Synacktiv's Avatar

Synacktiv

@synacktiv.com

Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.

614
Followers
3
Following
178
Posts
22.11.2024
Joined
Posts Following

Latest posts by Synacktiv @synacktiv.com

Preview
mitmproxy for fun and profit: Interception and Analysis of Application mitmproxy for fun and profit: Interception and Analysis of Application

πŸ”Ž Want to know what you can really do with #mitmproxy?

This deep dive shows how to intercept and modify application traffic on #Linux, #Android, and #iOS - from TLS MITM to gRPC/Protobuf tampering.

Read our latest article: www.synacktiv.com/en/publicati...

02.03.2026 15:37 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

πŸš€ Last December, the Synacktiv #WinterChallenge 2025 took place.
πŸ‘ Congratulations to the 25 participants for their outstanding solutions!
🧠 Read the write-up on the best techniques used to craft a constraint-compliant quinindrome: www.synacktiv.com/en/publicati...

24.02.2026 16:21 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

#IT evolves… and so do attacks. πŸ›‘οΈ

Sharpen your skills in March-April 2026 with our #cybersecurity courses: Forensic, Cloud, Active Directory & Malware Analysis.

πŸ“… Limited spots: www.synacktiv.com/en/offers/tr...

10.02.2026 11:19 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Beyond ACLs: Mapping Windows Privilege Escalation Paths with Beyond ACLs: Mapping Windows Privilege Escalation Paths with

In our latest article, @niozow.bsky.social dives into the inner workings of #Windows access tokens, privileges and logon rights.
As these rights often constitute a blind spot for AD enumeration tools, the article describes our PRs to integrate them into BloodHound ⬇️
www.synacktiv.com/en/publicati...

02.02.2026 15:30 πŸ‘ 1 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ” Synacktiv training courses - April 2026

Hands-on #cybersecurity courses led by #Synacktiv experts: Cloud Forensics (AWS), Azure & AD intrusion tactics.
πŸ“… March-April | Onsite & Remote
πŸ‘‰ www.synacktiv.com/en/offers/tr...

29.01.2026 10:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025 On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025

At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller.
Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit.

πŸ” www.synacktiv.com/en/publicati...

26.01.2026 10:05 πŸ‘ 6 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

On the podium at #Pwn2Own Automotive 2026 πŸ₯‰

Synacktiv ranked 3rd in Tokyo πŸ‡―πŸ‡΅ after successful attacks on #Tesla Infotainment (USB), #Sony XAV-9500ES (USB) and #Autel MaxiCharger (NFC).

πŸ“ Next stop: Berlin!

23.01.2026 11:38 πŸ‘ 5 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

Proud to announce that REVELΒ·IO has secured funding from @bpifrance-officiel.bsky.social under #France2030 πŸš€

With @synacktiv.com, this supports a new version to:
➑️ help CERT teams automate live forensic analysis
➑️ enable French & European judicial experts to perform reliable mobile extractions

16.01.2026 11:54 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Our experts will be at #Pwn2Own Automotive in Tokyo πŸ‡―πŸ‡΅

After taking 1st place in 2024 by uncovering #Tesla and automotive vulnerabilities, they’re back to explore new attack entry points!

Stay tuned πŸ”

16.01.2026 09:45 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Cyber threats evolve fast - so should your skills.
In March, join our hands-on #cybersecurity training covering Linux Forensics, Cloud Forensics (Azure & AWS) and Intrusion Tactics.

βŒ› Limited seats β†’ www.synacktiv.com/en/offers/tr...

#Cybersecurity #Forensics #CloudSecurity

14.01.2026 16:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025 Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025

From legacy WEP to WPA3-Enterprise: sharing our recent #WiFi field experiences. πŸ“‘

We detail various scenarios to better understand the risks, including WPA3 PEAP relaying & optimized online PSK brute-forcing.

‡️ www.synacktiv.com/en/publicati...

14.01.2026 10:22 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ”’ Feb 2026: #cybersecurity training with #Synacktiv!

5&6 Feb: Kubernetes Intrusion Tactics (Paris, FR)
9&10 Feb: AWS Intrusion Tactics (Paris, FR)
9-11 Feb: Malware Analysis (Remote, EN)
16-20 Feb: Attacking Web Apps (Paris, FR)

βœ… Register now: www.synacktiv.com/en/offers/tr...

29.12.2025 11:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Livewire: remote command execution through unmarshaling Livewire: remote command execution through unmarshaling

🚨 Pre-Auth RCE in #Livewire (CVE-2025-54068)!

Our specialists uncovered a critical flaw allowing remote code execution without the APP_KEY, exploiting Livewire’s hydration mechanism + PHP’s loose typing.

πŸ”— Patch now! (v3.6.4+)
www.synacktiv.com/en/publicati...

23.12.2025 16:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸš€ [Training 2026] Research & exploitation: embedded #Linux systems

5-day training on UART access, firmware analysis, QEMU emulation, fuzzing (AFL++), static analysis & persistence on compromised systems.

πŸ“ On site, Paris
πŸ‡«πŸ‡· French

Register πŸ‘‡
www.synacktiv.com/en/offers/tr...

23.12.2025 10:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ”₯ Synacktiv’s #CSIRT 2026 training sessions are coming!

