tlk @tlk___
France Joined May 2010-
Tweets653
-
Followers800
-
Following1K
-
Likes230
I've been seeing posts all over about the state of CTFs post-LLM. I've seen many attempts to explain why this is just a new evolution of CTFs, but I fundamentally disagree. I believe the original spirit is gone and I've written why in my blog. kabir.au/blog/the-ctf-s…
How a single typo led to RCE in Firefox Can you spot the bug? Read now at: kqx.io/post/firefox0d…
stop using ubuntu 24.04 to host your kernel pwn challenges lmao kqx.io/post/qemu-nday/
My writeup of the 2023 NSO in-the-wild iOS zero-click BLASTDOOR webp exploit: Blasting Past Webp - googleprojectzero.blogspot.com/2025/03/blasti…
Fun facts about this Firefox bug: (1) According to Mozilla, it got introduced in 2003, it predates Firefox 1.0! (2) Although it's a UaF, it doesn't rely on any JS callback, the entire PoC is a single function. (3) It was a purely manual find and just a fun bug to PoC.
Firefox: use-after-free in txMozillaXSLTProcessor project-zero.issues.chromium.org/issues/3835582…
If you see hypervisors as magic black boxes that are hard to break, join us to this training and learn to apply your reverse, bug hunting and exploit knowledge to build VM escapes !
For the first time, our training "Bug Hunting in Hypervisors" is open to the public at @reconmtl ! Designed for security researchers,we will dive into VM escapes, hypervisor attack surfaces, and real-world exploitation. More info: recon.cx/2025/trainingB…
Allocating new exploits Pwning browsers like a kernel & Digging into PartitionAlloc and Blink engine phrack.org/issues/71/10.h…
[Pwn2Own 2024](CVE-2024-2886)[330563095, 330575496] PinArrayBufferContent is insufficient to keep the backing store itself pinned and WebCodecs VideoFrame Race Condition UAF W -> RCE is now public with PoC, exploit and wp. issues.chromium.org/issues/3305754… issues.chromium.org/issues/3305630… @0x10n
(CVE-2024-2886)[330575496] UAF in WebCodecs->RCE. chromium-review.googlesource.com/c/chromium/src… @0x10n
We're naming names 🔥 because the harm is not hypothetical. Today we share "Buying Spying", our new report diving into the commercial surveillance/spyware industry. We dive into the players, the campaigns, the spyware, & the harm it perpetuates. blog.google/threat-analysi…
In this post I'll use CVE-2023-4069, a type confusion bug in the Maglev JIT compiler of Chrome that I reported in July, to gain RCE in the Chrome renderer sandbox: github.blog/2023-10-17-get…
En raison de la situation actuelle en Israël, on a quelques tickets pour @hexacon_fr en rab et @Cellebrite serait heureux de vous les offrir. Pour participer, il suffit de répondre à ce message et on sélectionnera des gagnants demain (12 octobre) dans l'après midi.
Last sponsor we want to introduce is a special one: it's @Synacktiv, the company organizing #HEXACON2023. Leader in offensive security, Synacktiv helps companies assess their networks's security. There will be a lot of ninjas in the conference, feel free to talk to them! 🤗
Don't miss @codeblue_jp! @_p0ly_ and @vdehors will present how they managed to compromise the Tesla during the latest #Pwn2Own event codeblue.jp/2023/en/talks/…
The program for @GrehackConf is out with 3 Synacktiv talks! 🖥️ Virtualization from an attacker Point-Of-View: @OnlyTheDuck & @MajorTomSec 🚘 Unlocking the Drive: Exploiting Tesla Model 3: @_p0ly_ & @vdehors 🐧 Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt: @jbcayrou
Hey folks! We're excited to present the #GreHack23 program. You can now consult it on our website: grehack.fr/program The first batch of tickets (including workshop & CTF) will be available on October 1, 2023 at 10:00am (UTC+2).
