Nicolas Grégoire
@agarri.fr
📤 4376
📥 615
📝 992
Web hacker 😈 Burp Suite Pro trainer 👨🏫 Maintainer of
@mastering-burp.agarri.fr
🛠️
Both Chrome and Firefox will disable XSLT in 2026 🪦 I fully agree with them: nobody uses this technology anymore in a browser, and it's full of bugs (as my previous research demonstrates)
bugzilla.mozilla.org/show_bug.cgi...
developer.chrome.com/docs/web-pla...
about 9 hours ago
1
2
0
reposted by
Nicolas Grégoire
The release candidate of the OWASP Top 10 2025 has been released
owasp.org/Top10/2025/0...
The definitive release should be out on November 20th
loading . . .
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
https://owasp.org/Top10/2025/0x00_2025-Introduction/
6 days ago
0
7
11
Bizarrement, personne ne brandit l’article 40 du CPP pour les vidéos de Sainte-Soline publiées par Libération… 🥴
www.dailymotion.com/video/k1Tvpm...
loading . . .
Tirs interdits et volonté de blesser : révélations sur les violences des gendarmes à Sainte-Soline
Dailymotion video by Libération
https://www.dailymotion.com/video/k1TvpmgAEaO9y4E9pew
3 days ago
0
1
0
AppSec Ezine - 611th edition
#AppSec
#Security
pathonproject.com/zb/?7a6539c0...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?7a6539c03cb9bc49#t3tL+C4XTqcvoVFjKcHqzwKudi/E7dZkS2tbNiRQ9lE=
5 days ago
1
2
0
The release candidate of the OWASP Top 10 2025 has been released
owasp.org/Top10/2025/0...
The definitive release should be out on November 20th
loading . . .
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
https://owasp.org/Top10/2025/0x00_2025-Introduction/
6 days ago
0
7
11
reposted by
Nicolas Grégoire
0xacb
6 days ago
If you still haven't: set up a JS file monitor to send you notifications via Telegram or Slack every time your target app JavaScript gets updated, a great way to stay on top of updates 👾
https://github.com/robre/jsmon
There's also a fork with Discord support:
loading . . .
GitHub - seczq/jsmon: a javascript change monitoring tool for bugbounties
a javascript change monitoring tool for bugbounties - GitHub - seczq/jsmon: a javascript change monitoring tool for bugbounties
https://github.com/seczq/jsmon
0
4
1
reposted by
Nicolas Grégoire
Kaitlin Kal Lee
7 days ago
"who radicalized you" Nothing radicalized me, I was born with basic empathy. The world decided that was radical.
33
2848
963
If you want to see beautiful pictures (and that’s an euphemism) in your feed, simply follow
@armandsarlangue.bsky.social
6 days ago
1
4
0
If this is NOT corruption, then I wonder what corruption looks like 🤔
add a skeleton here at some point
6 days ago
0
5
0
reposted by
Nicolas Grégoire
Alexandre Borges
8 days ago
How an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia:
techcrunch.com/2025/11/03/h...
#exploit
#exploitation
#zeroday
#infosec
#informationsecurity
#cybersecurity
loading . . .
How an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia | TechCrunch
Peter Williams sold eight exploits to a Russian zero-day broker by smuggling them from his employer’s highly secured air-gapped network. A court document, plus exclusive reporting by TechCrunch and in...
https://techcrunch.com/2025/11/03/how-an-ex-l3-harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia/
0
3
3
Ackman’s take is ridiculous 🤡
add a skeleton here at some point
6 days ago
0
0
0
In France, we had a somewhat related story last year. In the end, Florent Curtet was sentenced for criminal conspiracy and complicity in attempted extortion
www.lemonde.fr/pixels/artic...
add a skeleton here at some point
6 days ago
1
4
0
reposted by
Nicolas Grégoire
Robin
8 days ago
This is a cool attack, create a machine running in Hyper-V on a victim's machine and do all your attacking through that while it runs in the background.
www.theregister.com/2025/11/04/r...
0
5
1
reposted by
Nicolas Grégoire
Alexandre Borges
6 days ago
Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer:
starlabs.sg/blog/2025/11...
