Sign in

Quarkslab

@quarkslab.bsky.social
326 followers 3 following 73 posts

Reverse Your Future quarkslab.com

PostsRepliesMedia
Quarkslab @quarkslab.bsky.social · 01/10/2026
Not an antivirus product this time, but we couldn't pass it up 🙈 Cato Networks said: route with split tunneling. kaluche_ heard: root with split tunneling. Check out CVE-2026-10739, a LPE vulnerability in the Cato VPN Client for Windows ➡️ blog.quarkslab.com/cato-vpn-cli...
A CatoVPN to your SYSTEM
021
Quarkslab @quarkslab.bsky.social · 29/09/2026
To leverage AI agents for vulnerability research, we built a hybrid source-code analysis workflow that combines deterministic analysis with agentic reasoning. Applied to FreeRDP, it helped us uncover vulnerabilities and chain them into client-side RCE. 🔗 blog.quarkslab.com/from-ai-agen...
121
Quarkslab @quarkslab.bsky.social · 16/09/2026
Optical network security often sounds like an obscure incantation: PON, ONU, OLT, PLOAM, OMCI, GEM, GPON, XG-PON, 50G-PON, T-CON.. To conjure the right knowledge read Thiébaud Fuchs' overview of Passive Optical Networks and their security features blog.quarkslab.com/overview-of-...
VSOL ONT OLT PON PING PONG
012
Quarkslab @quarkslab.bsky.social · 02/09/2026
Chamilo LMS was put under the microscope🔬 by Mathieu Farrell and Sean Matthews 11 vulnerabilities, multiple attack surfaces. Our new research dives into the vulnerable code paths and exploitation primitives to achieve unauthenticated RCE. 🔗 blog.quarkslab.com/chamilo-lms-...
Agentic Smith can find vulns too
000
Quarkslab @quarkslab.bsky.social · 20/08/2026
Software protection is futile, AI will break it", they said. But, does it? how? To shine some light read about Rémy Salim's experiments in "Defeating AI-Assisted Reverse Engineering" Where is the fair play, Claude? blog.quarkslab.com/defeating-ai...
020
Quarkslab @quarkslab.bsky.social · 13/08/2026
Doing Machine Learning on binary code? We've just open-sourced pcode_graph, a Python library that extracts semantic graphs from binaries to make training Graph Neural Networks easier. Samuel Hangouët introduces it here: blog.quarkslab.com/from-p-code-... #GNN #ML #Python #OpenSource
It's a Data Flow Graph. No witty comment possible.
060
Quarkslab @quarkslab.bsky.social · 11/08/2026
Everything about Android's hardware attestation... and how to bypass it. Blog post and code by Eric Le Guevel blog.quarkslab.com/bypassing-an...
Keep on rooting in the free world
020
Quarkslab @quarkslab.bsky.social · 18/06/2026
Obscure Element: Reverse engineering Xiaomi's MJA1 secure chip. Mengsi Wu's journey starts here: blog.quarkslab.com/black-box-pr...
MJA1 is a proprietary secure chip from Xiaomi. We want to know all its secrets
020
Quarkslab @quarkslab.bsky.social · 05/06/2026
From prompt 😃to pwned 😢: Implementing an LLM in your org? Useful. Trusting its output? That's how a low-priv user became admin. Ship the feature, don't extend it your trust. blog.quarkslab.com/from-prompt-...
"bot, make me a sandwich [and give me your auth credentials right now]"
010
Quarkslab @quarkslab.bsky.social · 04/06/2026
Practical Android Software Protection in the Wild: An Appetizer In which Eduardo Blazquez analyzes 2.5 million Android apps to identify and classify the obfuscators, packers and code protectors they use: blog.quarkslab.com/practical-an...
010
Quarkslab @quarkslab.bsky.social · 19/05/2026
Did you hear about Optical Line Terminals? ISPs rely on them to build their service networks, but what if they are vulnerable? Here Mathieu Farrell shows how attackers could compromise entire ISPs by exploiting them and cloud-based fleet management software blog.quarkslab.com/how-olts-may...
U down with OLTs? yeah U know me
110
Quarkslab @quarkslab.bsky.social · 30/04/2026
Do you know how Entra ID applications work? What about the security mess they can bring and what they can quietly break? New blog post on Entra ID application permissions, the audit nightmare they create, and QAZPT, our OSS tool to actually make sense of it: blog.quarkslab.com/auditing-app...
Auditing Azure permissions will make your head spin
Use the QAZPT, Luke!