@arkark_ According to ECMAScript specification, IteratorClose calls iterator's 'return' method. Step 4.c 262.ecma-international.org/#sec-iteratorc…
After a bit of delay, we're finally releasing advisories for 139 vulnerabilities we found in 23 trustlets used on Huawei mobile devices. Some of them can be exploited to access the Secure World and retrieve sensitive data. 🧵 A thread of our most interesting findings
This year, #HEXACON2023 will introduce the social event with a lightning talks session! 💡 ⏳ 5 minutes long ⛔️ No bullshit/commercials 🎠 Fun topics appreciated 🍻 Beers allowed 🫵Open to everyone Short talks submission will take place during the event
Synacktiv @Synacktiv
21K Followers 274 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
Thiebaut Elsa @thiebaut_elsa
393 Followers 278 Following En charge du recrutement chez @Synacktiv 🥷 Si vous souhaitez des informations, n'hésitez pas à me contacter (MP ou [email protected])
Charles Fol @cfreal_
4K Followers 709 Following @Synacktiv – previously @ambionics @LexfoSecurite – blogs: https://t.co/cLoNdCGPU7 https://t.co/JVMLjUzTJU https://t.co/t9a5IcOXSU
Worty @_Worty
3K Followers 580 Following Organizer of @HeroCTF || ctf w/ @FlatNetworkOrg || TeamFR 2021, 2022 & 2025 🇫🇷 || Breaking stuff @ Depi
Axel Souchet @0vercl0k
13K Followers 581 Following ¯\_(ツ)_/¯, blogging on https://t.co/36oOc8Mgha and posting codes on https://t.co/P83Oen94Rc.
ekt0 @ektoplasma_
553 Followers 343 Following Malware analysis, RE, and DFIR Co-creator of DFIR-IRIS DFIR ninja @ Synacktiv
GreHack @GrehackConf
5K Followers 1K Following GreHack is a hacking & scientific infosec conference in Grenoble, France. Nov. 13 & 14, 2026
SaxX ¯\_(ツ)_/¯ @_SaxX_
61K Followers 343 Following 🥷🏽Gentil Hacker et Engagé ¦¦🎙Speaker à forte Valeur ajoutée ¦¦ 🤝 Cyber Diplomate ¦¦ 👳Mentor Guardia CS ¦¦ 🥂Épicurien 🍽
voydstack @voydstack
2K Followers 1K Following VR @Synacktiv | CTF with @RMUBYGG, @Hexagonctf, @ECSC_TeamFrance 20/21/22/23/24
Jonathan Salwan @JonathanSalwan
9K Followers 237 Following Program analysis, reverse engineering and vulnerability research at @Apple SEAR.
MM-Sangari @Dallatunawe
24 Followers 335 Following “Web3 Hunter | DFIR Learner | DexTrader | Exploring blockchain security & digital forensics to uncover tomorrow’s cyber frontiers.”
bluerust @bluerust
200 Followers 1K Following
Kabir Acharya @Kabir4charya
257 Followers 1K Following #1 Player @SecDim https://t.co/c05WbjSF8H Senior Pentest & CTI @Transgrid_AU @thehackerscrew1 CTF Player https://t.co/jjo3voyn8F Pro Team Player
Satar @satar_nz
669 Followers 8K Following
Jeff Tchelong @jeff_tchelong
14 Followers 611 Following Passionné par la sécurité informatique et le Ethical Hacking
Hosein @Hosein635643
4 Followers 865 Following
hypr @hyprdude
3K Followers 856 Following vuln research+exploit dev | pwn2own {'24, '25}, Master of Pwn '25 | bordeaux enjoyer | friend of all cats | @SummoningTeam
Mohammed | مُحَم... @mmuteb_
3K Followers 1K Following Mobile (Development/Security/Forensics) | DevSecOps
gimpy @canonometry
68 Followers 3K Following
Pyraun @pyraun
3 Followers 231 Following
Gabriel Prostitis @___prosti
332 Followers 151 Following CTF player for @TheRomanXpl0it, @towerofhanoi and @mhackeroni student at @polimi
Donncha Ó Cearbhaill @DonnchaC
6K Followers 5K Following Head of Security Lab at @AmnestyTech - Hunting spyware and unlawful surveillance targeting civil society (He/Him) - Fedi: @[email protected]
Filippo Roncari @f_roncari
2K Followers 621 Following Curious guy with a long-time passion for zero-days. CTO @prdgmshift. Prev: research director @■, co-founded @truel_it & more. Opinions are my own.
