Remember whnn you didnt need an AV on your Mac? It was today
You've never been more right to doubt your MacOS antivirus software π₯
Our latest research by Mathieu Farrell shows how Intego can be abused for Local Privilege Escalation
Yes, the antivirus.
Yes, as root.
blog.quarkslab.com/intego_lpe_m...
10.02.2026 16:44 β π 1 π 0 π¬ 0 π 0
Java is bomb you ride backwards
"Dr. Bytecode or: How I Learned to Stop Worrying and Obfuscate Java"
A tale about how @farena.in started his journey in Java software obfuscation.
blog.quarkslab.com/how-to-write...
05.02.2026 15:23 β π 2 π 1 π¬ 0 π 0
"Use a better system prompt" is the new "sanitize your inputs", but when your #AI agent's tools don't check permissions, you've got a problem and no amount of prompting will fix it.
Check Kaluche's blog post about #AgenticAI & the Confused Deputy issue β¬οΈ
blog.quarkslab.com/agentic-ai-t...
28.01.2026 16:35 β π 0 π 0 π¬ 0 π 0
@lfenergy.bsky.social EVerest underwent a security engagement facilitated by us with auditing by @quarkslab.bsky.social. This holistic security work impacts millions of EV charging stations worldwide. Read more at our blog:
ostif.org/everest-secu...
20.01.2026 17:48 β π 1 π 1 π¬ 0 π 0
We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide.
The audit was mandated by @ostifofficial.bsky.social π
blog.quarkslab.com/everest-secu...
20.01.2026 16:45 β π 2 π 2 π¬ 0 π 0
A decade is an eternity in security. π‘οΈ
Ten years ago, we released the Clang Hardening Cheat Sheet. Today, the landscape has changed. @0xTRIKKSS & @bcreusillet break down the latest mitigations to keep your code secure.
πRead the update: blog.quarkslab.com/clang-harden...
08.01.2026 15:28 β π 4 π 4 π¬ 0 π 0
A modern tale of Blinkenlights, cheap Christmas shopping and curiosity, narrated by Damien Cauquil
Firmware extraction and reverse engineering of a smartwatch FTW!
blog.quarkslab.com/modern-tale-...
11.12.2025 16:26 β π 1 π 0 π¬ 0 π 0
βπ₯οΈβ cesi n'est pas une named pipe
K7 Antivirus: Named pipe abuse, registry manipulation and privilege escalation.
A story of endpoint post-exploitation by Lucas Laise
blog.quarkslab.com/k7-antivirus...
02.12.2025 15:51 β π 3 π 0 π¬ 0 π 0
Bitcoin Core Audit Complete! β OSTIF.org
We've been a bit excited about this one.
We are excited and honored to have partnered with Bitcoin, brink, Chaincode Labs, and @quarkslab.bsky.social to collaborate on a security audit of Bitcoin Core. This was Bitcoin Core's first external audit.
Read more at our blog: ostif.org/bitcoin-core...
19.11.2025 15:31 β π 5 π 2 π¬ 1 π 0
Bitcoin Core audit - Quarkslab's blog
The Open Source Technology Improvement Fund, Inc. mandated Quarkslab to perform the first public security audit of Bitcoin core, the reference open-source implementation of the Bitcoin decentralized p...
Quarkslab engineers Robin David, Mihail Kirov and Kaname just completed the first public security audit of Bitcoin Core, led by
@ostifofficial.bsky.social and funded by Brink.dev
Details on the blog post:
blog.quarkslab.com/bitcoin-core...
Congrats to developers for such software masterpiece !
19.11.2025 15:40 β π 6 π 5 π¬ 0 π 0
Announcing the results of our Security Audit | KubeVirt.io
As part of our application to Graduate, KubeVirt has a security audit performed by a third-party, organised through the CNCF and OSTIF.
We are pleased to announce that the KubeVirt Security Audit report has been published, in collaboration with @quarkslab.bsky.social and @ostifofficial.bsky.social
Check out our blog post for all the details: kubevirt.io/2025/Announc...
12.11.2025 08:22 β π 4 π 3 π¬ 0 π 0
KubeVirt is open source virtualization technology for Kubernetes.
Recently we worked with the @kubevirt team on a security audit sponsored by @OSTIFofficial π
Read a summary of our findings and find the full report here:
blog.quarkslab.com/kubevirt-sec...
07.11.2025 16:26 β π 1 π 1 π¬ 0 π 0
Our 2025-2026 internship season has started.
Check out the list of openings and apply for fun and knowledge!
blog.quarkslab.com/internship-offers-for-the-2025-2026-season.html
21.10.2025 09:51 β π 3 π 3 π¬ 0 π 0
Unsigned FTW!
Finding a buggy driver is one thing, abusing it is anotherπ§
In his latest blog post, Luis Casvella shows you how BYOVD can be used as a Reflective Rootkit Loader ! π
β‘οΈ blog.quarkslab.com/exploiting-l...
09.10.2025 16:22 β π 3 π 2 π¬ 0 π 1
Signal: Yo dawg! I heard you liked ratchets, so we added a ratchet to our Double Ratchet.
Quantum computers are not quite here yet, but now's the time to get ready. After updating their protocol in 2023, @signal.org is now proposing a post-quantum version of their Double Ratchet for message encryption.
Let's see what Signal looks like now!
blog.quarkslab.com/triple-threa...
