Meet Mike Spicer (aka DarkMatter), a NOC lead at Black Hat, revealing how the team detected and tracked down a compromised attendee during the conference.
When a device connected to the network and started communicating with a known malicious source, an alert was triggered among hundreds of thousands of events. The team conducted a deep dive analysis, examining packet types and communication patterns to identify the threat actor through behavioral analysis. Using open-source intelligence techniques, the team fingerprinted the network communication, pieced together the digital breadcrumbs, and matched the activity to a registered attendee. The team successfully made contact to help secure the compromised device.
source https://www.youtube.com/shorts/ddpZoTcvGmQ
The Cyber Stream
Latest News for Cyber Security & Technology
Thursday, 18 June 2026
Black Hat Europe 2025 | Understanding Trends & Patterns In Insider Threat: Analysis Of 1,000+ Cases
This session examines the world of malicious insider threat by identifying the trends and patterns of the Tactics, Techniques, and Procedures (TTPs) observed in over 1,000 cases. Rather than focus on attitudinal surveys or anecdotal data, this session will explore the TTPs used by malicious insiders which are most valuable to digital forensic examiners and incident responders.
By: Michael Robinson | Senior Security Analyst, Google
https://ift.tt/bNAYdWc
source https://www.youtube.com/watch?v=-ueCcEdDjOM
source https://www.youtube.com/watch?v=-ueCcEdDjOM
Black Hat Europe 2025 | Token Injection: Crashing LLM Inference With Special Tokens
As large language models (LLMs) are deployed at scale, their underlying inference frameworks (e.g., vLLM, SGLang, TensorRT-LLM) have become critical operational pillars. These systems must splice user prompts with control structures, tokenise them, and schedule requests within milliseconds. Within this high-speed pipeline, we identify an underappreciated attack surface: special tokens.
We introduce the first "Token Injection" attack model, showing how a single prompt composed solely of special tokens can trigger uncaught exceptions in embedding and CUDA computation stages, resulting in denial of service (DoS) or full-service crashes. It can also cause inference manipulation, such as chat interruption and context pollution. The attack requires no authentication and works via standard input interfaces, affecting both self-hosted and managed deployments. We validate impact across multiple inference frameworks, including vLLM, SGLang, TensorRT-LLM, MLX, Ollama, and Hugging Face TGI; and across major platforms, including NVIDIA NIM, Google Vertex AI, Azure AI Foundry, Hugging Face, Meta AI, and OpenRouter.
This work shifts the AI security focus from "model output" to the security of inference infrastructure, offering practitioners a new perspective and a concrete defence paradigm.
By:
Pengyu Ding | PhD Student, Infra Security, Ant Group & Huazhong University of Science and Technology
Ziteng Xu | Senior Cybersecurity Expert, Infra Security, Ant Group
Zhiniang Peng | Associate Professor, Huazhong University of Science and Technology
Dongliang Mu | Associate Professor, Huazhong University of Science and Technology
https://ift.tt/v9tsYEh
source https://www.youtube.com/watch?v=ILnTkeuxPPw
source https://www.youtube.com/watch?v=ILnTkeuxPPw
Tuesday, 16 June 2026
Black Hat Europe 2025 | Insights From Phishing-Resistant Authentication
How many phishing attempts bypass enterprise pre-authentication security, including email gateways, DNS filtering, SASE, SWG, browser security, and endpoint protection, to trick users into malicious logins? And how effectively do current security systems detect and respond to these? While general phishing trends are known, the true impact and organizational defense postures remain unclear.
Analyzing two years of phishing attempts stopped only by phishing-resistant authentication, we quantify a notable volume of attacks that bypass the pre-authentication security layers and successfully trick users. We then dive into events linked to AiTM campaigns using EvilProxy kits, dissecting their patterns across verticals and company sizes, identifying indicators of compromise, and tracking longitudinal trends. As part of our investigation, we also reached out to impacted organizations, with a notable number indicating they hadn't detected these attempts until our notifications.
This work provides crucial, data-driven evidence highlighting the importance of phishing-resistant authentication and exposing many organizations' often mediocre security postures. It transforms failed authentication into actionable threat intelligence, revealing and helping address organizations' actual security gaps.
By: Fei Liu | Principal Emerging Technology Researcher, Okta
source https://www.youtube.com/watch?v=6jw8vG8FaEQ
source https://www.youtube.com/watch?v=6jw8vG8FaEQ
Tuesday, 9 June 2026
Sunday, 7 June 2026
Get One Step Ahead at Black Hat 🚀
Ari Herbert-Voss, Founder and CEO of RunSybil, explains how Black Hat helps cybersecurity professionals stay one step ahead by bringing together diverse perspectives and deep expertise. Take full advantage of the opportunity to learn, connect, and grow.
