Our second blog post is out here: bugscale.ch/blog/here-we-g… ! We managed to install arbitrary APKs on the Samsung Galaxy S25 from an app without install permissions. For this, @SachaKozma did most of the work, but it was great looking into Samsung's cloud gaming component with him
With @Hacker_Chai we just published our second blog post on Samsung security research! This one is about a local arbitrary APK install in Galaxy Store, combining a few vulns like a broken signature check, a file write, etc. Check it out here: bugscale.ch/blog/here-we-g…
If you missed the talk at @1ns0mn1h4ck , our latest blog post is now available for you to explore.
In this post, researchers @Hacker_Chai and @SachaKozma detail their journey to a 1-click RCE exploit on the Samsung S25 phone.
Check it out here: bugscale.ch/blog/shoot-for…
Our researchers @SachaKozma & @Hacker_Chai are taking the stage at @1ns0mn1h4ck today!
📍 Campus Auditorium B at 13:30
🎯 Shoot for the Galaxies: Our Samsung S25 1-click RCE Journey
If you're into mobile attack surface research, this one's not to miss! #INSO2026#insomnihack
🐞 Bugscale is thrilled to be sponsoring Hexacon again and we look forward to seeing everyone in Paris!
Thank you @bugscale for your continued support 🙏
Here is a new blog post, where I wrote about (some of) my recent work with angr, including:
- Adding support for Windows debug symbols
- Collecting and visualizing real-time coverage
- Improving debugging workflows
plowsec.github.io/angr-introspec…
🔥 We are thrilled to announce our first sponsor!
🙏 Thank you @bugscale for helping us make this highly technical conference possible
🐞 To find out more about Bugscale:
➡️ bugscale.chhexacon.fr/sponsors/#HEXACON2022
Team Bugscale continues #Pwn2Own#AfterDark with a successful exploit of the LAN interface of the NETGEAR R6700 router. They combined an auth bypass and a command injection bug to earn $5,000 and 1 Master of Pwn point. #P2OAustin
Success! The Bugscale team was able to take over a WD My Cloud Pro Series PR4100. They head off to the disclosure 'room' to provide the details of their demonstration. #Pwn2Own#P2OAustin
380 Followers 115 FollowingHeyo, I'm Tomo, 22.
AI/automations engineer @SoundImports.
Currently working on ParetoProof, an end-to-end lean benchmarking platform.
711 Followers 7K FollowingNight comes so people can sleep like fish
in black water. Then day.
Some people pick up their tools.
Others become the making itself.
// Rumi
21K Followers 273 FollowingOffensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
625 Followers 475 FollowingSecurity Engineer interested in Program Analysis with applications in (de)obfuscation, antivirus evasion or vulnerability research.
89K Followers 16 FollowingTrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.