Quarkslab
@quarkslab.bsky.social
📤 257
📥 1
📝 29
Securing every bit of your data
https://quarkslab.com
BYOVD is a well-known technique commonly used by threat actors to kill EDR 🔪 However, with the right primitives, you can do much more. Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver. 👇
blog.quarkslab.com/exploiting-l...
4 days ago
0
1
1
RTFM they say but if you read the manual and copy code examples from it you may inadvertently introduce vulns in your code 🙀 In April we audited the PHP code. Now we followed up with a review of the code snippets in PHP documentation and found 81 issues 👇
blog.quarkslab.com/security-rev...
loading . . .
Security review of PHP documentation - Quarkslab's blog
The Open Source Technology Improvement Fund, Inc., engaged with Quarkslab to perform a security audit of the code snippets in the English version of PHP documentation, focused on some specific pages.
https://blog.quarkslab.com/security-review-of-php-documentation.html
5 days ago
0
7
5
The two bytes that make size matter: Reverse engineering Apple's iOS 0-click CVE-2025-43300 improved bounds checking fix, by Madimodi Diawara
blog.quarkslab.com/patch-analys...
23 days ago
0
5
3
Hacking & Barbecue in the south of France. What could possibly be better? Barbhack starts this Saturday in Toulon and we're giving away a ticket to a student nearby looking to live the experience Send us a Chat msg with your name and school We will notify the winner tonight
www.barbhack.fr/2025/fr/
about 1 month ago
0
7
6
🚀Ever heard of ControlPlane, software to help you automate tasks on macOS? Turns out, it might also help you become root. Oops! 😱 @coiffeur0x90 found a Local Privilege Escalation vulnerability. Read before someone automates your admin rights 👉
blog.quarkslab.com/controlplane...
loading . . .
ControlPlane Local Privilege Escalation Vulnerability on macOS - Quarkslab's blog
A technical exploration of Local Privilege Escalation Vulnerability in ControlPlane on macOS.
https://blog.quarkslab.com/controlplane_lpe_macos.html
2 months ago
0
0
0
You finally pwned the Holy Confluence server. What now? Create a user? Reset a password? 🚨Best way to trigger an alert What if you craft your own Personal Access Token 🔑 for the Admin account ? Find out how in this blog post by Quarkslab's Red Teamer YV
blog.quarkslab.com/a-story-abou...
3 months ago
0
0
0
The leHack conference (
@le-hack.bsky.social
) starts tomorrow at the Cité des Sciences et de l’Industrie in Paris. We will be there to meet with peers and friends. 3 technical talks, a cool challenge & our famous Car in a Box to play with. Come and say hi at booth 20. Full program here:
lehack.org
loading . . .
leHACK 2025 incoming! - leHACK
false
https://lehack.org/
3 months ago
0
1
0
Are you a network protocol reverse engineer? Tired of writing Wireshark plugins in memory unsafe or esoteric languages named after celestial objects? Now you can do it in a few lines of Go, Python or Rust with Wirego. Benoit Girard explains how here:
blog.quarkslab.com/getting-star...
4 months ago
1
2
3
Attention ✨WomenAtSSTIC✨ We meet at 18:00 today at L'Equinoxe: 3 Place des Lices, 35000 Rennes See you there!
#sstic2025
add a skeleton here at some point
4 months ago
0
0
0
Are you a cyber professional, or a future one, coming to
#sstic2025
next week? Come to ✨WomenATsstic✨, an informal and unofficial friendly meetup on Wednesday, June 4th at 6 pm. We will reserve a bar/café near the Halle Martenot. Register here:
framadate.org/hH2t9FcRtgEG...
loading . . .
Sondage - Women@sstic 2025 - Framadate
Framadate est un service en ligne permettant de planifier un rendez-vous ou prendre des décisions rapidement et simplement.
https://framadate.org/hH2t9FcRtgEGmTWq
4 months ago
0
4
5
Good morning Singapore! The amazing Off by One Conference 2025 starts today. If you are attending don't miss Fred Raynal's (our fearless CEO) keynote at 9:35am: "Spyware for rent & the world of offensive cyber" The full agenda is available here:
offbyone.sg/agenda
5 months ago
0
0
0
Quarkslab was glad to sponsor the Real World Cryptography Paris Meetup 4 hosted by @Ledger last night. Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations. You can learn more about it here:
quarkslab.github.io/crypto-condo...
5 months ago
0
2
0
Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out Alexandre Nesic's article on how it came to exist after an assumed breach mission ⤵️ 👉
blog.quarkslab.com/proxyblobing...
5 months ago
0
1
2
While casually reading Moodle's code Mathieu Farrell found a SSRF bug exploitable by any authenticated user. Fun twist? This vuln matches exactly the example Orange Tsai presented at Black Hat 2017. Real life imitates conference slides 😅 Details here:
blog.quarkslab.com/auditing-moo...
5 months ago
0
1
0
reposted by
Quarkslab
6 months ago
We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF,
@thephpf.bsky.social
, and
@quarkslab.bsky.social
with funding provided by
@sovereign.tech
. For the report and further links, check out
ostif.org/php-audit-co...
0
5
3
reposted by
Quarkslab
The PHP Foundation
6 months ago
We are pleased to announce the completion of security audit of PHP core! Executed by
@quarkslab.bsky.social
in partnership with
@ostifofficial.bsky.social
and commissioned by the
@sovereign.tech
. Learn more:
thephp.foundation/blog/2025/04...
loading . . .
