Thursday, 27 August 2026

Black Hat Asia 2026 | Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices

The rapidly expanding Internet of Things (IoT) landscape is shifting toward cloudless architectures, removing reliance on centralized cloud services but exposing devices directly to the internet and increasing their vulnerability to cyberattacks. Our research revealed an unexpected pattern of substantial Tor network traffic targeting cloudless IoT devices, suggesting that attackers are using Tor to anonymously exploit undisclosed vulnerabilities (possibly obtained from underground markets). To delve deeper into this phenomenon, we developed TORCHLIGHT, a tool designed to detect both known and unknown threats targeting cloudless IoT devices by analyzing Tor traffic. TORCHLIGHT filters traffic via specific IP patterns, strategically deploys virtual private server (VPS) nodes for cost-effective detection, and uses a chain-of-thought (CoT) process with large language models (LLMs) for accurate threat identification. Our results are significant: for the first time, we have demonstrated that attackers are indeed using Tor to conceal their identities while targeting cloudless IoT devices. Over a period of 12 months, TORCHLIGHT analyzed 26 TB of traffic, revealing 45 vulnerabilities, including 29 zero-day exploits with 25 CVE-IDs assigned (5 CRITICAL, 3 HIGH, 16 MEDIUM, and 1 LOW) and an estimated value of approximately $312,000. These vulnerabilities affect around 12.71 million devices across 148 countries, exposing them to severe risks such as information disclosure, authentication bypass, and arbitrary command execution. The findings have attracted significant attention, sparking widespread discussion in cybersecurity circles, reaching the top 25 on Hacker News, and generating over 190,000 views. Yumingzhi Pan | Ph.D. Student, Southeast University Zhen Ling | Professor, Southeast University Yue Zhang | Professor, Shandong University Hongze Wang | Ph.D. Student, Southeast University Guangchi Liu | Professor, Southeast University Junzhou Luo | Professor, Southeast University https://ift.tt/QDxGp3A

source https://www.youtube.com/watch?v=UM-ej4hO9_U

Wednesday, 26 August 2026

Black Hat Asia 2026 | Exploiting DFIR Agents Through Adversarial Manipulation

In recent years, Digital Forensics and Incident Response (DFIR) tools have increasingly adopted Large Language Models (LLMs) to enhance automation, analysis, and reporting. Prominent examples include Velociraptor's MCP integration and Timesketch's AI Summary feature. This study empirically demonstrates that attackers can exploit prompt injection through boundary perturbation of structured data—a form previously considered resistant to manipulation. Importantly, this issue is not specific to any single tool; rather, it represents a broader class of risks that emerges whenever DFIR tools are integrated into autonomous LLM agents. By embedding malicious instructions into routine forensic artifacts such as logs and scheduled tasks, adversaries can cause DFIR LLM agents to misinterpret benign data as instructions, leading to three outcomes: Hide, Mislead, and Exploit. To the best of my knowledge, this is the first work to demonstrate structured-data injection attacks in LLM-integrated DFIR environments. The study also proposes practical defense-in-depth countermeasures, including enforcing least privilege, mandating strict structured output validation, and maintaining human-in-the-loop verification to ensure the reliability and safety of automated DFIR workflows. This Briefing aims to provide organizations advancing DFIR automation with LLM agents a foundation for rethinking, at the design level, how much autonomy should be granted to such agents and where human oversight must remain integral. Yusuke Nakajima | Security Analyst, NTTDATA https://ift.tt/RftH9kP