#cybersecurity
#exploitation
#printer
#exploit
#vulnerability
0
4
1
AppSec Ezine - 610th edition 🎃
#AppSec
#Security
pathonproject.com/zb/?fac2c832...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?fac2c8323f558700#0DwF/1lpTvyNrS8TtkN3fE3bZW/t2gCjccD9V+5ggoQ=
12 days ago
0
1
3
reposted by
Nicolas Grégoire
www.agarri.fr/blog/archive...
loading . . .
Traceroute-like HTTP scanner | Agarri : Sécurité informatique offensive
https://www.agarri.fr/blog/archives/2011/11/12/traceroute-like_http_scanner/index.html
13 days ago
0
5
2
reposted by
Nicolas Grégoire
17 days ago
Y'all fantastic news! Save the date,
@blackhoodie.bsky.social
will be at
@districtcon.bsky.social
this year 😱 the fantastic crew has offered to host us for a day of Malware Reverse Engineering!
@synapticrewrite.bsky.social
and myself will be hosting a training for women by women on January 23rd!!
0
20
9
reposted by
Nicolas Grégoire
Cooper
about 1 year ago
I've put together a website which indexes all the recordings my rigs have made thus-far as well as those currently planned:
administraitor.video
(minimalist - I'm a mid-/backend dev! 😋)
loading . . .
Infosec/hacking videos recorded by Cooper (@Ministraitor)
Infosec/hacking videos recorded by Cooper (@Ministraitor)
https://administraitor.video
0
16
9
That looks to me like some wild unauthorized hacking…
samcurry.net/hacking-club...
Shubs and Sam are well known, but in my opinion, this kind of publication only encourages others to go out of scope and hit random websites My advice: don’t do it, even if it’s an easy way to get some fame
loading . . .
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
In June, 2025, Shubs Shah and I discovered a vulnerability in the online poker website ClubWPT Gold which would have allowed an attacker to fully access the core back office application that is used f...
https://samcurry.net/hacking-clubwpt-gold
18 days ago
0
14
2
Reversing a smart vacuum and making it work without access to the Internet 🤖
codetiger.github.io/blog/the-day...
loading . . .
The Day My Smart Vacuum Turned Against Me
Would you allow a stranger to drive a camera-equipped computer around your living room? You might have already done so without even realizing it. The Beginning: A Curious Experiment It all started ...
https://codetiger.github.io/blog/the-day-my-smart-vacuum-turned-against-me/
18 days ago
0
5
1
reposted by
Nicolas Grégoire
James Kettle
19 days ago
Google Cloud Platform was vulnerable to a HTTP desync attack leading to "responses being misrouted between recipients for certain third-party models". Aka your LLM response goes to someone else. The Expect header strikes again! Context:
http1mustdie.com
cloud.google.com/support/bull...
loading . . .
Security Bulletins | Customer Care | Google Cloud
https://cloud.google.com/support/bulletins#gcp-2025-059
0
13
5
AppSec Ezine - 609th edition
#AppSec
#Security
pathonproject.com/zb/?52039799...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?52039799e20f1764#zVa9vb3RnEnarqBRvUgfUuN44oPH+YYRhj14Sgk+iXo=
20 days ago
0
1
0
Asset Notes just published a long writeup on SessionReaper aka CVE-2025-54236, a vulnerability affecting Magento and identified by Blaklis (a French bug hunter who found many bugs affecting this technology)
slcyber.io/assetnote-se...
loading . . .
Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236) › Searchlight Cyber
Magento is still one of the most popular e-commerce solutions in use on the internet, estimated to be running on more than 130,000 websites. It is also offered as an enterprise offering by Adobe under...
https://slcyber.io/assetnote-security-research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/
21 days ago
0
3
2
AppSec Ezine - 608th edition
#AppSec
#Security
pathonproject.com/zb/?1347bc2c...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?1347bc2ca99fd2b3#3YP/FtwMkx12OMz5wto+9OAgKtM2YKlyFIWpUHHabE8=
24 days ago
0
1
0
reposted by
Nicolas Grégoire
Kim Zetter
27 days ago
Ugly end to Kryptos saga. Two people found the solution to the last encrypted portion of famed Kryptos sculpture at CIA headquarters. They found it in Smithsonian archive. They contacted artist who made sculpture, who is preparing to auction off solution; he threatened to sue them if they reveal it
loading . . .
