🚨 The #Entrypoint2027 Call For Papers is now open! Have original offensive security research to share? New techniques, tools, or attack stories ? We want to hear from you. 📅 CFP closes: Sept 20, 2026. Our review board will be revealed soon. 👉 cfp.entrypoint.fr/entrypoint-2...
voydstack
@voydstack.re
VR @ Synacktiv, low level security enthusiast https://voydstack.re/
We've been working on something for a while. The talks your blue team doesn't want you to see. 🔴 Red Teaming. Initial Access. AD. Cloud & Web exploitation. 📍 Paris - Le Dernier Étage 📅 March 19–20, 2027 entrypoint.fr CFP and additional details coming soon.
Just ranked 2nd in SSTIC 2026 security challenge! 🏆️ www.sstic.org/2026/challen... My write-up is now live 📝 github.com/fishilico/ss...
Offensivecon's talks are now available on our YouTube channel! 🔗 buff.ly/g63xgm5
OffensiveCon26
OffensiveCon 2026 Talks
youtube.com
📣 Prochain Bière&Sécu Toulouse le mardi 17 Mars ! 🗓️ RDV au Rooster and Beer à partir de 18h30 👉 beta.framadate.org/polls/b12ed9... (merci d'indiquer votre présence, c'est pour la résa du bar) 🗣️ Contactez-nous si vous avez des sujets à présenter via Twitter, Bluesky ou Discord !
Bière&Sécu – Framadate BETA
beta.framadate.org
🎄 New Root-Xmas Challenge 🎄 ✨ Today, prove Santa his Christmas Gift Packager system is not that secure... 📌 Submitted by: @voydstack.re 🔗 Details & participation here: ctf.xmas.root-me.org Good luck to you all! 🎅
🎄 New Root-Xmas Challenge 🎄 ✨ Today, wish for anything you want... just make sure it’s properly formatted! 📌 Submitted by : @voydstack.re 🔗 Details & participation here: ctf.xmas.root-me.org Good luck to you all! 🎅
📣 Prochain Bière&Sécu Toulouse le mardi 2 décembre ! 🗓️ RDV au Rooster and Beer à partir de 18h30 👉 Framadate: beta.framadate.org/polls/606039... 🗣️ Contactez-nous si vous avez des sujets à présenter via Twitter, Bluesky ou Discord !
Bière&Sécu Toulouse – Framadate BETA
beta.framadate.org
Level up your pentesting skills in 2026 🚀 Join Synacktiv’s hands-on trainings: from Kubernetes & cloud hacks to web app attacks & AD intrusion. More information & registration : www.synacktiv.com/en/offers/tr...
Les formations
Synacktiv
synacktiv.com
Following their presentation at @hexacon.bsky.social, @mtalbi.bsky.social & Etienne detail how they exploited CVE-2023-40129, a critical vulnerability affecting the Bluetooth stack in Android ⬇️ www.synacktiv.com/en/publicati...
Paint it blue: Attacking the bluetooth stack
Paint it blue: Attacking the bluetooth stack
synacktiv.com
$1,024,750 - 73 unique bugs - a week of amazing research on display. #Pwn2Own Ireland had it all. Success. Failure. Intrigue. You name it. Congratulations to the Master of Pwn winners @SummoningTeam! Their outstanding work earned them $187,500 and 22 point. See you in Tokyo for Pwn2Own Automotive.
🎉 Big win at #Pwn2Own Cork! @pol-y.bsky.social of #Synacktiv successfully breached the @Ubiquiti AI Pro surveillance system 🦈🎶 What a way to wrap up the challenge - congrats, @pol-y.bsky.social 💪
🎥 Eyes wide shut! David Berard of @synacktiv.com just breached the @Ubiquiti AI Pro surveillance system at #Pwn2Own. He also serenaded us with round of "Baby Shark" played through the speaker. He's off to the disclosure room with an ear worm and the details.
Impressive work from our team today at #Pwn2Own! @mtalbi.bsky.social and Matthieu just pulled off an exploit on the Philips Hue Bridge without laying a finger on the device! Great demonstration of Synacktiv’s offensive expertise 👏 Come on 🔥
Congrats to tek and anyfun for landing the first successful entry at #Pwn2OwnCork - exploiting a stack overflow on Synology BeeStation Plus for $40,000 and 4 Master of Pwn points in the process 💥 Let’s keep pushing 💪 #P2OIreland #Synacktiv
A technical look at @grapheneos.org Hardened Malloc, a memory allocator designed to mitigate heap corruption vulnerabilities (UAF, overflows) and break common exploit primitives. Deep dive for security researchers & exploit developers by @nicoski.bsky.social www.synacktiv.com/en/publicati...
