Sign in

obilodeau

@obilodeau.bsky.social
208 followers 234 following 69 posts

Father of two. Hacker. President @NorthSec. Research at Flare. Cofounder of MontréHack. Love to teach and share. BlackHat, Defcon, SecTor speaker.

PostsRepliesMedia
Reposted by obilodeau
Émilio Gonzalez @res260.xyz · 23/01/2026
Submitted a talk about detection-as-code to the @nsec.io Call for Papers! You have until feb 2nd if you’re interested in submitting :)
052
Reposted by obilodeau
MontréHack @montrehack.bsky.social · 20/11/2025
🎅h0h0h0day CTF tickets are now on sale! 🎅 The idea is simple: Create a CTF challenge, send it to us, then solve other participant’s challenges in a festive ambiance! 🍕 and 🍺 offered thanks to NorthSec! 🎟️ h0h0h0dayctf2025.eventbrite.com/ 📜 montrehack.ca/2025/12/16/h...
022
Reposted by obilodeau
NorthSec @nsec.io · 16/11/2025
🔗 Conférence complète/Full Talk: youtu.be/pq0NMN9HHOY 🎟️ Billets/Tickets NorthSec 2026: nsec.io #NorthSec #cybersecurity #infosec
youtu.be
NorthSec 2025 - Wendy Nather - Keynote: A Tabletop As Big As the World
YouTube video by NorthSec
032
obilodeau @obilodeau.bsky.social · 16/10/2025
Learning about color mapping and LUT (cube files) and trying all sorts of ffmpeg tricks to make bland videos look good at 2 am.. Yup, it's about @nsec.io and trying to leverage cool video shots that we were given for free, but they were raw... Then you realize a phone does a lot of work for you...
001
obilodeau @obilodeau.bsky.social · 15/10/2025
I worked on a thing at work. One small cog in a huge team effort. www.newswire.com/news/flare-l...
newswire.com
Flare Launches Identity Exposure Management to Combat 50 Million Weekly Breached Identities and Stop Account Takeovers in Seconds
New solution enables organizations to detect, validate, and remediate leaked credentials and active sessions - before attackers strike.
000
obilodeau @obilodeau.bsky.social · 08/09/2025
Quick analysis of today's chalk / npm supply chain story. It requires the `window` object so it needs to be deployed and run in a browser. It means front-end projects would only be affected if the site itself was a cryptocurrency website. CLI projects unaffected. 1/3
110
Reposted by obilodeau
NorthSec @nsec.io · 02/09/2025
📸 𝗟𝗲𝘀 𝗽𝗵𝗼𝘁𝗼𝘀 𝗼𝗳𝗳𝗶𝗰𝗶𝗲𝗹𝗹𝗲𝘀 𝗱𝗲 𝗡𝗼𝗿𝘁𝗵𝗦𝗲𝗰 𝟮𝟬𝟮𝟱 𝘀𝗼𝗻𝘁 𝗱𝗶𝘀𝗽𝗼𝗻𝗶𝗯𝗹𝗲𝘀! • 𝗢𝗳𝗳𝗶𝗰𝗶𝗮𝗹 𝗡𝗼𝗿𝘁𝗵𝗦𝗲𝗰 𝟮𝟬𝟮𝟱 𝗣𝗵𝗼𝘁𝗼𝘀 𝗔𝗿𝗲 𝗢𝘂𝘁! Revivez les meilleurs moments de NorthSec avec notre album photo officiel! ⚓️ photos.app.goo.gl/bMCHe366jdP1...
132
Reposted by obilodeau
amye @amye.org · 01/09/2025
My advice for people who are applying to big conference for abstracts are: imagine that your reviewer is under a deadline of less than twelve hours and they are deeply deeply angry. Write to impress that person, but write the talk you'd be proud to give.
