Our ninja @kalimer0x00.bsky.social is now on stage at #x33fcon to talk about his journey from dissecting SCCM until the discovery of the critical CVE-2024-43468 and the post-exploitation opportunitiesπ₯
13.06.2025 14:46 β π 8 π 6 π¬ 0 π 0
Check out how I discover CVE-2025-33073 : RCE with NTLM reflectiv attack allowing authenticated user to compromise any machine without SMB signing enforced !
11.06.2025 10:42 β π 2 π 0 π¬ 0 π 0
NTLM reflection is dead, long live NTLM reflection! β An in-depth analysis of CVE-2025-33073
Microsoft just released the patch for #CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn.bsky.social and @wilfri3d.bsky.social.
www.synacktiv.com/publications...
11.06.2025 10:40 β π 7 π 5 π¬ 0 π 1
I had the privilege to attend this training at Synacktiv and it might be the best training you can get when it comes to Azure given by two guy who does Red Team all year round on this subject. Don't wait !
21.03.2025 18:03 β π 0 π 1 π¬ 0 π 0
Want to master cutting-edge techniques for attacking Azure?
Join us this summer at @blackhatevents.bsky.social in Vegas for a deep dive into red teaming on Azure, M365, Azure DevOps, and hybrid infrastructures.
Early bird tickets available until May 23rd!
www.blackhat.com/us-25/traini...
17.03.2025 16:16 β π 15 π 8 π¬ 0 π 1
Taking the relaying capabilities of multicast poisoning to the next level: tricking Windows SMB clients into falling back to WebDav
In our latest article, @croco-byte.bsky.social and @scaum.bsky.social demonstrate a trick allowing to make Windows SMB clients fall back to WebDav HTTP authentication, enhancing the NTLM and Kerberos relaying capabilities of multicast poisoning attacks!
www.synacktiv.com/publications...
27.02.2025 10:21 β π 10 π 5 π¬ 0 π 0
We've just updated our training catalog to include the latest additions, including a brand new course on ransomware investigations!
Find all the dates and details at www.synacktiv.com/en/offers/tr...
13.02.2025 11:00 β π 7 π 5 π¬ 0 π 0
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx
In our latest article, @croco_byte proposes an implementation of a trick discovered by James Forshaw in his research regarding Kerberos relaying. Discover how to perform pre-authenticated Kerberos relay over HTTP with our Responder and krbrelayx pull requests!
www.synacktiv.com/publications...
27.01.2025 12:06 β π 16 π 12 π¬ 0 π 1
Yay! Our offensive Azure training was accepted at BlackHat USA 2025 π₯³ Can't wait to see you there and share cutting-edge techniques for attacking Azure environments!
20.01.2025 09:24 β π 9 π 7 π¬ 0 π 0
BSides Las Vegas will take place on August 4th, 5th, and 6th, 2025
Sin City, USA Β· bsideslv.org
cybersecurity weather man. scanning the horizons for cloudy cyber. Expert at nothing except computer rubbish. Anti-ransomware since 2015.
Logging into things I shouldn't.
Red Team Lead @ NVIDIA
We bring the attackerβs mindset to every move, building defenses specifically designed to combat threats. Founded and led by practitioners who live and breathe security, we know what matters in the trenches - because weβre in them with you.
Penetration Testing, Purple Team, Red Team & Adversary Emulation.
Let our Offense, Prepare your Defense. https://redsiege.com
#weareoffensive
Security Engineer / IAM Security. Defending against people like me.
Placeholder profile : https://x.com/cyb3rops | glad to be in this respectful safe space | vi/vim
The worldβs premier hacker conference. Serving the global hacker community since 1993.
Defcon.org
Forum.defcon.org
Defcon.social
(he/him) Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary
CTO @TrustedSec.com | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Creator of Have I Been Pwned. Microsoft Regional Director. Pluralsight author. Online security, technology and βThe Cloudβ. Australian.
Cloud and container security β’ Security research and open source at Datadog
π¨ππ«π·
https://christophetd.fr
CEO, CISO, Trainer, Hacker, and Speaker.
AI + hacking + sec leadership.
ex:BuddoBot-Ubisoft-Bugcrowd-Fortify-HP-Redspin-Citrix.
Running on vibes. Cyber vibes.