Monday, 24 August 2026

Black Hat Asia 2026 | Cast Attack: A New Threat Posed by Ghost Bits in Java

In modern security defense systems, input validation and data integrity checks are the core to preventing attacks. However, a commonly overlooked source of vulnerabilities has long lurked in the code, not due to complex logic errors, but because of "ghost bits" silently erased during type conversion. This presentation reveals a novel attack technique called Cast Attack, which originates from data loss during Java's type casting process. In this talk, we will demonstrate how Cast Attack can be used to bypass defenses such as WAFs, as well as introduce four major attack surfaces: privilege/access bypass, arbitrary file read, SMTP injection, and XSS. Affected vendors include, but are not limited to Oracle, Spring, Eclipse, Apache, Atlassian, JetBrains, and others. The impact of Cast Attack far exceeds expectations. It not only challenges current input validation mechanisms but also provides attackers with a low-cost, stealthy attack vector that can cause unforeseen security vulnerabilities in critical systems. Could this become the next widely exploited attack technique? In this session, we will uncover this hidden threat together. Xinyu Bai | Security Researcher, Zhihui Chen | Security Engineer, Alibaba Cloud Zongzheng Zheng | Independent Researcher, University of New South Wales https://ift.tt/sZxYatH

source https://www.youtube.com/watch?v=HhbLr4LKIl0

Black Hat Asia 2026 | Practical Attacks Against Smartphone Boot ROMs

Boot ROMs are an immutable component of any hardware platform, and vulnerabilities in them can compromise the entire boot chain. This talk aims to outline the impact of vulnerabilities in the USB interface of smartphone Boot ROMs at a low level, demonstrating how a smartphone's entire ecosystem can be manipulated from a single vulnerability. Using example targets from two different manufacturers, this talk aims to outline the impact of code execution vulnerabilities in multiple boot stages of a smartphone, providing practical demonstrations of secure boot bypass on mobile devices, on-device fuzzing, and decryption of protected firmware images. Christopher Wade | Staff Engineer https://ift.tt/QhSE2uv

source https://www.youtube.com/watch?v=0hItwQVp8a4

Black Hat Asia 2026 | Subverting Screen Trust via State Disruption and ONE-WAY Flooding

As core components of graphics and input architecture, SurfaceFlinger and InputDispatcher share critical responsibilities in physical screen handling. Although they are tightly integrated in the system architecture and interact frequently via the Binder driver, surface composition and input processing are fundamentally independent workflows. This seemingly unremarkable premise exposes a unique attack surface: by forcing SurfaceFlinger's scheduler into mishandling VSYNC signals, malware can fully disable the device's UI protections. Android's ongoing tapjacking mitigations have made zero-permission exploitation extremely difficult over the past 8 years. Our talk aims to break this deadlock by exploiting multiple vulnerabilities to successfully attack the latest Android 15 devices and threaten nearly all downstream OEM vendors! This research spans SurfaceFlinger, SystemServer and WMShell, and also covers several critical core services. Additionally, we will introduce a universal exploitation technique that bypasses standard defenses—even when all protection mechanisms are functioning as intended—by exploiting design flaws in the Binder transaction mechanism. Overall, the attack chain enables zero-permission bypass of privileged window control logic, rendering most UI protections, including TRUSTED_OVERLAY, ineffective. These findings have earned over $42,000 in vulnerability rewards, with one vulnerability remaining unpatched since 2023. Beyond theoretical feasibility, this research will present the POC on production devices to validate its practical reliability and stability. Additionally, we will develop a fully weaponized version and simulate real-world malware targeting the system permission controller. This enables privilege escalation that exceeds conventional expectations, without any user awareness. WeiMin Cheng | Independent Researcher, Zhihan Lin | Security Engineer, Chengdu Royal Security Technology Co., Ltd. Sheng Cao | Mobile Security Researcher, Huazhong University of Science and Technology Songzhou Shi | Security Researcher, LSPosed Team https://ift.tt/aDCH02W

source https://www.youtube.com/watch?v=sYoeYDSBjrI

Sunday, 23 August 2026

Black Hat Asia 2026 | Systematically Exploring and Exploiting DNS Silent Vulnerabilities