Forensics, malware analysis, cloud investigations - all taught by our experts, available remotely or on site, in French or English.

Register πŸ‘‡
www.synacktiv.com/en/offers/tr...

18.12.2025 16:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Exploiting Anno 1404 Exploiting Anno 1404

[New blog post] As part of an R&D project, @tomtombinary.bsky.social identified several critical vulnerabilities in the LAN multiplayer mode of the game Anno 1404 (released in 2009) πŸ”

Want to know more?
Read the full article on our blog πŸ‘‡
www.synacktiv.com/en/publicati...

16.12.2025 15:56 πŸ‘ 3 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
ActivID administrator account takeover : the story behind ActivID administrator account takeover : the story behind

HID recently disclosed HID-PSA-2025-002, a critical flaw in the #ActivID Authentication Appliance 8.7.

In our new blog post, @us3r777.bsky.social and @pierregg.bsky.social break down exactly how they uncovered it, from methodology to exploitation πŸ’‘

Read it here ⬇️
synacktiv.com/en/publicati...

12.12.2025 15:22 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

πŸ”₯ #Synacktiv’s 2026 Internship Book is out!

Whether you're into pentest, reverse engineering, incident response or development, you’ll find our full list of internships plus practical tips to boost your chances.

πŸ“¬ Send us your CV: www.synacktiv.com/book_stage_s...

12.12.2025 09:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Trainings Synacktiv

Level up your #pentest skills in 2026 πŸš€

Join Synacktiv’s hands-on trainings: from Kubernetes & cloud hacks to web app attacks & AD intrusion.

More information & registration : www.synacktiv.com/en/offers/tr...

#cybersecurity

11.12.2025 12:22 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ•΅οΈβ€β™‚οΈ When an 'innocent' #PHP file hides a #backdoor…
During an investigation on a compromised server, we came across an obfuscated PHAR stub - a classic sign of a #webshell trying to evade basic scanners.

Check out our technical analysis πŸ”
Have you ever encountered this type of β€œpackaged” webshell? πŸ’¬

09.12.2025 14:38 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

πŸŽ“πŸš€ Ready to level up your #cybersecurity skills?

Synacktiv’s 2026 training programs are open for registration!
Get practical, expert-led sessions in offensive and defensive cybersecurity - online or in-person, in French or English πŸ‡«πŸ‡·πŸ‡¬πŸ‡§

πŸ”— Learn more: www.synacktiv.com/en/offers/tr...

04.12.2025 15:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Winter is here, it's time to test your assembly skills with the #Synacktiv Winter Challenge πŸ‚.
A code golf competition that guarantees hours of intense x86 instruction optimization!

πŸ”— Participate here: www.synacktiv.com/en/publicati...

02.12.2025 17:08 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1
Video thumbnail

Missed @hexacon.bsky.social 2025? 🀯
Good news, all #Synacktiv’s deep-dive talks on offensive research & reverse engineering are now online!

πŸŽ₯ Watch the full playlist: www.youtube.com/playlist?lis...

#cybersecurity

01.12.2025 15:12 πŸ‘ 8 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Breaking the BeeStation: Inside Our Pwn2Own 2025 Exploit Journey Breaking the BeeStation: Inside Our Pwn2Own 2025 Exploit Journey

At #Pwn2Own2025, our experts Tek & @anyfun.bsky.social remotely compromised a Synology Beestation Plus via a pre-auth exploit, leading to full system takeover.

The vuln is now tracked as CVE-2025-12686 πŸ”

πŸ”— Full write-up: www.synacktiv.com/en/publicati...

27.11.2025 14:59 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - synacktiv/itsm-exploit: Ivanti Neurons for ITSM (On Premise) exploits Ivanti Neurons for ITSM (On Premise) exploits. Contribute to synacktiv/itsm-exploit development by creating an account on GitHub.

@alexisdanizan.bsky.social discovered several critical flaws in an older #IvantiITSM version πŸ’₯
Already reported, but these exploits could still be useful and come with technical details ⬇️
github.com/synacktiv/it...

27.11.2025 10:34 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸš€ It’s the big day for the #CBCToulouse!

The #Synacktiv team is on-site and ready to connect with you throughout the event.
πŸ“ Visit our booth to learn more about our areas of expertise and our career opportunities!

πŸ“… 26–27 November 2025
ℹ️ More information: cbc-convention.com

26.11.2025 10:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Last Friday at #BlackAlps2025, noraj explored the hidden security challenges of #Unicode 🎀

With 1,000+ pages of specs, even small mistakes can become attack vectors.

Dive into the details πŸ‘‰ www.synacktiv.com/ressources%2...

25.11.2025 15:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Our specialists are on-site at #ECW - European Cyber Week!

Come meet us at booth 98 to talk #cybersecurity and explore our career opportunities.

Tomorrow is the last chance - don’t miss out πŸ‘‹

19.11.2025 11:53 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ”’ Only 7 days to go until the #CBC - Cyber Security Business Convention!

Come and meet our team:

πŸ”Ή Technical feedback,
πŸ”Ή Presentation of our training courses and career opportunities.

πŸ“ MEETT - Parc des Expositions, 31 840 AUSSONNE
ℹ️ cbc-convention.com

19.11.2025 09:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0