Kathleen Grace @KathleenGr18101
3 Followers 170 Following Recruiting webshell engineers to pe netrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/CNjnjmD3DR
Adelaide 😳 @Adelaide4331
11 Followers 43 Following Орen-mindеd lаdу loоking for fun withоut сommitmеnts
[email protected] @Fournica93
7 Followers 39 Following
-- @m0iP6odsbL5LH3F
343 Followers 2K Following
Bruce Dang @brucedang
5K Followers 1K Following Sweeping the floor at https://t.co/CM8ErzxC5z (we are hiring). Previously at Microsoft/Veramine/Apple. author of Practical Reverse Engineering.
Teatthea @Teattheaa4xuQd
39 Followers 4K Following
h4cking4rt @h4cking4rt
2 Followers 206 Following
arraybuffer @arraybuffer
0 Followers 440 Following
Shewtiez @ShewtieztJz
40 Followers 4K Following
An Trinh @aphtrinh
1K Followers 273 Following
Jack @xploit_dev
94 Followers 388 Following Principal Exploit Developer @breakpointres | https://t.co/jUrxTxxq3F
vlcnge @vlcnge
165 Followers 2K Following
dril @0xdril
164 Followers 2K Following
scud @5Cl_lD
22 Followers 302 Following
Jérôme Poggi @EdGtslFcbngq6sk
558 Followers 813 Following a personnal account of an IT security guy (CISO). edgtslfcbngq6sk(at)https://t.co/enVbvbIN5V or EdGtslFcbngq6sk(@t)https://t.co/CkKgHCxG18 (Picture is (c) RavenSkar - Viet-My Bui)
Mathieu RENARD @GotoHack
1K Followers 738 Following Low level Security researcher / iOS / Embedded systems / Hardware Attacks / Forensics / Wookey / Leia & Founder of https://t.co/pSkWgwEj91 & Founder CEO of @TwistedWiresIO
_kickflip0 @_kickflip0
4 Followers 176 Following
Advik @Ad_vi_k
71 Followers 4K Following
Eloi Benoist-Vanderbe... @elvanderb
5K Followers 291 Following Enthusiast reverse engineer of obfuscated and protected binaries. Exploit things @Synacktiv. Very occasionally on twitter.
Synacktiv @Synacktiv
21K Followers 274 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
TrendAI Zero Day Init... @thezdi
89K Followers 18 Following TrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
Hash Miser @H_Miser
9K Followers 1K Following Internet janitor, #CERT #BlueTeam and Whisk(e)y enthusiast "Everything you do is useless ! Enjoy 🍻" [email protected] https://t.co/pBOfukJZJi
Swissky @pentest_swissky
22K Followers 1K Following RedTeam | Pentest Author of PayloadsAllTheThings & SSRFmap https://t.co/w1ZLRqoafG
Laluka@OffenSkill @TheLaluka
6K Followers 1K Following Sharing is Caring, Hacker, Eternel Learner, Cat! =^~^=
vx-underground @vxunderground
444K Followers 372 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Nicolas Grégoire @Agarri_FR
28K Followers 628 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
Saar Amar @AmarSaar
18K Followers 359 Following
Thiebaut Elsa @thiebaut_elsa
393 Followers 278 Following En charge du recrutement chez @Synacktiv 🥷 Si vous souhaitez des informations, n'hésitez pas à me contacter (MP ou [email protected])
chompie @chompie1337
89K Followers 1K Following hacker, exploit developer/weird machine mechanic head of X-Force Offensive Research (XOR) @IBM
Alex Plaskett @alexjplaskett
14K Followers 591 Following Security Researcher | Pwn2Own 2018, 2021, 2022, 2024 | Posts about 0day, OS, mobile and embedded security.
