Sign in

Quarkslab

@quarkslab.bsky.social
322 followers 3 following 72 posts

Reverse Your Future quarkslab.com

PostsRepliesMedia
Quarkslab @quarkslab.bsky.social · 29/09/2026
To leverage AI agents for vulnerability research, we built a hybrid source-code analysis workflow that combines deterministic analysis with agentic reasoning. Applied to FreeRDP, it helped us uncover vulnerabilities and chain them into client-side RCE. 🔗 blog.quarkslab.com/from-ai-agen...
110
Quarkslab @quarkslab.bsky.social · 16/09/2026
Optical network security often sounds like an obscure incantation: PON, ONU, OLT, PLOAM, OMCI, GEM, GPON, XG-PON, 50G-PON, T-CON.. To conjure the right knowledge read Thiébaud Fuchs' overview of Passive Optical Networks and their security features blog.quarkslab.com/overview-of-...
VSOL ONT OLT PON PING PONG
012
Quarkslab @quarkslab.bsky.social · 02/09/2026
Chamilo LMS was put under the microscope🔬 by Mathieu Farrell and Sean Matthews 11 vulnerabilities, multiple attack surfaces. Our new research dives into the vulnerable code paths and exploitation primitives to achieve unauthenticated RCE. 🔗 blog.quarkslab.com/chamilo-lms-...
Agentic Smith can find vulns too
000
Quarkslab @quarkslab.bsky.social · 20/08/2026
Software protection is futile, AI will break it", they said. But, does it? how? To shine some light read about Rémy Salim's experiments in "Defeating AI-Assisted Reverse Engineering" Where is the fair play, Claude? blog.quarkslab.com/defeating-ai...
020
Quarkslab @quarkslab.bsky.social · 13/08/2026
Doing Machine Learning on binary code? We've just open-sourced pcode_graph, a Python library that extracts semantic graphs from binaries to make training Graph Neural Networks easier. Samuel Hangouët introduces it here: blog.quarkslab.com/from-p-code-... #GNN #ML #Python #OpenSource
It's a Data Flow Graph. No witty comment possible.
060
Quarkslab @quarkslab.bsky.social · 11/08/2026
Everything about Android's hardware attestation... and how to bypass it. Blog post and code by Eric Le Guevel blog.quarkslab.com/bypassing-an...
Keep on rooting in the free world
020
Quarkslab @quarkslab.bsky.social · 06/07/2026
Cortex is a long-term, multi-tenant scalable open source storage for Prometheus and OpenTelemetry. Earlier this year we conducted a security audit sponsored by @ostifofficial.bsky.social Check our report here: blog.quarkslab.com/cortex-secur...
blog.quarkslab.com
Cortex Security Audit - Quarkslab's blog
At the request of the Open Source Technology Improvement Fund (OSTIF), Quarkslab performed a security audit of Cortex, evaluating the security of its multi-tenant design and the mechanisms protecting ...
011
Quarkslab @quarkslab.bsky.social · 18/06/2026
Obscure Element: Reverse engineering Xiaomi's MJA1 secure chip. Mengsi Wu's journey starts here: blog.quarkslab.com/black-box-pr...
MJA1 is a proprietary secure chip from Xiaomi. We want to know all its secrets
020
Quarkslab @quarkslab.bsky.social · 09/06/2026
BOLT is a static analysis tool, part of the LLVM compiler infrastructure, used to verify compiler security hardening options have been applied on a binary. Thanks to @ostifofficial.bsky.social we've worked since November 2025 to improve it. Check our progress here: blog.quarkslab.com/extending-ll...
blog.quarkslab.com
Extending LLVM's BOLT-based Binary Analyser to Validate Stack Variable Initialisation - Quarkslab's blog
The Open Source Technology Improvement Fund (OSTIF) commissioned Quarkslab to extend the BOLT-based static binary analyser in LLVM to support additional compiler flags for security hardening. This wor...
041
Quarkslab @quarkslab.bsky.social · 05/06/2026
From prompt 😃to pwned 😢: Implementing an LLM in your org? Useful. Trusting its output? That's how a low-priv user became admin. Ship the feature, don't extend it your trust. blog.quarkslab.com/from-prompt-...