Domain names function as human-readable identifiers on the Internet, with characters serving as their essential building blocks. However, since the initial specification of domain names in 1983, the security implications of handling special characters within the domain name resolution process have remained largely overlooked. In this work, we conducted the first systematic study of special character handling logic in DNS, reviewing DNS RFCs and analyzing 31 widely-used DNS software implementations through source code review and gray-box testing. Our systematic analysis reveals two new DNS logic vulnerabilities arising from inconsistencies and silent handling behaviors, leading to two classes of attacks (four variants) that affect all DNS roles, including stub resolvers, forwarders, recursive resolvers, and authoritative nameservers. We name them the SHAR attack. Attackers can exploit these vulnerabilities to launch DNS cache poisoning and load balancing disruption attacks. Through comprehensive experiments, we validated the impact on the real world. All 31 tested mainstream DNS software implementations are vulnerable to SHAR. Notably, attackers can seize control of domain names, even the entire TLD or deceive victim resolvers to return invalid responses for legitimate queries, resulting in a persistent DoS effect. The SHAR attack can also enhance 10/13 well-known off-path DNS cache poisoning attacks (2002–2025). To further determine the impact in the wild, we test all DNS-related roles, including mainstream Wi-Fi routers, router OSes, public DNS services, table open DNS resolvers, Root servers, TLD servers, SLD servers, and domain names. The results show that the SHAR attack affects all tested Wi-Fi routers, router OSes, and public DNS services. In addition, we identified that over 12.5M domain names are also vulnerable to the SHAR attack. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors. Fasheng Miao | Master Student, Tsinghua University Xiang Li | Associate Professor, Nankai University Changqing An | Associate Researcher, Tsinghua University Jilong Wang | Professor, Tsinghua University https://ift.tt/Y5SJER7

source https://www.youtube.com/watch?v=2Euva5ZT-cA

Black Hat Asia 2026 | More JVM Memory Shells: JVM Memory Shell Auto Searching Program

A Java memory shell is a fileless backdoor that resides entirely in JVM memory, leaving no trace on disk. Attackers exploit code execution vulnerabilities—such as ScriptEngine injection or deserialization flaws—to use Java reflection to replace legitimate objects in web frameworks with malicious classes. Once implanted, specially crafted HTTP requests (mimicking normal traffic) trigger arbitrary command execution within the JVM, with results exfiltrated via standard HTTP responses. This stealthy technique blends seamlessly into legitimate traffic and bypasses firewalls that only allow ports 80/443, rendering traditional reverse shells ineffective. Over the past eight years, common variants have included Tomcat Filter, Tomcat Listener, and Spring Controller memory shells—all dynamically injected at runtime. However, the discovery of new types has largely stalled in recent years, relying almost exclusively on manual source code audits. We have developed an automated framework for discovering Java memory shells, integrating SAST (Static Application Security Testing), Java Agent–based hooking, JVM runtime memory introspection, and AIpowered PoC generation and validation capabilities. This framework dramatically accelerates the discovery of novel memory shells: in a very short time, it expanded the number of known Spring memory shell variants from just 2 to 9. Moreover, it is adaptable to any Java web framework for uncovering new memory shell techniques, significantly enhancing the efficiency of Java memory shell research and surpassing years of manual efforts. Litong Wan | Cyber Security Engineer, Alibaba Holding - Risk & Security Dept Fanghai Yu | Independent Security Researcher, Yang Jing | Cyber Security Engineer, Alibaba Holding - Risk & Security Dept Dongyan Zhang | Senior Security Engineer, Alibaba Holding - Risk & Security Dept Huan Zeng | Senior Security Engineer, Alibaba Holding - Risk & Security Dept https://ift.tt/FJb7ihN

source https://www.youtube.com/watch?v=YIuqIDm1mfk

Black Hat Asia 2026 | Ensuring the Cloud Quantum Computer Runs Your Program… But Learns Nothing

Quantum programs executed on cloud quantum computers expose three critical assets: 1. the input states, which may encode sensitive parameters or proprietary data; 2. the quantum circuit structure, which represents the designer's intellectual property; and 3. the quantum output, the high-value "gold nugget" produced by the computation — such as an RSA private key recovered by Shor's algorithm or the molecular structure of a breakthrough anti-aging drug. Our prior work, ObfusQate, protected quantum circuits by obfuscating their structure so that untrusted compilers cannot infer the algorithmic logic. In this work, we address the third and most valuable threat vector: quantum output theft. We will present a hybrid quantum-classical output-encryption mechanism in which carefully selected quantum gates are inserted before compilation to deliberately corrupt the measurement results that we call quantum encryption. Only the legitimate user — who holds a classical decryption key describing the inserted gates — can reconstruct the true output, classically without the need of a quantum computer. Evaluated across five benchmark algorithms, our approach yields high statistical divergence and strong functional corruption, ensuring that cloud providers cannot learn the output even after running the circuit. The technique is practical, compiler-agnostic, and imposes minimal overhead, making it suitable for protecting quantum IP in untrusted cloud environments. Vivek Balachandran | Associate Professor, Singapore Institute of Technology Amal Raj | Research Engineer, Singapore Institute of Technology https://ift.tt/QDabx7l

