Congrats to tek and anyfun for landing the first successful entry at #Pwn2OwnCork - exploiting a stack overflow on Synology BeeStation Plus for $40,000 and 4 Master of Pwn points in the process ๐ฅ
Letโs keep pushing ๐ช
#P2OIreland #Synacktiv
21.10.2025 15:32 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Quantum readiness: Hybridizing key exchanges
Quantum readiness: Hybridizing key exchanges
Our post-quantum cryptography series continues!
This new article by @bluesheeet.bsky.social unpacks the hybridization of key exchanges, covering theory and implementations.
Read all about why it matters, how to approach it safely, and some misconceptions here ๐
www.synacktiv.com/en/publicati...
16.10.2025 14:49 โ ๐ 1 ๐ 1 ๐ฌ 1 ๐ 0
LinkPro: new stealthy #Linux rootkit based on eBPF ๐๏ธ
Our #CSIRT team discovered and named LinkPro, a new Linux rootkit, during an incident response. It exploits eBPF for evasion and persistence.
Here are the four key technical points in the image below. ๐ก
๐ www.synacktiv.com/en/publicati...
14.10.2025 14:33 โ ๐ 4 ๐ 4 ๐ฌ 0 ๐ 0
That's a wrap for Hexacon 2025!
We hope that you've enjoyed the event at least as much as we did ๐คฉ
Please take a moment to fill out our satisfaction survey and help us make Hexacon 2026 even better ๐ฅ
Thank you for trusting us year after year ๐
13.10.2025 14:38 โ ๐ 5 ๐ 3 ๐ฌ 0 ๐ 0
๐ฏ New training session: #ActiveDirectory Intrusion Tactics โ Advanced Level
5 intense days diving into advanced AD intrusion techniques.
Donโt miss our upcoming offensive #cybersecurity courses!
๐ www.synacktiv.com/en/offers/tr...
13.10.2025 12:41 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
LLM Poisoning [1/3] - Reading the Transformer's Thoughts
LLM Poisoning [1/3] - Reading the Transformer's Thoughts
LLM Poisoning [1/3]: Local LLMs are vulnerable to supply chain attacks.
Inject a trigger-activated Trojan in a LLM. First step, build a probe to read a transformer's pre-down MLP activations to detect your chosen trojan trigger.
๐ Full article www.synacktiv.com/en/publicati...
08.10.2025 15:52 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
#LesAssises2025, here we go ๐
Come and meet us at ๐๐๐ฎ๐ป๐ฑ ๐๐ฎ๐ด to discuss your challenges and find out how we can strengthen your #cyber posture.
Adrien, Augustin and Neder will be on hand to answer all your questions and share their insights.
Seeing you there ๐ค
08.10.2025 10:29 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
A look back at our ninjas' first day at @hexacon.bsky.social !
We are proud of our experts Quentin and Etienne, who are leading the โiOS for Security Engineersโ training course.
At the same time, Matthieu and Paul are hard at work on the โAzure intrusion for red teamersโ training course ๐
07.10.2025 10:49 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
๐ข"Paint it Blue: Attacking the Bluetooth stack" by Mehdi Talbi and Etienne Helluy-Lafont
03.10.2025 15:58 โ ๐ 2 ๐ 2 ๐ฌ 0 ๐ 0
Tick tock... 7 days to go until #Hexacon2025 kicks off โณ
The @synacktiv.com team can't wait to see you at this crucial event for the #cyber ecosystem.
Our experts will be on hand to discuss the latest innovations in pentesting and reverse engineering with you !
โน๏ธ www.hexacon.fr
03.10.2025 09:22 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
What could go wrong when MySQL strict SQL mode is off?
What could go wrong when MySQL strict SQL mode is off?
In our new blogpost, Alexandre Z. shows how one can abuse Unicode characters to bypass filters and abuse shell globbing, regexp, HTTP query parameters or WAFs when #MySQL strict SQL mode is off ๐
www.synacktiv.com/en/publicati...
03.10.2025 07:45 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Join us on 24 November for the Azure Intrusion Tactics training course ๐ก๏ธ
Learn offensive techniques for compromising Azure environments. Realistic scenarios, stealthy approaches and cutting-edge expertise.
Information & registration ๐
www.synacktiv.com/en/offers/tr...
03.10.2025 14:26 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Last sponsor to announce: Synacktiv! ๐ฅท
@synacktiv.com strives to help firms evaluate and improve their IT security, everybody there is working to make it the ๐ซ๐ท standard in offensive security.
There will a be a lot of ninjas lurking around, feel free to reach them out!
03.10.2025 08:16 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 1
๐ข"Inside Apple Secure Enclave Processor in 2025" by Quentin Salingue
02.10.2025 15:21 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Sharing is caring โค๏ธ This month, our ninjas presented their research all over the world to the offsec community!