Halvar Flake @halvarflake
47K Followers 3K Following Choose disfavour where obedience does not bring honour. I do math. And was once asked by R. Morris Sr. : "For whom?" @[email protected]
Charles Fol @cfreal_
4K Followers 709 Following @Synacktiv – previously @ambionics @LexfoSecurite – blogs: https://t.co/cLoNdCGPU7 https://t.co/JVMLjUzTJU https://t.co/t9a5IcOXSU
mpgn @mpgn_x64
19K Followers 236 Following Flibustier du net ̿ ̿̿'̿'\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ Podcast Hack'n Speak @hacknspeak / https://t.co/GyACSFg9mw
Worty @_Worty
3K Followers 580 Following Organizer of @HeroCTF || ctf w/ @FlatNetworkOrg || TeamFR 2021, 2022 & 2025 🇫🇷 || Breaking stuff @ Depi
Axel Souchet @0vercl0k
13K Followers 581 Following ¯\_(ツ)_/¯, blogging on https://t.co/36oOc8Mgha and posting codes on https://t.co/P83Oen94Rc.
Charlie Bromberg « ... @_nwodtuhs
16K Followers 665 Following Trying to hack the way we hack things 🏴☠️
offensivecon @offensive_con
28K Followers 1 Following OffensiveCon is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #Offensivecon #Tokyo.
Kabir Acharya @Kabir4charya
257 Followers 1K Following #1 Player @SecDim https://t.co/c05WbjSF8H Senior Pentest & CTI @Transgrid_AU @thehackerscrew1 CTF Player https://t.co/jjo3voyn8F Pro Team Player
Unprompted AU @UnpromptedAU
702 Followers 0 Following https://t.co/YGo0O2YvDi - Security conference with an AI focus based in Sydney, Australia. Sister conference to Unprompted.
Advance-sec @advance_sec0
1K Followers 710 Following Advance-sec platform: is leader in acquisition of vulnerabilities and 0day exploits. Email: [email protected] Wire: @advance_sec Telegram: @advance_secur
Dave Aitel @daveaitel
29K Followers 2K Following Cyber Security Researcher | Policy Analyst | Technical Team Member at OpenAI | @[email protected]
hypr @hyprdude
3K Followers 856 Following vuln research+exploit dev | pwn2own {'24, '25}, Master of Pwn '25 | bordeaux enjoyer | friend of all cats | @SummoningTeam
French Response @FrenchResponse
209K Followers 8 Following Official response account of the French MFA 🇫🇷🇪🇺 (🏏) @francediplo_EN
David Kilzer @ddkilzer
714 Followers 708 Following Iowa State Cyclones; Apple, Safari, WebKit; Software Security & Privacy; EVs & green energy. My opinions are my own.
Shindan @shindan_io
80 Followers 5 Following Your automated smartphone and tablet security analysis solution. Powered by @RandoriSec
Stephen Fewer @stephenfewer
10K Followers 261 Following Senior Principal Security Researcher @rapid7. Specializing in software vulnerabilities and exploitation.
Donncha Ó Cearbhaill @DonnchaC
6K Followers 5K Following Head of Security Lab at @AmnestyTech - Hunting spyware and unlawful surveillance targeting civil society (He/Him) - Fedi: @[email protected]
Dataflow Forensics @df_forensics
647 Followers 3 Following
axi0mX @axi0mX
60K Followers 3K Following Bootrom exploit philanthropist. Apple silicon hacker. iOS jailbreaker. Join us as we dance madly on the lip of the volcano.
Thomas H. Ptacek @tqbf
36K Followers 626 Following Don't look at me sideways. Don't even look me straight on.