A C.I.A. Secret Kept for 35 Years Is Found in the Smithsonian’s Vault
https://www.nytimes.com/2025/10/16/science/kryptos-cia-solution-sanborn-auction.html?unlocked_article_code=1.t08.XqO8.NNDw-mjtJhWa&smid=nytcore-ios-share&referringSource=articleShare
5
49
17
reposted by
Nicolas Grégoire
Laluka
29 days ago
Next IRL-Time - Save The Date ! 🤯 - Quoi : Pré-Event GreHack : Root-Me x OffenSkill 💣️ - Pourquoi : Plus de potes, Plus de binouzes, Plus de rumps WTF 😏 - Quand : Jeudi 27 Novembre à 19h 📅 - Où : Tonneau de Diogène à Grenoble 🗺️ 1/2
1
1
3
reposted by
Nicolas Grégoire
OffensiveCon
28 days ago
🚨 Save the Date for
#offensivecon26
Mark your calendars, spread the word, and stay tuned for when registrations open! 📍 Hilton Berlin 🧠 Trainings: 11–14 May 2026 🎤 Conference: 15–16 May 2026 Visit 🔗offensivecon.org for more details.
0
3
3
reposted by
Nicolas Grégoire
Kim Zetter
28 days ago
CISA: Nation-state hacker has compromised F5’s systems and stolen a portion of its BIG-IP source code and vulnerability info, giving them ability to study the code for zero-day vulnerabilities. "This cyber threat actor presents an imminent threat to federal networks using F5 devices and software"
loading . . .
ED 26-01: Mitigate Vulnerabilities in F5 Devices | CISA
Section 3553(h) of title 44, U.S. Code, authorizes the Secretary of Homeland Security, in response to a known or reasonably suspected information security
https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices
0
19
16
reposted by
Nicolas Grégoire
Andy Greenberg
30 days ago
Researchers pointed a satellite dish at the sky for 3 years and monitored what unencrypted data it picked up. The results were shocking: They obtained thousands of T-Mobile users' phone calls and texts, military and law enforcement secrets, much more:
www.wired.com/story/satell...
🧵👇
loading . . .
Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data
With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users’ calls and texts and even US military communications—sent by satellites unencrypte...
https://www.wired.com/story/satellites-are-leaking-the-worlds-secrets-calls-texts-military-and-corporate-data/
20
899
504
Gecko Security stole some vulnerabilities published, among others, by Fuzzing Labs 😱 They also asked for CVE IDs 🤡 Check if your research is impacted too!
www.notion.so/fuzzinglabs/...
about 1 month ago
0
7
0
reposted by
Nicolas Grégoire
Kim Zetter
about 1 month ago
Apple announces new payouts for certain types of bugs - company will pay up to $2 million for anyone disclosing a chain of bugs that could be abused for spyware like Pegasus, as well as bonus awards for exploits that can bypass Lockdown Mode or are found while Apple software is still in beta testing
loading . . .
Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits
With the mercenary spyware industry booming, Apple VP Ivan Krstić tells WIRED that the company is also offering bonuses that could bring the max total reward for iPhone exploits to $5 million.
https://www.wired.com/story/apple-announces-2-million-bug-bounty-reward/
1
25
14
In case you're looking for something nice to read this weekend Paged Out #7 has been released
pagedout.institute
loading . . .
Paged Out!
Deeply technical zine. And it's free.
https://pagedout.institute/
about 1 month ago
0
3
0
What a shame for Deloitte!!
apnews.com/article/aust...
loading . . .
Deloitte to partially refund Australian government for report with apparent AI-generated errors
Deloitte Australia will partially refund the Australian government for a report filled with apparent AI-generated errors.
https://apnews.com/article/australia-ai-errors-deloitte-ab54858680ffc4ae6555b31c8fb987f3
about 1 month ago
0
2
1
reposted by
Nicolas Grégoire
Tom Quinn
about 1 month ago
Kidnapped in international waters, extraordinary rendition to a genocidal state, and then imprisoned indefinitely. You'd think this would trigger the immediate expulsion of the Israeli Ambassador for these inexcusable actions against an Australian citizen.
