Windows Inter-process Communication (IPC) is one of the most complex technologies within the Windows operating system. At the core of this ecosystem lies the Remote Procedure Call (RPC) mechanism, which can function as a standalone communication channel or as the underlying transport layer for more advanced inter-process communication technologies. Due to its complexity and broad usage, RPC has historically been a rich source of security issues. Over the years, researchers have identified numerous vulnerabilities in services that rely on RPC, ranging from local privilege escalations to full remote code execution.
In this Briefing, I will present a new vulnerability within the RPC architecture that enables a new local privilege escalation technique in all windows versions. This technique allows processes with impersonation privileges to elevate their permissions to SYSTEM level. Although this vulnerability is different from the known "Potato" exploit family, Microsoft has not issued a patch despite proper disclosure.
I will introduce five distinct exploitation paths that demonstrate how privileges can be escalated from various local or network service contexts to SYSTEM. Some approaches involve coercion, others require user interaction, and some leverage background services. Because this is an architectural flaw, the number of possible attack vectors is unlimited, any new process or service that depends on RPC may introduce an additional escalation path. For this reason, we will also describe a methodology for identifying such opportunities and constructing custom exploits.
This research is intended for vulnerability researchers, exploit developers, red team operators, and defenders seeking to understand, detect, and mitigate these classes of attacks.
Haidar Kabibo | Application Security Specialist, Kaspersky
https://ift.tt/ZobXLYI
source https://www.youtube.com/watch?v=krztD4lJK30
The Cyber Stream
Latest News for Cyber Security & Technology
Saturday, 22 August 2026
Black Hat Asia 2026 | Breaking Hybrid Boundaries Across Azure and Windows
Hybrid environments link on premises systems with Azure cloud services, creating a shared management and trust layer that organizations often assume to be secure by design. Our research shows how this assumption can hide critical exposure. During an assessment of Windows Admin Center in both Azure managed and on premises deployments, we uncovered four independent zero day vulnerabilities that can be combined into a full kill chain reaching from the local operating system to the Azure tenant including cross tenant compromise.
The issues include a cryptographic flaw that enables unauthenticated cross tenant influence, a local privilege escalation, weaknesses in a modern token verification flow that allow identity and authorization bypass, and a chain of client and server side validation problems that enable remote code execution and complete Active Directory compromise. These findings reveal how a single management service that operates across host, cloud and browser layers can create pathways for movement across boundaries that are normally considered isolated.
This presentation will show how attackers can progress from unauthenticated external or internal positions to full administrative control in both environments, and how defenders can identify and break the chain. By viewing the system through the combined lens of trust design, credential handling, and verification logic, the research highlights blind spots in hybrid architectures and shows where similar patterns may emerge in other platforms.
Ilan Kalendarov | Security Research Team Lead, Cymulate
Ben Zamir | Security Researcher, Cymulate
https://ift.tt/NMDFA1C
source https://www.youtube.com/watch?v=41GGT31rA8k
source https://www.youtube.com/watch?v=41GGT31rA8k
Black Hat Asia 2026 | RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox
DNS cache poisoning is a persistent game of attack and defense, posing an enduring challenge for the DNS community. Significant efforts have been made to uncover, detect, and mitigate vulnerabilities that increase the risk of cache poisoning. However, no work has systematically revisited whether the original cache poisoning attack based on the Birthday Paradox remains effective.
In this work, we will introduce RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. RebirthDay exploits newly uncovered, protocol-compliant vulnerabilities in DNS extension implementations to bypass the query aggregation mechanism intended to prevent DNS Birthday attacks that have not been well understood. We uncovered that 18 out of 22 mainstream DNS software are vulnerable due to weaknesses in the processing of a DNS extension (i.e., ECS option), specifically lacking or incorrectly implemented ECS coherence checks when handling DNS queries and responses, demonstrating the widespread susceptibility to RebirthDay. These flaws could be exploited to circumvent the query aggregation mechanism and launch RebirthDay attacks. Through comprehensive evaluation, we showed that RebirthDay attacks are highly practical and can have significant real-world impact, affecting 16 router vendors, 14 public DNS services, and 365K (15%) open DNS resolvers.