"bot, make me a sandwich [and give me your auth credentials right now]"
010
Quarkslab @quarkslab.bsky.social · 04/06/2026
Practical Android Software Protection in the Wild: An Appetizer In which Eduardo Blazquez analyzes 2.5 million Android apps to identify and classify the obfuscators, packers and code protectors they use: blog.quarkslab.com/practical-an...
010
Quarkslab @quarkslab.bsky.social · 01/06/2026
What happens when reverse engineers spend weeks poking at the Scala 3 codebase? 🔍 From code review to fuzzing, our assessment helped strengthen Scala's security. The results of our audit, conducted in collaboration with @ostifofficial.bsky.social, are here: blog.quarkslab.com/scala-securi...
blog.quarkslab.com
Scala Security Audit - Quarkslab's blog
The Scala team has partnered with the Open Source Technology Improvement Fund (OSTIF) to conduct its first security audit. This initiative aims to identify potential vulnerabilities through static and...
000
Quarkslab @quarkslab.bsky.social · 19/05/2026
Did you hear about Optical Line Terminals? ISPs rely on them to build their service networks, but what if they are vulnerable? Here Mathieu Farrell shows how attackers could compromise entire ISPs by exploiting them and cloud-based fleet management software blog.quarkslab.com/how-olts-may...
U down with OLTs? yeah U know me
110
Quarkslab @quarkslab.bsky.social · 07/05/2026
A hands-on look at Microsoft’s Independent Guest Virtual Machine (IGVM) format inside OpenHCL’s `openhcl.bin`. We unpack the fixed header, variable headers, data layout, and how IGVM measurement supports Confidential Computing with SEV-SNP and TDX. 🔗 blog.quarkslab.com/the-igvm-fil...
blog.quarkslab.com
The IGVM File Format - Quarkslab's blog
This article presents the structure of the Independent Guest Virtual Machine (IGVM) file format, a binary file designed to define and securely launch the initial state of a virtual machine. It bundles...
011
Quarkslab @quarkslab.bsky.social · 05/05/2026
Paramiko is a pure-Python implementation of SSHv2. Recently, we worked with the Paramiko team on a security audit sponsored by @ostifofficial.bsky.social 🙏 Read a summary of our findings and find the full report here: blog.quarkslab.com/paramiko-sec...
blog.quarkslab.com
Paramiko Security Audit - Quarkslab's blog
The OSTIF collaborated with Quarkslab to conduct a security audit of Paramiko, a pure-Python implementation of SSHv2 that provides both client- and server-side functionality. Given the sensitivity and...
000
Quarkslab @quarkslab.bsky.social · 30/04/2026
Do you know how Entra ID applications work? What about the security mess they can bring and what they can quietly break? New blog post on Entra ID application permissions, the audit nightmare they create, and QAZPT, our OSS tool to actually make sense of it: blog.quarkslab.com/auditing-app...
Auditing Azure permissions will make your head spin
Use the QAZPT, Luke!
000
Quarkslab @quarkslab.bsky.social · 16/04/2026
Obfuscation vs The Optimizer: A Battle in LLVM Middle End. Robert Yates shows us how the continuous improvement of the LLVM optimizer defeats naive code obfuscation, and how the obfuscator can fight back. An eternal fight in which all victories are ephemeral blog.quarkslab.com/obfuscation-...
I fought the LLVM and I lost
000
Quarkslab @quarkslab.bsky.social · 14/04/2026
🤔Ever wondered how your favorite tools work under the hood? During our work on SightHouse, we dug into BSIM, Ghidra's Binary function SIMilarity engine. Many tools have been built around it, yet its internals remained undocumented. Until now 👇 blog.quarkslab.com/bsim-explain...
Rerversering of all the NSA things!
011
Quarkslab @quarkslab.bsky.social · 09/04/2026
🚗 We traced a car’s life from China to Poland. By analyzing a BYD Telematic Control Unit, Romain Marchand econstructed its journey and identified a real-world event from GPS logs alone. Embedded forensics + OSINT = real stories hidden in data. 👉 blog.quarkslab.com/tearing-down...
yep, it is a car and a TCU, and yes, it is AI generated. Sorry.