000
Quarkslab @quarkslab.bsky.social · 16/04/2026
Obfuscation vs The Optimizer: A Battle in LLVM Middle End. Robert Yates shows us how the continuous improvement of the LLVM optimizer defeats naive code obfuscation, and how the obfuscator can fight back. An eternal fight in which all victories are ephemeral blog.quarkslab.com/obfuscation-...
I fought the LLVM and I lost
000
Quarkslab @quarkslab.bsky.social · 14/04/2026
🤔Ever wondered how your favorite tools work under the hood? During our work on SightHouse, we dug into BSIM, Ghidra's Binary function SIMilarity engine. Many tools have been built around it, yet its internals remained undocumented. Until now 👇 blog.quarkslab.com/bsim-explain...
Rerversering of all the NSA things!
011
Quarkslab @quarkslab.bsky.social · 09/04/2026
🚗 We traced a car’s life from China to Poland. By analyzing a BYD Telematic Control Unit, Romain Marchand econstructed its journey and identified a real-world event from GPS logs alone. Embedded forensics + OSINT = real stories hidden in data. 👉 blog.quarkslab.com/tearing-down...
yep, it is a car and a TCU, and yes, it is AI generated. Sorry.
020
Quarkslab @quarkslab.bsky.social · 07/04/2026
After Mathieu Farrell found 3 LPEs in Intego antivirus for macOS, Lucas Laise had to check the Windows version too. Spoiler: it was vulnerable. Here's the full write up of a symlink attack to achieve Local Privilege Escalation👇 blog.quarkslab.com/milking-the-...
010
Quarkslab @quarkslab.bsky.social · 03/04/2026
Tired of reversing the same libc for the 100th time? 👀 Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries. High-confidence function mapping. Works with any disassembler. By @Mad5quirrel & Sami. 🔗 blog.quarkslab.com/sighthouse-a...
032
Quarkslab @quarkslab.bsky.social · 31/03/2026
The dragon has a VM. Of course it does. Our latest blog walks through the analysis of a complex C++ binary hiding behind a virtual machine, themed as a classic RPG fight. QBDI & TritonDSE are your weapons of choice. The dragon doesn't stand a chance. 🐉 🔗 blog.quarkslab.com/qbdi-vs-trit...
001
Quarkslab @quarkslab.bsky.social · 26/03/2026
Rule 1️⃣ : "In WAF we (should not) trust" Your WAF is doing its best. That's just not enough 😮‍💨 A deep dive into Web Application Firewall bypass techniques, discovering why blocked ⛔ doesn't always mean safe. blog.quarkslab.com/in-waf-we-sh...
010
Quarkslab @quarkslab.bsky.social · 20/03/2026
"Intego X9: Never trust my updates" Read Mathieu Farrell's research showing how XPC interprocess communications and the update mechanism of the Intego antivirus for MacOS can be abused for local privilege escalation. blog.quarkslab.com/intego_lpe_m...
Too many skulls
000
Quarkslab @quarkslab.bsky.social · 12/03/2026
"How does it even work?" The question that keeps hackers' hearts pumping, blood pressure rising, and curiosity growing. This is Damien Cauquil's reverse engineering journey into a cheap smartwatch that measures at least one of those. blog.quarkslab.com/nerd-life-we...
Look Ma, no sensors!
011
Quarkslab @quarkslab.bsky.social · 11/03/2026
One bit flip to corrupt it all: Exploitation of an old Linux kernel vulnerability using PageJack, a modern technique to create Use After Free bugs. Here Jean Vincent shows you how blog.quarkslab.com/pagejack-in-...
What if I flip this little thingie?
010
Quarkslab @quarkslab.bsky.social · 05/03/2026
If you glitch one, can you glitch many? Extracting automotive firmware is a challenge. @phil-barr3tt.bsky.social explains how he bypassed the IDCODE protection in several variants of the RH850 MCU family using both voltage glitching and side-channel analysis ⚡️🚗 blog.quarkslab.com/bypassing-de...
012
Quarkslab @quarkslab.bsky.social · 05/03/2026
Reverse engineers often spend a lot of time deciphering third-party firmware libraries. At RE//verse 2026 (Fri, 5 PM), Benoit & Sami will introduce SightHouse, an open-source tool to automatically identify third-party functions and speed up analysis. Join us!
032
Quarkslab @quarkslab.bsky.social · 03/03/2026
Another antivirus 🛡️, another unfulfilled promise 😣. @kaluche_ turns Avira's protection into a privilege escalation playground. This time: 3 LPE vectors 🆙 via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749). Find out more: blog.quarkslab.com/avira-deseri...
