Sélim Lanouar (@whattheslime) 's Twitter Profile
Sélim Lanouar

@whattheslime

French cyber security auditor and researcher.

ID: 920941331345805312

calendar_today19-10-2017 09:14:58

9 Tweet

57 Followers

144 Following

The Hacker News (@thehackersnews) 's Twitter Profile Photo

Adobe Releases #Security Patch Updates for 11 Vulnerabilities in #Adobe Digital Editions, Framemaker, and Technical Communications Suite thehackernews.com/2018/10/adobe-… Bonus: Updates for Adobe Flash Don’t Include Any Security Fix This Month

Adobe Releases #Security Patch Updates for 11 Vulnerabilities in #Adobe Digital Editions, Framemaker, and Technical Communications Suite

thehackernews.com/2018/10/adobe-…

Bonus: Updates for Adobe Flash Don’t Include Any Security Fix This Month
Ambionics Security (@ambionics) 's Twitter Profile Photo

#Symfony's secret fragments: Learn how a configuration problem leads to Remote code Execution on Symfony-based applications : ambionics.io/blog/symfony-s…

Lexfo (@lexfosecurite) 's Twitter Profile Photo

Introducing sshimpanzee, a reverse shell made by Titouan Lazard based on openssh's sshd. It supports DNS, ICMP and HTTP encapsulation as well as SOCKS and HTTP Proxies : blog.lexfo.fr/sshimpanzee.ht…

Lexfo (@lexfosecurite) 's Twitter Profile Photo

New blogpost by matya ! Discover step by step how we created a Python tool to process large volume of credentials stolen by infostealers! 1/2 bit.ly/3SiNaOw

New blogpost by <a href="/m4tya_/">matya</a> ! Discover step by step how we created a Python tool to process large volume of credentials stolen by infostealers!  1/2
bit.ly/3SiNaOw
Ambionics Security (@ambionics) 's Twitter Profile Photo

We're proud to announce LIGHTYEAR, a tool that let you dump files, blind, in PHP, based on a new algorithm. ambionics.io/blog/lightyear…

Airbus Security Lab (@airbusseclab) 's Twitter Profile Photo

We’re glad to announce we released Soxy!🚀 A Rust-powered suite of services for Citrix, VMware Horizon & Windows RDP. Red teams & pentesters can use it to pivot for deeper access. Get the tool and more details: 🔗 github.com/airbus-seclab/…

Ambionics Security (@ambionics) 's Twitter Profile Photo

GLPI, an open-source IT service management software suite, has released version 10.0.18, addressing two critical vulnerabilities found by our experts : an SQL injection (CVE-2025-24799) and a remote code execution (CVE-2025-24801). Checkout our blog post: blog.lexfo.fr/glpi-sql-to-rc….

GLPI, an open-source IT service management software suite, has released version 10.0.18, addressing two critical vulnerabilities found by our experts : an SQL injection (CVE-2025-24799) and a remote code execution (CVE-2025-24801). Checkout our blog post: blog.lexfo.fr/glpi-sql-to-rc….
Sélim Lanouar (@whattheslime) 's Twitter Profile Photo

🚨 New exploit released 🚨 Converts limited PHP code execution into WordPress administrator account creation & login. CVE-2025-13486 (ACF Extended) 🔗 github.com/whattheslime/C…

BeeRumP (@beerump_paris) 's Twitter Profile Photo

Après 4 ans d'absence, BeeRumP revient ! 🍻 Le concept : des rumps (~10min) et de la bière à volonté, l'occasion de présenter des projets perso avec humour ! La soirée aura lieu dans les locaux d'Epita à Paris, le vendredi 19 juin. Envoyez vos rumps à [email protected] :)

Sélim Lanouar (@whattheslime) 's Twitter Profile Photo

Thanks to the Wordfence team for the bounty! 🙏 A blogpost with detection method and exploitation script will soon be released on blog.lexfo.fr — stay tuned Lexfo Ambionics Security 👀

Sélim Lanouar (@whattheslime) 's Twitter Profile Photo

Check out my first article on Lexfo's blog about a critical vulnerability I found in Ninja Forms File Uploads! (CVE-2026-0740) Python exploit script also available on GitHub: 👉 github.com/whattheslime/C… FOFA Hunter

Lexfo (@lexfosecurite) 's Twitter Profile Photo

Congratulations to our pentester nol on placing 2nd in the Web Senior category at the #FCSC2026 qualifications, with a score of 3,616 points. This kind of result speaks for itself. Best of luck for the next rounds! 🍀 #CTF #Cybersecurity

Congratulations to our pentester <a href="/nol_tech/">nol</a> on placing 2nd in the Web Senior category at the #FCSC2026 qualifications, with a score of 3,616 points.

This kind of result speaks for itself. Best of luck for the next rounds! 🍀

#CTF #Cybersecurity
Wordfence (@wordfence) 's Twitter Profile Photo

Attackers Actively Exploiting Critical Vulnerability in Ninja Forms – File Upload Plugin Estimated 50,000 WordPress sites are affected and should update to version 3.3.27 immediately. A critical vulnerability (CVE-2026-0740, CVSS 9.8) allows unauthenticated attackers to upload