Boom! Thomas Bouzerar (@MajorTomSec) and Etienne Helluy-Lafont from Synacktiv (@Synacktiv) close out #Pwn2Own in style with a guest-to-host escape in VMware Workstation. If confirmed, it will put the total contest payout at over $1,000,000! #Pwn2Own
During last week, I've played FCSC2025 and managed to reach first place in the web category !
I've written two writeups this year: one about pwning a Chrome extension, and another about a PostgREST service.
worty.fr/post/writeups/…worty.fr/post/writeups/…
Enjoy the read !
Bravo à l'équipe des esnarcotrafiquants, grands gagnants de cette édition 2025 de l'European Cyber Cup ! 🏆 🔥
Il y a comme un air de déjà vu, n'est-ce pas @EsnaBretagne... ?
#EC22025#europeancybercup
🔥Introducing Arion🔥
A high-performance C++ framework for emulating executable binaries.
Based on Unicorn and inspired by Qiling, Arion offers an easy-to-use interface and super low execution times making it a great ally for fuzzing or other applications.
github.com/h311d1n3r/Arion
With @Geluchat, we created a challenge for the @pwnmectf inspired by a bug he found in bug bounty a year ago! 🚀
If you have some time this weekend, give it a try! 👀
👉 pwnme.phreaks.fr
With @Geluchat, we created a challenge for the @pwnmectf inspired by a bug he found in bug bounty a year ago! 🚀
If you have some time this weekend, give it a try! 👀
👉 pwnme.phreaks.fr https://t.co/Zc19b4oGUx
Hey Folks ! 🏔️
Here is writeups for all my challenges of @GrehackConf CTF
- nishacid.guru/tags/grehack24/
It was great fun to create them all, thanks to all the participants and we hope you enjoy them.
I'm looking for feedback and don't hesitate to DM me if you have any questions 💚
I recently reported an RCE to Happy-DOM (a Node.js HTML parser), and it’s now fixed!
The bug itself wasn't complex, but since finding an RCE in an HTML parser isn’t very common, I'm quite happy with this one :D
github.com/capricorn86/ha…
[📍 CHANGEMENT D'ADRESSE 📍]
Ce samedi, retrouvez-nous au 6 rue Maryse Bastié, à Bruz, sur le Campus de Ker Lann.
Le bâtiment est situé à quelques mètres de l'ancien.
Restez à l'affût, nous vous communiquerons dans la foulée les talks ainsi que la liste de nos sponsors. 👀
SAVE THE DATE: Samedi 12 octobre 2024 - 9h30 à 23h
SteakOverflow revient à Rennes avec son mix de hacking, de bonne nourriture, et de bières 🍻 !
Conférences et rumps au programme 🏴☠.
📍 Campus Ker Lann
📩 On cherche des speakers : esnhack.fr/call-for-papers
Critical XSS in Roundcube webmail⚠
A victim only has to view a malicious email. As reported by @ESETresearch, APTs have exploited similar vulns in the past to steal government emails.
Our announcement:
sonarsource.com/blog/governmen…
(CVE-2024-42008, CVE-2024-42009, CVE-2024-42010)
DOMLogger++ v1.0.5 is now out and available! It comes with new features, including the ability to remove response headers, a PwnFox integration, and much more 🔥
A new config file is also available for CSPT hunting 👀
More details can be found here 👇
github.com/kevin-mizu/dom…
Hello Cybersec community !
It's time to update your SuiteCRM :D I've found 9-10 vulnerabilities, most of them Critical/High that impact all versions <7.4.14 and <8.6.1 !
That's at least 9 additionnal CVEs for my Resume 👀
github.com/salesagility/S…
Tired of writing bug bounty reports? Take a look at what @xanhacks has done, a list of report templates (EN/FR). It's a real time-saver on a daily basis 😄
gitlab.com/xanhacks/web-p…
👋 I've created my first medium/hard pwn challenge for @flag4jobs.
It's a whitebox HTTP server built in C. To get a shell, you'll need to find and exploit several vulnerabilities.
Feel free to check it out! The first blood has not been taken yet🩸
Hackyx now has a new UI and was rewritten using NextJS. In the next version, it will be easier to add new content to be indexed, so stay tuned!
( There is also a dark mode 👀 )
hackyx.io
DOMLogger++ v1.0.4 is now out and available in stores! It comes with new features that allow you, for example, to easily dig into DOM gadget occurrences after an innerHTML sink 🔥
More details can be found here 👇
github.com/kevin-mizu/dom…
1/3
655 Followers 3K FollowingGNU/Linux sysadmin with a taste for devops, cybersecurity, and programming.
I tweet about my work, open source, cryptography, privacy, freedom, and jiat0218.
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
10K Followers 6 FollowingBringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM
9K Followers 1K Following📍 @yeswehack (aka Hisxo) - I love to break things (and I'm paid for that) - Bug Hunter
🔗 Check my Github repository https://t.co/Sj3prhiZyu
#BugBounty
18K Followers 222 FollowingAnda boleh melakukan segala-galanya dari syurga ke bumi, wanita kecil!!
If you have any questions, please contact me
https://t.co/MkzsavUU9V
2K Followers 223 FollowingFull-time security researcher and bug bounty hunter |
CTF player @KalmarunionenDM |
Researcher for @ctbbpodcast lab |
Opinions are mine and mine only
22K Followers 0 FollowingAI-Powered Penetration Testing Assistant for offensive security testing, focused on web applications and network penetration testing.
2K Followers 774 FollowingEuropean Cyber Cup 🏆 | 1ère compétition d'eSport dédiée au hacking éthique, pendant le Forum International de la Cybersécurité @FIC_eu. | 📅 27 & 28 mars 2024
5K Followers 315 FollowingSecurity but not as in "national security". Playing CTFs with @redrocket_ctf (and @Sauercl0ud). Pwn2Own Vancouver 2020..=2024\{2023}. @[email protected]
11K Followers 7 FollowingCutting-edge security research by @SonarSource to educate the world about code security across all software.
We're also at @[email protected] 🦣