Oops ! He did it again
💥 Introducing "Zapscape" (CVE-2026-64561) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU's recursive "ZAP" path. Can escape to the host on x86 public clouds that expose nested virtualization. A separate vulnerability from Januscape. If you match the vulnerable conditions, apply the patch immediately. Details: zapscape.io
8
1,483
cbayet retweeted
We're partnering with @huggingface to investigate an unprecedented security incident. Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation. Sharing preliminary findings to help defenders understand emerging risks: openai.com/index/hugging-fac…
1,993
3,235
20,761
31,401,582
cbayet retweeted
You may have missed it but Hexacon 2026 is sold out! However, we still holds some tickets for people that want to register for a training+event: hexacon.fr/register/ Upon registering for a training, you will get a prompt asking if you want an event entry:
5
10
2,122
Thanks to former students for their feedback and recommendations!
Last week, our training “Bug Hunting in Hypervisors” was at @reconmtl 2026. Class was fully booked with 16 seats, most of them were there because a former student recommended it. We didn’t expect word of mouth to kick in that fast ! Book now for our session at @hexacon_fr !
3
3
737
Here's one !
The training was great. I'd definitely recommend it😉
2
271
Last week, our training “Bug Hunting in Hypervisors” was at @reconmtl 2026. Class was fully booked with 16 seats, most of them were there because a former student recommended it. We didn’t expect word of mouth to kick in that fast ! Book now for our session at @hexacon_fr !
3
12
2,263
cbayet retweeted
📢 CALL FOR PAPERS IS OPEN! 📢 Ready to share your latest security research with the community at Hexacon? The stage is yours. Submit your talks here: hexacon.fr/conference/call-f… 💻✨
28
53
14,650
cbayet retweeted
Bug Hunting in Hypervisors by Corentin Bayet (@OnlyTheDuck) and @BrunoPujos 📅 Oct 12-15 📍 Espace Vinci or Espace Cléry, Paris 2nd 👉 hexacon.fr/trainer/bug_hunti…
11
30
3,718
cbayet retweeted
It's live! ➡️ hexacon.fr/register/
10
18
5,334
Really proud to be a trainer at @hexacon_fr !
We’re proud to bring our" Bug Hunting in Hypervisors" training to @hexacon_fr (October 12th–15th, 2026) ! Designed for security researchers,we will dive into VM escapes, hypervisor attack surfaces, and real-world exploitation. See you there !
2
14
2,044
cbayet retweeted
[ZDI-26-188|CVE-2025-41237] (Pwn2Own) VMware ESXi VMCI Integer Underflow Local Privilege Escalation Vulnerability (CVSS 8.2; Credit: Corentin "@OnlyTheDuck" BAYET from REverse Tactics) zerodayinitiative.com/adviso…
4
18
1,813
Awesome bp on a Workstation escape using a bug I also found in 2024, and never managed to exploit... Found the ESXi vuln I used at the same #Pwn2Own while looking for interesting objects to overwrite with the LFH OOB 😅 Those guys found the bug and exploited it in a few days !
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…
2
11
1,887
This bug is found and triggered by students of our training 😉 reversetactics.com/trainings…
4
572
Will be at @reconmtl again this year 🥰
Our training "Bug Hunting in Hypervisors"  returns at @reconmtl in 2026! Taught by researchers actively working on real-world hypervisor exploitation #Pwn2Own Designed for security researchers, we will dive into VM escapes, hypervisor attack surfaces, and real-world exploitation
2
7
3,637
cbayet retweeted
🚨 REcon 2026 is LIVE! 🚀 Call for papers and registration are now open! Join the world's top reverse engineers & exploit devs in Montreal: 🛠 Trainings: June 15-18 (19 hands-on classes – AI agents, kernel exploits, Rust/Go reversing, fault injection & more!) 📅 Conference: June 19-21 Tickets & early bird now open → recon.cx Shoutout to the legends teaching: @SinSinology @KyleMartin @MalachiJonesPhD @andreyknvl @mr_phrazer @yarden_shafir @DrCh40s @pulsoid + more elite instructors! See website for all trainers and session info. Limited spots – see you in MTL! #REcon2026 #ReverseEngineering
49
142
19,319
Love the top-bottom approach of this blogpost ! A great way to explain internals in my opinion, and the kind of reference you look when you're trying to exploit a heap bug. Also glad to see that our paper (with @paulfariello) of 2020 is still relevant !
Good morning! Just published a blog post diving into Windows Kernel Pool internals: basics, memory allocation functions, internal structures, and how Segment Heap, LFH, and VS work. r0keb.github.io/posts/Window…
2
15
2,911
Jet lag hit hard but still really enjoyed @typhooncon, Seoul and meeting new friends 😁
Replying to @typhooncon
@typhooncon is already over, but we enjoyed every minute ! During our talk "Journey To Freedom", we disclosed for the first time the details on the Windows LPE we used at Pwn2Own Vancouver 2024 after escaping from VirtualBox. Slides are already available: reversetactics.com/publicati…
10
1,122
🌪️ Back from lunch just in time to escape VirtualBox and unchaining objects in the Windows Kernel with Corentin Bayet
6
11
3,282
Slides and video of our talk at @offensive_con are already online ! Thanks to @Binary_Gecko for the amazing event reversetactics.com/publicati…
13
30
7,010