hugow_vincent Profile Banner
Hugow Profile
Hugow

@hugow_vincent

Followers
913
Following
6K
Media
81
Statuses
3K

Red Team and research @synacktiv @rustyphasm.bsky.social

Joined January 2014
Don't wanna be here? Send us removal request.
@hugow_vincent
Hugow
10 months
Are you a cool kid ?.
@Synacktiv
Synacktiv
10 months
Oh, you didn't know? Cool kids are now relaying Kerberos over SMB šŸ˜.Check out our latest blogpost by @hugow_vincent to discover how to perform this attack:.
0
1
15
@hugow_vincent
Hugow
3 days
RT @lampnout: Looking at a Roadrecon collection through the lenses of SQLiteBrowser may pay dividends. It allows you to perform custom SQL….
stmxcsr.com
This post provides a list of SQL queries for the Roadrecon database to audit various areas of Microsoft Entra tenant configuration
0
22
0
@grok
Grok
7 days
Join millions who have switched to Grok.
269
540
4K
@hugow_vincent
Hugow
13 days
RT @_dirkjan: If you didn't find my Black Hat / Def Con slides yet, they are available on . Also includes the demo….
dirkjanm.io
0
69
0
@hugow_vincent
Hugow
14 days
RT @noperator: A new tool: Slice šŸ”Ŗ With the help of build-free CodeQL and Tree-Sitter, Slice can help GPT-5 can reliably reproduce discover….
0
41
0
@hugow_vincent
Hugow
14 days
RT @adnanthekhan: I don’t think people realize how bad this bug could have been. The fact they were vending a multi-tenant GitHub app priva….
0
10
0
@hugow_vincent
Hugow
27 days
RT @Synacktiv: Don't miss @kalimer0x00 at #DEFCON33! .His talk, "SCCM: The Tree That Always Bears Bad Fruits", covers modern attack paths a….
0
20
0
@hugow_vincent
Hugow
27 days
RT @Synacktiv: Catch us at #DEFCON33!.@quent0x1 and @wil_fri3d will show how to turn your Active Directory into the attacker’s C2. They'll….
0
15
0
@hugow_vincent
Hugow
29 days
RT @TheLaluka: Vous ĆŖtes vous dĆ©jĆ  demandĆ© pourquoi PARFOIS il n'y a pas stream ???.Well, soit boulot, soit. CA ! šŸ˜‡..
0
2
0
@hugow_vincent
Hugow
1 month
RT @vcslab: 🚨 Shocking impact from the SharePoint vulnerability we found at Pwn2Own! 😱.Despite our efforts to patch it šŸ¤, many systems are….
0
9
0
@hugow_vincent
Hugow
2 months
RT @frodosobon: Red teaming will go back ten years ago. Proxy Socks (nothing better than chisel) and no Fork&Run / BOF . Only proxychains.
0
3
0
@hugow_vincent
Hugow
2 months
RT @Synacktiv: šŸ” Data encryption in Laravel environments is based on one secret: the APP_KEY. Our ninja @_remsio_ studied the impact of its….
Tweet card summary image
synacktiv.com
Laravel: APP_KEY leakage analysis
0
39
0
@hugow_vincent
Hugow
2 months
RT @_dirkjan: How not to do multi-tenant apps. Nice find by @_harleo from modzero, compromising Synology Active Backup client secrets (from….
Tweet card summary image
modzero.com
0
41
0
@hugow_vincent
Hugow
3 months
RT @coffinxp7: Finally, here’s the detailed article where I walk you through, step by step how to find this vulnerability in real bug bount….
Tweet card summary image
infosecwriteups.com
Hackers Are Earning šŸ’ø$XX,000+ With This Secret Trickā€Šā€”ā€ŠNow It’s Your Turn
0
46
0
@hugow_vincent
Hugow
3 months
RT @TheLaluka: šŸ’£ Hello šŸ’£. Rien de prĆ©vu le 1er Juiller au soir ?.Cool. Maintenant oui ! šŸ˜Ž. RDV Mardi 1er Juillet Ć  21h sur .
0
20
0
@hugow_vincent
Hugow
3 months
RT @Synacktiv: Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromi….
0
261
0
@hugow_vincent
Hugow
3 months
RT @Synacktiv: For the second year in a row, we managed to get first place at the #HackTheBox Business #CTF 2025! šŸ„‡ Congratulations to @gmo….
0
23
0
@hugow_vincent
Hugow
3 months
RT @compasssecurity: Many CI/CD tools promise to keep your dependencies up to date - but if misconfigured, they can expose your organizatio….
0
2
0
@hugow_vincent
Hugow
3 months
RT @YuG0rd: šŸš€ We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability.It allows….
0
373
0
@hugow_vincent
Hugow
4 months
RT @UK_Daniel_Card: I don't bypass an EDR. I might avoid one, or I might just use a legitimate tool that is signed and doesn't alert. Th….
0
10
0