source https://www.youtube.com/watch?v=sK8omfWUMaM

Black Hat Asia 2026 | WhisperPair: A Security Analysis of Google Fast Pair

Google Fast Pair has promised "one-tap" Bluetooth onboarding and seamless account synchronisation across phones, laptops and tablets, since 2017. In practice, it has quietly become the default pairing path for modern earbuds, headphones and speakers across the Android ecosystem. Users trust that once an accessory is bonded, it will not suddenly attach to somebody else's phone without explicit consent. This Briefing shows that this trust was misplaced. We will present WhisperPair, a family of attacks that let a nearby adversary hijack Fast Pair compatible accessories that are not in pairing mode, seize audio, activate microphones, and silently attach the victim's device to the attacker's Google account for long term location tracking and stalking. The trick is simple but devastating: although the Fast Pair specification requires accessories to reject unauthorised pairing requests, a wide range of chipsets and vendors fail to enforce this in practice. Using only commodity hardware and standard Bluetooth stacks, we evaluated 25 commercial earbuds, headphones and speakers from 16 brands, covering what we believe to be all major audio manufacturers currently supporting Fast Pair. Most of them could be hijacked in under 15 seconds, and every vulnerable model that supported Google's Find Hub extension allowed covert account binding and stalking until factory reset. The Briefing walks through the attack in live demos, dissects what went wrong in Google's compliance chain, and releases a practical test harness that defenders can run against their own products. We will close with our proposed solution: IntentPair, a drop in protocol hardening that cryptographically binds user intent into Fast Pair without sacrificing usability. Our findings will show how a small usability "add-on" can introduce large-scale security and privacy risks for hundreds of millions of users when intent is not cryptographically bound, and how to address this to avoid such mass-scale problems. For further information about this work, please visit https://whisperpair.eu/ Seppe Wyns | PhD Student, DistriNet, KU Leuven Sayon Duttagupta | Scientific Researcher, COSIC, KU Leuven Nikola Antonijević | PhD Student, COSIC, KU Leuven Dave Singelée | Associate Professor, DistriNet - Group T, KU Leuven Bart Preneel | Professor, COSIC, KU Leuven https://ift.tt/x5sb0SN

source https://www.youtube.com/watch?v=mJlBPqiDdik

Monday, 24 August 2026

Black Hat Asia 2026 | Cast Attack: A New Threat Posed by Ghost Bits in Java

In modern security defense systems, input validation and data integrity checks are the core to preventing attacks. However, a commonly overlooked source of vulnerabilities has long lurked in the code, not due to complex logic errors, but because of "ghost bits" silently erased during type conversion. This presentation reveals a novel attack technique called Cast Attack, which originates from data loss during Java's type casting process. In this talk, we will demonstrate how Cast Attack can be used to bypass defenses such as WAFs, as well as introduce four major attack surfaces: privilege/access bypass, arbitrary file read, SMTP injection, and XSS. Affected vendors include, but are not limited to Oracle, Spring, Eclipse, Apache, Atlassian, JetBrains, and others. The impact of Cast Attack far exceeds expectations. It not only challenges current input validation mechanisms but also provides attackers with a low-cost, stealthy attack vector that can cause unforeseen security vulnerabilities in critical systems. Could this become the next widely exploited attack technique? In this session, we will uncover this hidden threat together. Xinyu Bai | Security Researcher, Zhihui Chen | Security Engineer, Alibaba Cloud Zongzheng Zheng | Independent Researcher, University of New South Wales https://ift.tt/sZxYatH

source https://www.youtube.com/watch?v=HhbLr4LKIl0

Black Hat Asia 2026 | Practical Attacks Against Smartphone Boot ROMs

Boot ROMs are an immutable component of any hardware platform, and vulnerabilities in them can compromise the entire boot chain. This talk aims to outline the impact of vulnerabilities in the USB interface of smartphone Boot ROMs at a low level, demonstrating how a smartphone's entire ecosystem can be manipulated from a single vulnerability. Using example targets from two different manufacturers, this talk aims to outline the impact of code execution vulnerabilities in multiple boot stages of a smartphone, providing practical demonstrations of secure boot bypass on mobile devices, on-device fuzzing, and decryption of protected firmware images. Christopher Wade | Staff Engineer https://ift.tt/QhSE2uv

source https://www.youtube.com/watch?v=0hItwQVp8a4

Black Hat Asia 2026 | Subverting Screen Trust via State Disruption and ONE-WAY Flooding

As core components of graphics and input architecture, SurfaceFlinger and InputDispatcher share critical responsibilities in physical screen handling. Although they are tightly integrated in the system architecture and interact frequently via the Binder driver, surface composition and input processing are fundamentally independent workflows. This seemingly unremarkable premise exposes a unique attack surface: by forcing SurfaceFlinger's scheduler into mishandling VSYNC signals, malware can fully disable the device's UI protections. Android's ongoing tapjacking mitigations have made zero-permission exploitation extremely difficult over the past 8 years. Our talk aims to break this deadlock by exploiting multiple vulnerabilities to successfully attack the latest Android 15 devices and threaten nearly all downstream OEM vendors! This research spans SurfaceFlinger, SystemServer and WMShell, and also covers several critical core services. Additionally, we will introduce a universal exploitation technique that bypasses standard defenses—even when all protection mechanisms are functioning as intended—by exploiting design flaws in the Binder transaction mechanism. Overall, the attack chain enables zero-permission bypass of privileged window control logic, rendering most UI protections, including TRUSTED_OVERLAY, ineffective. These findings have earned over $42,000 in vulnerability rewards, with one vulnerability remaining unpatched since 2023. Beyond theoretical feasibility, this research will present the POC on production devices to validate its practical reliability and stability. Additionally, we will develop a fully weaponized version and simulate real-world malware targeting the system permission controller. This enables privilege escalation that exceeds conventional expectations, without any user awareness. WeiMin Cheng | Independent Researcher, Zhihan Lin | Security Engineer, Chengdu Royal Security Technology Co., Ltd. Sheng Cao | Mobile Security Researcher, Huazhong University of Science and Technology Songzhou Shi | Security Researcher, LSPosed Team https://ift.tt/aDCH02W

