🚨 The #Entrypoint2027 Call For Papers is now open!
Have original offensive security research to share? New techniques, tools, or attack stories ? We want to hear from you.
📅 CFP closes: Sept 20, 2026.
Our review board will be revealed soon.
👉 https://t.co/gwUfqnNyql
We've been working on something for a while.
The talks your blue team doesn't want you to see.
🔴 Red Teaming. Initial Access. AD. Cloud & Web exploitation.
📍 Paris - Le Dernier Étage
📅 March 19–20, 2027
https://t.co/WcrpbyzSSV
CFP and additional details coming soon.
🧑🎓 Boost your offensive Active Directory skills with our Entry & Advanced trainings. Hands-on labs with dozens of machines + latest research from DEFCON, x33fcon & more! Seats are limited, don’t miss out!
🔗 Entry: https://t.co/7get5clXOg
🔗 Advanced: https://t.co/KEVNM9zdjF
Want to master cutting-edge techniques for attacking Azure? Join us this summer at @BlackHatEvents in Vegas for a deep dive into red teaming on Azure, M365, Azure DevOps, and hybrid infrastructures. Early bird tickets available until May 23rd! https://t.co/iJUIWBXknJ
GitLab recently released a patch for the Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409). Our ninjas @alexisdanizan and @b1two_ analyzed the patch and wrote the exploit code! https://t.co/RaP8lKDh8o
In our latest blogpost, @croco_byte explores the inner workings of SCCM policies and introduces https://t.co/SVc67SRKfl, a tool targeting secret policies in order to exploit misconfigurations, harvest credentials, and pivot across collections by impersonating legitimate clients.
https://t.co/EnS51OBRot
Here is the second part of my GitHub action exploitation series. You will find some exploitation scenarios on popular projects like Microsoft, Apache, FreeRDP, AutoGPT, Ant-Design, Cypress and others 👨💻
☁️ Whether it's on premises or in the cloud, a domain is a domain.
💪 Flex your intrusion muscles with @tiyeuse and @hugow_vincent's training!
➡️ https://t.co/exdDmnSCNm
📆 30/09-03/10 2024
📍Espace Vinci, Rue des Jeuneurs, Paris
A while ago during a security assessment, @0hexit identified multiple vulnerabilities on the PRTG Network Monitor application version 21.3.69.1333, allowing an attacker to perform XSS attacks. Read the technical details in the advisory: https://t.co/dt9LVuC7Jt
We have updated nord-stream, our #CI/CD secrets extraction tool to support GitLab. Turns out it is way easier to dump all the creds on GitLab, check out the updated version of our blogpost to understand why.
https://t.co/mYDewB36ec
Good news, Synacktiv 2023 trainings are open! Come and get trained by our best ninjas about pentesting Active Directory environments over 5 days, from 27 to 31/03 in our Parisian offices.
🇫🇷 More details here: https://t.co/QQotC0r69O
Register at [email protected]
Watchout! CVE-2023-22809 on Sudo was patched today to prevent a privilege escalation on sudoedit. Read the security advisory by @aevy__ and @v1csec: https://t.co/w2uco4PGhh