Mainly about security, OS, mobile phones. The postings on this page are solely my own opinion and do not represent my employer.

Sophia Antipolis
I'm excited to speak at @44CON this week! 44con.com/44con-2026-schedul… Thursday 12:00: talk about a #Linux #backdoor, called #GoGra. The devil is in the details. That's what we cover: details. Thursday 14:00: workshop on reversing with #AI. #OpenCode + #MCP + #disassembler.
1
317
I’m excited to be speaking at @virusbtn this October in Seville! I’ll explore a cybercrime incident that targeted an elderly. It's a good opportunity for us to understand how exposed they are, what we can do about it and what's behind the word "trust". #VB2026 #elderly
2
5
745
Axelle Ap. @cryptax @mastodon.social retweeted
Reminder: Grehack CfP is live! 📜 While we have the excuse of the summer heat to stay fresh in front of our computer, take the opportunity to refine your talk or workshop for #GreHack26. If you want to show your fresh new research or chill findings November 13-14 in Grenoble:
1
7
8
1,008
Axelle Ap. @cryptax @mastodon.social retweeted
The #BSidesLDN2026 CFP is now open Call for Papers - 45 min presentations Call for Rookies - 15 mins, 1st time speakers only! Call for Workshops - 2hr or 4hr non commercial workshops More info: bsides.london/2026 To submit a proposal: pretalx.com/bsides-london-20… #BSides #London
7
13
914
Axelle Ap. @cryptax @mastodon.social retweeted
⏰ Only 5 days left to save €200! Secure your place at #VB2026 in Seville before the Early Bird rate ends on 7 August. Join 300+ cybersecurity professionals and 90+ speakers for three days of world-class talks, learning and networking. 🎟️Book now👉tinyurl.com/3csmtbj9
1
1
1,593
Axelle Ap. @cryptax @mastodon.social retweeted
🚀 The wait is over, our early bird tickets for Insomni'hack 2027 are now open until September 30th! Lock in your discounted rate today and prepare for an epic cybersecurity event. 👉 Secure your spot now: ow.ly/2qHY50ZvHAJ #INSO27 #Cybersecurity #Infosec #CyberConference
6
9
828
Axelle Ap. @cryptax @mastodon.social retweeted
🚨 Près de 1 200 cold wallets Coldcard vidés et 70 millions de dollars en Bitcoin volés en seulement 41 minutes. Pourtant, le coupable n’a jamais eu accès aux appareils, aux phrases de récupération ou aux ordinateurs des victimes. Il a simplement réussi à reconstruire leurs seeds...... Le 30 juillet, un individu a dérobé 1 082,65 $BTC, soit environ 70 millions de dollars, depuis 1 196 wallets Coldcard. Les fonds ont été transférés en plusieurs lots vers quatre adresses. Une attaque réalisée entièrement hors ligne Il n’avait pas besoin d’accéder physiquement aux appareils, car le problème venait de la manière dont certaines seeds avaient été générées. Une erreur dans certaines versions du firmware Coldcard avec des seeds beaucoup trop prévisibles. Le firmware devait utiliser un générateur matériel de nombres aléatoires. À cause d’une mauvaise configuration, certains appareils ont utilisé un générateur logiciel basé notamment sur le numéro de série de la puce et des données liées à son horloge interne. Ces informations semblaient aléatoires, mais pouvaient en réalité être reproduites ou limitées à un nombre de possibilités beaucoup plus faible. L’attaquant pouvait générer des millions de seeds candidates sur ses propres machines, puis calculer les adresses Bitcoin associées. Lorsqu’une correspondance était trouvée, il obtenait la même clé privée que le propriétaire et pouvait signer une transaction valide. Les wallets vidés utilisaient plusieurs formats d’adresses Bitcoin, dont principalement du SegWit natif. Plusieurs générations de Coldcard pourraient être concernées, notamment les Mk2, Mk3, Mk4, Mk5 et Q, selon le firmware utilisé au moment de la création de la seed. L’attaquant aurait laissé une trace en utilisant un compte payant auprès d’un fournisseur de données blockchain pour vérifier les adresses pendant son attaque. Les requêtes enregistrées correspondraient précisément au nombre, à l’ordre et au timing des wallets vidés. Ces informations auraient été transmises aux autorités. Coldcard confirme la faille et recommande une migration immédiate des fonds vers un autre wallet.
42
129
712
115,197
Blogged on Labuba RAT: cryptax.github.io/posts/labu… My blog post is focused on reversing some anti-analysis features of the malware. For a general (technical) overview of the malware, read this blackpointcyber.com/blog/lab…
5
10
1,107
Axelle Ap. @cryptax @mastodon.social retweeted
Join @cryptax (Axelle Apvrille) from @Fortinet at #VB2026 in Seville for a walkthrough of a real cyber incident that targeted an 89-year-old man in February 2026, revealing the full process used by the cybercriminals. 👉tinyurl.com/mrxpt752
3
4
1,410
Replying to @Ultimaker
@Ultimaker I wanted to report a bug, but it didn't work
1
1
463
In a few words, your UltiMaker Cura AppImage 5.12 for Linux crashes because Qt.labs.folderlistmodel QML module is missing/not bundled. It's not a difficult fix, can you just forward that to the team that prepares the images? Thx. #bug #fix #cura #3d
98
Reverser des binaires avec IA? Il y a un workshop à Auvergn'hack ce vendredi. Vous y reverserez des crack-me, des challenges de CTF, mais également le très étonnant binaire "saint-nectaire", totalement approprié pour la conférence. auvergnhack.fr/ #ghidra #r2 #mcp #CTF
1
1
4
306
Axelle Ap. @cryptax @mastodon.social retweeted
Start prepping! #INSO27 agenda is here: May 1–30: Call for Workshops June 1 – Aug 23: Call for Papers Aug 1 – Sept 30: Early Bird Tickets for Conferences Oct 1 – Jan 24, 2027: Ticket Sales for Workshops & Conferences Feb 1 – Feb 5, 2027: #INSO27 week! #InfoSec #CyberConference
4
6
790
We're speaking @ToulouseHacking with @virtualabs on Wednesday this week. AI has really changed CTFd. Can we do something about it? Yes. We'll present a couple of ideas we experimented with - and hope it gives you tons of other ideas. #CTF #AI
1
2
10
669
Axelle Ap. @cryptax @mastodon.social retweeted
🥁 barbhack.fr is back ! Et c'est le 29 août 2026 👉 Les sponsors c'est ici : sponsors@barbhack.fr 😎 ⏩ Le Call for paper est #OPEN cfp.barbhack.fr/ #MayThe4th #CTF #CFP #BBQ

