mitmproxy for fun and profit: Interception and Analysis of Application
mitmproxy for fun and profit: Interception and Analysis of Application
π Want to know what you can really do with #mitmproxy?
This deep dive shows how to intercept and modify application traffic on #Linux, #Android, and #iOS - from TLS MITM to gRPC/Protobuf tampering.
Read our latest article: www.synacktiv.com/en/publicati...
02.03.2026 15:37
π 2
π 2
π¬ 0
π 0
π Last December, the Synacktiv #WinterChallenge 2025 took place.
π Congratulations to the 25 participants for their outstanding solutions!
π§ Read the write-up on the best techniques used to craft a constraint-compliant quinindrome: www.synacktiv.com/en/publicati...
24.02.2026 16:21
π 2
π 1
π¬ 0
π 0
#IT evolvesβ¦ and so do attacks. π‘οΈ
Sharpen your skills in March-April 2026 with our #cybersecurity courses: Forensic, Cloud, Active Directory & Malware Analysis.
π
Limited spots: www.synacktiv.com/en/offers/tr...
10.02.2026 11:19
π 1
π 2
π¬ 0
π 0
Beyond ACLs: Mapping Windows Privilege Escalation Paths with
Beyond ACLs: Mapping Windows Privilege Escalation Paths with
In our latest article, @niozow.bsky.social dives into the inner workings of #Windows access tokens, privileges and logon rights.
As these rights often constitute a blind spot for AD enumeration tools, the article describes our PRs to integrate them into BloodHound β¬οΈ
www.synacktiv.com/en/publicati...
02.02.2026 15:30
π 1
π 3
π¬ 0
π 0
π Synacktiv training courses - April 2026
Hands-on #cybersecurity courses led by #Synacktiv experts: Cloud Forensics (AWS), Azure & AD intrusion tactics.
π
March-April | Onsite & Remote
π www.synacktiv.com/en/offers/tr...
29.01.2026 10:30
π 0
π 0
π¬ 0
π 0
On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025
On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller.
Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit.
π www.synacktiv.com/en/publicati...
26.01.2026 10:05
π 6
π 1
π¬ 0
π 0
On the podium at #Pwn2Own Automotive 2026 π₯
Synacktiv ranked 3rd in Tokyo π―π΅ after successful attacks on #Tesla Infotainment (USB), #Sony XAV-9500ES (USB) and #Autel MaxiCharger (NFC).
π Next stop: Berlin!
23.01.2026 11:38
π 5
π 4
π¬ 0
π 0
Proud to announce that REVELΒ·IO has secured funding from @bpifrance-officiel.bsky.social under #France2030 π
With @synacktiv.com, this supports a new version to:
β‘οΈ help CERT teams automate live forensic analysis
β‘οΈ enable French & European judicial experts to perform reliable mobile extractions
16.01.2026 11:54
π 1
π 1
π¬ 0
π 0
Our experts will be at #Pwn2Own Automotive in Tokyo π―π΅
After taking 1st place in 2024 by uncovering #Tesla and automotive vulnerabilities, theyβre back to explore new attack entry points!
Stay tuned π
16.01.2026 09:45
π 1
π 1
π¬ 0
π 0
Cyber threats evolve fast - so should your skills.
In March, join our hands-on #cybersecurity training covering Linux Forensics, Cloud Forensics (Azure & AWS) and Intrusion Tactics.
β Limited seats β www.synacktiv.com/en/offers/tr...
#Cybersecurity #Forensics #CloudSecurity
14.01.2026 16:04
π 0
π 0
π¬ 0
π 0
Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025
Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025
From legacy WEP to WPA3-Enterprise: sharing our recent #WiFi field experiences. π‘
We detail various scenarios to better understand the risks, including WPA3 PEAP relaying & optimized online PSK brute-forcing.
β€΅οΈ www.synacktiv.com/en/publicati...
14.01.2026 10:22
π 3
π 2
π¬ 0
π 0
π Feb 2026: #cybersecurity training with #Synacktiv!
5&6 Feb: Kubernetes Intrusion Tactics (Paris, FR)
9&10 Feb: AWS Intrusion Tactics (Paris, FR)
9-11 Feb: Malware Analysis (Remote, EN)
16-20 Feb: Attacking Web Apps (Paris, FR)
β
Register now: www.synacktiv.com/en/offers/tr...
29.12.2025 11:09
π 0
π 0
π¬ 0
π 0
Livewire: remote command execution through unmarshaling
Livewire: remote command execution through unmarshaling
π¨ Pre-Auth RCE in #Livewire (CVE-2025-54068)!
Our specialists uncovered a critical flaw allowing remote code execution without the APP_KEY, exploiting Livewireβs hydration mechanism + PHPβs loose typing.
π Patch now! (v3.6.4+)
www.synacktiv.com/en/publicati...
23.12.2025 16:40
π 1
π 0
π¬ 0
π 0
π [Training 2026] Research & exploitation: embedded #Linux systems
5-day training on UART access, firmware analysis, QEMU emulation, fuzzing (AFL++), static analysis & persistence on compromised systems.
π On site, Paris
π«π· French
Register π
www.synacktiv.com/en/offers/tr...
23.12.2025 10:40
π 1
π 0
π¬ 0
π 0
π₯ Synacktivβs #CSIRT 2026 training sessions are coming!
Forensics, malware analysis, cloud investigations - all taught by our experts, available remotely or on site, in French or English.
