Sign in

Synacktiv

@synacktiv.com
656 followers 3 following 242 posts

Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.

PostsRepliesMedia
Synacktiv @synacktiv.com · 23/09/2026
During a Red Team assessment, laxa discovered multiple vulnerabilities on Ubika WAAP Gateway, including a pre-auth RCE as root. Technical details are available here ⬇️ www.synacktiv.com/advisories/u...
synacktiv.com
Ubika WAAP Gateway: multiple vulnerabilities including preauth RCE as
Ubika WAAP Gateway: multiple vulnerabilities including preauth RCE as root
000
Synacktiv @synacktiv.com · 15/09/2026
🚨 Un cluster Kubernetes est compromis. Où sont les preuves ? Conteneurs éphémères, logs distribués, workloads volatils… l’investigation forensique dans #Kubernetes ne s’improvise pas. Retrouvez notre formation : Kubernetes Forensics ⬇️ www.synacktiv.com/offres/forma...
000
Reposted by Synacktiv
Entrypoint @entrypoint-fr.bsky.social · 07/09/2026
🔥 What are you bringing to #Entrypoint? New technique? Tool release? Real-world compromise? Deep technical offensive security talk? 🎤 CFP closes 20 September. 📅 19-20 March 2027 | 📍 Paris ➡️ cfp.entrypoint.fr/entrypoint-2027/cfp
023
Synacktiv @synacktiv.com · 10/09/2026
🔐 Un #ActiveDirectory compromis : savez-vous reprendre le contrôle ? Notre formation AD: Hardening & Post-Compromise Recovery vous apprend à durcir l’AD, détecter les attaques et maîtriser la reprise de confiance après compromission. Inscrivez-vous ici ⬇️ www.synacktiv.com/offres/forma...
000
Synacktiv @synacktiv.com · 03/09/2026
Synacktiv recrute un Dev QA Red Team (H/F) ! Ta mission : tester & faire évoluer notre arsenal offensif (stabilité, perf, furtivité). 🛠️ Requis : Python, QA, culture cyber offensive, virtualisation. 📍 Paris 2e 🔗 www.synacktiv.com/developpeur-... 📩 apply+dev@synacktiv.com
000
Synacktiv @synacktiv.com · 02/09/2026
Approfondissez votre expertise #ActiveDirectory avec deux formations complémentaires : 🔹 AD Intrusion Tactics: Advanced : 16-20 nov ➡️ www.synacktiv.com/offres/forma... 🔹 AD Hardening & Post-Compromise Recovery : 23-27 nov ➡️ www.synacktiv.com/offres/forma... Inscrivez-vous dès maintenant !
000
Synacktiv @synacktiv.com · 31/08/2026
In our latest article, Quentin presents new scripts allowing to simulate legitimate AD services in a flexible manner, and demonstrates their use through GPO exploitation ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Simulating legitimate Active Directory services on the network: the
Simulating legitimate Active Directory services on the network: the
032
Synacktiv @synacktiv.com · 28/08/2026
🚨 Une fuite de données vient d’être détectée. Et maintenant ? Investigation, crise, conformité : préparez-vous à prendre les bonnes décisions. 📅 29/09 - #CampusCyber 🎓 Formation #Synacktiv x #Alcyconie 🔗 synacktiv.com/offres/formations/data-breach-investigations-crisis-management-compliance
001
Synacktiv @synacktiv.com · 27/08/2026
#NIS2, #DORA and the #CRA all aim to strengthen cyber resilience - but how can organisations demonstrate that their security measures are truly effective? Read our latest article ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Completing Compliance with Evidence : A Bottom-Up Approach to NIS2,
Completing Compliance with Evidence : A Bottom-Up Approach to NIS2,
010
Synacktiv @synacktiv.com · 26/08/2026
Envie de développer vos compétences en sécurité des systèmes embarqués ? 🔐 Inscrivez-vous à notre formation : 📅 Embedded Systems Exploitation : 19-23 oct. Firmware, QEMU, analyse statique, fuzzing AFL++ et exploitation de vulnérabilités ⬇️ www.synacktiv.com/offres/forma...