Exploring GrapheneOS secure allocator: Hardened Malloc
Exploring GrapheneOS secure allocator: Hardened Malloc
synacktiv.com
🚨 Time to reveal our first-class lineup for HEXACON 2025! ✨ A few training spots are still available if you want to join the party! 🎉 Unfortunately, trainings + conference packs are sold out www.hexacon.fr/conference/s...
Hexacon - Conference – Speakers
Discover the accepted talks for this edition!
hexacon.fr
Want to learn reverse engineering? There'll be a free, women*-only BlackHoodie workshop from October 6th to 9th in Paris! Topics: • Linux memory forensics 🕵️♀️ (by Sonia) • Web app and mobile app pentesting 🕸️📱 (by Paula) • iOS reversing 🍎 (by me)
We've just released a tool to decrypt all Synology encrypted archives! We used it to compare SynologyPhotos versions and highlight our #Pwn2Own Ireland 2024 vulnerability on the BeeStation BST150-4T. Check out our blog post for more details. www.synacktiv.com/en/publicati...
Extraction of Synology encrypted archives - Pwn2Own Ireland 2024
Context During Pwn2Own Ireland 2024 we targeted the BeeStation BST150-4T a NAS from Synology.
synacktiv.com
We’re thrilled to welcoming back @interruptlabs.bsky.social as an official sponsor of Hexacon! Interrupt Labs works at the cutting edge of vulnerability research and exploit development and it’s always pleasure having the team on board! 🤗
#ECSC2025 | 🐓 Découvrez la #TeamFrance 2025 ! 🇫🇷 Sélectionnés à l'issue du FCSC, les joueurs de la Team France représenteront la drapeau tricolore à Varsovie, en Pologne, dans le cadre de l'European Cybersecurity Challenge. 🔔 RDV en octobre ! PS: #YouAreAllWinners
🚗🔌 We reverse engineered the Tesla Wall Connector and uncovered a previously undocumented attack surface via the charging cable. From protocol analysis to code execution, a Pwn2Own Automotive 2025 exploit write-up. www.synacktiv.com/en/publicati...
Exploiting the Tesla Wall connector from its charge port connector
An interesting attack surface Over the past few years, Synacktiv has been analyzing Tesla vehicles for the Pwn2Own competition.
synacktiv.com
🔔 It is time to buy your HEXACON ticket! 💸 Discounted tickets are available (while supplies last) for students and professionals who do not receive support from their company. This approach is based on trust, but we may ask for proof. www.hexacon.fr/register/
For the second year in a row, we managed to get first place at the #HackTheBox Business #CTF 2025! 🥇 Congratulations to GMO Cybersecurity and Downscope who complete the podium and thanks to @hackthebox.bsky.social ox.bsky.social for the fun challenges! 🥳
📣 Prochain Bière&Sécu Toulouse le mardi 10 juin ! 🗓️ RDV au Rooster and Beer à partir de 18h30 👉 Framadate: framadate.org/M8dPvbvdQNgL1i… 🗣️ Contactez-nous si vous avez des sujets à présenter via Twitter, Bluesky ou Discord !
framadate.org
We're proud to announce the release of Binary Ninja 5.0. Here's some highlights: Union Support, Dyld Share Cache & Kernel Cache, Firmware Ninja, Auto Stack Arrays, Stack Structure Type Propagation, and so much more. Check out the blog post for more information: binary.ninja/2025/04/23/5...
iOS for Security Engineers by Quentin Meffre (@0xdagger.bsky.social) & Etienne Helluy-Lafont www.hexacon.fr/trainer/meff...
From firmware dumps to wireless exploration — check out our latest dive into DVB receiver analysis and the hidden attack surface it exposes! www.synacktiv.com/en/publicati...
Hack the channel: A Deep Dive into DVB Receiver Security
Introduction During a garage cleaning, we found a DVB receiver and thought it would be a great target for vulnerability research.
synacktiv.com
Don't forget @bieresecutls.bsky.social on Wednesday 9th before THCon, first round of drinks is on us 🍻
📢 Prochain Bière&Sécu mercredi 9 avril 🗓️ (veille de Thcon) ! RDV à partir de 19h au Rooster and Beer🐔🍺 @synacktiv.com offrira la première tournée de bières 🍻. Il n'y aura pas de présentation cette fois-ci mais n'hésitez pas à proposer des Rumps à THCon 😉
PagedOut! #6 magazine is out! This edition features two articles from our ninjas: - Implicit Unicode behaviors in database string functions - Calling Rust from Python: A story of bindings Dive into their insights here: pagedout.institute
Paged Out!
Deeply technical zine. And it's free.
pagedout.institute