Back in July, our ninjas @acervoise et @R3n1k were at @_leHACK_ explaining why you should be wary of playing old DOS games on your Linux laptop... and how you can protect yourself using AppArmor. Watch the talk in French!
youtube.com/watch?v=Ts7M9UJq…
Thank you everyone for this amazing second edition!
We hope you all had a blast and all the team is already eager to see you all next year for #HEXACON2024 🚀
Last sponsor we want to introduce is a special one: it's @Synacktiv, the company organizing #HEXACON2023.
Leader in offensive security, Synacktiv helps companies assess their networks's security.
There will be a lot of ninjas in the conference, feel free to talk to them! 🤗
ALT Synacktiv is the company organizing Hexacon 2023
Slides of @acervoise and @R3n1k presentation during #leHACK are now available! Besides resources about backdooring a program running in DosBox or Wine, you will find a great introduction to AppArmor!
synacktiv.com/sites/default/…
Have you ever tried to play an old Windows game on Linux? @acervoise and @r3n1k will present at #leHack why you should not trust abandonware and how you can harden your Linux workstation! More on lehack.org/track/pwned-by-ab…
A while ago, @acervoise and @blackndoor found two vulnerabilities in Kerlink KerOS granting an attacker access to an antenna over SSH or HTTP. Upgrade to version 5.7.2 and read the security advisory here: synacktiv.com/sites/default/…
Multiple vulnerabilities were recently fixed in n8n version 0.216.1, including authentication bypass, file reads and elevation of privileges. Read the security advisory from our experts and patch now! synacktiv.com/sites/default/…
Excellent start for the team! @_p0ly_ and @vdehors fully compromised the Tesla Model 3 gateway from the ethernet network 💪 We should book a new parking space now...
CONFIRMED! @Synacktiv successfully executed a TOCTOU exploit against Tesla – Gateway. They earn $100,000 as well as 10 Master of Pwn points and this Tesla Model 3. #Pwn2Own#P2OVancouver
Ninjas can be fan of dumpsters: @acervoise will present his methodology to loot sensitive data from your trash @hacksecureims_ hacksecureims.eu/conferences…
In their latest podcat, @nolimitsecu interviewed two of our experts about DMA attacks. If you understand 🇫🇷 and if you want to know more about DMA attacks, here's the link! nolimitsecu.fr/attaques-dma/
CALL FOR PAPERS
Last month rush before the end of the #pts23 CFP (April 14)!
Come to share your work about Security and FLOSS (or pen format/protocol) 💚
cfp.pass-the-salt.org/pts202…
You will enjoy a perfect mix of relaxed vibes, open minded people and expertise 😍
RT appreciated
You found a hardware keylogger on a laptop but don't know how to start your forensic? Our ninja @acervoise explains what can be done on different keylogger models in our latest blogpost: synacktiv.com/en/publication…