Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Security Research Labs

@srlabs@infosec.exchange
  • Open on infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

0 Followers
0 Following
11 Posts
Joined December 08, 2022

Posts

Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Mar 17, 2026
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

https://srlabs.de/blog/hacking-ai-agent

#AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

37
0
46
1
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Jul 01, 2025
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

Unveiled at #TROOPERS25 - Hexagon fuzzing unlocked

Hexagon is the architecture in Qualcomm basebands - they power most of the world's leading smartphones.

Until now, this baseband was out of reach.

We released the first open-source toolchain for system-mode Hexagon fuzzing, presented by Luca Glockow (@luglo@infosec.exchange), Rachna Shriwas, and Bruno Produit (@bruno@social.pileus.ch) at @WEareTROOPERS@infosec.exchange

Full post: https://www.srlabs.de/blog-post/hexagon-fuzz-full-system-emulated-fuzzing-of-qualcomm-basebands

How we opened up mobile firmware in 3 steps:
1. Boot real iPhone basebands with a custom QEMU fork
2. Rust-powered fuzzer controls execution via JSON configs
3. Ghidra integration maps coverage across threads

This brings full visibility to Qualcomm’s 4G/5G/GPS stacks.

Reproducible. Extendable. Open source.

Hexagon’s no longer off-limits - mobile security just got a lot more transparent.


🔗 Try it yourself: https://github.com/srlabs/hexagon_fuzz
📚 Docs: https://github.com/srlabs/hexagon_fuzz/blob/main/docs/reverse_engineering.md
🖥️ Slides from Troopers25: https://github.com/srlabs/hexagon_fuzz/blob/main/docs/talk/hexagon_fuzz_troopers2025.pdf
🛠️ Issues, ideas, or contributions? PRs welcome.

infosec.exchange

Infosec Exchange

34
4
35
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Apr 16, 2025
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

Currently available Go fuzzing tools were missing critical features - some don’t play well with the latest Go toolchain. So we set out to change that.

@bruno@social.pileus.ch, Nils Ollrogge, and colleagues explored more powerful ways to fuzz Go binaries. By tapping into Go’s native instrumentation — which is compatible with libFuzzer — we enabled effective fuzzing of Go code using LibAFL.

We’ve documented our approach and shared insights in our latest blog post: https://www.srlabs.de/blog-post/golibafl---fuzzing-go-binaries-using-libafl

Repo: https://github.com/srlabs/golibafl

17
4
19
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Sep 18, 2024
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

It has long been known that timing analyses are a *theoretical* attack on Tor. By distributing the circuits across different jurisdictions, the goal was to make these attacks impractical to implement:

Only a "global adversary" should be able to break the anonymity by correlating the traffic from entry and exit nodes. Correlation becomes even easier if delays or content can be actively introduced into the traffic pattern.

Just as we could (theoretically) become a "global adversary" by renting enough servers, law enforcement agencies can (practically) achieve this through close cooperation, especially since Tor nodes are not evenly distributed across jurisdictions but tend to cluster in certain regions.

Western law enforcement agencies seem to have reached the "global adversary" level through collaboration (in isolated cases and certainly with significant effort). What is problematic for Tor is that other "law enforcement agencies," whose focus is on dissidents, whistleblowers, and journalists, could do the same.

So, it is finally time for cover traffic and random delays: nodes in the Tor network would introduce a random traffic background noise as well as random delays to make targeted correlations more difficult. This would make Tor even slower. This is probably why it has been avoided until now.

In conclusion, we would like to emphasize that there is no reason for regular users of the Tor browser to worry about their anonymity. These are highly targeted attacks on individual accounts of the messenger "Ricochet" over extended periods of time. Because the messenger, unlike a browser, is also reachable, it naturally has an increased attack surface for timing analyses.

https://www.tagesschau.de/investigativ/panorama/tor-netzwerk-100.html

14
0
15
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Jun 27, 2024
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

Our Red Team regularly challenges Fortune 500 defenses. Often times, a decent ADCS honeypot could have stopped us.

So we built one.

Blog post: https://www.srlabs.de/blog-post/certiception-the-adcs-honeypot-we-always-wanted

Source code: https://github.com/srlabs/Certiception/

Presentation at @WEareTROOPERS@infosec.exchange, including a strategic guide to deception: https://github.com/srlabs/Certiception/blob/main/documentation/The_Red_Teamers_Guide_To_Deception.pdf

4
0
4
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · May 08, 2024
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

New Research – #BogusBazaar, a sprawling criminal fake webshop network:

• 75,000+ domains
• 450,000+ credit cards
• 1 million fraud cases
• USD 50+ million in fake orders

We publish our insights together with an international team of journalists from Die Zeit (Germany), The Guardian (United Kingdom), and Le Monde (France).

https://www.srlabs.de/blog-post/bogusbazaar

53
0
85
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · May 07, 2024
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

After months of intensive research, we are ready to drop new insights on yet another criminal group.

You might want to pick up a copy of Die Zeit (German), The Guardian (English) or Le Monde (French) tomorrow ;)

Stay tuned for updates!

37
0
28
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Feb 20, 2024
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

SRLabs joins Allurity!

We joined Allurity, a group of seven cyber pioneers across Europe. Starting SRLabs Chapter 2 today!

Over the past decade, our team of SRLabs hacking wizards helped clients all over the world push the envelope on hacking resilience.

In Allurity, we found a partner with a shared vision of how IT security should be done. Very happy to join forces with some of Europe’s greatest in our mission to bring effective security to innovation leaders.

Together, we continue fusing hacking with consulting, while exploring technology through research – just a bit more of everything.

A special thank you to our SRLabs teammates and alumni who made SRLabs Chapter 1 an ever-exciting journey!

Looking forward to the next chapter – together with our Allurity sisters!
@CSIS @Securix @Aiuken @IDNorth @Arcticgroup @cloudcomputing

https://allurity.com/cybersecurity-group-allurity-strengthens-its-position-through-the-acquisition-of-globally-recognized-srlabs/

2
0
1
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Jan 15, 2024
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

Unlocked - Ransomware edition 🔓🔧

Our colleague Tobias rocked the stage at #37C3 releasing your free decryptor for Black Basta – Germany's "second most used ransomware."

Watch the full talk including cryptographic kung fu: https://media.ccc.de/v/37c3-11903-unlocked_recovering_files_taken_hostage_by_ransomware

You can find the decryptor on Github: https://github.com/srlabs/black-basta-buster

For a closer look at our Black Basta research, stay tuned for a detailed blog post!

Bust Black Basta with the Black Basta Buster, basta!

5
0
2
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Oct 25, 2023
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

Meet @iyskierka@infosec.exchange Security Consultant at SRLabs! Watch her video where she shares her work experiences and OSCP study tips. 🔒💻
https://youtu.be/AzoZ1gnIo9Y?si=2zYbXtPHpkB3wUAo

0
0
0
0
Open post
srlabs
Security Research Labs @srlabs@infosec.exchange · Sep 05, 2023
Security Research Labs
@srlabs@infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

infosec.exchange

We have 6 solves so far on our SRLabs hacking challenges!🔓
As expected, the #telco challenge is the hardest to crack.

Do you want to hack a telco network or try the crypto and pwn categories?
https://hackingchallenge.srlabs.de

Running until 21.09
Discord: https://discord.gg/vusPXQzhVa

#ctf

1
0
1
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:28:07 UTC