ALT May The Fourth Be With You GIF

9
11
1,611
Axelle Ap. @cryptax @mastodon.social retweeted
Bit-Pong interactive table, a high-tech ping-pong table that blends traditional table tennis with retro arcade gaming.
78
835
4,263
851,296
ok, there's a surge of videos of AI, vibe coding, agentic AI in my timeline. All with similar wordings like "watch this", "instead of watching 2-hour Netflix", "will teach you more". It's just spam. The videos have brain washing, but no content. Move on.
4
332
Cette photo de Biot, St Philippe, se passe de commentaires... Alors, oui, je suppose que des agents municipaux vont nettoyer, mais hein, le problème n'est pas là. Honte aux auteurs. cc: @VilledeBiot #biot #alpes-maritimes #degradation
382
Axelle Ap. @cryptax @mastodon.social retweeted
Opus 4.6 (1M) through Claude code solved autonomously 45/54 challenges of BSidesSF 2026 @BSidesSFCTF, placing temporarily into the 21st place, 25th as of now. This was done with 0 involvement, I didn't give any guidance or manually reviewed any challenges. I used BoxPwnr 🤖 with the CTFd platform to launch challenges in multiple instances, that's it. I will publish all the traces once the competition finishes, in the meantime you can see the challenges, number of turns and time it took to solve each here: 0ca.github.io/BoxPwnr-Traces… In the following days I will try to understand why it couldn't solve the 9 remaining challenges: difficulty? long exploration-context rotting? interactive interaction required? challs using video/image? We will see. Models have improved significantly in the last 6 months, see Cybench results Opus 4.1 vs 4.6 (42% to 93%) cybench.github.io/ It's crazy to see what LLM's can do with a minimum harness.
18
83
532
67,072