Major_Tom

1.8K posts

Major_Tom banner
Major_Tom

Major_Tom

@MajorTomSec

Underground control to Major_Tom. Security ninja @Synacktiv CTF Player @SentryWhale

Lille, France Katılım Nisan 2013
384 Takip Edilen3.1K Takipçiler
Major_Tom
Major_Tom@MajorTomSec·
Proud to finally share the write-up of our VMware Workstation escape from P2O Berlin 2025, featuring a generic bypass for Windows LFH mitigations using side-channels. I hope it will be as fun to read as it was to exploit! x.com/Synacktiv/stat…
Synacktiv@Synacktiv

At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…

English
1
28
191
17.6K
Major_Tom retweetledi
Synacktiv
Synacktiv@Synacktiv·
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…
English
4
153
533
48.1K
Major_Tom retweetledi
TrendAI Zero Day Initiative
Confirmed! Thomas Bouzerar (@MajorTomSec) and Etienne Helluy-Lafont from Synacktiv (@Synacktiv) used a heap-based buffer overflow to exploit #VMware Workstation. They earn $80,000 and 8 Master of Pwn points - sending the contest to over $1,000,000 total! #Pwn2Own
TrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet media
English
1
21
128
13.2K
Major_Tom retweetledi
TrendAI Zero Day Initiative
Boom! Thomas Bouzerar (@MajorTomSec) and Etienne Helluy-Lafont from Synacktiv (@Synacktiv) close out #Pwn2Own in style with a guest-to-host escape in VMware Workstation. If confirmed, it will put the total contest payout at over $1,000,000! #Pwn2Own
TrendAI Zero Day Initiative tweet media
English
1
28
210
15.9K
Major_Tom retweetledi
TrendAI Zero Day Initiative
A successful collision! Corentin BAYET (@OnlyTheDuck) from @Reverse_Tactics used 2 bugs to exploit ESXi, but the Use of Uninitialized Variable bug collided with a prior entry. His integer overflow was unique though, so he still earns $112,500 & 11.5 Master of Pwn points. #Pwn2Own
TrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet media
English
1
6
63
7K
Major_Tom retweetledi
Synacktiv
Synacktiv@Synacktiv·
In iOS 18.4, Apple introduced a bug in dynamic symbol resolutions for some specific exports. @0xf4b took a long journey down a rabbit hole to understand its root cause. synacktiv.com/en/publication…
English
2
61
160
20.5K
Major_Tom retweetledi
Specter
Specter@SpecterDev·
I've published the repo for Byepervisor (we love named vulns out here). Contains exploit implementation for two PS5 hypervisor bugs for 2.xx and lower. Slides from the talk + vod should hopefully be published soon. github.com/PS5Dev/Byeperv…
English
42
119
652
98.6K
Major_Tom retweetledi
Specter
Specter@SpecterDev·
Feels great when an idea can finally be tested and works out after like a year :) Shouts to ChendoChap for working out the ROP chain. Protip: staying < 3.00 is a good idea.
Specter tweet media
English
50
90
771
124.6K
Major_Tom retweetledi
Synacktiv
Synacktiv@Synacktiv·
Here we are! 🥷 Masters of pwn for the third time 🎉 Congratulations to all the ninjas involved! #Pwn2Own
Synacktiv tweet mediaSynacktiv tweet media
English
19
46
330
24.4K
Major_Tom retweetledi
Synacktiv
Synacktiv@Synacktiv·
The program for @GrehackConf is out with 3 Synacktiv talks! 🖥️ Virtualization from an attacker Point-Of-View: @OnlyTheDuck & @MajorTomSec 🚘 Unlocking the Drive: Exploiting Tesla Model 3: @_p0ly_ & @vdehors 🐧 Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt: @jbcayrou
GreHack@GrehackConf

Hey folks! We're excited to present the #GreHack23 program. You can now consult it on our website: grehack.fr/program The first batch of tickets (including workshop & CTF) will be available on October 1, 2023 at 10:00am (UTC+2).

English
0
13
24
6.5K
Major_Tom retweetledi
Thiebaut Elsa
Thiebaut Elsa@thiebaut_elsa·
As announced at #FIC, @Synacktiv is opening a new office in the center of #lille with a team of 7 ninjas. All our positions are now open in Lille 📍7 Boulevard Louix XIV. If you want to join us : apply@synacktiv.com
Thiebaut Elsa tweet media
English
0
6
27
2.2K
Major_Tom retweetledi
p0up0u
p0up0u@_p0up0u_·
kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices: github.com/felix-pb/kfd
English
31
116
432
182.9K
Major_Tom retweetledi
Hexacon
Hexacon@hexacon_fr·
📦 Breaking Out of the Box: Technical analysis of VirtualBox VM escape with Windows LPE, by Thomas Bouzerar (@MajorTomSec) and Thomas Imbert (@masthoon)
Hexacon tweet media
English
1
9
44
11K
Major_Tom retweetledi
Hexacon
Hexacon@hexacon_fr·
🔪💻 Finding and exploiting an old XNU logic bug, by Eloi Benoist-Vanderbeken (@elvanderb)
Hexacon tweet media
Nederlands
0
5
33
9.9K
Major_Tom retweetledi
CTurt
CTurt@CTurtE·
Part 2 - Attacking the compiler process: cturt.github.io/mast1c0re-2.ht… Ultimately I didn't finish the exploit, but hopefully it's still interesting, and maybe we will see a full exploit implementation from someone else in the future.
English
39
90
365
64.8K