source https://www.youtube.com/watch?v=sYoeYDSBjrI

Sunday, 23 August 2026

Black Hat Asia 2026 | Systematically Exploring and Exploiting DNS Silent Vulnerabilities

Domain names function as human-readable identifiers on the Internet, with characters serving as their essential building blocks. However, since the initial specification of domain names in 1983, the security implications of handling special characters within the domain name resolution process have remained largely overlooked. In this work, we conducted the first systematic study of special character handling logic in DNS, reviewing DNS RFCs and analyzing 31 widely-used DNS software implementations through source code review and gray-box testing. Our systematic analysis reveals two new DNS logic vulnerabilities arising from inconsistencies and silent handling behaviors, leading to two classes of attacks (four variants) that affect all DNS roles, including stub resolvers, forwarders, recursive resolvers, and authoritative nameservers. We name them the SHAR attack. Attackers can exploit these vulnerabilities to launch DNS cache poisoning and load balancing disruption attacks. Through comprehensive experiments, we validated the impact on the real world. All 31 tested mainstream DNS software implementations are vulnerable to SHAR. Notably, attackers can seize control of domain names, even the entire TLD or deceive victim resolvers to return invalid responses for legitimate queries, resulting in a persistent DoS effect. The SHAR attack can also enhance 10/13 well-known off-path DNS cache poisoning attacks (2002–2025). To further determine the impact in the wild, we test all DNS-related roles, including mainstream Wi-Fi routers, router OSes, public DNS services, table open DNS resolvers, Root servers, TLD servers, SLD servers, and domain names. The results show that the SHAR attack affects all tested Wi-Fi routers, router OSes, and public DNS services. In addition, we identified that over 12.5M domain names are also vulnerable to the SHAR attack. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors. Fasheng Miao | Master Student, Tsinghua University Xiang Li | Associate Professor, Nankai University Changqing An | Associate Researcher, Tsinghua University Jilong Wang | Professor, Tsinghua University https://ift.tt/Y5SJER7

source https://www.youtube.com/watch?v=2Euva5ZT-cA

Black Hat Asia 2026 | More JVM Memory Shells: JVM Memory Shell Auto Searching Program

A Java memory shell is a fileless backdoor that resides entirely in JVM memory, leaving no trace on disk. Attackers exploit code execution vulnerabilities—such as ScriptEngine injection or deserialization flaws—to use Java reflection to replace legitimate objects in web frameworks with malicious classes. Once implanted, specially crafted HTTP requests (mimicking normal traffic) trigger arbitrary command execution within the JVM, with results exfiltrated via standard HTTP responses. This stealthy technique blends seamlessly into legitimate traffic and bypasses firewalls that only allow ports 80/443, rendering traditional reverse shells ineffective. Over the past eight years, common variants have included Tomcat Filter, Tomcat Listener, and Spring Controller memory shells—all dynamically injected at runtime. However, the discovery of new types has largely stalled in recent years, relying almost exclusively on manual source code audits. We have developed an automated framework for discovering Java memory shells, integrating SAST (Static Application Security Testing), Java Agent–based hooking, JVM runtime memory introspection, and AIpowered PoC generation and validation capabilities. This framework dramatically accelerates the discovery of novel memory shells: in a very short time, it expanded the number of known Spring memory shell variants from just 2 to 9. Moreover, it is adaptable to any Java web framework for uncovering new memory shell techniques, significantly enhancing the efficiency of Java memory shell research and surpassing years of manual efforts. Litong Wan | Cyber Security Engineer, Alibaba Holding - Risk & Security Dept Fanghai Yu | Independent Security Researcher, Yang Jing | Cyber Security Engineer, Alibaba Holding - Risk & Security Dept Dongyan Zhang | Senior Security Engineer, Alibaba Holding - Risk & Security Dept Huan Zeng | Senior Security Engineer, Alibaba Holding - Risk & Security Dept https://ift.tt/FJb7ihN

source https://www.youtube.com/watch?v=YIuqIDm1mfk

Black Hat Asia 2026 | Ensuring the Cloud Quantum Computer Runs Your Program… But Learns Nothing

