Sign in

voydstack

@voydstack.re
205 followers 204 following 0 posts

VR @ Synacktiv, low level security enthusiast voydstack.re

PostsRepliesMedia
Reposted by voydstack
Entrypoint @entrypoint-fr.bsky.social · 29/06/2026
🚨 The #Entrypoint2027 Call For Papers is now open! Have original offensive security research to share? New techniques, tools, or attack stories ? We want to hear from you. 📅 CFP closes: Sept 20, 2026. Our review board will be revealed soon. 👉 cfp.entrypoint.fr/entrypoint-2...
0109
Reposted by voydstack
Entrypoint @entrypoint-fr.bsky.social · 18/06/2026
We've been working on something for a while. The talks your blue team doesn't want you to see. 🔴 Red Teaming. Initial Access. AD. Cloud & Web exploitation. 📍 Paris - Le Dernier Étage 📅 March 19–20, 2027 entrypoint.fr CFP and additional details coming soon.
085
Reposted by voydstack
ioonag.bsky.social @ioonag.bsky.social · 04/06/2026
Just ranked 2nd in SSTIC 2026 security challenge! 🏆️ www.sstic.org/2026/challen... My write-up is now live 📝 github.com/fishilico/ss...
Screenshot of a remote terminal titled "weapon auth supervisor" with some messages related to Shadow stack mechanism.
052
Reposted by voydstack
OffensiveCon @offensivecon.bsky.social · 29/05/2026
Offensivecon's talks are now available on our YouTube channel! 🔗 buff.ly/g63xgm5
youtube.com
OffensiveCon26
OffensiveCon 2026 Talks
053
Reposted by voydstack
Bière Sécu Toulouse @bieresecutls.bsky.social · 04/03/2026
📣 Prochain Bière&Sécu Toulouse le mardi 17 Mars ! 🗓️ RDV au Rooster and Beer à partir de 18h30 👉 beta.framadate.org/polls/b12ed9... (merci d'indiquer votre présence, c'est pour la résa du bar) 🗣️ Contactez-nous si vous avez des sujets à présenter via Twitter, Bluesky ou Discord !
beta.framadate.org
Bière&Sécu – Framadate BETA
021
Reposted by voydstack
root-me.org @root-me.org · 23/12/2025
🎄 New Root-Xmas Challenge 🎄 ✨ Today, prove Santa his Christmas Gift Packager system is not that secure... 📌 Submitted by: @voydstack.re 🔗 Details & participation here: ctf.xmas.root-me.org Good luck to you all! 🎅
011
Reposted by voydstack
root-me.org @root-me.org · 16/12/2025
🎄 New Root-Xmas Challenge 🎄 ✨ Today, wish for anything you want... just make sure it’s properly formatted! 📌 Submitted by : @voydstack.re 🔗 Details & participation here: ctf.xmas.root-me.org Good luck to you all! 🎅
021
Reposted by voydstack
Bière Sécu Toulouse @bieresecutls.bsky.social · 20/11/2025
📣 Prochain Bière&Sécu Toulouse le mardi 2 décembre ! 🗓️ RDV au Rooster and Beer à partir de 18h30 👉 Framadate: beta.framadate.org/polls/606039... 🗣️ Contactez-nous si vous avez des sujets à présenter via Twitter, Bluesky ou Discord !
beta.framadate.org
Bière&Sécu Toulouse – Framadate BETA
053
Reposted by voydstack
Synacktiv @synacktiv.com · 30/10/2025
Level up your pentesting skills in 2026 🚀 Join Synacktiv’s hands-on trainings: from Kubernetes & cloud hacks to web app attacks & AD intrusion. More information & registration : www.synacktiv.com/en/offers/tr...
synacktiv.com
Les formations
Synacktiv
011
Reposted by voydstack
Synacktiv @synacktiv.com · 27/10/2025
Following their presentation at @hexacon.bsky.social, @mtalbi.bsky.social & Etienne detail how they exploited CVE-2023-40129, a critical vulnerability affecting the Bluetooth stack in Android ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Paint it blue: Attacking the bluetooth stack
Paint it blue: Attacking the bluetooth stack
065
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 24/10/2025
$1,024,750 - 73 unique bugs - a week of amazing research on display. #Pwn2Own Ireland had it all. Success. Failure. Intrigue. You name it. Congratulations to the Master of Pwn winners @SummoningTeam! Their outstanding work earned them $187,500 and 22 point. See you in Tokyo for Pwn2Own Automotive.