We have reported the identified vulnerabilities to affected vendors and discussed mitigation solutions with them. To date, we have received acknowledgments from 8 vendors, including BIND, Unbound, PowerDNS, and Quad9, and have been assigned 50 CVE-ids. Our study emphasizes the need for greater attention to the importance of coherent ECS verification and the DNS extension implementation, revealing new security risks introduced by them.
Xiang Li | Associate Professor, Nankai University
Yuqi Qiu | PhD Student, Nankai University
Mingming Zhang | Assistant Researcher, Zhongguancun Laboratory
Zuyao Xu | Master Student, Nankai University
Lu Sun | Master Student, Nankai University
Fasheng Miao | Master Student, Tsinghua University
https://ift.tt/sVxD8k7
source https://www.youtube.com/watch?v=oL12AWOwGRk
source https://www.youtube.com/watch?v=oL12AWOwGRk
Friday, 21 August 2026
Black Hat Asia 2026 | We'll Eat Your Serial for Breakfast
Serial-to-IP converters may sound like "boring" equipment whose only purpose is translating serial data into TCP/IP. Yet they are necessary and ubiquitous: they enable connectivity for medical devices in hospitals, PLCs, sensors and actuators in factories, and RTUs, IEDs and relays in electrical substations. Legacy serial-only devices are not going away any time soon.
Attackers do not find them boring at all. In 2015, an attack against Ukrainian power companies intentionally corrupted the firmware of several vulnerable serial-to-IP servers, rendering electrical substations inoperable and causing power outages. Even before that, researchers had reported major vulnerabilities in converters. Now that attacks on global critical infrastructure are more common, we have revisited serial-to-IP converters. To this end, we have:
* Quantitatively analyzed firmware from five major vendors, finding outdated components, n-day vulnerabilities and a lack of binary hardening similar to those in less critical devices.
* Performed an in-depth analysis of several devices from two major vendors often used in healthcare and OT environments, redacted, where we found 23 new vulnerabilities, some of which allow attackers to take full control of mission-critical devices connected via the serial link.
* Used open-source intelligence to find public evidence of these vendors' devices (often with pictures) in electrical substations, water treatment
plants and other critical infrastructure.
* Connected common serial devices such as temperature sensors, barcode scanners, industrial routers, and patient monitors to these vulnerable converters to demonstrate how easy it is to tamper with their data exchange and what impact that can have.
Unfortunately, not much has changed in the last decade. In this talk, we will demonstrate what attackers can achieve when exploiting serial-to-IP converters, which are sometimes less secure than a cheap home router.
Stanislav Dashevskyi | Principal Security Researcher, Forescout Technologies
Francesco La Spina | Senior Security Researcher, Forescout Technologies
https://ift.tt/UofrsL2
source https://www.youtube.com/watch?v=mSiD2TvlyWc
source https://www.youtube.com/watch?v=mSiD2TvlyWc
Black Hat Asia 2026 | Bypassing Authentication Reflection Mitigations for SYSTEM Shells
A year ago, authentication reflection vulnerabilities resurfaced as a powerful attack vector through the discovery of CVE-2025-33073. This logical vulnerability allowed taking over almost any Windows machine without any user interaction. Following the official patch by Microsoft, we had a gut feeling that the root cause of the issue was still not addressed. This presentation will cover our journey to bypass the mitigations and pop SYSTEM shells again.
In this session, we will start with a reminder regarding the internals of the CVE-2025-33073 vulnerability. We will then build on this to present the generic and iterative bypass methodology that was followed during the research. The methodology will be immediately illustrated by disclosing the first vulnerability that we uncovered: a trivial local privilege escalation via NTLM reflection.
Afterwards, we will transition to Kerberos where attack scenarios will be discussed, with both total and partial control of DNS. The attack vector will progressively be refined to finally achieve a full-blown RCE primitive as domain user, via a completely novel Kerberos authentication coercion technique. Throughout this part, in-depth and undocumented details on the inner workings of several specific Windows components will be shared to provide a better understanding of the vulnerability. In the second part, we will dive into how this vulnerability was short-lived and unintentionally patched. Eventually, our methodology will once again be applied to transform it into a privilege escalation vulnerability.
