🔥 Excited to announce our keynote!
We are thrilled to welcome Bruce Dang (@brucedang) and Thai Duong (@XorNinja) from @calif_io! With all their recent AI buzz, we had to check they aren't just LLMs in a trench coat. 🤖🧥
🎟️ Ticketing opens this Thursday at 2:00 PM CEST ⏰
iOS for Security Engineers by Quentin Meffre (@0xdagger) and Victor Cutillas (@v1csec)
📅 Oct 12-15
📍 Espace Vinci or Espace Cléry, Paris 2nd
👉 https://t.co/qsRDOljksx
Bug Hunting in Hypervisors by Corentin Bayet (@OnlyTheDuck) and @BrunoPujos
📅 Oct 12-15
📍 Espace Vinci or Espace Cléry, Paris 2nd
👉 https://t.co/bABXcLpDn5
🚗🔌 @Tesla patched our #Pwn2Own Automotive 2025 Wall Connector exploit with an anti-downgrade mechanism.
#Synacktiv experts bypassed it and replayed the same attack through the charging cable.
Part 2 write-up👇
https://t.co/xHSx7H019x
Make it blink!
This new article unpacks how Mehdi and Matthieu achieved an over-the-air exploitation of the #PhilipsHue Bridge via a #Zigbee bug.
Read all about the technical details, how they proved it is exploitable at #Pwn2Own Cork 2025, and the underlying vulnerability here 👇 https://t.co/IfPNhfU9nh
This second blogpost concludes @yaumn_'s research on #Windows authentication reflection.
He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥
A little bonus is even included at the end 👀👇
https://t.co/RsJHxCdIGe
Authentication reflection attacks are still not dead!
In our new blogpost series, @yaumn_ shares his journey into bypassing the mitigations of CVE-2025-33073 to pop SYSTEM shells again🚀
👇
https://t.co/pbZ2KjXq7Q
The training lineup for Hexacon 2026 is now available on our website 🧑🏼🏫
Training tickets sales will officially launch in mid-May 🎫
https://t.co/fFLYxCKV76
So glad to finally be able to present this research at @BlackHatEvents Asia! Blogposts are coming soon, on the menu: LPE via local NTLM reflection and RCE via a new arbitrary Kerberos authentication coercion technique 👀
Mozilla says Mythos helped identify 271 vulnerabilities in Firefox 150.
I went through the commits, CVEs, and bug links to see what that number really means.
My takeaway: relax folks.
https://t.co/9LEqL7sXX6
The #FCSC2026 ended today, and my write-ups are now available here:
https://t.co/6e2WWjxKpD 🚩
I'm really happy with the challenges I managed to create this year! It would be too long to list everything, so here's a little teaser 👇
1/2
This year again, with @BitK_ and @_Worty, we've made the Web challenges 🚩
The CTF is solo and lasts 10 days, if you have some time, please give it a look 😁
Even if you're not doing Web challenges, there are challenges in various categories, you should find something you like!
#FCSC 2026 started yesterday ! So grateful to be part of the challenge authors this year ! Wrote 3 pwn challenges : "Boring", "Not So Boring" (still unsolved) and "wsd". Come check them out alongside many other quality challenges😄🚩
#FCSC | 🦖 « Rex ne veut pas qu’on le nourrisse, il veut chasser ».
🚩 La chasse aux drapeaux commence aujourd'hui avec le retour du France Cybersecurity Challenge jusqu'au 12 avril !
🔔 Rendez-vous dès 14h :
https://t.co/0zmE194yXH