Trending
Aloïs Thévenot's Avatar

Aloïs Thévenot

@techbrunch.fr

Jack of all trades, master of some. CTO / Pentester

48
Followers
294
Following
24
Posts
04.07.2023
Joined
Posts Following

Latest posts by Aloïs Thévenot @techbrunch.fr

Chrome 137+ added a CNG wrinkle to App-Bound Encryption.

@harmj0y.bsky.social & @tifkin.bsky.social share how Nemesis 2.2 handles it, automating DPAPI decryption from SYSTEM & user masterkeys through Chromekey1 to cookie/login recovery, w/ retroactive artifact linking. https://ghst.ly/3OzfkFN

04.03.2026 18:08 👍 0 🔁 2 💬 0 📌 0
What’s Running on That Port? Introducing Nerva for Service Fingerprinting

What’s Running on That Port? Introducing Nerva for Service Fingerprinting

02.03.2026 17:39 👍 0 🔁 1 💬 0 📌 0
Preview
Havoc Professional Release The initial release of the long awaited Havoc Professional and the Kaine-kit is finally here and new team member.

Havoc Professional Finally Released! 🕸️🕷️

I'm excited to finally share the work my team and I have put in over the past year. This is just the beginning of what we have planned.

www.infinitycurve.org/blog/release

24.02.2026 01:50 👍 5 🔁 4 💬 0 📌 0
Preview
Don’t expose yourself in public — let AWS error messages do it for you AWS now reveals public permissions in error messages. Learn how a deny-all session policy exposes which actions would succeed safely.

Hey wake up! New offensive AWS meta just dropped! Thanks to Daniel Grzelak, we now have an effective oracle for determining if resources are publicly exposed without leaving logs. (As an offsec person) LFG!!!

www.plerion.com/blog/dont-ex...

20.02.2026 15:43 👍 2 🔁 2 💬 0 📌 0
Post image

On Apple M3, a Linux KDE plasma desktop under Fedora Asahi Remix is now WORKING! Super excited to share this update and happy to answer any questions! Co-credits to noopwafel and Shiz. :)

26.01.2026 11:26 👍 413 🔁 69 💬 15 📌 11
Preview
On the Coming Industrialisation of Exploit Generation with LLMs Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…

We are on the verge of the commoditization of exploitation. Every vuln will functionally have a public PoC available because attackers can generate them in minutes.

The advantage will increasingly belong to organizations that can detect, respond, and contain fast.

sean.heelan.io/2026/01/18/o...

19.01.2026 03:24 👍 6 🔁 2 💬 0 📌 0
Preview
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8554 | Datadog Security Labs A look at how Kubernetes CVE-2020-8554 works

I've been meaning to write more about "the unpatchable 4", which are a set of Kubernetes CVEs for which there are no patches, you need to mitigate them with configuration or architecture choices.

First up is CVE-2020-8554.

securitylabs.datadoghq.com/articles/unp...

14.01.2026 09:46 👍 11 🔁 6 💬 0 📌 0
Preview
Last Week in Security (LWiS) - 2026-01-12 SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more!

SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more!

blog.badsectorlabs.com/last-week-in...

13.01.2026 22:08 👍 1 🔁 1 💬 0 📌 0
Preview
Fortinet warns of critical FortiCloud SSO login auth bypass flaws Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO…

Fortinet warns of critical FortiCloud SSO login auth bypass flaws www.bleepingcomputer.com/news/securit...

10.12.2025 18:43 👍 0 🔁 1 💬 0 📌 0
LOC record - Wikipedia

TIL: On peut mettre des coordonnées GPS dans un record DNS !
en.wikipedia.org/wiki/LOC_rec...

Pour tester ça : on se retrouve à l'adresse une-tasse-de.cafe le 12 & 13 février 😇

09.12.2025 15:36 👍 8 🔁 2 💬 0 📌 1
Preview
Red Team Ops II Gain the knowledge and skills necessary to operate against advanced defences.

The new version of RTO II is finally available to purchase.
www.zeropointsecurity.co.uk/course/red-t...

28.11.2025 14:30 👍 11 🔁 8 💬 1 📌 1
Preview
'Unauthorized' Edit to Ukraine's Frontline Maps Point to Polymarket's War Betting It looks like someone invented a fake Russia advance in Ukraine to manipulate online gambling markets.

So it sure looks like someone invented a fake Russian advance in Ukraine to manipulate the online gambling market Polymarket. Gamblers are making money by betting on the outcomes of battles big and small in the war. Edited map is run by DC-based think tank

www.404media.co/unauthorized...

01.12.2025 18:48 👍 251 🔁 111 💬 13 📌 37
Preview
Pesticides : quand les équipements censés protéger exposent davantage Peu adaptées aux conditions de travail réelles des agriculteurs, les équipements censées les protéger des expositions aux pesticides se révèlent bien souvent inefficaces voire même néfastes.

Un rappel sur la fiction du contrôle des risques que constituent ces équipements pour les agris.

theconversation.com/pesticides-q...

17.11.2025 19:27 👍 14 🔁 6 💬 1 📌 1
Preview
Release 3.1.0 · sensepost/gowitness A new release, this time focussing on performance and various bug fixes! Thanks to all of the contributors! Enjoy! 🎉 New Refactor the chromedp driver, focussing on performance. The new implementat...

Landed a new gowitness release, this time focussing on performance! 🎉 v3.1.0

github.com/sensepost/go...

17.11.2025 19:31 👍 2 🔁 2 💬 0 📌 0
Preview
TOAD Attacks via Entra Guest Invites A new reverse phishing campaign uses Microsoft Entra Guest invites to bypass email filters.

