https://quarkslab.com
Recently we worked with the @kubevirt team on a security audit sponsored by @OSTIFofficial 🙏
Read a summary of our findings and find the full report here:
blog.quarkslab.com/kubevirt-sec...
Recently we worked with the @kubevirt team on a security audit sponsored by @OSTIFofficial 🙏
Read a summary of our findings and find the full report here:
blog.quarkslab.com/kubevirt-sec...
Check out the list of openings and apply for fun and knowledge!
blog.quarkslab.com/internship-offers-for-the-2025-2026-season.html
Check out the list of openings and apply for fun and knowledge!
blog.quarkslab.com/internship-offers-for-the-2025-2026-season.html
In his latest blog post, Luis Casvella shows you how BYOVD can be used as a Reflective Rootkit Loader ! 🚀
➡️ blog.quarkslab.com/exploiting-l...
In his latest blog post, Luis Casvella shows you how BYOVD can be used as a Reflective Rootkit Loader ! 🚀
➡️ blog.quarkslab.com/exploiting-l...
Let's see what Signal looks like now!
blog.quarkslab.com/triple-threa...
Let's see what Signal looks like now!
blog.quarkslab.com/triple-threa...
However, with the right primitives, you can do much more.
Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver.
👇
blog.quarkslab.com/exploiting-l...
However, with the right primitives, you can do much more.
Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver.
👇
blog.quarkslab.com/exploiting-l...
Reverse engineering Apple's iOS 0-click CVE-2025-43300 improved bounds checking fix, by Madimodi Diawara
blog.quarkslab.com/patch-analys...
Reverse engineering Apple's iOS 0-click CVE-2025-43300 improved bounds checking fix, by Madimodi Diawara
blog.quarkslab.com/patch-analys...
Barbhack starts this Saturday in Toulon and we're giving away a ticket to a student nearby looking to live the experience
Send us a Chat msg with your name and school
We will notify the winner tonight
www.barbhack.fr/2025/fr/
Barbhack starts this Saturday in Toulon and we're giving away a ticket to a student nearby looking to live the experience
Send us a Chat msg with your name and school
We will notify the winner tonight
www.barbhack.fr/2025/fr/
🚨Best way to trigger an alert
What if you craft your own Personal Access Token 🔑 for the Admin account ?
Find out how in this blog post by Quarkslab's Red Teamer YV
blog.quarkslab.com/a-story-abou...
🚨Best way to trigger an alert
What if you craft your own Personal Access Token 🔑 for the Admin account ?
Find out how in this blog post by Quarkslab's Red Teamer YV
blog.quarkslab.com/a-story-abou...
Now you can do it in a few lines of Go, Python or Rust with Wirego.
Benoit Girard explains how here:
blog.quarkslab.com/getting-star...
Now you can do it in a few lines of Go, Python or Rust with Wirego.
Benoit Girard explains how here:
blog.quarkslab.com/getting-star...
The amazing Off by One Conference 2025 starts today.
If you are attending don't miss Fred Raynal's (our fearless CEO) keynote at 9:35am:
"Spyware for rent & the world of offensive cyber"
The full agenda is available here:
offbyone.sg/agenda
The amazing Off by One Conference 2025 starts today.
If you are attending don't miss Fred Raynal's (our fearless CEO) keynote at 9:35am:
"Spyware for rent & the world of offensive cyber"
The full agenda is available here:
offbyone.sg/agenda
Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations.
You can learn more about it here:
quarkslab.github.io/crypto-condo...
Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations.
You can learn more about it here:
quarkslab.github.io/crypto-condo...
It's ProxyBlob, a reverse proxy over Azure.
Check out Alexandre Nesic's article on how it came to exist after an assumed breach mission ⤵️
👉 blog.quarkslab.com/proxyblobing...
It's ProxyBlob, a reverse proxy over Azure.
Check out Alexandre Nesic's article on how it came to exist after an assumed breach mission ⤵️
👉 blog.quarkslab.com/proxyblobing...
Fun twist? This vuln matches exactly the example Orange Tsai presented at Black Hat 2017.
Real life imitates conference slides 😅
Details here:
blog.quarkslab.com/auditing-moo...
Fun twist? This vuln matches exactly the example Orange Tsai presented at Black Hat 2017.
Real life imitates conference slides 😅
Details here:
blog.quarkslab.com/auditing-moo...
Exploiting a Local Privilege Escalation vulnerability in CCleaner version 1 for MacOS, by @Coiffeur0x90
blog.quarkslab.com/ccleaner_lpe...
Exploiting a Local Privilege Escalation vulnerability in CCleaner version 1 for MacOS, by @Coiffeur0x90
blog.quarkslab.com/ccleaner_lpe...
Join him next Monday at Campus Cyber Hauts-the-France:
www.meetup.com/hack-the-box...
Join him next Monday at Campus Cyber Hauts-the-France:
www.meetup.com/hack-the-box...
Here Célian Glénaz, Dahmun Goudarzi and Julio Loayza Meneses tell you how they did it:
blog.quarkslab.com/finding-bugs...
Here Célian Glénaz, Dahmun Goudarzi and Julio Loayza Meneses tell you how they did it:
blog.quarkslab.com/finding-bugs...
In 2024 we worked with @anssi-fr.bsky.social to develop fuzzysully, an OPC UA fuzzer.
Today we are glad to announce that this tool is now open source:
github.com/ANSSI-FR/fuz...
In 2024 we worked with @anssi-fr.bsky.social to develop fuzzysully, an OPC UA fuzzer.
Today we are glad to announce that this tool is now open source:
github.com/ANSSI-FR/fuz...
Learn some infrastructure tricks and delivery methods to bypass common detection.
👉 blog.quarkslab.com/technical-di...
(promise this one is legit 👀)
Learn some infrastructure tricks and delivery methods to bypass common detection.
👉 blog.quarkslab.com/technical-di...
(promise this one is legit 👀)
Our audit was focused on the 3-token pool implementation and no critical vulnerabilities were found.
The summary and full report can be read here
blog.quarkslab.com/audit-of-all...
Our audit was focused on the 3-token pool implementation and no critical vulnerabilities were found.
The summary and full report can be read here
blog.quarkslab.com/audit-of-all...
In part 2 of "Pwn Everything, Bounce Everywhere, all at once" Mathieu Farrell tells you how to chain them for unautheticated RCE
blog.quarkslab.com/pwn-everythi...
In part 2 of "Pwn Everything, Bounce Everywhere, all at once" Mathieu Farrell tells you how to chain them for unautheticated RCE
blog.quarkslab.com/pwn-everythi...
Mathieu Farrell shows you how in the "Pwn Everything, Bounce Everywhere, all at once" blog post series.
blog.quarkslab.com/pwn-everythi...
Mathieu Farrell shows you how in the "Pwn Everything, Bounce Everywhere, all at once" blog post series.
blog.quarkslab.com/pwn-everythi...
Finding and exploiting two vulnerabilities in AMD's UEFI firmware for fun and gaming.
A Christmas gift in February, brought to you by the amazing Gwaby 🫶
blog.quarkslab.com/being-overlo...
Finding and exploiting two vulnerabilities in AMD's UEFI firmware for fun and gaming.
A Christmas gift in February, brought to you by the amazing Gwaby 🫶
blog.quarkslab.com/being-overlo...
blog.quarkslab.com/security-aud...
blog.quarkslab.com/security-aud...