Lynn shares how Black Hat brings the cybersecurity community together year after year, creating lasting connections and bringing the community to life.
source https://www.youtube.com/shorts/FGSAf8vzCB8
Saturday, 3 October 2026
Friday, 2 October 2026
Black Hat Stories | Tony Lee, Black Hat Review Board Member and VP of Operations at HackerOne
In this episode of Black Hat Stories, Tony reflects on his journey from attendee and trainer to presenter and Review Board member. He shares why Black Hat continues to grow, the energy that makes Arsenal a must-see destination, and how the community creates opportunities for learning, collaboration, and lasting connections.
From showcasing innovative tools to meeting peers at every stage of their careers, Tony explains why Black Hat remains one of the most valuable gathering places in cybersecurity.
source https://www.youtube.com/watch?v=wwk4SGLGcfY
source https://www.youtube.com/watch?v=wwk4SGLGcfY
Thursday, 1 October 2026
Black Hat Stories | Executive Director at Women in Cybersecurity (WiCyS)
Lynn shares why Black Hat is a valuable place to learn, connect, and prepare for the future of cybersecurity.
source https://www.youtube.com/shorts/ar0xeVxtER0
source https://www.youtube.com/shorts/ar0xeVxtER0
Monday, 21 September 2026
Black Hat USA 2026 | Applying Information Retrieval to Vulnerability Research
You bought an IoT device, extracted the firmware, and dropped the main runtime binary into your favorite reverse engineering tool. Now you're staring at thousands of decompiled functions with no source, no symbols, and no obvious place to start bug hunting. How might an LLM help find signal in the noise, even before you've clearly established what "signal" looks like?
The SiftRank algorithm reframes this uncertainty as an information retrieval problem. Instead of treating vulnerability discovery as an open-ended task for an interactive agent, SiftRank uses an LLM to repeatedly rank small batches of decompiled functions by their likelihood of containing a target vulnerability class. It aggregates each function's rank distribution, refines the candidate set across multiple rounds, and returns a fully ranked dataset with a calibrated top-k cutoff for focused analyst review.
On BinPool, a real-world binary vulnerability dataset containing 95 CVEs across 28 CWE classes, SiftRank achieves 2.26x greater precision in binary vulnerability discovery compared to zero-shot classification. With SiftRank, the relatively small GPT-5 Nano outperforms its much larger sibling, GPT-5, by 32% in precision at a model tier that is 25x cheaper per input token. I'll demonstrate this algorithm on firmware extracted from a commercial network power controller. SiftRank processed 5,710 decompiled functions and surfaced a hidden diagnostic endpoint at rank #1, allowing RCE and leading directly to CVE-2026-41446. This case study tangibly reflects the same pattern that the benchmark shows broadly, which is that small well-harnessed models can behave like serious vulnerability research tools.
This Briefing is a call for hackers to keep the hands-on imperative alive in the age of generative AI. Instead of surrendering the whole discovery process to an agent, we can get our hands dirty, decompose the problem, and invoke LLMs to make bounded, inspectable judgments as a basic research primitive.
Caleb Gross | Security Researcher
https://ift.tt/8ae3hfA
source https://www.youtube.com/watch?v=1ADD60wyrbg
source https://www.youtube.com/watch?v=1ADD60wyrbg
Black Hat Stories | Ryan & Isabella Barnett
From conducting research together to presenting at Black Hat, discover how collaboration and shared experiences make the conference memorable.
source https://www.youtube.com/shorts/uQhAv68GjGE
source https://www.youtube.com/shorts/uQhAv68GjGE
Saturday, 19 September 2026
Black Hat Stories | The Black Hat Experience
From new connections to meaningful conversations, discover what makes the Black Hat experience unique.
source https://www.youtube.com/shorts/nzUs5QhYExY
source https://www.youtube.com/shorts/nzUs5QhYExY
Friday, 18 September 2026
Ryan & Isabella Barnett, Akamai | Black Hat Stories
Black Hat is where the #cybersecurity community comes together to share ideas, tackle challenges, and learn from one another. Hear from Ryan and Izzy as they share their #BlackHat experience.
