quarkslab

1.7K posts

quarkslab banner
quarkslab

quarkslab

@quarkslab

Securing every bit of your data https://t.co/hqdd8jMkYM https://t.co/GOXPtukIXE

Paris, France Katılım Ekim 2011
13 Takip Edilen12.2K Takipçiler
quarkslab
quarkslab@quarkslab·
"How does it even work?" The question that keeps hackers' hearts pumping, blood pressure rising, and curiosity growing. This is @virtualabs's reverse engineering journey into a cheap smartwatch that measures at least one of those. blog.quarkslab.com/nerd-life-week…
quarkslab tweet media
English
0
14
44
2.8K
quarkslab retweetledi
Pass the SALT Conference
Pass the SALT Conference@passthesaltcon·
SPONSOR 📣 Today, we are very happy to announce the @quarkslab Gold level sponsoring 😍 📄 @quarkslab provides to companies Security Audit capabilities, Consulting expertise powered by its cutting edge R&D and Qshield, its comprehensive security suite 1/2
Pass the SALT Conference tweet media
English
1
1
6
709
quarkslab retweetledi
Gyorgy Miru (Gym)
Gyorgy Miru (Gym)@gymiru·
@quarkslab @kaluche_ We were not careful enough and run into that NDA when reporting Avast bugs. To their credit Gendigital ended up being absolutely reasonable about it and greenlit the full disclosure. The truly shameful part is Bugcrowd default policy with the NDA. Very hostile.
English
0
1
7
1.6K
quarkslab retweetledi
Ryan Naraine
Ryan Naraine@ryanaraine·
🤯 Quarkslab spent five months trying to report vulns to security vendor Avira/Gen Digital but hit a deadlock because Gen Digital would only accept reports through their bug bounty platform (which required an NDA), so Quarkslab eventually just emailed the report and published after 90 days. This timeline explains the madness blog.quarkslab.com/avira-deserial…
English
1
38
162
31.3K
quarkslab
quarkslab@quarkslab·
If you glitch one, can you glitch many? Extracting automotive firmware is a challenge. @Phil_BARR3TT explains how he bypassed the IDCODE protection in several variants of the RH850 MCU family using both voltage glitching and side-channel analysis ⚡️🚗 blog.quarkslab.com/bypassing-debu…
quarkslab tweet media
English
5
15
52
5.1K
quarkslab
quarkslab@quarkslab·
Reverse engineers often spend a lot of time deciphering third-party firmware libraries. At RE//verse 2026 (Fri, 5 PM), Benoit & Sami will introduce SightHouse, an open-source tool to automatically identify third-party functions and speed up analysis. Join us!
quarkslab tweet media
English
1
24
176
8.9K
quarkslab
quarkslab@quarkslab·
Another antivirus 🛡️, another unfulfilled promise 😣. @kaluche_ turns Avira's protection into a privilege escalation playground. 3 LPE vectors via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749). Find out more: blog.quarkslab.com/avira-deserial…
quarkslab tweet media
English
3
38
131
9.7K
quarkslab
quarkslab@quarkslab·
Why macOS AVs shouldn’t trust PIDs 😄🍏 - new post by @Coiffeur0x90 Intego X9: XPC validation falls back to PID → PID reuse + posix_spawn() shenanigans 😏 ⇒ confused deputy / privileged methods abused 🤡🧨 Lesson: PID ≠ identity. blog.quarkslab.com/intego_lpe_mac…
quarkslab tweet media
English
1
13
54
4.4K
quarkslab
quarkslab@quarkslab·
You've never been more right to doubt your MacOS antivirus software 😥 Our latest research by @Coiffeur0x90 shows how Intego can be abused for Local Privilege Escalation Yes, the antivirus. Yes, as root. blog.quarkslab.com/intego_lpe_mac…
quarkslab tweet media
English
0
19
80
9.5K
quarkslab
quarkslab@quarkslab·
"Use a better system prompt" is the new "sanitize your inputs", but when your #AI agent's tools don't check permissions, you've got a problem and no amount of prompting will fix it. Check @kaluche_ 's post about #AgenticAI & the Confused Deputy issue ⬇️ blog.quarkslab.com/agentic-ai-the…
quarkslab tweet media
English
0
11
28
2.3K
quarkslab
quarkslab@quarkslab·
We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide. The audit was mandated by @OSTIFofficial 🙏 blog.quarkslab.com/everest-securi…
quarkslab tweet media
English
0
5
20
2.5K
quarkslab
quarkslab@quarkslab·
Quarkslab is sponsoring @GrehackConf 2025! @rayanlecat is proposing an Active Directory Pwning workshop and our team #qsec will also be there for the CTF. Come & say hi!
English
0
2
14
2.4K
quarkslab retweetledi
GreHack
GreHack@GrehackConf·
🔥 Another returning sponsor for this year’s edition, @quarkslab ! Their team combines deep expertise in software security, cryptography and automotive systems to build tools and solutions that strengthen cybersecurity worldwide. 🧠🔐 🤝We thank them for their support!
GreHack tweet media
English
1
1
6
1.5K