001
Synacktiv @synacktiv.com · 24/08/2026
🚨 When an EKS cluster is compromised, evidence spans the control plane, nodes & AWS. Yet almost nothing is logged by default. @ekt0plasm.bsky.social’s new post maps EKS data sources & tools for DFIR: audit logs, GuardDuty, CloudTrail, and ready-to-use queries ⬇️ www.synacktiv.com/en/publicati...
110
Synacktiv @synacktiv.com · 20/08/2026
🚨 Une fuite de données ne se résume pas à un incident technique. Le 29 septembre, Synacktiv & Alcyconie proposent au Campus Cyber une formation sur l’investigation, la gestion de crise et la conformité. 🔗 synacktiv.com/offres/formations/data-breach-investigations-crisis-management-compliance
000
Synacktiv @synacktiv.com · 19/08/2026
Cet automne, renforcez vos compétences en sécurité offensive dans les environnements cloud. 🔹 Cloud Intrusion Tactics : 28 septembre - 2 octobre ➡️ www.synacktiv.com/offres/forma... 🔹 Azure Intrusion Tactics : 5-9 octobre ➡️ www.synacktiv.com/offres/forma... Inscrivez-vous dès maintenant !
000
Synacktiv @synacktiv.com · 12/08/2026
Vous souhaitez renforcer vos compétences en sécurité DevOps, Linux et Kubernetes ? Participez à nos prochaines formations : 🔹 DevOps & Linux Breach Tactics : 28 septembre - 2 octobre ➡️ www.synacktiv.com/offres/forma... 🔹 Kubernetes Forensics : 12 - 14 octobre ➡️ www.synacktiv.com/offres/forma...
001
Synacktiv @synacktiv.com · 11/08/2026
Ready to take your malware analysis skills to the next level? Join our experts at #Nullcon Berlin 2026 for our hands-on Malware Analysis training. 📅 2-4 Nov 2026 Sign up 👉 nullcon.net/training/adv...
000
Synacktiv @synacktiv.com · 03/08/2026
Register for our Active Directory Intrusion Tactics: Advanced Level training with @wilfri3d.bsky.social and @rustyphasm.bsky.social at #Nullcon Berlin, from 2-4 Nov 2026 📚 Learn real-world AD attack paths, lateral movement, and defence strategies ⬇️ nullcon.net/training/act...
000
Synacktiv @synacktiv.com · 30/07/2026
Interested in old video game vulnerabilities? 🎮 Checkout our latest blogpost on Titan Quest : Anniversary Edition by @tomtombinary.bsky.social ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Exploiting Titan Quest
Exploiting Titan Quest
001
Synacktiv @synacktiv.com · 30/07/2026
Compliance is no longer enough. Technical evidence is what matters. How can you prove your security measures are actually effective? Discover how #Synacktiv helps organisations move beyond compliance with evidence-based security assessments ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Completing Compliance with Evidence : A Bottom-Up Approach to NIS2,
Completing Compliance with Evidence : A Bottom-Up Approach to NIS2,
011
Synacktiv @synacktiv.com · 29/07/2026
Synacktiv recrute de nouveaux profils Red Teamer H/F 🥷 🎯 Exercices Red Team (AD, Cloud...), Lab & Furtivité, 0-Day 👤 3+ ans d'expérience 📍 6 bureaux en France ou 100% remote 📩 apply+pentest@synacktiv.com 🔗 www.synacktiv.com/red-teamer
010
Synacktiv @synacktiv.com · 10/07/2026
After MySQL, it's now SQL Server's turn. noraj takes a deep dive into Unicode-related security issues. 📚 Read the full article: www.synacktiv.com/en/publicati...
synacktiv.com
The SQL Server Unicode problem: why your data might not be what you
The SQL Server Unicode problem: why your data might not be what you
022
Synacktiv @synacktiv.com · 10/07/2026
🔒 #Recrutement | @synacktiv.com recherche un(e) Officier de Sécurité à Paris. Vous souhaitez contribuer à la protection de l'information au sein d'une société d'expertise en cybersécurité ? 👉 Postulez dès maintenant : www.synacktiv.com/officier-sec...