source https://www.youtube.com/watch?v=lS4qlzbFN6c

Saturday, 22 August 2026

Black Hat Asia 2026 | PhantomRPC: A New Privilege Escalation Flaw in Windows RPC

Windows Inter-process Communication (IPC) is one of the most complex technologies within the Windows operating system. At the core of this ecosystem lies the Remote Procedure Call (RPC) mechanism, which can function as a standalone communication channel or as the underlying transport layer for more advanced inter-process communication technologies. Due to its complexity and broad usage, RPC has historically been a rich source of security issues. Over the years, researchers have identified numerous vulnerabilities in services that rely on RPC, ranging from local privilege escalations to full remote code execution. In this Briefing, I will present a new vulnerability within the RPC architecture that enables a new local privilege escalation technique in all windows versions. This technique allows processes with impersonation privileges to elevate their permissions to SYSTEM level. Although this vulnerability is different from the known "Potato" exploit family, Microsoft has not issued a patch despite proper disclosure. I will introduce five distinct exploitation paths that demonstrate how privileges can be escalated from various local or network service contexts to SYSTEM. Some approaches involve coercion, others require user interaction, and some leverage background services. Because this is an architectural flaw, the number of possible attack vectors is unlimited, any new process or service that depends on RPC may introduce an additional escalation path. For this reason, we will also describe a methodology for identifying such opportunities and constructing custom exploits. This research is intended for vulnerability researchers, exploit developers, red team operators, and defenders seeking to understand, detect, and mitigate these classes of attacks. Haidar Kabibo | Application Security Specialist, Kaspersky https://ift.tt/ZobXLYI

source https://www.youtube.com/watch?v=krztD4lJK30

Black Hat Asia 2026 | Breaking Hybrid Boundaries Across Azure and Windows

Hybrid environments link on premises systems with Azure cloud services, creating a shared management and trust layer that organizations often assume to be secure by design. Our research shows how this assumption can hide critical exposure. During an assessment of Windows Admin Center in both Azure managed and on premises deployments, we uncovered four independent zero day vulnerabilities that can be combined into a full kill chain reaching from the local operating system to the Azure tenant including cross tenant compromise. The issues include a cryptographic flaw that enables unauthenticated cross tenant influence, a local privilege escalation, weaknesses in a modern token verification flow that allow identity and authorization bypass, and a chain of client and server side validation problems that enable remote code execution and complete Active Directory compromise. These findings reveal how a single management service that operates across host, cloud and browser layers can create pathways for movement across boundaries that are normally considered isolated. This presentation will show how attackers can progress from unauthenticated external or internal positions to full administrative control in both environments, and how defenders can identify and break the chain. By viewing the system through the combined lens of trust design, credential handling, and verification logic, the research highlights blind spots in hybrid architectures and shows where similar patterns may emerge in other platforms. Ilan Kalendarov | Security Research Team Lead, Cymulate Ben Zamir | Security Researcher, Cymulate https://ift.tt/NMDFA1C