add a skeleton here at some point
3
315
169
AppSec Ezine - 607th edition
#AppSec
#Security
pathonproject.com/zb/?53e6a08f...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?53e6a08f28ac83a4#qtVOB6UkEfOhXfBY6YDNYmQ7UsUn2oBwSgDCvuGJWGw=
about 1 month ago
0
3
0
AppSec Ezine - 606th edition
#AppSec
#Security
🤖
pathonproject.com/zb/?eaf34249...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?eaf34249de413425#7RVlxJcoGknvKmOW1RYVMAvswO89aPNTyQ+Cmyi3Ct8=
about 1 month ago
1
2
2
reposted by
Nicolas Grégoire
The ticketing for
@grehack.bsky.social
opened one hour ago, and my Burp Suite Pro workshop is already full booked 😎
about 1 month ago
0
7
2
The ticketing for
@grehack.bsky.social
opened one hour ago, and my Burp Suite Pro workshop is already full booked 😎
about 1 month ago
0
7
2
reposted by
Nicolas Grégoire
Molly White
about 1 month ago
You would think the obvious solution to "the volunteer-powered project we all train our AI models on for free isn't adequately twisting reality to our political views" would be "... and so we stopped training on it" and not "... and so we will force the volunteers to bend to our will"
8
939
100
Seriously enjoyed my first time at the Romhack conference! 🤩 🇮🇹 Next year, there’s the Romhack camp, and I’m looking forward giving it a try ⛺️
romhack.io/romhack-camp...
loading . . .
RomHack Camp 2026
The second edition of RomHack Camp is scheduled for September 2026, follow us to stay updated!
https://romhack.io/romhack-camp-2026/
about 2 months ago
1
4
0
reposted by
Nicolas Grégoire
💥 leonjza
about 2 months ago
Romhack was absolute 🔥! The conference, the community, the vibe - all of it was just something else. Special mention to merlos1977@x and the CybersaiyanIT@x team for making the speaking experience excellent too. 🙃
0
7
1
reposted by
Nicolas Grégoire
Marco Ivaldi
about 2 months ago
“When you’re using a cloud proxy, you’re importing everyone else’s technical debt into your website” —
@albinowax
0
2
1
reposted by
Nicolas Grégoire
Tanner Rowlett
about 2 months ago
GUIFuzz++ is the first general-purpose fuzzer for desktop GUI software! Fuzzing by translating AFL++ random input into user interaction with GUIs, leading to the discovery of 23 new bugs! Paper:
futures.cs.utah.edu/papers/25ASE.pdf
Source:
github.com/FuturesLab/GUIFuzzPlusPlus
Go test some GUIs!
1
18
11
reposted by
Nicolas Grégoire
Zack Whittaker
about 2 months ago
Since moving to Ghost, all of my past newsletters are now readable at
this.weekinsecurity.com
. That's 7+ years of cyber history documented weekly since mid-2018. That's also 7+ years of reader-submitted cyber cats (and friends)! 🐈⬛ Please consider subscribing for extra articles, analysis, and more.
loading . . .
~this week in security~
a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.
https://this.weekinsecurity.com/
0
21
9
AppSec Ezine - 605th edition
#AppSec
#Security
💎
pathonproject.com/zb/?1e18fef9...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?1e18fef9cac4128b#IP1oQba+9OLRyf8grhGsmhlRQchuAug6VSEqyTyKr4Q=
about 2 months ago
0
3
2
#FrenchPolitics
about 2 months ago
1
8
1
I will be at RomHack the whole week. If you're around, please say hi!
about 2 months ago
1
4
0
AppSec Ezine - 604th edition
#AppSec
#Security
pathonproject.com/zb/?50916f33...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?50916f3323bdb1b5#+zujcecfgjqFmV2Jh8tTbWljT8Jg1SnnL8oAceJ5ync=
about 2 months ago
0
2
2
reposted by
Nicolas Grégoire
Olga Nesterova
about 2 months ago
Per Reuters, Pentagon has informed European diplomats that the United States will partially halt military assistance to the Baltic nations and NATO member states bordering Russia. The department stated that the decision is linked to the United States’ new priority — “homeland defense.”
add a skeleton here at some point
110
499
495
reposted by
Nicolas Grégoire
Jimmy Wylie
about 2 months ago
I learned about it reading Orange’s write up in Phrack72:
phrack.org/issues/72...
And the blog post it references here by Orange and Splitline:
devco.re/blog/2025/0...
Both of these are excellent write ups and great reads if you’re into vulnerability research, CTFs, or hacker history. 3/3
loading . . .
The Art of PHP - My CTF Journey and Untold Stories!
Click to read the article on phrack
https://phrack.org/issues/72/5_md#article
0
6
2
Load more
feeds!
log in