0397
obilodeau @obilodeau.bsky.social · 14/08/2025
Here is all the cool stuff I brought back from @bsideslv.org, @blackhatofficial.bsky.social and @defcon.bsky.social. Was thrilled to do the trio! Chrono order: Sponsor at BSides LV, speaking at BlackHat USA and DEFCON. I wasn't even trying to bring stuff back, it just happened! 🙏 cool people I met!
A table full of stickers and infosec schwag
001
obilodeau @obilodeau.bsky.social · 13/08/2025
I caught up on a lot of tasks tonight, but I still haven’t written my post–HackerWeek LinkedIn update or caught up on the NorthSec Slack and emails 🙃
020
obilodeau @obilodeau.bsky.social · 04/08/2025
Met @malwarejake.bsky.social in real life! Glad I got to talk to him about Estelle and I recent work on stealer logs with incident response use cases
1171
obilodeau @obilodeau.bsky.social · 04/08/2025
Look at this nice hardware badge! Real filament tubes!
040
obilodeau @obilodeau.bsky.social · 04/08/2025
Free give-aways all week during Hacker Summer Camp! I'll be at the Flare booth during @bsideslv.org, I'll be roaming around and giving a talk at @blackhatofficial.bsky.social (brag) and I'll also be roaming around + giving a talk at @defcon.bsky.social (brag). Come and see me. Let's chat! Cheers
Table full of hacker lootAuthor of post showing his face with some of the loot
130
Reposted by obilodeau
Étienne H @eh0urdeba1gt.bsky.social · 20/07/2025
🔐 This could reshape privacy engineering. Google open-sourced their zero-knowledge proof (ZKPs) age verification libraries on Jul 3 called "Longfellow" letting you prove you're 18+ without revealing birthdate, name, or any PII. blog.google/technology/s... (1/8) 🧵
blog.google
Opening up ‘Zero-Knowledge Proof’ technology to promote privacy in age assurance
Today, we open sourced our Zero-Knowledge Proof (ZKP) libraries, fulfilling a promise and building on our partnership with Sparkasse to support EU age assurance.
121
Reposted by obilodeau
NorthSec @nsec.io · 02/07/2025
Missing the NorthSec community already? We made you a starter pack to help you quickly find us on Bluesky! Saw someone missing from this starter pack? Let us know! go.bsky.app/JZeo2ad
163
obilodeau @obilodeau.bsky.social · 02/07/2025
A dream come true: I wrote POC-level code that I thought would be a good addition to our platform, and someone rewrote it and integrated it. We are now protecting more customers automatically with it! Now onto the next POC!
A pop-up that says: Microsoft Entra ID Exposed Credential Verification is now available!
040
obilodeau @obilodeau.bsky.social · 16/06/2025
Another law enforcement takedown announced today. Operation Deep Sentinel targeted the Archetyp darknet forum (drug). These takedown videos keep getting better! Go watch: operation-deepsentinel.com
operation-deepsentinel.com
Operation Deep Sentinel
010
obilodeau @obilodeau.bsky.social · 16/06/2025
I have two student tickets to give away for BlackHat USA as part of their student scholarship program: www.blackhat.com/us-25/speake.... Let me know if you are interested.
blackhat.com
Black Hat
Black Hat
001
Reposted by obilodeau
Lam the Maker of Things @lamthemaker.bsky.social · 25/05/2025
Wanted to show a snippet of how I made the mechanical component of the #Northsec 2025 slot machine for the CTF www.youtube.com/watch?v=WCLc...