PHP Core Security Audit Results
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
https://thephp.foundation/blog/2025/04/10/php-core-security-audit-results/
0
19
11
Quarkslab audited PHP-SRC, the open source interpreter of PHP. The security audit, sponsored by
@ostifofficial.bsky.social
with funding from
@sovereign.tech
, aimed at strengthening the project's security ahead of the upcoming PHP 8.4 release. Here's what we found:
blog.quarkslab.com/security-aud...
loading . . .
Security audit of PHP-SRC
The Open Source Technology Improvement Fund, Inc, thanks to funding provided by Sovereign Tech Fund, engaged with Quarkslab to perform a security audit of PHP-SRC, the interpreter of the PHP language.
https://blog.quarkslab.com/security-audit-of-php-src.html
6 months ago
0
6
3
There is a small bug in the signature verification of OTA packages in the Android Open Source Framework. Official builds doing normal double verification of packages are not vulnerable but OEMs and third party apps may be. Jérémy Jourdois explains it here:
blog.quarkslab.com/aosp_ota_sig...
loading . . .
A small bug in the signature verification of AOSP OTA packages
A signature verification bypass in a function that verifies the integrity of ZIP archives in the AOSP framework
https://blog.quarkslab.com/aosp_ota_signature_bug.html
6 months ago
0
5
5
New GUI or root access? Choose wisely! Exploiting a Local Privilege Escalation vulnerability in CCleaner version 1 for MacOS, by @Coiffeur0x90
blog.quarkslab.com/ccleaner_lpe...
6 months ago
0
1
0
Next week at the Hack The Box 0x4d meetup in Lille, France
@rayanle.cat
will talk about PwnShop, the challenge he prepared for the PwnMe CTF 2025 and how he accidentally discovered a RCE 0day while doing so. Join him next Monday at Campus Cyber Hauts-the-France:
www.meetup.com/hack-the-box...
6 months ago
0
7
2
The Fifth Element: Using Quarkslab's cryptographic test suite to find bugs in the reference implementation of HQC, the latest algorithm added to the NIST PQC standard. Here Célian Glénaz, Dahmun Goudarzi and Julio Loayza Meneses tell you how they did it:
blog.quarkslab.com/finding-bugs...
6 months ago
0
1
0
The Open Platform Communications Unified Architecture (OPC UA) is an open standard for industrial systems. In 2024 we worked with
@anssi-fr.bsky.social
to develop fuzzysully, an OPC UA fuzzer. Today we are glad to announce that this tool is now open source:
github.com/ANSSI-FR/fuz...
6 months ago
0
1
1
From classic HTML pages to advanced MFA bypasses, dive in with
@atsika.bsky.social
in an exploration of phishing techniques 🎣. Learn some infrastructure tricks and delivery methods to bypass common detection. 👉
blog.quarkslab.com/technical-di...
(promise this one is legit 👀)
7 months ago
0
5
6
We completed our 2nd audit of Allbrige's Estrela, a decentralized exchange built on the Soroban platform. Our audit was focused on the 3-token pool implementation and no critical vulnerabilities were found. The summary and full report can be read here
blog.quarkslab.com/audit-of-all...
7 months ago
0
2
0
ICYMI: 5 vulnerabilities in SOPlanning, an open source project management application used by major consulting services providers. In part 2 of "Pwn Everything, Bounce Everywhere, all at once" Mathieu Farrell tells you how to chain them for unautheticated RCE
blog.quarkslab.com/pwn-everythi...
7 months ago
0
1
1
A Plan to Pwn: Reviving a 17 year old bug or winning a race against Project Management? We've got both. Mathieu Farrell shows you how in the "Pwn Everything, Bounce Everywhere, all at once" blog post series.
blog.quarkslab.com/pwn-everythi...
7 months ago
0
3
2
Unrestrict the restricted mode for USB on iPhone. A first analysis
@citizenlab.ca
#CVE-2025-24200
👉
blog.quarkslab.com/first-analys...
8 months ago
0
17
10
AMD published Security Bulletin AMD-SB-7027 addressing CVE-2024-0179 and CVE-2024-21925, the two UEFI SMM vulnerabilities disclosed in our blog post. Data center, desktop, mobile and embedded processors products are affected:
www.amd.com/en/resources...
add a skeleton here at some point
8 months ago
0
2
2
Good tools are made of bugs: How to monitor your Steam Deck with one byte. Finding and exploiting two vulnerabilities in AMD's UEFI firmware for fun and gaming. A Christmas gift in February, brought to you by the amazing Gwaby 🫶
blog.quarkslab.com/being-overlo...
8 months ago
1
15
9
Another audit finalized with
@ostifofficial.bsky.social
and CNCF! 🔍 Quarkslab reviewed Notary Project’s new cryptographic features — timestamping & certificate revocation — identifying 11 issues, including 2 CVEs! 📖 Read more in our blog post:
blog.quarkslab.com/security-aud...
8 months ago
0
0
1
こんにちは Tokyo! "Of all things, I liked bugs best." ― Nikola Tesla Quarkslab is happy to participate in Pwn2Own Automotive and tomorrow we will try to demonstrate a RCE on an Electric Vehicle Charger on stage. Nikola enlight us, Murphy stay home!
www.zerodayinitiative.com/blog/2025/1/...
loading . . .
Zero Day Initiative — Pwn2Own Automotive 2025: The Full Schedule
こんにちは and welcome to the second annual Pwn2Own Automotive competition. We are at Automotive World in Tokyo, and we’ve brought together some of the best researchers in the world to test the latest au...
https://www.zerodayinitiative.com/blog/2025/1/21/pwn2own-automotive-2025-the-full-schedule
8 months ago
0
5
2
you reached the end!!
feeds!
log in