voydstack

691 posts

voydstack banner
voydstack

voydstack

@voydstack

VR @Synacktiv | CTF with @RMUBYGG, @Hexagonctf, @ECSC_TeamFrance 20/21/22/23/24

France Katılım Ağustos 2018
991 Takip Edilen2K Takipçiler
voydstack retweetledi
Synacktiv
Synacktiv@Synacktiv·
Make it blink! This new article unpacks how Mehdi and Matthieu achieved an over-the-air exploitation of the #PhilipsHue Bridge via a #Zigbee bug. Read all about the technical details, how they proved it is exploitable at #Pwn2Own Cork 2025, and the underlying vulnerability here 👇 synacktiv.com/en/publication…
English
0
18
78
6.1K
voydstack retweetledi
Synacktiv
Synacktiv@Synacktiv·
This second blogpost concludes @yaumn_'s research on #Windows authentication reflection. He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥 A little bonus is even included at the end 👀👇 synacktiv.com/en/publication…
English
2
57
126
11K
voydstack retweetledi
Synacktiv
Synacktiv@Synacktiv·
Authentication reflection attacks are still not dead! In our new blogpost series, @yaumn_ shares his journey into bypassing the mitigations of CVE-2025-33073 to pop SYSTEM shells again🚀 👇 synacktiv.com/en/publication…
English
2
55
153
15K
voydstack retweetledi
Hexacon
Hexacon@hexacon_fr·
The training lineup for Hexacon 2026 is now available on our website 🧑🏼‍🏫 Training tickets sales will officially launch in mid-May 🎫 hexacon.fr/trainings/
English
1
12
27
15.7K
voydstack retweetledi
Guillaume André
Guillaume André@yaumn_·
So glad to finally be able to present this research at @BlackHatEvents Asia! Blogposts are coming soon, on the menu: LPE via local NTLM reflection and RCE via a new arbitrary Kerberos authentication coercion technique 👀
Synacktiv@Synacktiv

Tomorrow, @yaumn_ will be presenting his research on Windows authentication reflection at @BlackHatEvents Asia 2026 in Singapore! The talk will be at 15:20 local time in Simpor Junior Ballroom 4810, come say hi! 😄 #BHASIA ℹ️ #the-gift-that-keeps-on-giving-bypassing-authentication-reflection-mitigations-for-system-shells-51084" target="_blank" rel="nofollow noopener">blackhat.com/asia-26/briefi…

English
0
11
44
3.4K
voydstack retweetledi
xarkes
xarkes@xarkes_·
Mozilla says Mythos helped identify 271 vulnerabilities in Firefox 150. I went through the commits, CVEs, and bug links to see what that number really means. My takeaway: relax folks. xark.es/b/mythos-firef…
English
10
119
753
117.5K
voydstack retweetledi
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
The #FCSC2026 ended today, and my write-ups are now available here: mizu.re/post/fcsc-2026… 🚩 I'm really happy with the challenges I managed to create this year! It would be too long to list everything, so here's a little teaser 👇 1/2
Kévin GERVOT (Mizu) tweet media
Kévin GERVOT (Mizu)@kevin_mizu

This year again, with @BitK_ and @_Worty, we've made the Web challenges 🚩 The CTF is solo and lasts 10 days, if you have some time, please give it a look 😁 Even if you're not doing Web challenges, there are challenges in various categories, you should find something you like!

English
3
20
78
7.4K
voydstack retweetledi
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
This year again, with @BitK_ and @_Worty, we've made the Web challenges 🚩 The CTF is solo and lasts 10 days, if you have some time, please give it a look 😁 Even if you're not doing Web challenges, there are challenges in various categories, you should find something you like!
Kévin GERVOT (Mizu) tweet media
English
4
18
142
24.4K
voydstack
voydstack@voydstack·
#FCSC 2026 started yesterday ! So grateful to be part of the challenge authors this year ! Wrote 3 pwn challenges : "Boring", "Not So Boring" (still unsolved) and "wsd". Come check them out alongside many other quality challenges😄🚩
ANSSI@ANSSI_FR

#FCSC | 🦖 « Rex ne veut pas qu’on le nourrisse, il veut chasser ». 🚩 La chasse aux drapeaux commence aujourd'hui avec le retour du France Cybersecurity Challenge jusqu'au 12 avril ! 🔔 Rendez-vous dès 14h : fcsc.fr

English
0
0
2
434
voydstack retweetledi
Worty
Worty@_Worty·
For this year’s FCSC, I’m proud to have had the opportunity to develop four web challenges: - Shellfish Say - FCSC Aquarium - Secure Mood Notes (Part 1 & 2) There are many more challenges available (created by @kevin_mizu and @BitK_), so don’t hesitate to give them a try! :)
Worty tweet media
English
1
5
46
5.1K
voydstack retweetledi
Seth Jenkins
Seth Jenkins@__sethJenkins·
Just derestricted a now-fixed kernel bug in Pixel 10. I think this ranks as the most easily exploited kernel bug of all time😬 Thanks to @tehjh for collab'ing on this driver and full credits for noticing this bug in the first 5 minutes of auditing😂 project-zero.issues.chromium.org/issues/4634382…
English
5
46
189
17.2K
kiddo
kiddo@kiddo_pwn·
@voydstack @freddo_1337 it was nice to meeting you! synacktiv entries seemed like different level 🤯
English
1
0
2
120
kiddo
kiddo@kiddo_pwn·
After a long rest, I’m happy to share Team DDOS (or known as KIMCHI and YOGURT 😅) got 2nd place !! My first appreciation goes to my best teammate, @freddo_1337. And congrats to all the teams - there's no doubt how much effort we all put into this! Lastly, thanks to all friends I met and chatted with there, including ZDI and researchers! Wishing you all the best after the competition 💙
TrendAI Zero Day Initiative@thezdi

$1,047,000 USD - 76 unique 0-day vulnerabilities - three days of incredible research on display. #Pwn2Own Automotive 2026 had it all: bold exploits, clever techniques, and collisions. Congrats to Fuzzware.io (@ScepticCtf, @diff_fusion, @SeTcbPrivilege), Master of Pwn with $215,500 and 28 points! #P2OAuto

English
4
2
68
7.5K
voydstack retweetledi
Major_Tom
Major_Tom@MajorTomSec·
Proud to finally share the write-up of our VMware Workstation escape from P2O Berlin 2025, featuring a generic bypass for Windows LFH mitigations using side-channels. I hope it will be as fun to read as it was to exploit! x.com/Synacktiv/stat…
Synacktiv@Synacktiv

At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…

English
1
28
190
17.8K
voydstack retweetledi
Synacktiv
Synacktiv@Synacktiv·
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…
English
4
151
534
49.4K
voydstack retweetledi
Synacktiv
Synacktiv@Synacktiv·
On the podium at #Pwn2Own Automotive 2026 🥉 Synacktiv ranked 3rd in Tokyo 🇯🇵 after successful attacks on #Tesla Infotainment (USB), #Sony XAV-9500ES (USB) and #Autel MaxiCharger (NFC). 📍Next stop: Berlin!
Synacktiv tweet mediaSynacktiv tweet media
English
0
4
68
5K