π Big win at #Pwn2Own Cork!
@pol-y.bsky.social of #Synacktiv successfully breached the @Ubiquiti AI Pro surveillance system π¦πΆ
What a way to wrap up the challenge - congrats, @pol-y.bsky.social πͺ
π Big win at #Pwn2Own Cork!
@pol-y.bsky.social of #Synacktiv successfully breached the @Ubiquiti AI Pro surveillance system π¦πΆ
What a way to wrap up the challenge - congrats, @pol-y.bsky.social πͺ
A pre-auth RCE combining 2 critical vulnerabilities on the Production Environment extension of the PHP low-code website generator ScriptCase has been found by noraj and cabir. No upstream fix yet, please apply the workaround.
www.synacktiv.com/advisories/s...
ππ We reverse engineered the Tesla Wall Connector and uncovered a previously undocumented attack surface via the charging cable. From protocol analysis to code execution, a Pwn2Own Automotive 2025 exploit write-up.
www.synacktiv.com/en/publicati...
Weβre receiving a lot of requests to buy tickets, but the conference is sold out! Only tickets bundled with training are still available. You can also join the waiting list or submit a talk to our CFP (cfp.hexacon.fr/hexacon-2025/) π
Thank you all for your amazing support! π
π It is time to buy your HEXACON ticket!
πΈ Discounted tickets are available (while supplies last) for students and professionals who do not receive support from their company. This approach is based on trust, but we may ask for proof.
www.hexacon.fr/register/
π’ Our Call For Papers is open until 14 July!
β‘οΈ Details & benefits: www.hexacon.fr/conference/c...
Also, conference tickets will be on sale today at 4PM (UTC+2)
The last #Sth4ck talk was @pol-y.bsky.social talking about the Tesla WallConnector β‘οΈ
26.05.2025 07:06 β π 4 π 4 π¬ 0 π 0Our second talk of the day was Hooking Windows Named Pipes by Thomas
23.05.2025 11:08 β π 5 π 3 π¬ 0 π 0Time for our first talk at #Sth4ck! Vic presents his tips and tricks to reverse Objective-C code.
23.05.2025 08:26 β π 9 π 4 π¬ 0 π 0
π Training ticket sales for HEXACON 2025 open TODAY at 2PM UTC+2!
Limited spots available π₯
www.hexacon.fr/register/
π
Mark your calendars!
www.hexacon.fr
Time to start announcing our trainings for Hexacon 2025! π£
π 6th-9th October 2025
πΆ 4800β¬
π Near the conference
π Registrations will open in May
www.hexacon.fr/trainings/
Hypervisor development for security analysis
by Satoshi Tanda
www.hexacon.fr/trainer/tanda/
AI Agents for Cybersecurity
by Richard Johnson (@richinseattle.bsky.social)
www.hexacon.fr/trainer/john...
Azure intrusion for red teamers
by Paul BarbΓ© & Matthieu Barjole
www.hexacon.fr/trainer/barb...
Don't forget @bieresecutls.bsky.social on Wednesday 9th before THCon, first round of drinks is on us π»
07.04.2025 08:49 β π 6 π 4 π¬ 0 π 0
Synacktiv is looking for an additional team leader in Paris for its Reverse-Engineering Team!
Find out if you are a good candidate by reading our offer (π«π·).
www.synacktiv.com/responsable-...
π’ Prochain BiΓ¨re&SΓ©cu mercredi 9 avril ποΈ (veille de
Thcon) ! RDV Γ partir de 19h au Rooster and BeerππΊ
@synacktiv.com offrira la premiΓ¨re tournΓ©e de biΓ¨res π».
Il n'y aura pas de prΓ©sentation cette fois-ci mais n'hΓ©sitez pas Γ proposer des Rumps Γ THCon π
I had so much fun designing and executing this attack, from hardware to software! Huge thanks to @thezdi.bsky.social for introducing such devices and attack vectors into the contest!
23.01.2025 19:50 β π 10 π 3 π¬ 0 π 0Confirmed! @Synacktiv used a logic bug as a part of their chain to exploit the Tesla Wall Connector via the Charging Connector. Their outstanding (and inventive) research earns them $45,000 and 7 Master of Pwn points. #P2OAuto #Pwn2Own
23.01.2025 09:54 β π 10 π 4 π¬ 1 π 0Wow. Just wow. The @synacktiv team was able to take over the #Tesla Wall Connector while having their exploit originate from the Charging Connector. To our knowledge, that's never been demonstrated publicly before. They head to the disclosure room with details. #P2OAuto #Pwn2Own
23.01.2025 07:41 β π 18 π 13 π¬ 1 π 0
π£ Prochain BiΓ¨re & SΓ©cu Toulouse le mardi 4 fΓ©vrier!
ποΈ RDV au Rooster and Beer Γ partir de 18h30
π Merci de vous inscrire sur le framadate : framadate.org/rZveOzrGMyNb...
π£οΈ Contactez-nous si vous avez des sujets Γ prΓ©senter via Twitter, Bluesky ou Discord !
Kickstart 2025 with a cloud exploitation training like no other!
π Join our experts on Feb 10th to master cutting-edge techniques in GCP, AWS, Azure & Kubernetes. Don't miss out! www.synacktiv.com/en/offers/tr...
You can now relay any protocol to SMB over Kerberos with krbrelayx.py and the latest PRs from Hugo Vincent.
Thanks @dirkjanm.io for merging it!
Here is an example from SMB to SMB:
A few weeks ago, Rapid7 released a new version of #Velociraptor to patch CVE-2024-10526, a local privilege escalation discovered by jbms. You can read the advisory here:
www.synacktiv.com/advisories/l...
We are now on #BlueSky! We'll start posting our news here too π
22.11.2024 15:46 β π 22 π 8 π¬ 1 π 0