just_user

user_just
Moderator
Регистрация
19.08.25
Сообщения
372
Реакции
264
Презентации - Для просмотра ссылки Войди или Зарегистрируйся
Content:
1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud
8 Out of 10 Banks in Belgium HATE This One Weird eID RCE
A Provider for the MOFia — Distributed Post-Ex Capabilities
Beyond the Ceremony: The 2026 Passkey Attack Surface
Bird Hunting Season: The Final Flight
BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft
Breaking Hardware CFI with Sigreturn
Breaking into Amazon lockers by any means necessary
Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys
Bring Your Own Root Of Trust
Bring-Your-Own-EDR — Breaking Windows Process Protection to build EDR-Protected Malware
C(2)YA: Inside the Adversary's Inbox
Chaining Logical Bugs for Reliable Windows LPE
Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel
CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale
Compounding Interest: Exploiting the ATM Supply Chain
Cracking North Korea's Information Control
Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming
CUDA've done better — Hacking Nvidia GPUs for container-escape and privilege escalation
Data Tomb Raider: Raiding Modern AI Vaults with Legacy Flaws for Treasure Stealing
Dylib Hijacking on macOS: Dead or Alive?
ESP32 as a counter-surveillance platform
Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services
From square root to /root: escalating privileges in Azure containers with Python in Excel
Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild
Going the Distance: Long-Range Keystroke Injection via Meshtastic
Gone in 60 Frames — USB Video Exploitation
Gotta Catch 'Em All: How To Capture 3.5 Billion WhatsApp Accounts
Gotta Phish 'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle
gpwn: Wiretapping fiber (GPON) ISP deployments from the comfort of your home
Hacking the EOD Bot: How I Learned to Stop Worrying and Love the Boomba
Hacking the Government: How Two Researchers Turned Late-Night Boredom Into a National Audit
Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Underground VPN Infrastructure
Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design
Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations
High Voltage Heist: Turning Your EV into my Power Bank
How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs?
Install Me Maybe: Turning Claimable VS Code Extension IDs into Supply-Chain Attacks
Keychained Melody — Grabbing the Keys to the iCloud Kingdom
LaunchBreak: a Sip of Tea, a Click, and a Full Multi-stage Desktop Takeover
Lessons from a decade of building whistleblower tech
LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
Looking and Peering: Attacking from beyond BGP Adjacency
Lowering the Orbit: Exploiting Satellite Protocols and communications via Software-Defined-Radio and GS
Memory Laundering via Metal: What EDR Can't See on Your Mac
No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes
noRecognition: Could a pattern on your clothing fool Facial Recognition?
OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise
One Chain to Own Them All — Breaking AI Infrastructures
Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet's V8 on the Galaxy S25
Plug And Pwn: Weaponizing Windows PnP Auto-Install
Pwning Rekordbox: Unauthenticated filesystem access in the world's most popular DJ software
Rage Against the Sandbox: Bypassing Apple's iOS Security to Run Unsigned Code via SSH
Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking)
Riding for Free — Breaking Public Transport RFID at Scale
Root From Kilometers Away: Ubiquiti AirMax RCE
Sliding into the Flight Deck's DMs: Practical Message Attacks on CPDLC
Smile, you're on camera! Livestreaming from North Korea's IT workers laptop farm
Taking on the Dark Fleet... in Cyberspace!
Talkers Without Borders: Worldwide Free Speech without an Internet Connection
Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System
TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
Texas Incidents — How we broke the OMAP-L138 Trusted Execution Environment
The Compiler That Can't Read: Crashing Every 5G Phone With One Byte
The Enclave is Lying to You: Breaking TEE Trust Boundaries Through Boot-Time State
The Ghost Key: Illusions of "Time Management" in TTLock Smart Locks
The Stream Is Dead, Long Live the Stream: How HTTP/2 Lets Dead Streams Keep Servers Working
Thin Client? Thin Crypto — Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher
Throw Out the Alphabet: Token-Based Markov Chains for Password Cracking
Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children and Vehicles
Transformers: Dark Side of the Type — Weaponizing the Conversion Layer
Very Pwned: Hacking Verifone's card machine three times in a row
Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written
Witchcraft Solver: Automated 0day Discovery in Stripped Binaries
Wrestling with a Python: Escaping Copilot Studio's AI-Guarded Sandbox
You've Got Mail (That Was Meant For No One)
Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet
Your Packets Are Showing: Hybrid Quantum ML for Passive OS Fingerprinting
Your WAF Blocked Us, That Was The Exploit — Remote Agent Takeover via Cloudflare, Sentry and Cloud APMs
Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks
 
  • Like
Реакции: Nowheretogo