07.10.2025 14:25 β π 5 π 3 π¬ 0 π 1
RW physical memory pages with a side of LSTAR MSR overwrite? YOLO!
BYOVD is a well-known technique commonly used by threat actors to kill EDR πͺ
However, with the right primitives, you can do much more.
Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver.
π
blog.quarkslab.com/exploiting-l...
23.09.2025 17:01 β π 1 π 1 π¬ 0 π 0
Security review of PHP documentation - Quarkslab's blog
The Open Source Technology Improvement Fund, Inc., engaged with Quarkslab to perform a security audit of the code snippets in the English version of PHP documentation, focused on some specific pages.
RTFM they say but if you read the manual and copy code examples from it you may inadvertently introduce vulns in your code π
In April we audited the PHP code. Now we followed up with a review of the code snippets in PHP documentation and found 81 issues π
blog.quarkslab.com/security-rev...
22.09.2025 15:51 β π 6 π 5 π¬ 0 π 0
Yo dawg, I heard you like Improved Bounds Checking
So I improved the bound checks of the bound checks
The two bytes that make size matter:
Reverse engineering Apple's iOS 0-click CVE-2025-43300 improved bounds checking fix, by Madimodi Diawara
blog.quarkslab.com/patch-analys...
04.09.2025 16:09 β π 5 π 2 π¬ 0 π 1
The Barbhack 2025 logo
m000000
Hacking & Barbecue in the south of France. What could possibly be better?
Barbhack starts this Saturday in Toulon and we're giving away a ticket to a student nearby looking to live the experience
Send us a Chat msg with your name and school
We will notify the winner tonight
www.barbhack.fr/2025/fr/
26.08.2025 15:05 β π 7 π 6 π¬ 0 π 0
ControlPlane Local Privilege Escalation Vulnerability on macOS - Quarkslab's blog
A technical exploration of Local Privilege Escalation Vulnerability in ControlPlane on macOS.
πEver heard of ControlPlane, software to help you automate tasks on macOS? Turns out, it might also help you become root.
Oops! π± @coiffeur0x90 found a Local Privilege Escalation vulnerability.
Read before someone automates your admin rights
π blog.quarkslab.com/controlplane...
15.07.2025 17:09 β π 0 π 0 π¬ 0 π 0
You finally pwned the Holy Confluence server. What now? Create a user? Reset a password?
π¨Best way to trigger an alert
What if you craft your own Personal Access Token π for the Admin account ?
Find out how in this blog post by Quarkslab's Red Teamer YV
blog.quarkslab.com/a-story-abou...
03.07.2025 15:56 β π 0 π 0 π¬ 0 π 0
leHACK 2025 incoming! - leHACK
false
The leHack conference (@le-hack.bsky.social) starts tomorrow at the CitΓ© des Sciences et de lβIndustrie in Paris.
We will be there to meet with peers and friends.
3 technical talks, a cool challenge & our famous Car in a Box to play with.
Come and say hi at booth 20.
Full program here:
lehack.org
26.06.2025 12:36 β π 1 π 0 π¬ 0 π 0
A Go gopher surfing over a Wireshark shark
Are you a network protocol reverse engineer? Tired of writing Wireshark plugins in memory unsafe or esoteric languages named after celestial objects?
Now you can do it in a few lines of Go, Python or Rust with Wirego.
Benoit Girard explains how here:
blog.quarkslab.com/getting-star...
10.06.2025 16:28 β π 2 π 3 π¬ 1 π 0
Attention β¨WomenAtSSTICβ¨
We meet at 18:00 today at L'Equinoxe:
3 Place des Lices, 35000 Rennes
See you there!
#sstic2025
04.06.2025 12:07 β π 0 π 0 π¬ 0 π 0
Sondage - Women@sstic 2025 - Framadate
Framadate est un service en ligne permettant de planifier un rendez-vous ou prendre des dΓ©cisions rapidement et simplement.
Are you a cyber professional, or a future one, coming to #sstic2025 next week?
Come to β¨WomenATssticβ¨, an informal and unofficial friendly meetup on Wednesday, June 4th at 6 pm.
We will reserve a bar/cafΓ© near the Halle Martenot. Register here:
framadate.org/hH2t9FcRtgEG...
30.05.2025 15:01 β π 4 π 4 π¬ 0 π 1
Good morning Singapore!
The amazing Off by One Conference 2025 starts today.
If you are attending don't miss Fred Raynal's (our fearless CEO) keynote at 9:35am:
"Spyware for rent & the world of offensive cyber"
The full agenda is available here:
offbyone.sg/agenda
07.05.2025 23:57 β π 0 π 0 π¬ 0 π 0
Julio Loayza Meneses talking about Crypto Condor at RWC2005 Paris
The top bird of crypto implemetation testing
Quarkslab was glad to sponsor the Real World Cryptography Paris Meetup 4 hosted by @Ledger last night.
Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations.
You can learn more about it here:
quarkslab.github.io/crypto-condo...
30.04.2025 15:32 β π 2 π 0 π¬ 0 π 0
Proxybloby, the read teamer's mascot that will byte your SOCKS if left alone in your internal network
Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS?
It's ProxyBlob, a reverse proxy over Azure.
Check out Alexandre Nesic's article on how it came to exist after an assumed breach mission ‡οΈ
π blog.quarkslab.com/proxyblobing...
29.04.2025 17:32 β π 1 π 1 π¬ 0 π 1