Links and more details below ๐๏ธ
30.09.2025 15:23 โ ๐ 1 ๐ 1 ๐ฌ 5 ๐ 0
Quantum readiness: Hybridizing signatures
Quantum readiness: Hybridizing signatures
Missed our post-quantum cryptography series?
In our latest article, we explore cryptographic hybridization, with a focus on digital signatures.
Learn how to ensure a safe transition and avoid basic implementations pitfalls here๐
www.synacktiv.com/en/publicati...
29.09.2025 15:40 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
The Phantom Extension: Backdooring chrome through uncharted pathways
The Phantom Extension: Backdooring chrome through uncharted pathways
How safe is your browser?
Our ninja, Riadh Bouchahoua, uncovers how attackers can exploit Chromium extension loading to steal data, maintain persistent access, and breach confidentiality on Chromium-based browsers.
Read more here โฌ๏ธ
www.synacktiv.com/en/publicati...
26.09.2025 10:29 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 0
Exploring GrapheneOS secure allocator: Hardened Malloc
Exploring GrapheneOS secure allocator: Hardened Malloc
A technical look at @grapheneos.org Hardened Malloc, a memory allocator designed to mitigate heap corruption vulnerabilities (UAF, overflows) and break common exploit primitives.
Deep dive for security researchers & exploit developers by @nicoski.bsky.social
www.synacktiv.com/en/publicati...
22.09.2025 13:41 โ ๐ 11 ๐ 6 ๐ฌ 0 ๐ 0
This summer @synacktiv.com organized an interesting challenge: the aim was to craft a container image as small as possible which replicated itself (i.e. an OCI Image Quine), bsky.app/profile/syna....
I am now publishing a write-up of what I did (Rust/asm/code golfing/...): github.com/fishilico/sy...
18.09.2025 20:47 โ ๐ 5 ๐ 3 ๐ฌ 0 ๐ 0
DCOM is everywhere, but its inner workings feel like black magic. ๐ช Unveil the mystery with @kevintell.bsky.social's new article on DCOM basics. Trust us, it's way cooler than it sounds!
www.synacktiv.com/en/publicati...
16.09.2025 13:12 โ ๐ 8 ๐ 3 ๐ฌ 0 ๐ 0
Aaaand the first talk to be announced is... ๐ฅ
Exploiting the Undefined: PWNing Firefox by Settling its Promises by Tao Yan & Edouard Bochin
12.09.2025 09:18 โ ๐ 5 ๐ 2 ๐ฌ 0 ๐ 0
Hexacon - Conference โ Speakers
Discover the accepted talks for this edition!
๐จ Time to reveal our first-class lineup for HEXACON 2025! โจ
A few training spots are still available if you want to join the party! ๐
Unfortunately, trainings + conference packs are sold out
www.hexacon.fr/conference/s...
12.09.2025 09:12 โ ๐ 6 ๐ 5 ๐ฌ 0 ๐ 0
๐งโ๐ Boost your offensive Active Directory skills with our Entry & Advanced trainings. Hands-on labs with dozens of machines + latest research from DEFCON, x33fcon & more! Seats are limited, donโt miss out!
๐ Entry: www.synacktiv.com/en/offers/tr...
๐ Advanced: www.synacktiv.com/en/offers/tr...
12.09.2025 11:13 โ ๐ 4 ๐ 2 ๐ฌ 0 ๐ 0
๐ Grab your seat for Sept 29! ๐
Join our Cloud Intrusion Tactics training for a hands-on overview of offensive security across AWS, Azure, GCP & Kubernetes. Seats are limited, donโt miss out! ๐ www.synacktiv.com/en/offers/tr...
05.09.2025 12:11 โ ๐ 2 ๐ 2 ๐ฌ 0 ๐ 0
โก๏ธ Ready for some Rust โ๏ธ + hacking ๐ต๏ธโโ๏ธ? Two of our ninjas will land in Florence ๐ฎ๐น for #rustLab2025!
๐
Nov 2โ4 ๐ฅ Workshop: Network Interception in Rust โ Build a MITM Tool from Scratch
Hands-on. Real packets. Real fun. ๐ rustlab.it/talks/networ...
03.09.2025 10:56 โ ๐ 2 ๐ 1 ๐ฌ 1 ๐ 0
Weโre thrilled to announce Donncha ร Cearbhaill (@donncha.is) as our keynote speaker for HEXACON 2025! ๐ฅ
No doubt he has plenty of juicy stories up his sleeve ๐พ
02.09.2025 08:46 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Extraction of Synology encrypted archives - Pwn2Own Ireland 2024
Context During Pwn2Own Ireland 2024 we targeted the BeeStation BST150-4T a NAS from Synology.
We've just released a tool to decrypt all Synology encrypted archives! We used it to compare SynologyPhotos versions and highlight our #Pwn2Own Ireland 2024 vulnerability on the BeeStation BST150-4T. Check out our blog post for more details.
www.synacktiv.com/en/publicati...
11.08.2025 12:02 โ ๐ 5 ๐ 3 ๐ฌ 0 ๐ 0