source https://www.youtube.com/shorts/lCbjqj9KIQM
source https://www.youtube.com/shorts/lCbjqj9KIQM
Friday, 11 September 2026
Black Hat Stories | Ryan & Isabella Barnett, Akamai
Ryan and Isabella Barnett from Akamai talk about how Black Hat's cutting-edge research helps them stay one step ahead.
source https://www.youtube.com/shorts/p-XAEc3Hc2s
source https://www.youtube.com/shorts/p-XAEc3Hc2s
Thursday, 10 September 2026
Black Hat Stories | Ryan & Isabella Barnett, Akamai
On this episode of Black Hat Stories, Ryan Barnett, Senior Threat Research Manager, and his daughter Isabella Barnett, a Software Engineering Intern at Akamai, share what it's like to present together at Black Hat, staying ahead of attackers, and what keeps them coming back year after year.
From Isabella's early Black Hat experiences to Ryan's decade-plus of attending, they talk about what makes Black Hat special: the energy, innovation, and community.
source https://www.youtube.com/watch?v=62ljM9dO_ns
source https://www.youtube.com/watch?v=62ljM9dO_ns
Monday, 7 September 2026
Black Hat Stories | Founder and Creator of Black Hat
Cybersecurity is constantly evolving. 🔐 Hear from Jeff Moss on the realities shaping the industry today.
source https://www.youtube.com/shorts/MP757qc0rbw
source https://www.youtube.com/shorts/MP757qc0rbw
Saturday, 5 September 2026
Founder and Creator of Black Hat | Jeff Moss
Black Hat Founder Jeff Moss talks about Black Hat, the evolution of cybersecurity, and what it takes to stay one step ahead.
source https://www.youtube.com/shorts/E9rG0QNF7uQ
source https://www.youtube.com/shorts/E9rG0QNF7uQ
Thursday, 3 September 2026
Black Hat Stories | Jeff Moss
Black Hat brings together the people, perspectives, and expertise that help cybersecurity professionals stay one step ahead.
source https://www.youtube.com/shorts/4mmHnhaMf-4
source https://www.youtube.com/shorts/4mmHnhaMf-4
Black Hat Asia 2026 | Mobile Track Spotlight
Mobile security continues to evolve at a breakneck pace, with new attack surfaces, ecosystem shifts, and research breakthroughs reshaping the landscape every year. In this interactive session, members of the Black Hat Asia Review Board will highlight the trends, techniques, and vulnerabilities that stood out during this year's Briefings review cycle.
Join us for a fast paced discussion on what's emerging, what's escalating, and what practitioners should be paying attention to next. Bring your questions—this session is designed to be conversational and candid.
Anant Shrivastava | Founder, Cyfinoid Research
Pamela O'Shea | Director, Shea Security
Shanna Daly | CEO, Torin Cyber Group
https://ift.tt/vSWGwVg
source https://www.youtube.com/watch?v=QZGwGYxYVCY
source https://www.youtube.com/watch?v=QZGwGYxYVCY
Tuesday, 1 September 2026
Black Hat Stories | Jeff Moss, Founder and Creator of Black Hat
In this episode, Black Hat Founder Jeff Moss reflects on the evolution of cybersecurity, the rise of AI and automation, and the growing challenge of separating trustworthy insights from an overwhelming volume of information. In a world of endless content, Black Hat continues to bring together the people, perspectives, and expertise that help cybersecurity professionals learn, connect, and navigate an increasingly complex landscape.
source https://www.youtube.com/watch?v=HbPqeqUm9fQ
source https://www.youtube.com/watch?v=HbPqeqUm9fQ
Monday, 31 August 2026
Black Hat Asia 2026 | Revealing User Activity on macOS for Apple Silicon
Apple's M-series now powers a huge portion of executive, enterprise, and developer laptops. One blind spot has stayed largely off the radar: interrupt-based side channels where signals raised by normal device activities such as networking, input, and display can be sensed by an unprivileged attacker. We show that a determined attacker can turn those signals into high-fidelity surveillance of user activities on macOS for Apple Silicon.