052
Reposted by voydstack
Synacktiv @synacktiv.com · 23/10/2025
🎉 Big win at #Pwn2Own Cork! @pol-y.bsky.social of #Synacktiv successfully breached the @Ubiquiti AI Pro surveillance system 🦈🎶 What a way to wrap up the challenge - congrats, @pol-y.bsky.social 💪
076
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 23/10/2025
🎥 Eyes wide shut! David Berard of @synacktiv.com just breached the @Ubiquiti AI Pro surveillance system at #Pwn2Own. He also serenaded us with round of "Baby Shark" played through the speaker. He's off to the disclosure room with an ear worm and the details.
034
Reposted by voydstack
Synacktiv @synacktiv.com · 22/10/2025
Impressive work from our team today at #Pwn2Own! @mtalbi.bsky.social and Matthieu just pulled off an exploit on the Philips Hue Bridge without laying a finger on the device! Great demonstration of Synacktiv’s offensive expertise 👏 Come on 🔥
0137
Reposted by voydstack
Synacktiv @synacktiv.com · 21/10/2025
Congrats to tek and anyfun for landing the first successful entry at #Pwn2OwnCork - exploiting a stack overflow on Synology BeeStation Plus for $40,000 and 4 Master of Pwn points in the process 💥 Let’s keep pushing 💪 #P2OIreland #Synacktiv
044
Reposted by voydstack
Synacktiv @synacktiv.com · 22/09/2025
A technical look at @grapheneos.org Hardened Malloc, a memory allocator designed to mitigate heap corruption vulnerabilities (UAF, overflows) and break common exploit primitives. Deep dive for security researchers & exploit developers by @nicoski.bsky.social www.synacktiv.com/en/publicati...
synacktiv.com
Exploring GrapheneOS secure allocator: Hardened Malloc
Exploring GrapheneOS secure allocator: Hardened Malloc
0116
Reposted by voydstack
Hexacon @hexacon.bsky.social · 12/09/2025
🚨 Time to reveal our first-class lineup for HEXACON 2025! ✨ A few training spots are still available if you want to join the party! 🎉 Unfortunately, trainings + conference packs are sold out www.hexacon.fr/conference/s...
hexacon.fr
Hexacon - Conference – Speakers
Discover the accepted talks for this edition!
065
Reposted by voydstack
jiska @naehrdine.bsky.social · 10/09/2025
Want to learn reverse engineering? There'll be a free, women*-only BlackHoodie workshop from October 6th to 9th in Paris! Topics: • Linux memory forensics 🕵️‍♀️ (by Sonia) • Web app and mobile app pentesting 🕸️📱 (by Paula) • iOS reversing 🍎 (by me)
12415
Reposted by voydstack
Synacktiv @synacktiv.com · 11/08/2025
We've just released a tool to decrypt all Synology encrypted archives! We used it to compare SynologyPhotos versions and highlight our #Pwn2Own Ireland 2024 vulnerability on the BeeStation BST150-4T. Check out our blog post for more details. www.synacktiv.com/en/publicati...
synacktiv.com
Extraction of Synology encrypted archives - Pwn2Own Ireland 2024
Context During Pwn2Own Ireland 2024 we targeted the BeeStation BST150-4T a NAS from Synology.