youtube.com
Northsec 2025 Slot Machine Mech Assembly [Preview]
Quick 60 seconds summary of the assembly process of for the lever of the slot machine
021
obilodeau @obilodeau.bsky.social · 22/05/2025
Estelle Ruellan and I were accepted at BlackHat USA!! "Hackers Dropping Mid-Heist Selfies: LLM ldentifies Information Stealer Infection Vector and Extracts loCs" Couldn't be happier sharing what we did on a worldwide stage! p.s.: picture of us celebrating from Botconf after our talk today #BHUSA
021
obilodeau @obilodeau.bsky.social · 19/05/2025
NorthSec is delivered. It was an incredible edition! Great keynotes, our best party so far and our world-class in-person CTF scenario and huge set of diverse and accessible challenges were a great success! I didn't take much photos, I'll report back later. ✈️🇫🇷 to botconf now! 😅
000
Reposted by obilodeau
Lam the Maker of Things @lamthemaker.bsky.social · 12/05/2025
Quite a few SAO to solder and collect this year at Northsec 😍 See you Thursday
011
obilodeau @obilodeau.bsky.social · 14/05/2025
80+ volunteers have worked on this all year. It's time for another NorthSec and it's going to be epic!
A big room full of road cases of gear ready to be deployed to run our crazy 2 day conference followed by an even crazier 48 hour CTF
040
Reposted by obilodeau
NorthSec @nsec.io · 08/05/2025
Forget about the waitlist! 😎 You can once again buy tickets for the CTF. 🤩💫 Hurry up, the limit to buy tickets is may 12th! This edition will be our biggest to date, be it in physical tracks, number of challenges and integration with the scenario. ⛴️⚓ tickets.nsec.io/2025/ #ctf #nsec2025 #infosec
tickets.nsec.io
NorthSec 2025
May 10th – 18th, 2025
022
obilodeau @obilodeau.bsky.social · 26/04/2025
Achievement unlocked: presenting on a cinema screen The movie starts in 15 minutes in theatre 14! Thanks @bsidessf.org for having me!
010
obilodeau @obilodeau.bsky.social · 23/04/2025
On my 4th day in Europe I finally woke up at a normal hour. And unfortunately it is my last full day here 🙃 I'll be in San Francisco Friday. I wonder how I'll hold this weird schedule...
020
obilodeau @obilodeau.bsky.social · 19/04/2025
Due to work travel, I had to vote in advance this year. The ballot is in 🗳️☑️ The experience was quite smooth. A 5 minute wait maybe. Now I hope my candidate and his leader don't do anything extremely stupid until the actual vote date 😆
010
Reposted by obilodeau
NorthSec @nsec.io · 19/04/2025
⚠️ Freezing CTF registrations soon ⚠️ There are about 40 garanteed tickets left for the CTF. When this limit is reached, we'll open a waitlist. If you have not bought your CTF ticket yet, hurry up! And don't hesitate to register on the waitlist when it opens. tickets.nsec.io/2025/
tickets.nsec.io
NorthSec 2025
May 10th – 18th, 2025
001
Reposted by obilodeau
Marc-André Moreau @awakecoding.com · 15/04/2025
I’m looking for on-demand virtual lab platforms that can spin up full Active Directory environments (8 vCPUs, 64GB RAM, nested virt). It needs to support complex enterprise scenarios to showcase Remote Desktop Manager with other Devolutions products. Any recommendations? 🙏
633
obilodeau @obilodeau.bsky.social · 11/04/2025
AtlSecCon is an incredible event! That's it. That's the post.
000
obilodeau @obilodeau.bsky.social · 03/04/2025
J'ai passé au podcast PolySécure pour parler des information stealer malware en français et c'était chouette: polysecure.ca/posts/episod...
polysecure.ca
PolySécure Podcast - SéQCure/Teknik - Au-delà du maliciel de type infostealer - vecteurs d’infection, les actifs dérobés inusités et les contre-mesures
Podcast francophone sur la cybersécurité. Pour professionels et curieux.
021
obilodeau @obilodeau.bsky.social · 26/03/2025
Hello @hackerschoice.bsky.social. Curious about the Telegram claims in this article: blog.thc.org/keep-pavel-d.... Can you follow so we can DM?
