Security "expert" @synacktiv ⛩️

Joined March 2013
7 Photos and videos
_Flo retweeted
iOS for Security Engineers by Quentin Meffre (@0xdagger) and Victor Cutillas (@v1csec) 📅 Oct 12-15 📍 Espace Vinci or Espace Cléry, Paris 2nd 👉 hexacon.fr/trainer/ios_for_s…
5
20
1,723
_Flo retweeted
So glad to finally be able to present this research at @BlackHatEvents Asia! Blogposts are coming soon, on the menu: LPE via local NTLM reflection and RCE via a new arbitrary Kerberos authentication coercion technique 👀
Tomorrow, @yaumn_ will be presenting his research on Windows authentication reflection at @BlackHatEvents Asia 2026 in Singapore! The talk will be at 15:20 local time in Simpor Junior Ballroom 4810, come say hi! 😄 #BHASIA ℹ️ blackhat.com/asia-26/briefin…
11
44
3,457
_Flo retweeted
Double trouble at #SOCON2026! Our ninja @kalimer0x00 was busy breaking down Microsoft SCCM (once again!), while @croco_byte unveiled new GPO-based attack paths & his latest BloodHound contributions targeting OUs & AD Sites. Awesome job! 👏
1
6
44
4,165
_Flo retweeted
On se retrouve demain à partir de 19h ! 👇🏼 📍Boulangerie Bar - 02/03 (salle du bas)
Le prochain meetup aura lieu ce lundi 02/03👾 Au programme : - @Lefnui : Fonctionnement d’un DRM - @4rchib4ld : La Corée du nord et le remote 📍Boulangerie Bar - 02/03 à partir de 19h (Salle du bas)
1
3
323
_Flo retweeted
Le prochain meetup aura lieu ce lundi 02/03👾 Au programme : - @Lefnui : Fonctionnement d’un DRM - @4rchib4ld : La Corée du nord et le remote 📍Boulangerie Bar - 02/03 à partir de 19h (Salle du bas)
3
6
633
_Flo retweeted
Proud to finally share the write-up of our VMware Workstation escape from P2O Berlin 2025, featuring a generic bypass for Windows LFH mitigations using side-channels. I hope it will be as fun to read as it was to exploit! x.com/Synacktiv/status/20157…

At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…
1
28
188
17,884
_Flo retweeted
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…
4
150
531
49,682
_Flo retweeted
27 Nov 2025
Something big is coming... @Bug_Recon
3
1
2
1,002
_Flo retweeted
In a normal world, this should be an immense scandal in Europe. Le Monde has a long article (lemonde.fr/international/art…) describing the hellish life of Nicolas Guillou, a French judge at the ICC in The Hague, due to U.S. sanctions punishing him for authorizing arrest warrants against Netanyahu and Gallant for war crimes in Gaza. Guillou's daily existence has been transformed into a Kafkaesque nightmare. He cannot: open or maintain accounts with Google, Amazon, Apple, or any US company; make hotel reservations (Expedia canceled his booking in France hours after he made it); conduct online commerce, since he can't know if the packaging is American; use any major credit card (Visa, Mastercard, Amex are all American); access normal banking services, even with non-American banks, as banks worldwide close sanctioned accounts; conduct virtually any financial transaction. He describes it as being "economically banned across most of the planet," including in his own country, France, and where he works, the Netherlands. That's the real shocking aspect of this: the Americans are: - punishing a European citizen - for doing his job in Europe - applying laws Europe officially supports - at an institution based in Europe - that Europe helped create and fund and Europe is not only doing essentially nothing to protect him, they're actively enforcing America's sanctions against their own citizen - European banks closing his accounts, European companies refusing him service, European institutions standing by while Washington destroys a European judge's life on European soil. Again, in a normal world, European leaders and citizens should be absolutely outraged about this. But we've so normalized the hollowing out of European sovereignty that the sight of a European citizen being economically executed on European soil for upholding European law is treated, at best, as an unfortunate technical complication in transatlantic relations.
1,474
16,948
37,392
3,912,682
_Flo retweeted
18 Oct 2025
Watch how reflection attacks are still a thing in 2025 on the livestream where @yaumn_ and I will present how we discovered and analyzed CVE-2025-33073 !
18 Oct 2025
Follow No Hat 2025 research track live streaming at youtube.com/live/f-nIbNcx_SA
5
7
1,179
_Flo retweeted
12 Oct 2025
That's a wrap for Hexacon 2025! We hope that you've enjoyed the event at least as much as we did 🤩 Please take a moment to fill out our satisfaction survey and help us make Hexacon 2026 even better 🔥 Thank you for trusting us year after year 🙏
11
92
11,543
_Flo retweeted
2 Oct 2025
The web is a prime target for attackers. Want to refine your intrusion methods? Join our ‘Attacking Web Applications’ training course from 17 to 21 November! ▪️ 5 days of expertise ▪️ 35 hours of lessons, more than 30 exercises ▪️ Java, PHP, Python, ASP.NET... Information & registration via 👇 synacktiv.com/en/offers/trai…
7
17
2,846
_Flo retweeted
Hello ! Rendez-vous ce lundi 29/09 pour le meetup de septembre ! 👾 On parlera CTI avec @4rchib4ld Au programme : - Iranian APT tracking 📍Boulangerie Bar - 29/09 à partir de 19h (Salle du bas) #Lille #Cyber #infosec
1
2
253
_Flo retweeted
14 Sep 2025
Bonjour je tente le tout pour le tout ici on sait jamais. Ma copine recherche un job en consultant GRC à Rennes ou aux alentours. Elle a une bonne expérience et elle vient de finir ses études en alternance. Elle a trouvé un CDI à Paris mais elle tient vraiment à rester à Rennes.
1
6
8
1,712
_Flo retweeted
12 Sep 2025
🧑‍🎓 Boost your offensive Active Directory skills with our Entry & Advanced trainings. Hands-on labs with dozens of machines latest research from DEFCON, x33fcon & more! Seats are limited, don’t miss out! 🔗 Entry: synacktiv.com/en/offers/trai… 🔗 Advanced: synacktiv.com/en/offers/trai…
11
20
2,961
_Flo retweeted
Replying to @Formation_bzh
@Formation_bzh annule à J-15 la 1re année BTS SIO SLAM (11 admissibles). Une honte ! Pour les jeunes : nouvelle école à trouver, alternance, logements... Traitement inhumain de ses jeunes considérés comme des lignes d'un tableau excel. On attend des réponses. #ESNA #UIMM
1
12
29
2,814
_Flo retweeted
20 Jul 2025
Imagine having the master key to a building: that’s what the APP_KEY is for Laravel app. With it, an attacker can craft a payload that Livewire doesn’t see as harmful. Join @_remsio_ & @_Worty at #NullconBerlin2025 Know More: nullcon.net/berlin-2025/spea… #Laravel #APP_KEY
9
20
1,981
_Flo retweeted
16 Apr 2025
iOS for Security Engineers by Quentin Meffre (@0xdagger) & Etienne Helluy-Lafont hexacon.fr/trainer/meffre_he…
8
30
13,040
_Flo retweeted
28 Jun 2025
Le workshop active directory c’est ce soir 21h zone 2 room 2 à #leHack ! 2 domaines vous attendent sous le thème Star Wars 😁
1
1
17
1,896
_Flo retweeted
11 Jun 2025
☁️ Already wrapping up our 3-day offensive Azure training at #x33fcon! Huge thanks to the x33fcon team for hosting us, and to all our amazing students for their energy, curiosity, and sharp questions throughout the session. Now it’s time to switch gears — conference mode on! 🎤
4
13
1,925