053
Reposted by voydstack
Hexacon @hexacon.bsky.social · 15/07/2025
We’re thrilled to welcoming back @interruptlabs.bsky.social as an official sponsor of Hexacon! Interrupt Labs works at the cutting edge of vulnerability research and exploit development and it’s always pleasure having the team on board! 🤗
021
Reposted by voydstack
ANSSI @anssi-fr.bsky.social · 23/06/2025
#ECSC2025 | 🐓 Découvrez la #TeamFrance 2025 ! 🇫🇷 Sélectionnés à l'issue du FCSC, les joueurs de la Team France représenteront la drapeau tricolore à Varsovie, en Pologne, dans le cadre de l'European Cybersecurity Challenge. 🔔 RDV en octobre ! PS: #YouAreAllWinners
2137
Reposted by voydstack
Synacktiv @synacktiv.com · 17/06/2025
🚗🔌 We reverse engineered the Tesla Wall Connector and uncovered a previously undocumented attack surface via the charging cable. From protocol analysis to code execution, a Pwn2Own Automotive 2025 exploit write-up. www.synacktiv.com/en/publicati...
synacktiv.com
Exploiting the Tesla Wall connector from its charge port connector
An interesting attack surface Over the past few years, Synacktiv has been analyzing Tesla vehicles for the Pwn2Own competition.
0138
Reposted by voydstack
Hexacon @hexacon.bsky.social · 02/06/2025
🔔 It is time to buy your HEXACON ticket! 💸 Discounted tickets are available (while supplies last) for students and professionals who do not receive support from their company. This approach is based on trust, but we may ask for proof. www.hexacon.fr/register/
045
Reposted by voydstack
Synacktiv @synacktiv.com · 28/05/2025
For the second year in a row, we managed to get first place at the #HackTheBox Business #CTF 2025! 🥇 Congratulations to GMO Cybersecurity and Downscope who complete the podium and thanks to @hackthebox.bsky.social ox.bsky.social for the fun challenges! 🥳
052
Reposted by voydstack
Bière Sécu Toulouse @bieresecutls.bsky.social · 19/05/2025
📣 Prochain Bière&Sécu Toulouse le mardi 10 juin ! 🗓️ RDV au Rooster and Beer à partir de 18h30 👉 Framadate: framadate.org/M8dPvbvdQNgL1i… 🗣️ Contactez-nous si vous avez des sujets à présenter via Twitter, Bluesky ou Discord !
framadate.org
122
Reposted by voydstack
Binary Ninja @binary.ninja · 23/04/2025
We're proud to announce the release of Binary Ninja 5.0. Here's some highlights: Union Support, Dyld Share Cache & Kernel Cache, Firmware Ninja, Auto Stack Arrays, Stack Structure Type Propagation, and so much more. Check out the blog post for more information: binary.ninja/2025/04/23/5...
02515
Reposted by voydstack
Hexacon @hexacon.bsky.social · 16/04/2025
iOS for Security Engineers by Quentin Meffre (@0xdagger.bsky.social) & Etienne Helluy-Lafont www.hexacon.fr/trainer/meff...
076
Reposted by voydstack
Synacktiv @synacktiv.com · 09/04/2025
From firmware dumps to wireless exploration — check out our latest dive into DVB receiver analysis and the hidden attack surface it exposes! www.synacktiv.com/en/publicati...
synacktiv.com
Hack the channel: A Deep Dive into DVB Receiver Security
Introduction During a garage cleaning, we found a DVB receiver and thought it would be a great target for vulnerability research.
01211
Reposted by voydstack
Synacktiv @synacktiv.com · 07/04/2025
Don't forget @bieresecutls.bsky.social on Wednesday 9th before THCon, first round of drinks is on us 🍻
054
Reposted by voydstack
Synacktiv @synacktiv.com · 03/04/2025
PagedOut! #6 magazine is out! This edition features two articles from our ninjas: - Implicit Unicode behaviors in database string functions - Calling Rust from Python: A story of bindings Dive into their insights here: pagedout.institute
pagedout.institute
Paged Out!
Deeply technical zine. And it's free.