🎥 Watch the full episode to hear more about Ari's experience at Black Hat.
source https://www.youtube.com/shorts/ame3xiDUe-0
source https://www.youtube.com/shorts/ame3xiDUe-0
Friday, 5 June 2026
Inside the Black Hat community 💻
Ari Herbert-Voss shares what makes the Black Hat community unique, welcoming to newcomers while staying highly technical and focused on cutting-edge research.
🎥 Watch the full Episode 5 to hear more about Ari's Black Hat experience.
source https://www.youtube.com/shorts/NnDcponpls8
source https://www.youtube.com/shorts/NnDcponpls8
Thursday, 4 June 2026
Black Hat Europe 2025 | Network Operations Center (NOC) Report
Back with another year of soul-crushing statistics, the Black Hat NOC team will be sharing all of the data that keeps us equally puzzled, and entertained, year after year. We'll let you know all the tools and techniques we're using to set up, stabilize, and secure the network, and what changes we've made over the past year to try and keep doing things better. Of course, we'll be sharing some of the more humorous network activity and what it helps us learn about the way security professionals conduct themselves on an open WiFi network.
By:
Neil Wyler | Vice President of Defensive Services, Coalfire
Bart Stump | Managing Principal, Coalfire
https://ift.tt/rLtDyUC
source https://www.youtube.com/watch?v=onxC-5-zYus
source https://www.youtube.com/watch?v=onxC-5-zYus
Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI Systems
AI vision systems see differently than humans do. When platforms downscale uploads to save compute, the mathematical properties of interpolation algorithms create exploitable artifacts. In this presentation, we'll show how to craft images which use invisible pixel perturbations to reveal malicious prompts after downscaling, triggering unauthorized tool execution across Google Gemini, Vertex AI, Google Assistant, and Genspark. Beyond image downscaling, we'll explore the broader attack surface, including audio transformations, dithering algorithms, and other preprocessing steps that become prompt injection vectors. You'll learn to fingerprint vulnerable systems using test patterns that reveal specific downscaling implementations across AI libraries. We'll demo Anamorpher, our open-source tool for automated attack generation, with both Python APIs and visual interfaces, as well as examine practical mitigations from displaying actual processed images to implementing design patterns resistant to prompt injection, such as the action selector pattern.
By:
Suha Hussain | AI Research Engineer, Product Security, Harvey
Kikimora Morozova | Security Researcher, Trail of Bits
https://ift.tt/MuZqL6N
source https://www.youtube.com/watch?v=rHvFGz7_67k
source https://www.youtube.com/watch?v=rHvFGz7_67k
Why leaders in cybersecurity keep coming back to Black Hat
Ari Herbert-Voss, Founder and CEO of RunSybil, shares how Black Hat helps drive business exposure and build meaningful connections within the cybersecurity community.
From reconnecting with industry peers to staying close to evolving trends, events like Black Hat continue to play an important role for professionals in the space.
🎥 Check out episode 5 to hear more about Ari's Black Hat experience.
source https://www.youtube.com/shorts/wtnhDand0HI
source https://www.youtube.com/shorts/wtnhDand0HI
Tuesday, 2 June 2026
Black Hat Europe 2025 | You Win Some, You CheckSum: A Kerberos Delegation Vulnerability
In Active Directory networks, user identity impersonation is commonly used when applications need to access network resources on behalf of the user. One of the safest ways to implement this is through Kerberos Constrained Delegation (KCD), which enforces trust boundaries between the application and the target services.
In this talk, we'll dive into the internals of the authentication process behind these mechanisms and present CVE-2025-60704: a logical vulnerability we discovered in Microsoft's Kerberos implementation. Using Machine-in-the-Middle technique, this flaw allowed us to impersonate arbitrary users and ultimately gain control over the entire domain.
To understand how the vulnerability works, we'll walk through protocol behavior, trust assumptions, and some light reverse engineering of Windows internals that helped us trace the flaw down to its root. Finally, we'll discuss mitigation strategies and how to better protect environments relying on Kerberos delegation.
By:
Eliran Partush | Security Researcher, Silverfort
Dor Segal | Security Research Team Lead, Silverfort
https://ift.tt/jG2l19v
source https://www.youtube.com/watch?v=G_Q75jocldo
source https://www.youtube.com/watch?v=G_Q75jocldo
Subscribe to:
Posts (Atom)
-
Unmasking State-Sponsored Mobile Surveillance Malware from Russia, China, and North Korea – Threat Actors, Tactics, and Defense Strategies S...
-
Germany recalled its ambassador to Russia for a week of consultations in Berlin following an alleged hacker attack on Chancellor Olaf Scho...