In this talk, we will present TIDE, which works like a stethoscope for the OS: every time macOS returns from the kernel to user space, it produces a tiny, deterministic "heartbeat we can feel from user space". By listening for that heartbeat, TIDE pinpoints exactly when an interrupt occurs without any timers. With TIDE as our sensor, we reverse-engineer Apple's publicly undocumented interrupt delivery and reveal that shared peripheral interrupts are uniformly distributed across all active cores. This quirk means an unprivileged attacker no longer has to "chase the right core" to spy on user activities within the same OS.
To demonstrate the effectiveness of TIDE, we will present two live, end-to-end attacks on real Apple Silicon hardware. One is website fingerprinting on Safari with about 94% Top-1 accuracy in closed-world and about 91% in open-world to reveal the websites users have visited. The other is Video fingerprinting with roughly 80% to identifying streaming content from its interrupt patterns. We conclude with potential software-only mitigations Apple can deploy, plus longer-term OS/SoC directions. We call for more parties to join in this effort to enhance the security of macOS.
Xin Zhang | Ph.D. Student, Peking University
Zhi Zhang | Senior Lecturer, The University of Western Australia
Chang Liu | Ph.D. Student, Tsinghua University
Qingni Shen | Full Professor, Peking University
Trevor E. Carlson | Associate Professor, National University of Singapore
https://ift.tt/tNBT93X
source https://www.youtube.com/watch?v=PuQIMyz0BeQ
source https://www.youtube.com/watch?v=PuQIMyz0BeQ
Sunday, 30 August 2026
Black Hat Asia 2026 | Model Files → Memory Corruption → RCE: The Triple-Stage AI Attack Chain
Amidst the rapid advancement of artificial intelligence technologies, an increasing number of enterprises and individuals are adopting AI solutions. As the core vessel of AI systems, model files encapsulate substantial training outcomes and intellectual achievements from researchers. With the proliferation of large language models and the maturation of open-source communities, leading organizations are actively promoting model open-sourcing and sharing, making cutting-edge models accessible to developers worldwide.
However, in practical applications, the model loading process has emerged as a critical security vulnerability hotspot. Existing research reveals significant security risks in the model loading mechanisms of mainstream deep learning frameworks. For instance, PyTorch's historical use of pickle for model serialization introduces inherent deserialization vulnerabilities, while TensorFlow is susceptible to remote code execution (RCE) through maliciously crafted Lambda Layers. More alarmingly, as these frameworks predominantly employ C/C++ implementations for high-performance computing, they remain exposed to conventional memory safety threats such as buffer overflows. This raises a crucial question: Can these memory vulnerabilities be weaponized into complete and reliable RCE attack chains?
In this Briefing, to the best of our knowledge, we will present the first publicly disclosed study that systematically exploits memory corruption vulnerabilities in AI model files to achieve reliable remote code execution. By analyzing the memory management mechanisms of mainstream deep learning frameworks, we construct a complete, end-to-end three-stage attack chain — from malicious model files to arbitrary code execution — through carefully designed heap layouts and control-flow hijacking techniques. We further validate the practical exploitability of this attack chain across real-world AI inference systems.
Ji'an Zhou | Security Researcher
Lei Lu | Security Researcher
Li'shuo Song | Security Researcher
https://ift.tt/o07khlr
source https://www.youtube.com/watch?v=nQml4Ng9iVc
source https://www.youtube.com/watch?v=nQml4Ng9iVc
Black Hat Asia 2026 | Payload Compromised: Full Key Recovery in Rocket.Chat E2EE
Rocket.Chat is used in more than 150 countries, where many organizations rely on its end-to-end encryption (E2EE) for security-critical communication. This talk presents the first comprehensive analysis of Rocket.Chat's E2EE as deployed in real systems. By combining automated symbolic analysis with in-depth manual inspection of the implementation, we identify practical attacks that break both confidentiality and integrity.