The final section will cover the patches' analysis, as well as our thoughts on the current state of authentication reflection vulnerabilities.
Guillaume André | Security Researcher, Synacktiv
https://ift.tt/OCQGAuU
source https://www.youtube.com/watch?v=EBmssApSYDM
source https://www.youtube.com/watch?v=EBmssApSYDM
Black Hat Asia 2026 | Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCache & Friends
Large language models (LLMs) are now embedded in every cloud, SOC, and product team—but almost nobody is looking at the "boring" cache layer that keeps them fast. In this Briefing, we will show how that invisible layer becomes a powerful offensive entry point.
Modern serving stacks such as vLLM, SGLang, GPTCache and commercial gateways aggressively cache prefixes, multimodal features, and semantic embeddings to save GPU time. We performed a systematic teardown of these caching implementations and found that performance shortcuts—non‑cryptographic hashes, lossy serialization, and fuzzy similarity matching—open a brand‑new attack surface during inference, not training.
We will walk through six practical attack primitives: system‑prompt hash collisions that silently rewrite assistant instructions for every tenant sharing a cache; block‑wise collisions that make entire malicious blocks "invisible" to the model; multimodal collisions that let a weaponized image inherit a benign cache entry and pass content moderation; and two forms of semantic fuzzy poisoning that turn customer‑support or RAG pipelines into a misinformation delivery channel. Each attack costs under one US dollar to run and, in our experiments, reached up to 100% cache‑hit rate for targeted prompts and 75% poisoned‑hit rate against popular semantic caches.
We then flip to the defender's perspective. Based on real patches and CVEs issued by major frameworks, we show what actually works in production: salted and cryptographic prefix hashes, canonical serialization for images and tensors, safer cache isolation in multi‑tenant deployments, and cheap LLM‑based filters that sit in front of semantic caches to kill poisoned hits before users see them. Attendees will leave with a concrete checklist they can apply to their own LLM APIs, gateways, and "AI platform" teams to stop cache‑layer abuses before attackers get there first. We will release PoC tooling that operators can immediately run against their own stacks to detect vulnerable deployments.
Xiangfan Wu | Student, Ocean University of China and Tencent Zhuque Lab
Lingyun Ying | Researcher, QI-ANXIN Technology Research Institute
Guoqiang Chen | Security Researcher, QI-ANXIN Technology Research Institute
Yacong Gu | Postdoctoral Researcher, Tsinghua University
Haipeng Qu | Professor, Ocean University of China
https://ift.tt/MB3CetL
source https://www.youtube.com/watch?v=P0KDHhGLXgE
source https://www.youtube.com/watch?v=P0KDHhGLXgE
Thursday, 20 August 2026
Black Hat Asia 2026 | How OS, Libraries, and Hardware Keep Your AES Keys Alive
FIPS 140-3 requires cryptographic modules to ensure that sensitive security parameters, including AES keys, are reliably zeroized once they are no longer needed. In practice, however, real systems behave very differently from what this requirement implies. Even when applications appear to implement proper zeroization, surrounding layers such as cryptographic libraries, operating systems, and hardware continue to influence how long keys remain in memory in ways developers cannot easily observe.
In this Briefing, we will present the first system-wide, empirical analysis of key zeroization behavior using an FPGA-based live memory forensic technique capable of monitoring physical memory independently of the CPU. By applying this method to Linux and Windows 11 on AArch64 SoC environment (Xilinx KR260) and Intel/AMD PCs with Alinx AXKU3 via Thunderbolt, we uncover several previously unrecognized zeroization failures. AES round keys processed within CPU vector registers are copied into kernel save areas during context switches and remain unzeroized after process termination. Abnormal termination conditions, including signal-based crashes, cause keys to persist for seconds to hours, and distribution-specific crash reporting mechanisms may duplicate them further into core dumps. Most strikingly, we observe that certain systems fail to zeroize memory during reboot, allowing AES keys to survive across system restarts despite expectations derived from FIPS 140-3 guidance.