020
Quarkslab @quarkslab.bsky.social · 07/04/2026
After Mathieu Farrell found 3 LPEs in Intego antivirus for macOS, Lucas Laise had to check the Windows version too. Spoiler: it was vulnerable. Here's the full write up of a symlink attack to achieve Local Privilege Escalation👇 blog.quarkslab.com/milking-the-...
010
Quarkslab @quarkslab.bsky.social · 03/04/2026
Tired of reversing the same libc for the 100th time? 👀 Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries. High-confidence function mapping. Works with any disassembler. By @Mad5quirrel & Sami. 🔗 blog.quarkslab.com/sighthouse-a...
032
Quarkslab @quarkslab.bsky.social · 31/03/2026
The dragon has a VM. Of course it does. Our latest blog walks through the analysis of a complex C++ binary hiding behind a virtual machine, themed as a classic RPG fight. QBDI & TritonDSE are your weapons of choice. The dragon doesn't stand a chance. 🐉 🔗 blog.quarkslab.com/qbdi-vs-trit...
001
Quarkslab @quarkslab.bsky.social · 26/03/2026
Rule 1️⃣ : "In WAF we (should not) trust" Your WAF is doing its best. That's just not enough 😮‍💨 A deep dive into Web Application Firewall bypass techniques, discovering why blocked ⛔ doesn't always mean safe. blog.quarkslab.com/in-waf-we-sh...
010
Quarkslab @quarkslab.bsky.social · 20/03/2026
"Intego X9: Never trust my updates" Read Mathieu Farrell's research showing how XPC interprocess communications and the update mechanism of the Intego antivirus for MacOS can be abused for local privilege escalation. blog.quarkslab.com/intego_lpe_m...
Too many skulls
000
Quarkslab @quarkslab.bsky.social · 12/03/2026
"How does it even work?" The question that keeps hackers' hearts pumping, blood pressure rising, and curiosity growing. This is Damien Cauquil's reverse engineering journey into a cheap smartwatch that measures at least one of those. blog.quarkslab.com/nerd-life-we...
Look Ma, no sensors!
011
Quarkslab @quarkslab.bsky.social · 11/03/2026
One bit flip to corrupt it all: Exploitation of an old Linux kernel vulnerability using PageJack, a modern technique to create Use After Free bugs. Here Jean Vincent shows you how blog.quarkslab.com/pagejack-in-...
What if I flip this little thingie?
010
Quarkslab @quarkslab.bsky.social · 05/03/2026
If you glitch one, can you glitch many? Extracting automotive firmware is a challenge. @phil-barr3tt.bsky.social explains how he bypassed the IDCODE protection in several variants of the RH850 MCU family using both voltage glitching and side-channel analysis ⚡️🚗 blog.quarkslab.com/bypassing-de...
012
Quarkslab @quarkslab.bsky.social · 05/03/2026
Reverse engineers often spend a lot of time deciphering third-party firmware libraries. At RE//verse 2026 (Fri, 5 PM), Benoit & Sami will introduce SightHouse, an open-source tool to automatically identify third-party functions and speed up analysis. Join us!
032
Quarkslab @quarkslab.bsky.social · 03/03/2026
Another antivirus 🛡️, another unfulfilled promise 😣. @kaluche_ turns Avira's protection into a privilege escalation playground. This time: 3 LPE vectors 🆙 via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749). Find out more: blog.quarkslab.com/avira-deseri...
141
Quarkslab @quarkslab.bsky.social · 26/02/2026
Why macOS AVs shouldn’t trust PIDs 😄🍏 - new post by @Coiffeur0x90 Intego X9: XPC validation falls back to PID → PID reuse + posix_spawn() shenanigans 😏 ⇒ confused deputy / privileged methods abused 🤡🧨 Lesson: PID ≠ identity. Check it out 🔗 blog.quarkslab.com/intego_lpe_m...
000
Quarkslab @quarkslab.bsky.social · 10/02/2026
You've never been more right to doubt your MacOS antivirus software 😥 Our latest research by Mathieu Farrell shows how Intego can be abused for Local Privilege Escalation Yes, the antivirus. Yes, as root. blog.quarkslab.com/intego_lpe_m...