022
Synacktiv @synacktiv.com · 09/07/2026
During an internal assessment, our expert found several vulnerabilities in #Xpra (Screen for X11) which, chained together, allow a malicious server to gain RCE on the client. Update your packages! ⬇️ www.synacktiv.com/en/advisorie...
synacktiv.com
Multiple vulnerabilities in the Xpra client
Multiple vulnerabilities in the Xpra client
021
Synacktiv @synacktiv.com · 09/07/2026
Tu aimes chercher des failles et passer ton temps sur de la technique et de la R&D ? L'équipe Pentest de @synacktiv.com recrute. 📍 Paris, Rennes, Toulouse, Lille, Lyon, Bordeaux (+ télétravail pour profils expérimentés) Je postule 📝 www.synacktiv.com/pentester-di...
000
Synacktiv @synacktiv.com · 08/07/2026
🚀 Le pôle Reverse de @synacktiv.com recrute ! Vous poncez les CTF ? Vous aimez la R&D et vous souhaitez évoluer aux côtés d'experts reconnus dans le domaine ? Rejoignez-nous ! 📍 Paris, Rennes, Toulouse, Lille, Bordeaux, Lyon ou full remote (France). 👉 www.synacktiv.com/recherche-et...
022
Synacktiv @synacktiv.com · 07/07/2026
Who said KYC is not fun? Discover how @kevintell.bsky.social and @log-s.bsky.social exploited new #AI techniques to bypass Age Verification and how this technology reshuffles the deck ⬇️ www.synacktiv.com/en/publicati...
023
Synacktiv @synacktiv.com · 06/07/2026
Back from @passthesaltcon.bsky.social 🧂 Our team presented: 💥 Livewire RCE (CVE-2025-54068) – @remsio.bsky.social, alongside Worty 🔍 Dicozorus for smarter web fuzzing – us3r777 💥 BadUSB Forensics – acervoise Tools 👇 github.com/synacktiv/Li... github.com/synacktiv/di...
112
Synacktiv @synacktiv.com · 03/07/2026
A huge thank you to everyone who stopped by our stand at @le-hack.bsky.social ! Congrats to everyone who took on our challenge 🎯 Missed it? It's now available on our #GitHub, along with the write up: github.com/synacktiv/le... See you next year 🚀
000
Synacktiv @synacktiv.com · 02/07/2026
#RBCD attacks in Impacket have been extended across an arbitrary number of domains! 🚀 Discover how to impersonate arbitrary identities through complex #ActiveDirectory forest trusts, including SPN-less exploitation. 📚 www.synacktiv.com/en/publicati... 🔨 github.com/synacktiv/im...
synacktiv.com
Exploring cross-domain & cross-forest RBCD: part 2
Exploring cross-domain & cross-forest RBCD: part 2
152
Synacktiv @synacktiv.com · 02/07/2026
A month ago we pointed our local LLM at #FreeBSD and it helped us find a local root exploit plus an ASLR bypass on SUID binaries to go with it 🚨 Both now patched (CVE-2026-49415 & CVE-2026-49414). Update your boxes! ➡️ www.freebsd.org/security/adv... ➡️ www.freebsd.org/security/adv...
