@voydstacki
iAccount based inFrance
About this account
- Account based in
- France
- Connected via
- France Android App
Account-level information from X, not a live location or the device used for a specific post.
VR @Synacktiv | CTF with @RMUBYGG, @Hexagonctf, @ECSC_TeamFrance 20/21/22/23/24
France
Joined August 2018
- Tweets736
- Following1K
- Followers2K
- Likes10K
voydstack retweeted
The wait is over! 🚀 The talks for Hexacon 2026 are officially out, and the lineup is absolute fire 🔥
hexacon.fr/conference/speake…
voydstack retweeted
CFP IS STILL OPEN FOR TALKS !
GreHack 2026 is coming soon... 🫣We invite you to share your talk about a cybersecurity topic of your choice ! 😁
Go now at GreHack.fr to send your talk before it's too late !👀Ending at the 13th.⌚
Thanks to everyone ! Cheers ! 🍻
voydstack retweeted
Today, Project Zero is releasing MAccConc, a tool by @tehjh that enables deterministic testing of race conditions on Linux. It can be used for fuzzing, ad-hoc exploration, regression tests and more!
projectzero.google/2026/09/m…
voydstack retweeted
A logical bug that I've reported to MariaDB has just been disclosed! 🎉
It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D
You can find more details 👇
hackerone.com/reports/387643…
voydstack retweeted
🔥 What are you bringing to #Entrypoint?
New technique? Tool release? Real-world compromise? Deep technical offensive security talk?
🎤 CFP closes 20 September.
📅 19-20 March 2027 | 📍 Paris
➡️ cfp.entrypoint.fr/entrypoint…
voydstack retweeted
Check your inboxes! All CFP responses have been sent out 📩
A huge thank you to everyone who submitted. We were absolutely blown away by the sheer volume and incredible quality of your proposals. Making the final selection was very tough!
voydstack retweeted
I've published UniBLEed, a fully wormable proximity Bluetooth RCE affecting Unitree's G1 humanoids. Blog spans cloud, mobile, firmware, Bluetooth & hardware. Two multi-bug RCE chains. 3 months into ~80 minutes, $6,700 in bounties. Go jailbreak your G1s!!
boschko.ca/g1-ble-rce/
We have conducted a thorough investigation into the Hugging Face incident.
We are releasing a technical report and accompanying blog post that reconstruct the agents’ activity, explain why existing safeguards failed, and detail how we’re preventing recurrence.
openai.com/index/hugging-fac…
Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud.
V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything.
Two separate critical bugs: arbitrary read and RCE.
Here's how. 🧵
voydstack retweeted
⚡Meet Qwen3.8-Flash, a multimodal MoE and an early preview of the Qwen4 architecture, now open-weight!
The production version Qwen3.8-Flash will be available soon via QwenCloud API at just $ 0.16/1M input tokens and $ 0.47/1M output tokens.
125B parameters + 51B N-gram embeddings, with just 6B activated per token. Unmatched cost-efficiency.
What's new: 🥳
- Next architecture: GDN + QSA hybrid attention, Gated Residual, N-gram Embedding & Muon optimizer, serving as a precursor to the architecture used in Qwen4.
- Dramatically lower training and inference costs: trained at just 1/9 the cost of Qwen3.7-Plus, while outperforming it across the board with especially strong gains in coding and office tasks.
- Strong performance: scoring 58.7 on DeepSWE 1.1, 62.5 on SWE-bench Pro, 73.9 on CoWorkBench, 84.5 on AndroidWorld, and 95.7 on MathVision (with CI).
- 262K native context, extensible to 1M with YaRN.
We’re also releasing the weights for Qwen3.8-Flash-Next, giving the community an early look at the new architecture we’re exploring for Qwen4.🚀
We can't wait to see what you build with Qwen3.8-Flash!👀👇
- Blog: qwen.ai/blog?id=qwen3.8-flas…
- Technical Report: github.com/QwenLM/Qwen3.8-Fl…
- Hugging Face: huggingface.co/Qwen/Qwen3.8-…
- ModelScope: modelscope.cn/models/Qwen/Qw…
voydstack retweeted
We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times.
In its final escape, the agent found three 0-days on its own and chained them into a working exploit. blog.trailofbits.com/2026/08…
voydstack retweeted
Envie de développer vos compétences en sécurité des systèmes embarqués ? 🔐
Inscrivez-vous à notre formation :
📅 Embedded Systems Exploitation : 19-23 oct.
Firmware, QEMU, analyse statique, fuzzing AFL++ et exploitation de vulnérabilités ⬇️
synacktiv.com/offres/formati…
voydstack retweeted
We just got a root shell on a @Starlink terminal antenna! To our knowledge, this is the first full exploit of a "square dish" since @LennertWo's attack on the "circular" one in 2021.
@SpaceX security team has done an amazing job, leaving us no choice but a *hardware attack* to achieve this 👏 The demo below shows what's only possible on actual rooted hardware: reading fuse register contents, accessing hardware-encrypted "file_edr" data, and more.
voydstack retweeted
Want to learn firmware reverse engineering on an IoT device? I'll be giving a free, women-only workshop with BlackHoodie at Hexacon in Paris on October 15. #reverseengineering
blackhoodie.re/Hexacon2026/
voydstack retweeted
🎙️🇫🇷 Nouvel épisode du podcast Hack'n Speak accompagné de @kevin_mizu 🔥🥇
Épisode dédié à son parcours, ses recherches, son XSS DOMPurify et bien sûr un peu, beaucoup d'IA :)
Bonne écoute à toutes et à tous 🎶
creators.spotify.com/pod/pro…
voydstack retweeted
Finally it got published.
We found a working remote Spectre attack against Cloudflare Workers. We already fixed it. No exploitation in the wild. Blog post and paper out now:
cfl.re/4qKdP6V
voydstack retweeted
🚨 The Entrypoint 2027 CFP is still open!
AD, Cloud, CI/CD, Initial Access, web exploitation... if you've got a technique or a real-world engagement story, we want to hear it.
➡️ cfp.entrypoint.fr/entrypoint…
🎫 Website and ticketing information will be released soon!
voydstack retweeted
Recently, I've been looking at DOMPurify again, trying to find ways to bypass 3.x.x after browsers started encoding attrs during serialization.
I ended up with a nice ≤3.2.6 Safari default-configuration bypass using only SMIL tags/attrs :D
Details 👇
mizu.re/post/dompurify-bypas…