141
Quarkslab @quarkslab.bsky.social · 26/02/2026
Why macOS AVs shouldn’t trust PIDs 😄🍏 - new post by @Coiffeur0x90 Intego X9: XPC validation falls back to PID → PID reuse + posix_spawn() shenanigans 😏 ⇒ confused deputy / privileged methods abused 🤡🧨 Lesson: PID ≠ identity. Check it out 🔗 blog.quarkslab.com/intego_lpe_m...
000
Quarkslab @quarkslab.bsky.social · 10/02/2026
You've never been more right to doubt your MacOS antivirus software 😥 Our latest research by Mathieu Farrell shows how Intego can be abused for Local Privilege Escalation Yes, the antivirus. Yes, as root. blog.quarkslab.com/intego_lpe_m...
Remember whnn you didnt need an AV on your Mac? It was today
010
Quarkslab @quarkslab.bsky.social · 05/02/2026
"Dr. Bytecode or: How I Learned to Stop Worrying and Obfuscate Java" A tale about how @farena.in started his journey in Java software obfuscation. blog.quarkslab.com/how-to-write...
Java is bomb you ride backwards
021
Quarkslab @quarkslab.bsky.social · 28/01/2026
"Use a better system prompt" is the new "sanitize your inputs", but when your #AI agent's tools don't check permissions, you've got a problem and no amount of prompting will fix it. Check Kaluche's blog post about #AgenticAI & the Confused Deputy issue ⬇️ blog.quarkslab.com/agentic-ai-t...
000
Quarkslab @quarkslab.bsky.social · 20/01/2026
We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide. The audit was mandated by @ostifofficial.bsky.social 🙏 blog.quarkslab.com/everest-secu...
022
Quarkslab @quarkslab.bsky.social · 08/01/2026
A decade is an eternity in security. 🛡️ Ten years ago, we released the Clang Hardening Cheat Sheet. Today, the landscape has changed. @0xTRIKKSS & @bcreusillet break down the latest mitigations to keep your code secure. 🔗Read the update: blog.quarkslab.com/clang-harden...
044
Quarkslab @quarkslab.bsky.social · 11/12/2025
A modern tale of Blinkenlights, cheap Christmas shopping and curiosity, narrated by Damien Cauquil Firmware extraction and reverse engineering of a smartwatch FTW! blog.quarkslab.com/modern-tale-...
000
Quarkslab @quarkslab.bsky.social · 02/12/2025
K7 Antivirus: Named pipe abuse, registry manipulation and privilege escalation. A story of endpoint post-exploitation by Lucas Laise blog.quarkslab.com/k7-antivirus...
​🖥️​ cesi n'est pas une named pipe
030
Quarkslab @quarkslab.bsky.social · 07/11/2025
KubeVirt is open source virtualization technology for Kubernetes. Recently we worked with the @kubevirt team on a security audit sponsored by @OSTIFofficial 🙏 Read a summary of our findings and find the full report here: blog.quarkslab.com/kubevirt-sec...
011
Quarkslab @quarkslab.bsky.social · 21/10/2025
Our 2025-2026 internship season has started. Check out the list of openings and apply for fun and knowledge! blog.quarkslab.com/internship-offers-for-the-2025-2026-season.html
033
Quarkslab @quarkslab.bsky.social · 09/10/2025
Finding a buggy driver is one thing, abusing it is another🧠 In his latest blog post, Luis Casvella shows you how BYOVD can be used as a Reflective Rootkit Loader ! 🚀 ➡️ blog.quarkslab.com/exploiting-l...
Unsigned FTW!
032
Quarkslab @quarkslab.bsky.social · 07/10/2025
Quantum computers are not quite here yet, but now's the time to get ready. After updating their protocol in 2023, @signal.org is now proposing a post-quantum version of their Double Ratchet for message encryption. Let's see what Signal looks like now! blog.quarkslab.com/triple-threa...
Signal: Yo dawg! I heard you liked ratchets, so we added a ratchet to our Double Ratchet.
053
Quarkslab @quarkslab.bsky.social · 23/09/2025
BYOVD is a well-known technique commonly used by threat actors to kill EDR 🔪 However, with the right primitives, you can do much more. Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver. 👇 blog.quarkslab.com/exploiting-l...
RW physical memory pages with a side of LSTAR MSR overwrite? YOLO!
011
Quarkslab @quarkslab.bsky.social · 04/09/2025
The two bytes that make size matter: Reverse engineering Apple's iOS 0-click CVE-2025-43300 improved bounds checking fix, by Madimodi Diawara blog.quarkslab.com/patch-analys...