033
Synacktiv @synacktiv.com · 01/07/2026
CI/CD pwnage with a pre-auth RCE in #ArgoCD by @rustyphasm.bsky.social 💥 Discover how a single misconfiguration in a Helm chart can lead to a full cluster compromise sprinkled with some CodeQL shenanigans! 🥷 www.synacktiv.com/en/publicati...
synacktiv.com
Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL
Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL
131
Synacktiv @synacktiv.com · 30/06/2026
"We're compliant." But can you prove it? With #NIS2, #DORA and the #CRA, compliance is no longer just about documentation. Organisations must demonstrate that their security measures actually work. Learn how technical evidence strengthens compliance 👇 www.synacktiv.com/en/publicati...
synacktiv.com
Completing Compliance with Evidence : A Bottom-Up Approach to NIS2,
Completing Compliance with Evidence : A Bottom-Up Approach to NIS2,
000
Reposted by Synacktiv
Entrypoint @entrypoint-fr.bsky.social · 29/06/2026
🚨 The #Entrypoint2027 Call For Papers is now open! Have original offensive security research to share? New techniques, tools, or attack stories ? We want to hear from you. 📅 CFP closes: Sept 20, 2026. Our review board will be revealed soon. 👉 cfp.entrypoint.fr/entrypoint-2...
0109
Synacktiv @synacktiv.com · 30/06/2026
📚 Kindle research, exploitation methodology, and jailbreak development. Missed @le-hack.bsky.social? SidewayRE's talk, "Bootstrapping Kindle Research for the Lazy Attacker", is now available. Read the slides 👇 www.synacktiv.com/sites/defaul...
010
Synacktiv @synacktiv.com · 29/06/2026
Using #Helm and #Kubernetes in your CI/CD pipeline? An attacker only needs access to the values.yaml file to compromise your cluster. Recent research by Paul BARBE details a new injection technique to escalate privileges and deploy unauthorized resources ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Charting your way in: Helm template injection
Charting your way in: Helm template injection
012
Synacktiv @synacktiv.com · 26/06/2026
🚀 @le-hack.bsky.social starts today! Come meet the #Synacktiv team at stand 22 and try the challenge we designed for the event: puzzles to solve, secrets to find, and flags to capture 🔒 See you there 👋
020
Synacktiv @synacktiv.com · 19/06/2026
Kernel LPEs dropping before patches are widely available? It's been a wild month for Linux defenders. Our CIO breaks down how tried-and-true hardening measures can raise the bar and buy your Blue Team time against N-days. 🔗 www.synacktiv.com/en/publicati...
synacktiv.com
Surviving the surge of new Linux LPE : Defense in Depth not dead
Surviving the surge of new Linux LPE : Defense in Depth not dead
020
Synacktiv @synacktiv.com · 19/06/2026
⏳ 7 days to go until #LeHack ! On 26-27 June, visit #Synacktiv and take on a challenge designed especially for the event 🔒 Gain access, uncover secrets and solve puzzles. Can you capture every flag before time runs out? ⏱️ 📍 Stand 22 Who’s up for the challenge? 👀
000
Synacktiv @synacktiv.com · 16/06/2026
Working with #AWS and looking to improve visibility across your #cloud environment? This article introduces the key AWS security and logging services to help strengthen your detection, investigation and incident response capabilities ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
AWS Forensics : What you need to know
AWS Forensics : What you need to know
000
Synacktiv @synacktiv.com · 15/06/2026
🇵🇱 At #x33fcon, our experts unveiled new offensive DCOM techniques, including a COMouflage variant enabling arbitrary executable execution and a fileless lateral movement method based on .NET deserialisation. DCOMIllusionist is now available: 🔗 github.com/synacktiv/DC...
022
Synacktiv @synacktiv.com · 09/06/2026
Another excellent edition of #SSTIC2026 🎉 Several #Synacktiv consultants were proud to present their research and exchange ideas with the cybersecurity community. Congratulations to all our speakers! Find all presentations here: www.sstic.org/2026/program...
010
Synacktiv @synacktiv.com · 08/06/2026
🚀 Training week is underway at #x33fcon! Our consultants are delivering: 🔐 Azure Intrusion Tactics 🖥️ Advanced Active Directory Red Teaming Three days of hands-on labs, realistic attack scenarios, and offensive security techniques. Great to see so many participants joining us!
