Saturday, 19 September 2026

Friday, 18 September 2026

Ryan & Isabella Barnett, Akamai | Black Hat Stories

Black Hat is where the #cybersecurity community comes together to share ideas, tackle challenges, and learn from one another. Hear from Ryan and Izzy as they share their #BlackHat experience.

source https://www.youtube.com/shorts/lCbjqj9KIQM

Friday, 11 September 2026

Black Hat Stories | Ryan & Isabella Barnett, Akamai

Ryan and Isabella Barnett from Akamai talk about how Black Hat's cutting-edge research helps them stay one step ahead.

source https://www.youtube.com/shorts/p-XAEc3Hc2s

Thursday, 10 September 2026

Black Hat Stories | Ryan & Isabella Barnett, Akamai

On this episode of Black Hat Stories, Ryan Barnett, Senior Threat Research Manager, and his daughter Isabella Barnett, a Software Engineering Intern at Akamai, share what it's like to present together at Black Hat, staying ahead of attackers, and what keeps them coming back year after year. From Isabella's early Black Hat experiences to Ryan's decade-plus of attending, they talk about what makes Black Hat special: the energy, innovation, and community.

source https://www.youtube.com/watch?v=62ljM9dO_ns

Monday, 7 September 2026

Saturday, 5 September 2026

Founder and Creator of Black Hat | Jeff Moss

Black Hat Founder Jeff Moss talks about Black Hat, the evolution of cybersecurity, and what it takes to stay one step ahead.

source https://www.youtube.com/shorts/E9rG0QNF7uQ

Thursday, 3 September 2026

Black Hat Stories | Jeff Moss

Black Hat brings together the people, perspectives, and expertise that help cybersecurity professionals stay one step ahead.

source https://www.youtube.com/shorts/4mmHnhaMf-4

Black Hat Asia 2026 | Mobile Track Spotlight

Mobile security continues to evolve at a breakneck pace, with new attack surfaces, ecosystem shifts, and research breakthroughs reshaping the landscape every year. In this interactive session, members of the Black Hat Asia Review Board will highlight the trends, techniques, and vulnerabilities that stood out during this year's Briefings review cycle. Join us for a fast paced discussion on what's emerging, what's escalating, and what practitioners should be paying attention to next. Bring your questions—this session is designed to be conversational and candid. Anant Shrivastava | Founder, Cyfinoid Research Pamela O'Shea | Director, Shea Security Shanna Daly | CEO, Torin Cyber Group https://ift.tt/vSWGwVg

source https://www.youtube.com/watch?v=QZGwGYxYVCY

Tuesday, 1 September 2026

Black Hat Stories | Jeff Moss, Founder and Creator of Black Hat

In this episode, Black Hat Founder Jeff Moss reflects on the evolution of cybersecurity, the rise of AI and automation, and the growing challenge of separating trustworthy insights from an overwhelming volume of information. In a world of endless content, Black Hat continues to bring together the people, perspectives, and expertise that help cybersecurity professionals learn, connect, and navigate an increasingly complex landscape.

source https://www.youtube.com/watch?v=HbPqeqUm9fQ

Monday, 31 August 2026

Black Hat Asia 2026 | Revealing User Activity on macOS for Apple Silicon

Apple's M-series now powers a huge portion of executive, enterprise, and developer laptops. One blind spot has stayed largely off the radar: interrupt-based side channels where signals raised by normal device activities such as networking, input, and display can be sensed by an unprivileged attacker. We show that a determined attacker can turn those signals into high-fidelity surveillance of user activities on macOS for Apple Silicon. In this talk, we will present TIDE, which works like a stethoscope for the OS: every time macOS returns from the kernel to user space, it produces a tiny, deterministic "heartbeat we can feel from user space". By listening for that heartbeat, TIDE pinpoints exactly when an interrupt occurs without any timers. With TIDE as our sensor, we reverse-engineer Apple's publicly undocumented interrupt delivery and reveal that shared peripheral interrupts are uniformly distributed across all active cores. This quirk means an unprivileged attacker no longer has to "chase the right core" to spy on user activities within the same OS. To demonstrate the effectiveness of TIDE, we will present two live, end-to-end attacks on real Apple Silicon hardware. One is website fingerprinting on Safari with about 94% Top-1 accuracy in closed-world and about 91% in open-world to reveal the websites users have visited. The other is Video fingerprinting with roughly 80% to identifying streaming content from its interrupt patterns. We conclude with potential software-only mitigations Apple can deploy, plus longer-term OS/SoC directions. We call for more parties to join in this effort to enhance the security of macOS. Xin Zhang | Ph.D. Student, Peking University Zhi Zhang | Senior Lecturer, The University of Western Australia Chang Liu | Ph.D. Student, Tsinghua University Qingni Shen | Full Professor, Peking University Trevor E. Carlson | Associate Professor, National University of Singapore https://ift.tt/tNBT93X

source https://www.youtube.com/watch?v=PuQIMyz0BeQ

Sunday, 30 August 2026

Black Hat Asia 2026 | Model Files → Memory Corruption → RCE: The Triple-Stage AI Attack Chain

Amidst the rapid advancement of artificial intelligence technologies, an increasing number of enterprises and individuals are adopting AI solutions. As the core vessel of AI systems, model files encapsulate substantial training outcomes and intellectual achievements from researchers. With the proliferation of large language models and the maturation of open-source communities, leading organizations are actively promoting model open-sourcing and sharing, making cutting-edge models accessible to developers worldwide. However, in practical applications, the model loading process has emerged as a critical security vulnerability hotspot. Existing research reveals significant security risks in the model loading mechanisms of mainstream deep learning frameworks. For instance, PyTorch's historical use of pickle for model serialization introduces inherent deserialization vulnerabilities, while TensorFlow is susceptible to remote code execution (RCE) through maliciously crafted Lambda Layers. More alarmingly, as these frameworks predominantly employ C/C++ implementations for high-performance computing, they remain exposed to conventional memory safety threats such as buffer overflows. This raises a crucial question: Can these memory vulnerabilities be weaponized into complete and reliable RCE attack chains? In this Briefing, to the best of our knowledge, we will present the first publicly disclosed study that systematically exploits memory corruption vulnerabilities in AI model files to achieve reliable remote code execution. By analyzing the memory management mechanisms of mainstream deep learning frameworks, we construct a complete, end-to-end three-stage attack chain — from malicious model files to arbitrary code execution — through carefully designed heap layouts and control-flow hijacking techniques. We further validate the practical exploitability of this attack chain across real-world AI inference systems. Ji'an Zhou | Security Researcher Lei Lu | Security Researcher Li'shuo Song | Security Researcher https://ift.tt/o07khlr

source https://www.youtube.com/watch?v=nQml4Ng9iVc