Rajvardhan Agarwal @rajxnull
6K Followers 409 Following Security Engineer @zellic_io | prev: @Apple | Opinions my own
Super Guesser @SuperGuesser
3K Followers 28 Following CTF Team Super Guesser Official / not recruiting
green @greentheonly
89K Followers 0 Following I report what I see. If it's good, it's good; if it's bad, it's bad. Does not depend on me. Make them release more awesome stuff. Don't shoot the messenger.
Filippo Roncari @f_roncari
2K Followers 621 Following Curious guy with a long-time passion for zero-days. CTO @prdgmshift. Prev: research director @■, co-founded @truel_it & more. Opinions are my own.
TRUEL IT @truel_it
801 Followers 10 Following First Italian research-driven security firm, providing exclusive zero-day capabilities and tailored on-demand research, along with security consulting services.
Security Bug Aggregat... @BugsAggregator
4K Followers 1 Following Aggregate disclosed Chromium security bugs.
emma @carrot_c4k3
4K Followers 317 Following cyber torture pioneer. bug bounty billionaire. most controversial pwn2own winner (contested). en🇺🇸/ru🇰🇿. she/her 🏳️⚧️
Sam Thomas @_s_n_t
2K Followers 85 Following Security researcher at Oracle. Speaker at Blackhat USA 2018, Successful entries at pwn2own IOT/Mobile 2021,2022,2023,2024, ICS 2022. Opinions are my own etc..
joernchen @joernchen
8K Followers 518 Following Your mom's favorite hacker. Also at @[email protected]
Laszlo Szapula @LaTsa99
113 Followers 126 Following Keep calm and pwn! Security researcher @TaszkSecLabs
Ken Gannon (伊藤 �... @Yogehi
3K Followers 311 Following 95% random tweets, 5% security related tweets. Pwn2Own '23/'24/'25. YayTweetsAreMyOwnYay
Alexandre Borges @ale_sp_brazil
31K Followers 174 Following iOS and Windows | Exploit Developer and Vulnerability Researcher
Carl Smith @cffsmith
1K Followers 733 Following Security @Google; @FluxFingers/@Sauercl0ud; previously V8 Security, Intern {Project Zero, @XI_Research}. Personal account. https://t.co/w9zosKSHdh on Bluesky.
David Balland @Morveus
7K Followers 2K Following Quarantenaire marié père de famille grand patron d'industrie PDG magnat milliardaire pionnier sapé comme un ado (d'après les médias)
radu motspan @_moradek_
129 Followers 380 Following
Gabriel Thierry @gabrielthierry
3K Followers 11 Following Journaliste, aux manettes de @pwned_fr, intéressé par #cybercrime, #tech et #geopolitique | [email protected] https://t.co/d3C1fHpH5rjericho @attritionorg
18K Followers 11 Following Vulnerability Historian. InfoSec recriminator. Consumer advocate. T1D. Champion of misunderstood creatures. $85,568 raised for charity. (do -not- DM here!)
Youngjoo (Jay) Lee @ashuu_lee
2K Followers 414 Following Browser Security @Apple | alias NextLine | CTFs w/ WreckTheLine, CodeRed(KR)
Jack @xploit_dev
94 Followers 388 Following Principal Exploit Developer @breakpointres | https://t.co/jUrxTxxq3F
vlcnge @vlcnge
165 Followers 2K Following
Phenol @Phenol__
929 Followers 746 Following Former chemistry student. @42born2code student. Reversing and pwning stuffs at @RandoriSec.
dunadan @udunadan
1K Followers 87 Following An open-eyed man falling into the well of weird warring state machines. I talk about reverse engineering, vulnerability research and exploit development.
ZachXBT @zachxbt
1.1M Followers 2K Following Scam survivor turned 2D investigator, Advisor @paradigm












































