If you're a regular Velociraptor user or just looking for a flexible forensic tool, come and discover how Velociraptor's new features make forensic analysis of VMware ESXi hypervisor possible.
https://t.co/aJg7DyTuJy
The Synacktiv ninjas are ready for the @FIC_eu! 🥷
Come and meet us at Booth N°D45. We’re excited to share our expertise and discuss your challenges and the latest trends in cybersecurity. See you there! 👋
#InCyber2024
If you ever get authenticated access on a Commvault CommServe web console < 11.34, you might be able to elevate privileges and execute remote commands. Check out how in the advisory by @yaumn_ and @hugoclout!
https://t.co/Cit1Gy1bDd
Our ninjas have been busy this weekend! The team solved all the challenges during #HTB#CyberApocalypse24, giving them 3rd place for now, while @0xf4b scored the @ToulouseHacking pre-challenge. Congratz! 🔥
During a security assessment on Ricoh Device Manager NX, our ninja @kalimer0x00 uncovered multiple vulnerabilities. When combined, these flaws could allow attackers to gain remote code execution on the server. Read the details in our advisory: https://t.co/r2PfHjsqxa
Sometimes you just need to abuse functionalities to be a ninja! Discover how Collabora Online could be abused to conduct SSRFs and steal your cloud secrets.
https://t.co/yB5sBDGJo9
Ever faced a WAF/EDR while exploiting a Java deserialization? Checkout our latest blogpost by @loadlow for a stealthier exploitation, exfiltration and persistence by diving deep into translets, transformers and more!
https://t.co/NT8SQbklYs
Following our recent research on PHP filter chains, our ninjas @_remsio_ and Raphaël Lob found two arbitrary file leaks affecting the MISP project < 2.4.187. If you are intrigued by this kind of exploitation, take a look at: https://t.co/A79wsIkNFX
Synacktiv is looking for an additional team leader for its Reverse-Engineering Team! Find out if you are a good candidate by reading our offer (🇫🇷).
https://t.co/ERvABDYkz3
That’s a wrap for Day 2 of #Pwn2Own Automotive. We’ve already awarded over $1,000,000 in prizes this week (¥150 million!) Tune back in tomorrow here or at the ZDI blog for the final day of the contest! Here are the current standings leading into the final day:
To facilitate reverse-engineering of large programs, vulnerability research and root-cause analysis on iOS, Android, and other major platforms, @myr463 and @Hexabeast released Frinet, a tool combining Frida with an enhanced version of Tenet.
https://t.co/d0epwjylji
Thank you everyone for this amazing second edition!
We hope you all had a blast and all the team is already eager to see you all next year for #HEXACON2024 🚀
Have something to share? Don't forget to submit your lightning talk at [email protected] you might win our specially crafted Hexacon Champagne Cuvée 2023 #HEXACON2023 🍾