These findings reveal a fundamental gap between the zeroization guarantees assumed during module development and the actual behavior of deployed systems. Our work provides a new methodology for evaluating zeroization on real hardware and offers practical insights for application developers, library maintainers, and OS vendors seeking to meet the intent of FIPS 140-3. Ultimately, we show that zeroization must be validated as a system property, not merely as a software implementation detail.
Toyofumi Sawa | Ph.D. Candidate, Institute of Information Security
Kuniyasu Suzaki | Professor, Institute of Information Security
https://ift.tt/NfcePBa
source https://www.youtube.com/watch?v=r5kkRtEsKT0
source https://www.youtube.com/watch?v=r5kkRtEsKT0
Black Hat Asia 2026 | Remote Server, Local Root. Welcome to MCP.
As Large Language Models (LLMs) evolve into autonomous agents, the Model Context Protocol (MCP) has become the de facto standard for connecting AI to external systems. MCP not only enables tool invocation through structured message exchanges, but also supports privileged user-data retrieval from remote servers. To support this, MCP adopts several OAuth-based mechanisms to dynamically establish authorization sessions. However, in doing so, it unintentionally introduces new threat vectors that traditional OAuth applications were never exposed to.
In this Briefing, we will uncover a novel attack surface within the MCP authorization flow. By abusing the dynamic nature of this flow, we demonstrate how authorization metadata—traditionally sourced from pre-registered, trusted identity providers—becomes a powerful attack vector when MCP clients accept it dynamically from arbitrary remote servers. Through a systematic analysis of three major classes of MCP clients—browser-based, process-based, and hybrid—we show how this design flaw leads to severe outcomes, including Remote Code Execution (RCE), Local File Execution (LFE), Account Takeover, and Cross-Tenant Data Exfiltration, depending on the client architecture.
Our analysis was validated across real MCP implementations and acknowledged by major vendors, including Anthropic and Google. To date, our research has resulted in five assigned CVEs and multiple bounty rewards, including an RCE in MCP Inspector (CVE-2025-58444) and a command injection vulnerability in Google's Gemini CLI. Additional CVEs were assigned to Cherry Studio (CVE-2025-54074), Dify (CVE-2025-58747), and other MCP clients, along with further confirmed impacts across multiple SaaS platforms.
Jiacheng Zhong | Security Researcher,
Shuyang Wang | Head of Security Research, Obsidian Security
Zhengyu Liu | Ph.D. Student, Johns Hopkins University
Aonan Guan | Senior Cloud Security Engineer, Wyze Labs
https://ift.tt/idtmhnM
source https://www.youtube.com/watch?v=wYcG_6SS788
source https://www.youtube.com/watch?v=wYcG_6SS788
Black Hat Asia 2026 | Exploiting Message Queue Flaws in AI Inference Servers for Widespread RCE
AI inference servers have become critical infrastructure for deploying large language models at scale, with platforms like vLLM, SGLang, TensorRT-LLM, and others processing millions of enterprise AI workloads daily. These systems rely on inter-process communication channels to coordinate distributed model inference across GPU clusters, but we discovered that the standard architectural patterns used across the industry contain fundamental security flaws.
We identified multiple Remote Code Execution vulnerabilities in the message queue implementations used by all major open-source AI inference platforms, affecting deployments from Meta, NVIDIA, Microsoft, and the PyTorch ecosystem. Through our internet-wide scanning, we confirmed thousands of vulnerable instances are directly exposed online, creating an attacker-accessible pathway into AI infrastructure at organizations worldwide. The vulnerabilities stem from dangerous code reuse patterns where insecure "reference implementations" were copied across projects, propagating the same logical flaws throughout the AI supply chain.
In this Briefing, we will reveal the complete technical details and working exploits for these RCE vulnerabilities, demonstrate attacks against multiple platforms, and share our complex coordinated disclosure process across numerous vendors. We'll show how attackers can gain code execution on AI servers, potentially stealing models worth millions in training costs, poisoning inference results, or pivoting into broader enterprise networks. This research exposes critical lessons about security versus performance trade-offs in AI systems and the unique risks of rapid open-source code sharing in the AI community.