072
Reposted by voydstack
Synacktiv @synacktiv.com · 28/03/2025
Synacktiv is looking for an additional team leader in Paris for its Reverse-Engineering Team! Find out if you are a good candidate by reading our offer (🇫🇷). www.synacktiv.com/responsable-...
synacktiv.com
Responsable équipe reverse engineering
076
Reposted by voydstack
Synacktiv @synacktiv.com · 10/03/2025
Interested in vulnerabilities in video games? 🎮 @tomtombinary.bsky.social presented critical flaws in Neverwinter Nights Enhanced Edition at #Hexacon, which could allow attackers to take control of players' computers. 🛡️ Check out the full details of these bugs!👇 www.synacktiv.com/en/publicati...
synacktiv.com
Exploiting Neverwinter Nights
Introduction Neverwinter Nights is an RPG based video game developed by BioWare and Obsidian Entertainment in 2002.
088
Reposted by voydstack
Bière Sécu Toulouse @bieresecutls.bsky.social · 03/03/2025
📢 Prochain Bière&Sécu mercredi 9 avril 🗓️ (veille de Thcon) ! RDV à partir de 19h au Rooster and Beer🐔🍺 @synacktiv.com offrira la première tournée de bières 🍻. Il n'y aura pas de présentation cette fois-ci mais n'hésitez pas à proposer des Rumps à THCon 😉
024
Reposted by voydstack
Karsten @gr4yf0x.bsky.social · 26/02/2025
Pumpkin (@u1f383 on X) does cool work. Here is another cool read about an interesting race condition involving signal handling u1f383.github.io/linux/2025/0...
u1f383.github.io
Linux Kernel Some Vsock Vulnerabilities Analysis
After CVE-2024-50264, the Theori team reported five more issues in the Linux kernel vsock subsystem, and syzbot recently discovered two additional issues. I believe these provide valuable insights int...
044
Reposted by voydstack
dmnk @dmnk.bsky.social · 15/02/2025
github.com/AFLplusplus/... 👀 LibAFL 🤝 Unicorn #LibAFL #🤝 #Unicorn by @henri2h.bsky.social
github.com
Add support for Unicorn engine by henri2h · Pull Request #1054 · AFLplusplus/LibAFL
Add support for unicorn engine for CPU emulation Currently support X86 ARM ARM64 Supersede: henri2h#1
0124
Reposted by voydstack
Kévin Gervot (Mizu) @mizu.re · 10/02/2025
I'm very happy to finally share the second part of my DOMPurify security research 🔥 This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)! Link 👇 mizu.re/post/explori... 1/2
22711
Reposted by voydstack
Kévin Gervot (Mizu) @mizu.re · 07/02/2025
Thanks to the recent @portswiggerres.bsky.social top 10, I finally found the motivation to finish writing the 2nd article about DOMPurify security! 😁 Before releasing it, I would like to share a small challenge 🚩 Challenge link 👇 challenges.mizu.re/xss_04.html 1/2
1176
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 24/01/2025
Looking for the results from Day Three of #Pwn2Own Automotive? Look no further. You can find them at www.zerodayinitiative.com/blog/2025/1/... #P2OAuto
zerodayinitiative.com
Zero Day Initiative — Pwn2Own Automotive 2025 - Day Three and Final Results
Welcome to the third and final day of Pwn2Own Automotive 2025. Over the past two days, we have awarded $718,250 for 39 unique 0-days. Sina Kheirkhah has a commanding lead for Master of Pwn, but anythi...
011
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 24/01/2025
Confirmed! The @Synacktiv team used a single integer overflow to exploit the Sony IVI. Their work earns them another $10,000 and 2 Master of Pwn points. #P2OAuto #Pwn2Own
055
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 24/01/2025
Confirmed! The @Synacktiv team used a single buffer overflow to exploit the Autel MaxiCharger. They were also able to demonstrate signals being transmitted via the Charging Connector for the add on. This work earns them $35,000 and 6 Master of Pwn points. #P2OAuto #Pwn2Own
0105
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 23/01/2025
Day 2 of #Pwn2Own Automotive comes to a close. We awarded $335,500, which brings the event total to $718,250. So far, 39 unique 0-days have been disclosed, & we've seen research never before demonstrated. @SinSinology has a commanding lead for Master of Pwn. Stay tuned for Day 3.
