Mathieu Tarral

2.9K posts

Mathieu Tarral banner
Mathieu Tarral

Mathieu Tarral

@mtarral

Security Research @intel · kAFL : HW assisted feedback fuzzer for x86 VMs · tsffs : Coverage guided fuzzer built on SIMICS · OSWatcher: Git for OS

Paris Katılım Ekim 2010
1.3K Takip Edilen1.9K Takipçiler
Sabitlenmiş Tweet
Mathieu Tarral
Mathieu Tarral@mtarral·
🚀 OSWatcher 0.5 Structs and Symbols are here for Windows ! - ntoskrnl.exe - kernel32.dll - ntdll.dll Diff them at OS or patch level granularity 👏 Note: Other plugins access are available by invite. ➡️oswatcher.github.io/frontend/
English
2
9
34
3K
Mathieu Tarral retweetledi
Alex Matrosov
Alex Matrosov@matrosov·
How one git push --force compromised thousands of CI pipelines (Trivy attack): ⓵ Steal a maintainer's PAT ⓶ git tag -f v0.34.2 && git push -f origin v0.34.2 ⓷ Every workflow using v0.34.2 now runs your code ⓸ Dump /proc/*/mem of the Runner.Worker process ⓹ Grep for "isSecret":true and harvest every secret No branch protection fires. No review required. No status check runs. Tags are unprotected by default. GitHub has tag rulesets but almost nobody enables them.
solst/ICE of Astarte@IceSolst

