation Plus for $40,000 and 4 Master of Pwn points in the process 💥 Let’s keep pushing 💪 #P2OIreland #Synacktiv
044
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 22/10/2025
Impressive work from our team today at #Pwn2Own! @mtalbi.bsky.social and Matthieu just pulled off an exploit on the Philips Hue Bridge without laying a finger on the device! Great demonstration of Synacktiv’s offensive expertise 👏 Come on 🔥
0137
Mehdi Talbi @mtalbi.bsky.social · 22/10/2025
Exploit inside #pwn2own
030
Reposted by Mehdi Talbi
Hexacon @hexacon.bsky.social · 03/10/2025
📢"Paint it Blue: Attacking the Bluetooth stack" by Mehdi Talbi and Etienne Helluy-Lafont
022
Reposted by Mehdi Talbi
Hexacon @hexacon.bsky.social · 12/09/2025
Aaaand the first talk to be announced is... 🥁 Exploiting the Undefined: PWNing Firefox by Settling its Promises by Tao Yan & Edouard Bochin
052
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 05/06/2025
It's already #SSTIC2025 day 2! @remi-j.bsky.social and us3r present the Windows kernel shadow stack mitigation 🪟
095
Reposted by Mehdi Talbi
Hexacon @hexacon.bsky.social · 02/06/2025
📢 Our Call For Papers is open until 14 July! ➡️ Details & benefits: www.hexacon.fr/conference/c... Also, conference tickets will be on sale today at 4PM (UTC+2)
024
Reposted by Mehdi Talbi
Synacktiv @synacktiv.com · 10/04/2025
In iOS 18.4, Apple introduced a bug in dynamic symbol resolutions for some specific exports. @0xf4b.bsky.social took a long journey down a rabbit hole to understand its root cause. www.synacktiv.com/en/publicati...
synacktiv.com
iOS 18.4 - dlsym considered harmful
Observations We first observed the bug in a custom iOS application compiled for the arm64e architecture (thus supporting PAC instructions).
0159
Reposted by Mehdi Talbi
Phrack Zine @phrack.org · 15/02/2025
Hackers rejoice! We are releasing the Phrack 71 PDF for you today! Don't forget this year is Phrack's 40th anniversary release! Send in your contribution and be part of this historical issue! The CFP is still open, you can find it and the PDF link at phrack.org
phrack.org
.:: Phrack Magazine ::.
Phrack staff website.
26232
Reposted by Mehdi Talbi
Alex Plaskett @alexplaskett.bsky.social · 26/12/2024
Ten Years of Rowhammer: A Retrospect (and Path to the Future) fahrplan.events.ccc.de/congress/202... From Convenience to Contagion: The Libarchive Vulnerabilities Lurking in Windows 11 fahrplan.events.ccc.de/congress/202...
fahrplan.events.ccc.de
Ten Years of Rowhammer: A Retrospect (and Path to the Future) 38C3
The density of memory cells in modern DRAM is so high that disturbance errors, like the Rowhammer effect, have become quite frequent. An attacker can exploit Rowhammer to flip bits in inaccessible mem...
1137
Reposted by Mehdi Talbi
Phrack Zine @phrack.org · 16/12/2024
We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org
screenshot of the CFP on phrack.org
411658