Our most severe finding is a practical key-recovery attack.
An attacker with access to encrypted user backups can recover private keys and all derived group keys in twelve days under realistic assumptions. We validate this attack with practical proof-of-concept exploits. This results from weak offline-attack resistance combined with a biased, low-entropy password generator used to encrypt key backups. At the time of reporting, any server operating under a malicious-server threat model could execute the attack.
We also uncover structural failures in the platform's key-rotation workflow. Although E2EE passwords and a master key were rotated, the group keys protecting message content were never replaced. Clients continued to accept and redistribute compromised group keys, which were then reused to encrypt new messages and decrypt past ones. A single key recovery therefore enabled expanding and persistent compromise across group communication.
Manual analysis further revealed integrity failures, including ciphertext forgery made possible by unauthenticated AES-CBC encryption.
Beyond the technical flaws, we also reconstruct how this fragile design emerged by examining public development discussions and historical commits. This OSINT analysis explains why several fundamental E2EE principles were never integrated and how long-term structural risks accumulated.
The most severe vulnerabilities, including key recovery and broken key rotation, were fixed within six months of disclosure, and remaining integrity issues were patched after extended coordination. Attendees will learn how to analyze real-world E2EE systems, detect specification-implementation gaps, and replace password-based architectures with modern best practices.
Hayato Kimura | Researcher, National Institute of Information and Communications Technology & The University of Osaka
Ryoma Ito | Senior Researcher, National Institute of Information and Communications Technology
Kazuhiko Minematsu | Research Fellow, NEC Corporation
Takanori Isobe | Professor, The University of Osaka
https://ift.tt/5f7G03M
source https://www.youtube.com/watch?v=35kun8wzFRU
source https://www.youtube.com/watch?v=35kun8wzFRU
Black Hat Asia 2026 | Exploiting BLE Re-Pairing with the BLERP Attacks
Bluetooth Low Energy (BLE) security relies on a Long-Term Key (LTK) that serves as a root of trust. Users implicitly trust their paired devices, such as laptops, mice, and keyboards, assuming that once paired, they are secure. We show that this trust is fragile.
In this talk, we introduce the BLE Re-Pairing Attacks (BLERP), a new class of protocol-level attacks that weaponize the standard re-pairing mechanism to overwrite trusted LTKs with attacker-controlled keys, compromising the BLE security model. We reveal six critical design flaws affecting re-pairing in the latest Bluetooth standard (v6.1), and we show how these flaws enable device impersonation and Man-in-the-Middle (MitM) attacks, even against the most secure BLE configurations. The BLERP attacks are stealthy and practical: they are "0-click" on headless devices, such as keyboards, and require a single unauthenticated interaction on smartphones.
We describe the BLERP Toolkit, an open-source framework built on low-cost nRF52 hardware that enables over-the-air testing of BLE pairing and allows attendees to audit their own devices. The talk includes a live demonstration of a re-pairing Peripheral Impersonation attack against a smartphone and concludes with immediate, actionable mitigations to protect against the BLERP attacks. Attendees will learn about BLE security, how BLERP attacks undermine it, and how to defend against these newly identified threats.
Tommaso Sacchetti | PhD Candidate, EURECOM
Daniele Antonioli | Assistant Professor, EURECOM
https://ift.tt/2lL4dVj
source https://www.youtube.com/watch?v=_08bb55Q33o
source https://www.youtube.com/watch?v=_08bb55Q33o
Saturday, 29 August 2026
Black Hat Asia 2026 | Bad Vibes - Pwning Coding Agents 70 Times With The Same Bugs
It seems like everyone with access to a keyboard is vibe-coding these days, with an increasingly significant amount of code being written through the use of AI Coding Agents. These tools, whether specialized IDEs, IDE extensions, or CLI utilities, come with varying features, interfaces and architectures. However, they all suffer from the same fundamental, severe vulnerabilities and flawed design choices, which we will expose.