Register π
www.synacktiv.com/en/offers/tr...
18.12.2025 16:37
π 1
π 0
π¬ 0
π 0
Exploiting Anno 1404
Exploiting Anno 1404
[New blog post] As part of an R&D project, @tomtombinary.bsky.social identified several critical vulnerabilities in the LAN multiplayer mode of the game Anno 1404 (released in 2009) π
Want to know more?
Read the full article on our blog π
www.synacktiv.com/en/publicati...
16.12.2025 15:56
π 3
π 3
π¬ 0
π 0
ActivID administrator account takeover : the story behind
ActivID administrator account takeover : the story behind
HID recently disclosed HID-PSA-2025-002, a critical flaw in the #ActivID Authentication Appliance 8.7.
In our new blog post, @us3r777.bsky.social and @pierregg.bsky.social break down exactly how they uncovered it, from methodology to exploitation π‘
Read it here β¬οΈ
synacktiv.com/en/publicati...
12.12.2025 15:22
π 3
π 2
π¬ 0
π 0
π₯ #Synacktivβs 2026 Internship Book is out!
Whether you're into pentest, reverse engineering, incident response or development, youβll find our full list of internships plus practical tips to boost your chances.
π¬ Send us your CV: www.synacktiv.com/book_stage_s...
12.12.2025 09:21
π 0
π 0
π¬ 0
π 0
Trainings
Synacktiv
Level up your #pentest skills in 2026 π
Join Synacktivβs hands-on trainings: from Kubernetes & cloud hacks to web app attacks & AD intrusion.
More information & registration : www.synacktiv.com/en/offers/tr...
#cybersecurity
11.12.2025 12:22
π 0
π 1
π¬ 0
π 0
π΅οΈββοΈ When an 'innocent' #PHP file hides a #backdoorβ¦
During an investigation on a compromised server, we came across an obfuscated PHAR stub - a classic sign of a #webshell trying to evade basic scanners.
Check out our technical analysis π
Have you ever encountered this type of βpackagedβ webshell? π¬
09.12.2025 14:38
π 1
π 1
π¬ 0
π 0
ππ Ready to level up your #cybersecurity skills?
Synacktivβs 2026 training programs are open for registration!
Get practical, expert-led sessions in offensive and defensive cybersecurity - online or in-person, in French or English π«π·π¬π§
π Learn more: www.synacktiv.com/en/offers/tr...
04.12.2025 15:00
π 0
π 0
π¬ 0
π 0
Winter is here, it's time to test your assembly skills with the #Synacktiv Winter Challenge π.
A code golf competition that guarantees hours of intense x86 instruction optimization!
π Participate here: www.synacktiv.com/en/publicati...
02.12.2025 17:08
π 3
π 1
π¬ 0
π 1
Missed @hexacon.bsky.social 2025? π€―
Good news, all #Synacktivβs deep-dive talks on offensive research & reverse engineering are now online!
π₯ Watch the full playlist: www.youtube.com/playlist?lis...
#cybersecurity
01.12.2025 15:12
π 8
π 2
π¬ 0
π 0
Breaking the BeeStation: Inside Our Pwn2Own 2025 Exploit Journey
Breaking the BeeStation: Inside Our Pwn2Own 2025 Exploit Journey
At #Pwn2Own2025, our experts Tek & @anyfun.bsky.social remotely compromised a Synology Beestation Plus via a pre-auth exploit, leading to full system takeover.
The vuln is now tracked as CVE-2025-12686 π
π Full write-up: www.synacktiv.com/en/publicati...
27.11.2025 14:59
π 4
π 1
π¬ 0
π 0
GitHub - synacktiv/itsm-exploit: Ivanti Neurons for ITSM (On Premise) exploits
Ivanti Neurons for ITSM (On Premise) exploits. Contribute to synacktiv/itsm-exploit development by creating an account on GitHub.
@alexisdanizan.bsky.social discovered several critical flaws in an older #IvantiITSM version π₯
Already reported, but these exploits could still be useful and come with technical details β¬οΈ
github.com/synacktiv/it...
27.11.2025 10:34
π 2
π 0
π¬ 0
π 0
π Itβs the big day for the #CBCToulouse!
The #Synacktiv team is on-site and ready to connect with you throughout the event.
π Visit our booth to learn more about our areas of expertise and our career opportunities!
π
26β27 November 2025
βΉοΈ More information: cbc-convention.com
26.11.2025 10:08
π 0
π 0
π¬ 0
π 0
Last Friday at #BlackAlps2025, noraj explored the hidden security challenges of #Unicode π€
With 1,000+ pages of specs, even small mistakes can become attack vectors.
Dive into the details π www.synacktiv.com/ressources%2...
25.11.2025 15:07
π 0
π 0
π¬ 0
π 0
Our specialists are on-site at #ECW - European Cyber Week!
Come meet us at booth 98 to talk #cybersecurity and explore our career opportunities.
Tomorrow is the last chance - donβt miss out π
19.11.2025 11:53
π 0
π 0
π¬ 0
π 0
π Only 7 days to go until the #CBC - Cyber Security Business Convention!
Come and meet our team:
πΉ Technical feedback,
πΉ Presentation of our training courses and career opportunities.
π MEETT - Parc des Expositions, 31 840 AUSSONNE
βΉοΈ cbc-convention.com
19.11.2025 09:35
π 0
π 0
π¬ 0
π 0