Vous êtes victime d’un incident de sécurité ? Contactez notre CERT

Publication of a security audit report performed on Shibboleth

Our internal Security Evaluation Laboratory conducted recently a security audit of Shibboleth. This audit aim was to assess the security level of the identification and authentication capabilities of Shibboleth, mainly targeting SAML, OpenIDConnect and Multi-Factor authentication, focusing on code source analysis and dynamic testing and analysis of the authentication mechanisms.

Custom Memory Management in HAProxy

HAProxy operates under a master-worker process model. The master process is launched with elevated privileges and is responsible for spawning, monitoring, and reloading worker processes. Each worker runs inside a chroot and drops its privileges. This architecture drastically reduces the impact of a successful attack.

Publication of a security audit report performed on HashiCorp Vault

During the last months of 2025, our internal Security Evaluation Laboratory had the chance to conduct a security audit of HashiCorp Vault. This audit aim was to assess the security level of Vault, focusing on code source analysis and dynamic penetration testing (configuration handling, authentication and ACL, secure storage of secrets, API robustness).