Our research has uncovered 70+ serious vulnerabilities across a broad array of major platforms, including GitHub Copilot, Google Gemini CLI and Antigravity, OpenAI Codex, Claude Code, Amazon Q and Kiro, Cursor, and more. These vulnerabilities demonstrate that the industry is collectively making similar, fundamental mistakes in securing these agentic applications, which means that not only coding agents may suffer from similar problems.
In this session, we will first map out what an attacker needs to achieve in order to truly compromise an AI agent. We will present a variety of issues which lead to severe consequences, making coding agents perform actions significantly more devious than just writing terrible code. Come vibe with us as we demonstrate these attacks across multiple products, showing how to turn a successful prompt injection into a devastating machine compromise using various command-line tricks, creative path manipulation techniques, and turning sandbox features against themselves to bypass established defenses.
By detailing the common, critical mistakes shared across these vendors, we aim to provide developers and architects with actionable takeaways to avoid these deep-seated vulnerabilities and better secure the future of AI development tools.
Philip Tsukerman | Vulnerability Research Team Lead, Cyberark
Nil Ashkenazi | Cyber Security Researcher, Cyberark
Alon Zahavi | Senior Security Researcher, Cyberark
https://ift.tt/wUQOSoD
source https://www.youtube.com/watch?v=7UCpHzFYF40
source https://www.youtube.com/watch?v=7UCpHzFYF40
Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning
For years, macOS researchers have focused on high-privilege system and user domain services—yet a vast class of background daemons has quietly operated beneath the radar: PID-domain services. These processes, often reachable even from sandboxed apps, expose privileged functionality and sensitive system controls. Despite their enormous attack surface, they've remained largely unexplored and unprotected—until now.
In this Briefing, we will unveil the first large-scale automated framework for discovering logic vulnerabilities in PID-domain services, powered by LLM-assisted static analysis. We will start by dissecting historical flaws and Apple's patching patterns to formalize a repeatable attack model. Building on that foundation, our framework automatically enumerates connectable PID-domain daemons, decompiles their exported APIs, and leverages LLM semantic reasoning to classify sensitive operations across five categories—from file and privacy access to interprocess privilege crossing. We then map entitlements to these operations and apply taint analysis to trace attacker-controlled data into privileged sinks—surfacing hidden logic flaws that manual auditing would almost certainly miss.
Our evaluation uncovered 12 previously unknown vulnerabilities, including multiple sandbox escapes and TCC privacy bypasses—six of which have already been assigned CVEs by Apple. This research exposes a massive, underestimated attack surface within macOS's userspace and demonstrates how LLMs can be weaponized for scalable vulnerability discovery in closed-source ecosystems. Attendees will gain new insights into Apple's userspace attack surface, automated bug-hunting methodologies, and the next frontier of human–AI collaboration in exploit development.
l_m_h l_m_h | Independent Security Researcher
Yinyi Wu | Security Researcher, Dawn Security Lab, JD.com
Yingqi Shi | Security Researcher, DBAPPSecurity
Yuchong Xie | Security Researcher, The Hong Kong University of Science and Technology
Cheng Li | Security Researcher
Yizhuo Wang | Security Researcher
https://ift.tt/vSPIcka
source https://www.youtube.com/watch?v=uFgB_aMw5-g
source https://www.youtube.com/watch?v=uFgB_aMw5-g
Subscribe to:
Posts (Atom)
-
WeChat, with over 1.2 billion monthly active users, stands as the most popular messaging and social media platform in China and third global...
-
Unmasking State-Sponsored Mobile Surveillance Malware from Russia, China, and North Korea – Threat Actors, Tactics, and Defense Strategies S...