000
Synacktiv @synacktiv.com · 27/05/2026
🔒 Think you can crack them all? Join #Synacktiv at @le-hack.bsky.social and take on a challenge at our stand, crafted by @niozow.bsky.social 🚀 One laptop. Multiple flags. Encrypted safes. Break in, unlock everything, and recover every secret before time runs out ⏱️💻 See you at stand 22!
001
Synacktiv @synacktiv.com · 12/05/2026
🚗🔌 #Tesla patched our #Pwn2Own Automotive 2025 Wall Connector exploit with an anti-downgrade mechanism. #Synacktiv experts bypassed it and replayed the same attack through the charging cable. Part 2 write-up 👇 www.synacktiv.com/en/publicati...
synacktiv.com
Exploiting the Tesla Wall Connector from its charge port connector -
Exploiting the Tesla Wall Connector from its charge port connector -
011
Synacktiv @synacktiv.com · 07/05/2026
Back from #THCON 2026 🔥 Proud to see our teams share their latest offensive security research once again this year: 📡 Wi-Fi pentesting in 2025 & WPA3 bypasses - Quentin 🛡️ Cross-domain & cross-forest RBCD - Simon 🏴 THCON pre-challenge write-up - @0xf4b.bsky.social Great work everyone 👏
141
Synacktiv @synacktiv.com · 06/05/2026
Make it blink! Our latest article explains how @mtalbi.bsky.social & Matthieu achieved an over-the-air exploitation of the #PhilipsHue Bridge via a #Zigbee flaw. Includes technical details and their #Pwn2Own Cork 2025 demo 👇 www.synacktiv.com/en/publicati...
synacktiv.com
Make it Blink: Over-the-Air Exploitation of the Philips Hue Bridge
Make it Blink: Over-the-Air Exploitation of the Philips Hue Bridge
011
Synacktiv @synacktiv.com · 05/05/2026
🚀 Join #Synacktiv at #x33fcon for two hands-on trainings (June 8–10): 🔐 Azure Intrusion Tactics (intermediate): x33fcon.com#!t/MattheuBa... 🖥️ Advanced Active Directory Red Teaming (advanced) Led by our experts: x33fcon.com#!t/WilfriedB... Sharpen your offensive skills in realistic environments!
000
Synacktiv @synacktiv.com · 30/04/2026
This second blogpost concludes @yaumn.bsky.social's research on #Windows authentication reflection. He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥 A little bonus is even included at the end 👀👇 www.synacktiv.com/en/publicati...
synacktiv.com
Bypassing Windows authentication reflection mitigations for SYSTEM
Bypassing Windows authentication reflection mitigations for SYSTEM
131
Synacktiv @synacktiv.com · 28/04/2026
Authentication reflection attacks are still not dead! In our new blogpost series, @yaumn.bsky.social shares his journey into bypassing the mitigations of CVE-2025-33073 to pop SYSTEM shells again! 🚀 👇 www.synacktiv.com/en/publicati...
synacktiv.com
Bypassing Windows authentication reflection mitigations for SYSTEM
Bypassing Windows authentication reflection mitigations for SYSTEM
032
Synacktiv @synacktiv.com · 23/04/2026
Tomorrow, @yaumn.bsky.social will be presenting his research on Windows authentication reflection at @blackhatevents.bsky.social Asia 2026 in Singapore! The talk will be at 15:20 local time in Simpor Junior Ballroom 4810, come say hi! 😄 #BHASIA ℹ️ blackhat.com/asia-26/brie...
blackhat.com
Black Hat
Black Hat
000
Synacktiv @synacktiv.com · 23/04/2026
Say hi to Pike! Our latest article introduces #Pike, an experimental #LLM agent that generates & analyses #Linux execution traces to: 🔍 Debug crashes 🛡️ Detect malware 📊 Provide high-level insights All through a natural chat interface. www.synacktiv.com/en/publicati...
synacktiv.com
Say hi to Pike!
Say hi to Pike!
022