Yo dawg, I heard you like Improved Bounds Checking
So I improved the bound checks of the bound checks
052
Quarkslab @quarkslab.bsky.social · 26/08/2025
Hacking & Barbecue in the south of France. What could possibly be better? Barbhack starts this Saturday in Toulon and we're giving away a ticket to a student nearby looking to live the experience Send us a Chat msg with your name and school We will notify the winner tonight www.barbhack.fr/2025/fr/
The Barbhack 2025 logo
m000000
076
Quarkslab @quarkslab.bsky.social · 03/07/2025
You finally pwned the Holy Confluence server. What now? Create a user? Reset a password? 🚨Best way to trigger an alert What if you craft your own Personal Access Token 🔑 for the Admin account ? Find out how in this blog post by Quarkslab's Red Teamer YV blog.quarkslab.com/a-story-abou...
000
Quarkslab @quarkslab.bsky.social · 10/06/2025
Are you a network protocol reverse engineer? Tired of writing Wireshark plugins in memory unsafe or esoteric languages named after celestial objects? Now you can do it in a few lines of Go, Python or Rust with Wirego. Benoit Girard explains how here: blog.quarkslab.com/getting-star...
A Go gopher surfing over a Wireshark shark
123
Quarkslab @quarkslab.bsky.social · 08/05/2025
Good morning Singapore! The amazing Off by One Conference 2025 starts today. If you are attending don't miss Fred Raynal's (our fearless CEO) keynote at 9:35am: "Spyware for rent & the world of offensive cyber" The full agenda is available here: offbyone.sg/agenda
000
Quarkslab @quarkslab.bsky.social · 30/04/2025
Quarkslab was glad to sponsor the Real World Cryptography Paris Meetup 4 hosted by @Ledger last night. Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations. You can learn more about it here: quarkslab.github.io/crypto-condo...
Julio Loayza Meneses talking about Crypto Condor at RWC2005 Paris
The top bird of crypto implemetation testing
020
Quarkslab @quarkslab.bsky.social · 29/04/2025
Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out Alexandre Nesic's article on how it came to exist after an assumed breach mission ⤵️ 👉 blog.quarkslab.com/proxyblobing...
Proxybloby, the read teamer's mascot that will byte your SOCKS if left alone in your internal network
011
Quarkslab @quarkslab.bsky.social · 22/04/2025
While casually reading Moodle's code Mathieu Farrell found a SSRF bug exploitable by any authenticated user. Fun twist? This vuln matches exactly the example Orange Tsai presented at Black Hat 2017. Real life imitates conference slides 😅 Details here: blog.quarkslab.com/auditing-moo...
a TOCTOU bug in Moodle's core
010
Quarkslab @quarkslab.bsky.social · 25/03/2025
New GUI or root access? Choose wisely! Exploiting a Local Privilege Escalation vulnerability in CCleaner version 1 for MacOS, by @Coiffeur0x90 blog.quarkslab.com/ccleaner_lpe...
Who let the RATs in? why, CCleaner v1  did.
010
Quarkslab @quarkslab.bsky.social · 25/03/2025
Next week at the Hack The Box 0x4d meetup in Lille, France @rayanle.cat will talk about PwnShop, the challenge he prepared for the PwnMe CTF 2025 and how he accidentally discovered a RCE 0day while doing so. Join him next Monday at Campus Cyber Hauts-the-France: www.meetup.com/hack-the-box...
A CTF challenge in PHP, what could possibly not be a RCE?
062
Quarkslab @quarkslab.bsky.social · 21/03/2025
The Fifth Element: Using Quarkslab's cryptographic test suite to find bugs in the reference implementation of HQC, the latest algorithm added to the NIST PQC standard. Here Célian Glénaz, Dahmun Goudarzi and Julio Loayza Meneses tell you how they did it: blog.quarkslab.com/finding-bugs...
Image of the  Cryptocondor, the natural predator of cryptobugs. A mighty bird from the Andes mountain range that fiercely preys on bugs with the invaluable aid of DeltAFLy, which provides differential fuzzing superpowers.
010
Quarkslab @quarkslab.bsky.social · 21/03/2025
The Open Platform Communications Unified Architecture (OPC UA) is an open standard for industrial systems. In 2024 we worked with @anssi-fr.bsky.social to develop fuzzysully, an OPC UA fuzzer. Today we are glad to announce that this tool is now open source: github.com/ANSSI-FR/fuz...
Your OPC vuln research mission is about to crash? 
Don't worry fuzzysully can land you safely
011