000
Reposted by obilodeau
Renegade Zed @renegadezed.bsky.social · 11/02/2025
This is a shot in the dark, but I'm looking for an internship in the cyber security field. Don't hesitate to comment or DM for questions. My career change isn't easy. But I think it's going to be worth it. I'm in the greater Montreal area, QC, Canada. #cybersecurity #internship #montreal
002
Reposted by obilodeau
NorthSec @nsec.io · 05/03/2025
Attention à vos yeux! Vous pourriez être aveuglés par ces étoiles brillantes! Notre premier round de conférenciers est affiché sur notre site web ! ✨💫 Watch out for your eyes! You might get blinded by these shining stars! Our first round of speakers are now on our website ! ✨💫 nsec.io/speakers/
nsec.io
Speakers
054
Reposted by obilodeau
NorthSec @nsec.io · 27/02/2025
Local legend Charles F. Hamilton is coming back this year with another amazing training 🤩 Sharpen your offensive red team tools during these intense 2 days and learn from the best! See you in May, hackers! ✨ nsec.io/training/202...
021
Reposted by obilodeau
NorthSec @nsec.io · 26/02/2025
Last week to get your tickets at the Early Birds price ‼️ Would be a shame to spend ALL your budget on tickets and lack funds for your thursday night party's outfit! 😓 tickets.nsec.io/2025/ #infosec #dev #hackerspace #hackers #security #ctf #cfp #devops #montreal #mtl #tickets
tickets.nsec.io
NorthSec 2025
May 10th – 18th, 2025
043
obilodeau @obilodeau.bsky.social · 25/02/2025
Running an infosec conference is also having to deal with vulnerabilities because someone has an XSS payload in his bio 😆👾 Filtering would have been easy but it would strip the joke. We needed to keep it. Vuln path: Pretalx -> markdown processor -> yaml -> jekyll to HTML. Fixed now.
030
obilodeau @obilodeau.bsky.social · 20/02/2025
I love the MontréHack community. New faces, familiar faces all willing to learn, hands on the keyboard. They are starting their *13 years* of *free* *monthly* cybersecurity challenge training sessions! Incredible!
011
Reposted by obilodeau
Émilio Gonzalez @res260.xyz · 13/02/2025
Today, Palo Alto released a security advisory regarding CVE-2025-0111, an authenticated file read vulnerability in the management interface of PAN-OS. I participated in disclosing this vuln. This is my first CVE and first bug bounty! 🙏 security.paloaltonetworks.com/CVE-2025-0111
security.paloaltonetworks.com
CVE-2025-0111 PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS fil...
031
obilodeau @obilodeau.bsky.social · 05/02/2025
Big round of events lining up: - FIRST-CTI: a 4h hands-on workshop on darknet breach investigation 🤯 😱 - CyberEco's Cyberconference - Botconf (@botconf.infosec.exchange.ap.brid.gy) - of course operating @northsec.bsky.social Waiting to hear back from: AtlSecCon, BSides SF, FIRST
040
Reposted by obilodeau
Phillip Wylie @phillipwylie.bsky.social · 04/02/2025
Lilly Chalupowski's Journey Into Malware Analysis podcasters.spotify.c...