Remember whnn you didnt need an AV on your Mac? It was today
010
Quarkslab @quarkslab.bsky.social · 05/02/2026
"Dr. Bytecode or: How I Learned to Stop Worrying and Obfuscate Java" A tale about how @farena.in started his journey in Java software obfuscation. blog.quarkslab.com/how-to-write...
Java is bomb you ride backwards
021
Quarkslab @quarkslab.bsky.social · 28/01/2026
"Use a better system prompt" is the new "sanitize your inputs", but when your #AI agent's tools don't check permissions, you've got a problem and no amount of prompting will fix it. Check Kaluche's blog post about #AgenticAI & the Confused Deputy issue ⬇️ blog.quarkslab.com/agentic-ai-t...
000
Reposted by Quarkslab
ostifofficial.bsky.social @ostifofficial.bsky.social · 20/01/2026
@lfenergy.bsky.social EVerest underwent a security engagement facilitated by us with auditing by @quarkslab.bsky.social. This holistic security work impacts millions of EV charging stations worldwide. Read more at our blog: ostif.org/everest-secu...
011
Quarkslab @quarkslab.bsky.social · 20/01/2026
We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide. The audit was mandated by @ostifofficial.bsky.social 🙏 blog.quarkslab.com/everest-secu...
022
Quarkslab @quarkslab.bsky.social · 08/01/2026
A decade is an eternity in security. 🛡️ Ten years ago, we released the Clang Hardening Cheat Sheet. Today, the landscape has changed. @0xTRIKKSS & @bcreusillet break down the latest mitigations to keep your code secure. 🔗Read the update: blog.quarkslab.com/clang-harden...
044
Quarkslab @quarkslab.bsky.social · 11/12/2025
A modern tale of Blinkenlights, cheap Christmas shopping and curiosity, narrated by Damien Cauquil Firmware extraction and reverse engineering of a smartwatch FTW! blog.quarkslab.com/modern-tale-...
000
Quarkslab @quarkslab.bsky.social · 02/12/2025
K7 Antivirus: Named pipe abuse, registry manipulation and privilege escalation. A story of endpoint post-exploitation by Lucas Laise blog.quarkslab.com/k7-antivirus...
​🖥️​ cesi n'est pas une named pipe
030
Reposted by Quarkslab
ostifofficial.bsky.social @ostifofficial.bsky.social · 19/11/2025
We've been a bit excited about this one. We are excited and honored to have partnered with Bitcoin, brink, Chaincode Labs, and @quarkslab.bsky.social to collaborate on a security audit of Bitcoin Core. This was Bitcoin Core's first external audit. Read more at our blog: ostif.org/bitcoin-core...
ostif.org
Bitcoin Core Audit Complete! – OSTIF.org
152
Quarkslab @quarkslab.bsky.social · 19/11/2025
Quarkslab engineers Robin David, Mihail Kirov and Kaname just completed the first public security audit of Bitcoin Core, led by @ostifofficial.bsky.social and funded by Brink.dev Details on the blog post: blog.quarkslab.com/bitcoin-core... Congrats to developers for such software masterpiece !
blog.quarkslab.com
Bitcoin Core audit - Quarkslab's blog
The Open Source Technology Improvement Fund, Inc. mandated Quarkslab to perform the first public security audit of Bitcoin core, the reference open-source implementation of the Bitcoin decentralized p...
065
Reposted by Quarkslab
KubeVirt @kubevirt.bsky.social · 12/11/2025
We are pleased to announce that the KubeVirt Security Audit report has been published, in collaboration with @quarkslab.bsky.social and @ostifofficial.bsky.social Check out our blog post for all the details: kubevirt.io/2025/Announc...
kubevirt.io
Announcing the results of our Security Audit | KubeVirt.io
As part of our application to Graduate, KubeVirt has a security audit performed by a third-party, organised through the CNCF and OSTIF.
043
Quarkslab @quarkslab.bsky.social · 07/11/2025
KubeVirt is open source virtualization technology for Kubernetes. Recently we worked with the @kubevirt team on a security audit sponsored by @OSTIFofficial 🙏 Read a summary of our findings and find the full report here: blog.quarkslab.com/kubevirt-sec...