source https://www.youtube.com/watch?v=41GGT31rA8k

Black Hat Asia 2026 | RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox

DNS cache poisoning is a persistent game of attack and defense, posing an enduring challenge for the DNS community. Significant efforts have been made to uncover, detect, and mitigate vulnerabilities that increase the risk of cache poisoning. However, no work has systematically revisited whether the original cache poisoning attack based on the Birthday Paradox remains effective. In this work, we will introduce RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. RebirthDay exploits newly uncovered, protocol-compliant vulnerabilities in DNS extension implementations to bypass the query aggregation mechanism intended to prevent DNS Birthday attacks that have not been well understood. We uncovered that 18 out of 22 mainstream DNS software are vulnerable due to weaknesses in the processing of a DNS extension (i.e., ECS option), specifically lacking or incorrectly implemented ECS coherence checks when handling DNS queries and responses, demonstrating the widespread susceptibility to RebirthDay. These flaws could be exploited to circumvent the query aggregation mechanism and launch RebirthDay attacks. Through comprehensive evaluation, we showed that RebirthDay attacks are highly practical and can have significant real-world impact, affecting 16 router vendors, 14 public DNS services, and 365K (15%) open DNS resolvers. We have reported the identified vulnerabilities to affected vendors and discussed mitigation solutions with them. To date, we have received acknowledgments from 8 vendors, including BIND, Unbound, PowerDNS, and Quad9, and have been assigned 50 CVE-ids. Our study emphasizes the need for greater attention to the importance of coherent ECS verification and the DNS extension implementation, revealing new security risks introduced by them. Xiang Li | Associate Professor, Nankai University Yuqi Qiu | PhD Student, Nankai University Mingming Zhang | Assistant Researcher, Zhongguancun Laboratory Zuyao Xu | Master Student, Nankai University Lu Sun | Master Student, Nankai University Fasheng Miao | Master Student, Tsinghua University https://ift.tt/sVxD8k7

source https://www.youtube.com/watch?v=oL12AWOwGRk

Friday, 21 August 2026

Black Hat Asia 2026 | We'll Eat Your Serial for Breakfast

Serial-to-IP converters may sound like "boring" equipment whose only purpose is translating serial data into TCP/IP. Yet they are necessary and ubiquitous: they enable connectivity for medical devices in hospitals, PLCs, sensors and actuators in factories, and RTUs, IEDs and relays in electrical substations. Legacy serial-only devices are not going away any time soon. Attackers do not find them boring at all. In 2015, an attack against Ukrainian power companies intentionally corrupted the firmware of several vulnerable serial-to-IP servers, rendering electrical substations inoperable and causing power outages. Even before that, researchers had reported major vulnerabilities in converters. Now that attacks on global critical infrastructure are more common, we have revisited serial-to-IP converters. To this end, we have: * Quantitatively analyzed firmware from five major vendors, finding outdated components, n-day vulnerabilities and a lack of binary hardening similar to those in less critical devices. * Performed an in-depth analysis of several devices from two major vendors often used in healthcare and OT environments, redacted, where we found 23 new vulnerabilities, some of which allow attackers to take full control of mission-critical devices connected via the serial link. * Used open-source intelligence to find public evidence of these vendors' devices (often with pictures) in electrical substations, water treatment plants and other critical infrastructure. * Connected common serial devices such as temperature sensors, barcode scanners, industrial routers, and patient monitors to these vulnerable converters to demonstrate how easy it is to tamper with their data exchange and what impact that can have. Unfortunately, not much has changed in the last decade. In this talk, we will demonstrate what attackers can achieve when exploiting serial-to-IP converters, which are sometimes less secure than a cheap home router. Stanislav Dashevskyi | Principal Security Researcher, Forescout Technologies Francesco La Spina | Senior Security Researcher, Forescout Technologies https://ift.tt/UofrsL2

source https://www.youtube.com/watch?v=mSiD2TvlyWc

Black Hat Asia 2026 | Bypassing Authentication Reflection Mitigations for SYSTEM Shells

A year ago, authentication reflection vulnerabilities resurfaced as a powerful attack vector through the discovery of CVE-2025-33073. This logical vulnerability allowed taking over almost any Windows machine without any user interaction. Following the official patch by Microsoft, we had a gut feeling that the root cause of the issue was still not addressed. This presentation will cover our journey to bypass the mitigations and pop SYSTEM shells again. In this session, we will start with a reminder regarding the internals of the CVE-2025-33073 vulnerability. We will then build on this to present the generic and iterative bypass methodology that was followed during the research. The methodology will be immediately illustrated by disclosing the first vulnerability that we uncovered: a trivial local privilege escalation via NTLM reflection. Afterwards, we will transition to Kerberos where attack scenarios will be discussed, with both total and partial control of DNS. The attack vector will progressively be refined to finally achieve a full-blown RCE primitive as domain user, via a completely novel Kerberos authentication coercion technique. Throughout this part, in-depth and undocumented details on the inner workings of several specific Windows components will be shared to provide a better understanding of the vulnerability. In the second part, we will dive into how this vulnerability was short-lived and unintentionally patched. Eventually, our methodology will once again be applied to transform it into a privilege escalation vulnerability. The final section will cover the patches' analysis, as well as our thoughts on the current state of authentication reflection vulnerabilities. Guillaume André | Security Researcher, Synacktiv https://ift.tt/OCQGAuU

source https://www.youtube.com/watch?v=EBmssApSYDM