Avi Lumelsky | Senior AI Researcher, Oligo Security
Uri Katz | Senior Vulnerability Researcher, Oligo Security
Gal Elbaz | CTO and Co-Founder, Oligo Security
https://ift.tt/mRYtoTX
source https://www.youtube.com/watch?v=R7RWtcN5rAY
source https://www.youtube.com/watch?v=R7RWtcN5rAY
Wednesday, 19 August 2026
Black Hat Asia 2026 | Qualcomm BootROM: A Journey Through Sahara
BootROM is a critical component in the security architecture of many system-on-chips (SoCs), including the Qualcomm Snapdragon and MSM/MDM-family SoCs, deployed in billions of smartphones and IoT devices worldwide. As an embedded, immutable component, BootROM serves as the root of trust for the entire Secure Boot chain.
This Briefing will present a comprehensive analysis of new vulnerabilities found by our team at the BootROM level: vulnerabilities in Emergency Download Mode (EDL) and its Sahara protocol, which allow bypassing cryptographic verification of Secondary Boot Loader (SBL) images and subsequent boot stages.
The Briefing will demonstrate that functional vulnerabilities in EDL mode allow an attacker with physical access to the device to gain complete control of the modem subsystem and its QuRT operating system.
Alexander Kozlov | Principal Security Researcher, Kaspersky Lab
Sergey Anufrienko | Security Research Group Manager, Kaspersky Lab
https://ift.tt/GT6lNwY
source https://www.youtube.com/watch?v=ZlWvdRBuxpc
source https://www.youtube.com/watch?v=ZlWvdRBuxpc
Black Hat Asia 2026 | When Office Attacks: XLL Chains and Enterprise EDR Nightmares
Threat actors using malicious macros and XLLs as an attack vector is a tale as old as time. EDR and AV products developed to mitigate this are now well-equipped to stop malicious Microsoft Office macros, right? Turns out, not necessarily! Three years and countless malware infections later, we'll demonstrate how attackers continue to innovate, finding new ways to weaponize Office macros and XLL files to establish footholds in protected environments.
As a red teamer, I spend an abundance of time doing security R&D to identify unique ways to break in, hide or break out of systems. The outcome of one such research cycle this year was a Frankenstein's monster of payloads, created using well-documented techniques and tactics to gain a foothold in a Windows system and bypass enterprise-level EDR detections. By combining Excel XLLs and Word macros, I created an attack chain that exploits the implicit trust organizations placed in legitimate business workflows.
In this talk, I will dissect my custom initial access payload that chains macros and XLLs in unexpected ways with several sophisticated evasion techniques. We will explore the inner workings of Excel add-ins, COM automation, and process relationships that enable this technique to evade current popular EDR solutions. More importantly, we will examine why enterprise EDR deployments struggle with detection when operating at scale.
Both offensive and defensive practitioners will gain valuable insights from this research. Red teamers will understand how legitimate business tools can be leveraged for initial access, while defenders will learn critical detection engineering strategies and incident response techniques. We will explore practical methods to identify, investigate and respond to such exploits and monitoring strategies, including a key configuration in a top EDR solution to detect this attack chain. This Briefing bridges the gap between offensive research and enterprise defense, providing actionable intelligence for organizations looking to strengthen their security posture against sophisticated macro-based attacks.
Thanmayee Rao | Senior Red Team Engineer, Amazon
https://ift.tt/JnfEKi4
source https://www.youtube.com/watch?v=RVAya4SoVBU
source https://www.youtube.com/watch?v=RVAya4SoVBU
Subscribe to:
Posts (Atom)
-
WeChat, with over 1.2 billion monthly active users, stands as the most popular messaging and social media platform in China and third global...
-
Unmasking State-Sponsored Mobile Surveillance Malware from Russia, China, and North Korea – Threat Actors, Tactics, and Defense Strategies S...