0102
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2025
Whew! It took two attempts but the #Synacktiv team successfully exploited the #ChargePoint EV Charger and demonstrated signal manipulation over the connector. They are off to the disclosure room to go over how they did it. #P2OAuto #Pwn2Own
1107
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 22/01/2025
We're doomed! At least the #Kenwood IVI is since @Synacktiv exploited the system and loaded a video of the classic FPS. They're off to the disclosure room to provide details on the exploit and why Doom isn't playable. #P2OAuto #Pwn2Own
196
Reposted by voydstack
TrendAI Zero Day Initiative @thezdi.bsky.social · 23/01/2025
Wow. Just wow. The @synacktiv team was able to take over the #Tesla Wall Connector while having their exploit originate from the Charging Connector. To our knowledge, that's never been demonstrated publicly before. They head to the disclosure room with details. #P2OAuto #Pwn2Own
11813
Reposted by voydstack
Kévin Gervot (Mizu) @mizu.re · 16/01/2025
Looks like my DOMPurify article has been nominated! I know I haven't released part 2 yet, but if you enjoyed it, I would really appreciate if you could vote for it! 🫶 mizu.re/post/explori...
093
Reposted by voydstack
cfreal.bsky.social @cfreal.bsky.social · 16/01/2025
This year again, I am lucky enough to get nominated twice for the Top Ten Hacking Techniques, for my research on iconv and PHP, and lightyear. This time feels a bit special however, as these are my last blog posts on ambionics. www.ambionics.io/blog/iconv-c... www.ambionics.io/blog/lightye...
ambionics.io
Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine (part 1)
A few months ago, I stumbled upon a 24 years old buffer overflow in the glibc, the base library for linux programs. Despite being reachable in multiple well-known libraries or executables, it proved r...
0124
Reposted by voydstack
Bière Sécu Toulouse @bieresecutls.bsky.social · 08/01/2025
📣 Prochain Bière & Sécu Toulouse le mardi 4 février! 🗓️ RDV au Rooster and Beer à partir de 18h30 👉 Merci de vous inscrire sur le framadate : framadate.org/rZveOzrGMyNb... 🗣️ Contactez-nous si vous avez des sujets à présenter via Twitter, Bluesky ou Discord !
framadate.org
Sondage - Bière&Sécu Toulouse - Framadate
Framadate est un service en ligne permettant de planifier un rendez-vous ou prendre des décisions rapidement et simplement.
066
Reposted by voydstack
s1r1us | Mohan Sri Rama Krishna Pedhapati @mohansrk.bsky.social · 14/12/2024
Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earned a $5,000 bounty for it. Here's the story and a beginner-friendly deep dive into V8 exploit development. watch: youtu.be/R3SE4VKj678?...
youtu.be
Hacking Discord for $5000 Bounty
YouTube video by Mrgavyadha
1188
Reposted by voydstack
Laluka @laluka.bsky.social · 18/12/2024
Petit cadeau de noël avant l'heure ! 🎁 Les replays de la Drink-Love-Share-V2 🍻💜🔁 la DLSv2 a eu lieu il y a quelques semaines, en collaboration avec @rootme_org (X) la veille de @grehack.bsky.social ! 🫶 La playlist ➡️ www.youtube.com/playlist?lis...
youtube.com
DrinkLoveShare-V2 - Rumps & Confs - YouTube
DrinkLoveShare-V2 - Rumps & Confs
131
Reposted by voydstack
Synacktiv @synacktiv.com · 11/12/2024
The 2025 training season is here! 🚀 Join our best ninjas for 5-day sessions on pentesting, reverse-engineering, and forensics (in French). Check out all the dates and topics on our website: www.synacktiv.com/offres/forma...
synacktiv.com
Les formations
Synacktiv - IT Security expertise - Penetration tests, Security audits, Code review, Training, Consulting, Vulnerability research
096