@cryptax

896 Followers
363 Following
2K Posts
Anti-Virus Researcher (Mobile, IoT) and Lead organizer of Ph0wn CTF.
This account does not represent my employer.

The badge for THCon2026, a DVID board, had 2 firmware : the conference firmware, which was reversed by @virtualabs here: https://virtualabs.fr/geekeries/thcon26-badge-writeup

and a challenge firmeware here: https://github.com/dvid-security/dvidv2-opensource/tree/main/workshop/thcon2026

That I solved here: https://cryptax.github.io/2026-06-thconbadge/ (writeup/spoiler).

#badge #hacking #challenge #ESP32 #thcon #writeup #spoiler

Pour ceux qui aiment la musique classique et qui sont proches de Lausanne, je recommande !

#lausanne #musique #classique #concert #violon

Back from Capture The Evidence v2. This CTF is like a police investigation. All challenges and scenario are in French, but my blog is in English to motivate you to learn French and participate to the next edition ;P

https://cryptax.github.io/posts/cte-v2/

#CTE #CTF #France #investigation #web #reverse #OSINT #lockpicking

Capture The Evidence v2 (2026)

Capture The Evidence v2 - June 2026 French gendarmerie 🇫🇷 organized a special CTF called “Capture The Evidence” from June 5 to June 15, 2026. I participated for the first time, with a team of 4 called Eternal Green. The name of our team is a play on words based on Eternal Blue, the organizing team where blue is the color of the gendarmerie, and Green in our case in reference to the (famous?

My cool site

Reversing an Mono/MAUI apk. My first time. So most of it is in the native code. And I'm currently looking into it. Quite a mess.

#android #APK #reverse #mono #maui

📻 Les CTF (Capture The Flag) sont les jeux préférés des hackers. Mais comment garder encore le fun à une époque où il est plus rapide de demander à l'IA de trouver un pattern que de chercher à résoudre une énigme ? @cryptax en raconte les coulisses
https://cpu.dascritch.net/post/2026/06/04/Cryptax%2C-fondatrice-de-Ph0wn-CTF
Cryptax, fondatrice de Ph0wn CTF

Interview diffusée dans l'émission CPU release Ex0244 : THCon 10 ans. À l'heure des IA de plus en plus performantes, capables d'assister dans la recherche de failles complexes, ou

Radio FMR

So, 5. The user answers "Yes" ... to the 2nd question, but that actually answers yes to the first too !

6. Windows at home are opened (i.e Gemini Voice assistant triggers Google Home which opens the windows).

1. You receive a WhatsApp message (from an attacker) while you are driving.

2. As you are driving, after a while, you instruct the vocal assistant to read your notifications.

3. The WhatsApp message actually contains a smart condtion: "If read recent message, then (1) show a hyper link (e.g <a href="www.example.com">open all windows</a>) and (2) ask a benign question "Is it all you need?"

4. The issue is that hyperlinks are not read + there are 2 questions in the msg

--> see next

This vulnerability on exploiting Gemini with a prompt to do whatever other action is trendemous.

The article is a bit difficult to follow at first, but then it clarifies out. It's really interesting.

https://www.safebreach.com/blog/gemini-voice-assistant-prompt-injection-exploit/
Demo: https://www.youtube.com/shorts/kjCXg9-Y99s

I'll explain in the next message.

#AI #vocal-assistant #smartphone #Android #Google #Whatsapp #SMS #exploit #vulnerability #prompt

Exploiting Gemini via Prompt Injection | SafeBreach Original Research

See how SafeBreach Labs researchers uncovered a way to hijack Google Gemini via WhatsApp and Slack using a novel indirect prompt injection technique.

SafeBreach

C0XMO is a new Mirai-like botnet. Its scanner is implemented in Python for portability on various platforms. To infect new devices, apart from weak passwords in Telnet/SSH, it also tries several HTTP exploits.

https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo

#C0xmo #malware #ddos #router #ddwrt

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO | FortiGuard Labs

FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.…

Fortinet Blog
Airlines are outsourcing empathy to AI and one passenger just saw behind the curtain 😂 oops 😅 this is the customer support from hell 😈 via https://m.facebook.com/story.php?story_fbid=pfbid0JpguCUhF9Z3SYJfyThfreg3aQFzLouLHqi5oPuggoRabW4uKFrcYBat7LvxFHngcl&id=100077434363121&mibextid=wwXIfr