podcasters.spotify.com
Lilly Chalupowski's Journey Into Malware Analysis by Phillip Wylie Show
About The Guest:Lilly Chalupowski, also known as Cerberus, is a malware reverse engineer specializing in criminal malware. She has extensive experience in analyzing various malware families and has developed open-source projects to aid in the detection and extraction of intelligence from malware. Lilly is also a talented musician and often incorporates guitar playing into her live Twitch streams. Summary:Lilly Chalupowski shares her inspiring hacker origin story, from starting out in computer science to pursuing a degree in music and facing financial hardships. She discusses the importance of having a healthy relationship with failure and the value of continuous learning and practice. Lilly also provides valuable advice for aspiring malware analysts, emphasizing the significance of creating a portfolio and actively participating in the cybersecurity community. Key Takeaways: Don't be afraid of failure; view it as a normal part of the learning process. Dedicate time each day to practice and improve your skills, even if it's just half an hour. Establish a portfolio to showcase your work and value to potential employers. Attend local cybersecurity meetups and network with professionals in the field. Create a virtual machine and practice analyzing malware samples from open-source resources. Quotes: "Be okay with failure and if you enjoy it, keep doing it and you'll improve over time." "Half an hour to an hour a day, put it on your calendar and make time for what you're passionate about." "Your value is showcased through your output, not just a resume." "You have nothing to lose by applying; what's the worst thing they can tell you? No." "VMs are literally the gateway drug to malware analysis." Socials and Resources: https://www.linkedin.com/in/lillypads/ https://twitter.com/c3rb3ru5d3d53c https://www.twitch.tv/c3rb3ru5d3d53c https://c3rb3ru5d3d53c.github.io
063
obilodeau @obilodeau.bsky.social · 31/01/2025
🚨 Following a flood in Montreal called "the "geyser", @northsec.bsky.social's VP of logistics, lost $375,000 worth of equipment. With no compensation from the city or government, he faces a critical situation. Let's help a pillar of our community get back on his feet! Donate: gofund.me/f834dbc2
gofund.me
Faites un don à Martin Lebel (et NorthSec) inondé par le bris d'aqueduc, organisée par Olivier Bilodeau
Bonjour, je suis Olivier Bilodeau, président de NorthSec et j… Olivier Bilodeau a besoin de votre soutien pour Martin Lebel (et NorthSec) inondé par le bris d'aqueduc
152
obilodeau @obilodeau.bsky.social · 31/01/2025
Mon ami Simon donne une formation qui a l'air très chouette à @northsec.bsky.social! Inscrivez-vous! Détails ici: nsec.io/training/202...
nsec.io
Adoptez la Mentalité d'un Pentester : Formation Pratique de Deux Jours
000
Reposted by obilodeau
Émilio Gonzalez @res260.xyz · 31/01/2025
Fellow cybersecurity folks: Make sure to follow @northsec.bsky.social if you came to bluesky from Twitter! Great conference in Montreal and probably the biggest on-site CTF in the world.
035
Reposted by obilodeau
Marc-André Moreau @awakecoding.com · 30/01/2025
Update: I have decided to cancel my attendance at the RDP IO Lab event, and to make the presentation as a Devolutions webinar instead. Stay tuned for the registration link which will be coming up soon!
3132
obilodeau @obilodeau.bsky.social · 29/01/2025
Rejected from RSAC again! Submitted both a learning lab and a presentation. I've only been accepted twice in seven years of trying. I don't understand what they want... They say they want technical content but my best stuff is always rejected and when I look at the program I don't see much tech...
000
Reposted by obilodeau
Marc-André Moreau @awakecoding.com · 28/01/2025
My RDP IO Lab presentation on "Decrypting and Inspecting RDP traffic in Wireshark" was just *cancelled* - apparently Microsoft decided they would only do internal presentations, with no guest speakers 😠 What's the point of even trying when you get treated like this?
4195
obilodeau @obilodeau.bsky.social · 21/01/2025
Video from our SmhooCon talk last week: youtu.be/5YHcw-qj094?...
youtu.be
ShmooCon 2025 Day 2 Belay It! Track
YouTube video by StrongWind
100
Reposted by obilodeau
Bruce ("grymoire") Barnett @grymoire.bsky.social · 14/01/2025
The #ShmooCon 2025 talks have been uploaded youtube.com/playlist?lis...
youtube.com
ShmooCon 2025 - YouTube
You can reach me at https://twitter.com/Strong1Wind
02210
obilodeau @obilodeau.bsky.social · 16/01/2025
Excited to announce my upcoming online training on RDP Interception next Tuesday! A two-hour session (11:00-13:00 EST) with lots of hands-on and demos. Register here: try.flare.io/academy/remo...
try.flare.io
Join Our Live Cybersecurity Training on January 21st - Don't Miss Out!
Remote Desktop Protocol Interception with PyRDP
110