011
Quarkslab @quarkslab.bsky.social · 21/10/2025
Our 2025-2026 internship season has started. Check out the list of openings and apply for fun and knowledge! blog.quarkslab.com/internship-offers-for-the-2025-2026-season.html
033
Quarkslab @quarkslab.bsky.social · 14/10/2025
From kernel oops to kernel exploit: How two little bugs (CVE-2025-23330, CVE-2025-23280) in #NVIDIA open GPU #Linux driver can lead to full system compromise. Full technical breakdown inside, #vmalloc exploitation technique included! blog.quarkslab.com/nvidia_gpu_k...
blog.quarkslab.com
Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers - Quarkslab's blog
This article details two bugs discovered in the NVIDIA Linux Open GPU Kernel Modules and demonstrates how they can be exploited. The bugs can be triggered by an attacker controlling a local unprivileg...
022
Quarkslab @quarkslab.bsky.social · 09/10/2025
Finding a buggy driver is one thing, abusing it is another🧠 In his latest blog post, Luis Casvella shows you how BYOVD can be used as a Reflective Rootkit Loader ! 🚀 ➡️ blog.quarkslab.com/exploiting-l...
Unsigned FTW!
032
Quarkslab @quarkslab.bsky.social · 07/10/2025
Quantum computers are not quite here yet, but now's the time to get ready. After updating their protocol in 2023, @signal.org is now proposing a post-quantum version of their Double Ratchet for message encryption. Let's see what Signal looks like now! blog.quarkslab.com/triple-threa...
Signal: Yo dawg! I heard you liked ratchets, so we added a ratchet to our Double Ratchet.
053
Reposted by Quarkslab
Fabrice Rossi @fabricerossi.eurosky.social · 30/09/2025
Brand new paper with Roxane Cohen, Robin David (both from @quarkslab.bsky.social ) and Florian Yger on obfuscation detection in binary code doi.org/10.1007/s411... We show that carefully selected features can be leveraged by graph neural networks to outperform classical solutions.
doi.org
Identifying obfuscated code through graph-based semantic analysis of binary code - Applied Network Science
Protecting sensitive program content is a critical concern in various situations, ranging from legitimate use cases to unethical contexts. Obfuscation is one of the most used techniques to ensure such a protection. Consequently, attackers must first detect and characterize obfuscation before launching any attack against it. This paper investigates the problem of function-level obfuscation detection using graph-based approaches, comparing algorithms, from classical baselines to advanced techniques like Graph Neural Networks (GNN), on different feature choices. We consider various obfuscation types and obfuscators, resulting in two complex datasets. Our findings demonstrate that GNNs need meaningful features that capture aspects of function semantics to outperform baselines. Our approach shows satisfactory results, especially in a challenging 11-class classification task and in two practical binary analysis examples. It highlights how much obfuscation and optimization are intertwined in binary code and that a better comprehension of these two principles are fundamental in order to obtain better detection results.
1127
Quarkslab @quarkslab.bsky.social · 23/09/2025
BYOVD is a well-known technique commonly used by threat actors to kill EDR 🔪 However, with the right primitives, you can do much more. Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver. 👇 blog.quarkslab.com/exploiting-l...
RW physical memory pages with a side of LSTAR MSR overwrite? YOLO!
011
Quarkslab @quarkslab.bsky.social · 22/09/2025
RTFM they say but if you read the manual and copy code examples from it you may inadvertently introduce vulns in your code 🙀 In April we audited the PHP code. Now we followed up with a review of the code snippets in PHP documentation and found 81 issues 👇 blog.quarkslab.com/security-rev...
blog.quarkslab.com
Security review of PHP documentation - Quarkslab's blog
The Open Source Technology Improvement Fund, Inc., engaged with Quarkslab to perform a security audit of the code snippets in the English version of PHP documentation, focused on some specific pages.
065
Quarkslab @quarkslab.bsky.social · 04/09/2025
The two bytes that make size matter: Reverse engineering Apple's iOS 0-click CVE-2025-43300 improved bounds checking fix, by Madimodi Diawara blog.quarkslab.com/patch-analys...
Yo dawg, I heard you like Improved Bounds Checking
So I improved the bound checks of the bound checks
052