Quantum programs executed on cloud quantum computers expose three critical assets: 1. the input states, which may encode sensitive parameters or proprietary data; 2. the quantum circuit structure, which represents the designer's intellectual property; and 3. the quantum output, the high-value "gold nugget" produced by the computation — such as an RSA private key recovered by Shor's algorithm or the molecular structure of a breakthrough anti-aging drug. Our prior work, ObfusQate, protected quantum circuits by obfuscating their structure so that untrusted compilers cannot infer the algorithmic logic. In this work, we address the third and most valuable threat vector: quantum output theft. We will present a hybrid quantum-classical output-encryption mechanism in which carefully selected quantum gates are inserted before compilation to deliberately corrupt the measurement results that we call quantum encryption. Only the legitimate user — who holds a classical decryption key describing the inserted gates — can reconstruct the true output, classically without the need of a quantum computer. Evaluated across five benchmark algorithms, our approach yields high statistical divergence and strong functional corruption, ensuring that cloud providers cannot learn the output even after running the circuit. The technique is practical, compiler-agnostic, and imposes minimal overhead, making it suitable for protecting quantum IP in untrusted cloud environments. Vivek Balachandran | Associate Professor, Singapore Institute of Technology Amal Raj | Research Engineer, Singapore Institute of Technology https://ift.tt/QDabx7l

source https://www.youtube.com/watch?v=lS4qlzbFN6c

Saturday, 22 August 2026

Black Hat Asia 2026 | PhantomRPC: A New Privilege Escalation Flaw in Windows RPC

Windows Inter-process Communication (IPC) is one of the most complex technologies within the Windows operating system. At the core of this ecosystem lies the Remote Procedure Call (RPC) mechanism, which can function as a standalone communication channel or as the underlying transport layer for more advanced inter-process communication technologies. Due to its complexity and broad usage, RPC has historically been a rich source of security issues. Over the years, researchers have identified numerous vulnerabilities in services that rely on RPC, ranging from local privilege escalations to full remote code execution. In this Briefing, I will present a new vulnerability within the RPC architecture that enables a new local privilege escalation technique in all windows versions. This technique allows processes with impersonation privileges to elevate their permissions to SYSTEM level. Although this vulnerability is different from the known "Potato" exploit family, Microsoft has not issued a patch despite proper disclosure. I will introduce five distinct exploitation paths that demonstrate how privileges can be escalated from various local or network service contexts to SYSTEM. Some approaches involve coercion, others require user interaction, and some leverage background services. Because this is an architectural flaw, the number of possible attack vectors is unlimited, any new process or service that depends on RPC may introduce an additional escalation path. For this reason, we will also describe a methodology for identifying such opportunities and constructing custom exploits. This research is intended for vulnerability researchers, exploit developers, red team operators, and defenders seeking to understand, detect, and mitigate these classes of attacks. Haidar Kabibo | Application Security Specialist, Kaspersky https://ift.tt/ZobXLYI

source https://www.youtube.com/watch?v=krztD4lJK30

Black Hat Asia 2026 | Breaking Hybrid Boundaries Across Azure and Windows

Hybrid environments link on premises systems with Azure cloud services, creating a shared management and trust layer that organizations often assume to be secure by design. Our research shows how this assumption can hide critical exposure. During an assessment of Windows Admin Center in both Azure managed and on premises deployments, we uncovered four independent zero day vulnerabilities that can be combined into a full kill chain reaching from the local operating system to the Azure tenant including cross tenant compromise. The issues include a cryptographic flaw that enables unauthenticated cross tenant influence, a local privilege escalation, weaknesses in a modern token verification flow that allow identity and authorization bypass, and a chain of client and server side validation problems that enable remote code execution and complete Active Directory compromise. These findings reveal how a single management service that operates across host, cloud and browser layers can create pathways for movement across boundaries that are normally considered isolated. This presentation will show how attackers can progress from unauthenticated external or internal positions to full administrative control in both environments, and how defenders can identify and break the chain. By viewing the system through the combined lens of trust design, credential handling, and verification logic, the research highlights blind spots in hybrid architectures and shows where similar patterns may emerge in other platforms. Ilan Kalendarov | Security Research Team Lead, Cymulate Ben Zamir | Security Researcher, Cymulate https://ift.tt/NMDFA1C

source https://www.youtube.com/watch?v=41GGT31rA8k