List of resources on the Trivy supply chain compromise

English
3
11
44
9.3K
Mathieu Tarral retweetledi
Halvar Flake
Halvar Flake@halvarflake·
My friends at @zymtrace are looking for Rust engineers 🦀 They're building the platform that makes GPUs go brr — fully remote, early stage, real impact DM me for an intro, or email team@zymtrace.com I can vouch that the team is top notch.
English
10
27
112
9K
Mathieu Tarral retweetledi
Origin
Origin@originhq·
Windows Insider builds now have a native, OS-level broker for MCP servers. We reverse engineered Odr.exe to understand how it validates clients, manages consent, and controls access - uncovering undocumented COM interfaces and a full ETW audit trail. originhq.com/blog/msft-odr-…
English
2
25
58
5.3K
Mathieu Tarral retweetledi
Joe Kent
Joe Kent@joekent16jan19·
After much reflection, I have decided to resign from my position as Director of the National Counterterrorism Center, effective today. I cannot in good conscience support the ongoing war in Iran. Iran posed no imminent threat to our nation, and it is clear that we started this war due to pressure from Israel and its powerful American lobby. It has been an honor serving under @POTUS and @DNIGabbard and leading the professionals at NCTC. May God bless America.
Joe Kent tweet media
English
72.9K
219.9K
847.8K
100M
Mathieu Tarral retweetledi
Arthur Mensch
Arthur Mensch@arthurmensch·
Looking forward to building frontier open source AI models together with @Nvidia as we join the Nemotron Coalition and start training the first base models.
Arthur Mensch tweet media
English
48
149
1.5K
142.4K
Mathieu Tarral retweetledi
Current Report
Current Report@Currentreport1·
BREAKING: France has officially rejected Trump's request, saying it will not send warships to the Strait of Hormuz
Current Report tweet mediaCurrent Report tweet media
English
3.2K
13.3K
77.4K
6.1M
Mathieu Tarral retweetledi
Hadas Weiss
Hadas Weiss@weiss_hadas·
europeans when asked to help unblock the strait of hormuz
English
626
6.2K
48K
2.2M
Mathieu Tarral retweetledi
Chris Murphy 🟧
Chris Murphy 🟧@ChrisMurphyCT·
It’s crystal clear now that Trump has lost control of this war. He badly misjudged Iran’s ability to retaliate. The region is on fire. 1/ I’m going to explain to you in this🧵what I’ve learned - in part from closed door briefings - about the four biggest current crises.
English
4.3K
10.1K
41.4K
5.5M
Mathieu Tarral retweetledi
𝐑.𝐎.𝐊 👑
𝐑.𝐎.𝐊 👑@r0ktech·
5pm: “Claude usage limit reached. Your limit will reset at 7pm..” Me from 5pm to 6:59pm:
English
106
1.1K
13.8K
402.5K
Mathieu Tarral
Mathieu Tarral@mtarral·
Next features in mind: - MCP Server - Git log <struct/field>: track how stable a structure is across 28 years of Windows - Binary hardening timeline with checksec analysis Happy to hear your ideas ! 💡
English
0
2
2
339
Mathieu Tarral
Mathieu Tarral@mtarral·
🚀 OSWatcher 0.5 Structs and Symbols are here for Windows ! - ntoskrnl.exe - kernel32.dll - ntdll.dll Diff them at OS or patch level granularity 👏 Note: Other plugins access are available by invite. ➡️oswatcher.github.io/frontend/
English
2
9
34
3K
faulty *ptrrr
faulty *ptrrr@0x_shaq·
I didn’t know there are python packages specifically for pretty-printing things like that. I literally wrote that progress bar in 5 minutes last night
English
2
0
24
3.8K
Mathieu Tarral retweetledi
Mathieu Tarral retweetledi
BlueHat IL
BlueHat IL@BlueHatIL·
Due to the current situation, we’ve decided to postpone BlueHat IL 2026. We’ll share a new date when possible. Until then - take care and stay safe 💙
English
0
7
43
5.9K
Mathieu Tarral retweetledi
Joan Larroumec
Joan Larroumec@larroumecj·
Nouvel enrichissement du tableau de bord de la France avec ce qu'on m'a le plus réclamé : une projection de notre système de retraites selon différents scénarios, et la capacité de faire varier soi-même les paramètres. Les conclusions me semblent évidentes : - le système actuel ne tiendra pas une génération de plus. Avant 2050, à ce rythme, nous n'aurons plus les moyens de financer ne serait-ce que le régalien et les services publics. - même les scénarios très optimistes du COR sont des scénarios de crise chronique. - même une réforme ambitieuse des retraites, bien qu'indispensable, n'est pas suffisante. - il faut une réforme complète de notre économie et renouer durablement avec la croissance. Sinon, nous aurons une crise financière majeure à la grecque, et une dégradation durable de notre niveau de vie et de notre capacité à maîtriser notre destin. - alors que la troisième révolution industrielle est là et nécessite des investissements massifs, retrouver nos marges de manœuvre financières devrait être notre priorité absolue. Vous pouvez jouer avec le modèle et même partager vos scénarios ici : #retraites" target="_blank" rel="nofollow noopener">francetdb.com/#retraites Comme d'habitude, si vous voyez des erreurs, faîtes le moi savoir, je corrigerai aussi vite que possible.
Joan Larroumec tweet mediaJoan Larroumec tweet media
Français
50
218
764
79.7K
Mathieu Tarral retweetledi
abdel
abdel@AbdelStark·
Is France the first country in the world to actually ship a fully functional MCP (and OPEN SOURCE!!!) for a governemental service or am I tripping ? France trailblazing governmental agentic transition was not on my bingo card. Champion mon frère 🇫🇷🥖
abdel@AbdelStark

Official MCP server for the data(.)gouv(.)fr French governmental platform. Honestly I am genuinely surprised. Usually French is pretty slow (despite having some of the best talents in tech, math, AI etc) to adopt innovations especially for governmental services. I tried the MCP, works flawlessly and can be very useful. I think the repo can be more agentic native / friendly but it's a very nice initiative, love it! Franchement bravo

English
19
31
451
66.8K
Mathieu Tarral retweetledi
Natalie Silvanovich
Natalie Silvanovich@natashenka·
In the final part of his blog series, @tiraniddo tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphfh-…
English
0
54
190
20.3K
Mathieu Tarral retweetledi
Sydney Jones 🇬🇧 (POB)
Sydney Jones 🇬🇧 (POB)@JournoJones05·
“Police vehicles were used to traffic her and some of the abuse events were called ‘cop nights.'” “torture included waterboarding and strangulation by rope.” “raped by a dog, filmed, and forced to rewatch the footage as the men placed bets.” “she witnessed the murder of at least three girls, one of whom was allegedly killed as a punishment for speaking to the police force.” You aren’t angry enough.
Rupert Lowe MP@RupertLowe10

A statement from the Rape Gang Inquiry.

English
301
5.4K
22K
483.1K