Actual threat intelligence! A few friends and I identified a new reverse phishing campaign leveraging Entra Guest User invitations.

This campaign was newly discovered and corroborated. I recommend reviewing organization email for these invitations.

taggart-tech.com/ent...

14.11.2025 18:12 👍 5 🔁 4 💬 0 📌 1
Preview
Insiders – Now free for everyone - Material for MkDocs We just released 9.7.0 – the final version of Material for MkDocs, which includes all features that were previously exclusive to sponsors

📣 Material for MkDocs Insiders now free for everyone!

With 9.7.0, we release all Insiders features previously exclusive to sponsors! This marks the last version of Material that includes new features, as we now enter maintenance mode.

A thread ⬇ 1/4

squidfunk.github.io/mkdocs-mater...

11.11.2025 16:21 👍 8 🔁 4 💬 2 📌 0

Same, I followed their webinar and now I'm less worried about getting replaced by AI :)

13.11.2025 19:34 👍 0 🔁 0 💬 0 📌 0
Preview
Nano Banana can be prompt engineered for extremely nuanced AI image generation Nano Banana allows 32,768 input tokens and I’m going to try to use them all dammit.

New blog post up: I spent a lot of time researching Nano Banana, Google's new generative AI model, and not only is it substantially better than ChatGPT, it is capable of taking extremely nuanced prompts even thousands of tokens long to generate exactly what you want. minimaxir.com/2025/11/nano...

13.11.2025 17:40 👍 26 🔁 3 💬 0 📌 0

"I did give a heads up to Elastic before publishing this post. They have taken this technique into account and are working on updates to the detection rules to catch this."

"Provided as a Crystal Palace shared library. Format inspired by @rastamouse.me 's LibTP. "

Ground truth security research.

06.11.2025 15:38 👍 5 🔁 2 💬 0 📌 0
Introduction - OWASP Top 10:2025 RC1 OWASP Top 10:2025 RC1

Here we go, new OWASP Web Top 10:

06.11.2025 17:52 👍 1 🔁 2 💬 0 📌 0
Preview
FBI Tries to Unmask Owner of Infamous Archive.is Site The FBI has subpoenaed the domain registrar of archive.today, demanding information about the owner.

The FBI is trying to unmask the owner of infamous archiving site Archive.is, according to a subpoena the site posted. No other information given, the site quietly posted the document a few days ago. FBI telling domain registrar to hand over all sorts of ID'ing info
www.404media.co/fbi-tries-to...

06.11.2025 15:16 👍 550 🔁 279 💬 22 📌 29
Video thumbnail

Found an XSS but got blocked by the CSP?

https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇

21.10.2025 09:16 👍 7 🔁 6 💬 1 📌 0
Parts 136 and 137 of the UK ICO report detail the Costs of Implementation of Active Directory tiering at Capita. Specifically, acknowledging that this Standard of Care requires a complex, potentially costly, and resource-intensive task to meet.

Parts 136 and 137 of the UK ICO report detail the Costs of Implementation of Active Directory tiering at Capita. Specifically, acknowledging that this Standard of Care requires a complex, potentially costly, and resource-intensive task to meet.

Penalty Notice Capita Plc by UK ICO

Detailed breach analysis after 2023 ransomware attack. £14M fine. Which standards of care weren't met?

* Understaffed SOC (1 analyst/shift)
* 58hr SOC response vs. 4.5hr AD takeover
* Failure to implement Active Directory tiering.

ico.org.uk/media2/pv5nh...

16.10.2025 08:34 👍 3 🔁 2 💬 0 📌 1

pagedout.institute ← we've just released Paged Out! zine Issue #7
pagedout.institute/download/Pag... ← direct link
lulu.com/search?page=... ← prints for zine collectors
pagedout.institute/download/Pag... ← issue wallpaper
Enjoy!

Please please please share to spread the news - thank you!

04.10.2025 10:40 👍 19 🔁 17 💬 1 📌 3

I'll unpack a few thoughts on this...

28.09.2025 05:11 👍 4 🔁 1 💬 1 📌 0
Preview
‘I Was a Weird Kid’: Jailhouse Confessions of a Teen Hacker Noah Urban’s role in the notorious Scattered Spider gang was talking people into unwittingly giving criminals access to sensitive computer systems.

A lire, le long récit saisissant de la dérive criminelle de Noah Urban par Bloomberg www.bloomberg.com/news/feature...

25.09.2025 07:56 👍 1 🔁 1 💬 0 📌 0
Post image

1/ PingCastle now highlights when no policy is in place to prevent scripting files (such as .js) from being executed via double-click.

21.09.2025 11:06 👍 1 🔁 1 💬 1 📌 0
A meme I created. It shows Calvin (from Calvin & Hobbes) seated at a table with a sign saying "Chaining two instances of Burp Suite is such an underrated technique. Change my mind"

A meme I created. It shows Calvin (from Calvin & Hobbes) seated at a table with a sign saying "Chaining two instances of Burp Suite is such an underrated technique. Change my mind"

The talk @parsiya.bsky.social gave at Defcon should be a required read for all users of Burp Suite

Bonus point: it contains a meme I created 😊

github.com/parsiya/Pres...

16.08.2025 20:21 👍 8 🔁 5 💬 1 📌 0
A top-level overview of the presentation presented as a grid of thumbnails, showing 42 slides.

A top-level overview of the presentation presented as a grid of thumbnails, showing 42 slides.

Thank you to everyone who made it out for my DEF CON 33 presentation, "Shaking Out Shells With SSHamble", you can find the materials online at hdm.io/decks/MOORE%...

This deck includes some lightly-censored zero-day (more decks @ hdm.io)

10.08.2025 21:14 👍 9 🔁 4 💬 0 📌 1