#blackhat2024 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blackhat2024, aggregated by home.social.
-
A cool #blackhat2024 talk on using Wi-Fi routers for population #surveillance
TLDR; Every person with an iPhone is a spy for #bigdata.
-
A cool #blackhat2024 talk on using Wi-Fi routers for population #surveillance
TLDR; Every person with an iPhone is a spy for #bigdata.
-
#CoPilot: Wenn einem Sicherheit unwichtig ist, kann man da tolle Sachen mit machen.
Michael Bargury auf der #BlackHat2024:
https://www.youtube.com/watch?v=FH6P288i2PE -
#CoPilot: Wenn einem Sicherheit unwichtig ist, kann man da tolle Sachen mit machen.
Michael Bargury auf der #BlackHat2024:
https://www.youtube.com/watch?v=FH6P288i2PE -
#CoPilot: Wenn einem Sicherheit unwichtig ist, kann man da tolle Sachen mit machen.
Michael Bargury auf der #BlackHat2024:
https://www.youtube.com/watch?v=FH6P288i2PE -
#CoPilot: Wenn einem Sicherheit unwichtig ist, kann man da tolle Sachen mit machen.
Michael Bargury auf der #BlackHat2024:
https://www.youtube.com/watch?v=FH6P288i2PE -
#CoPilot: Wenn einem Sicherheit unwichtig ist, kann man da tolle Sachen mit machen.
Michael Bargury auf der #BlackHat2024:
https://www.youtube.com/watch?v=FH6P288i2PE -
#Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
#MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
https://www.pcmag.com/news/signal-developer-explains-why-early-encrypted-messaging-tools-flopped -
#Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
#MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
https://www.pcmag.com/news/signal-developer-explains-why-early-encrypted-messaging-tools-flopped -
#Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
#MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
https://www.pcmag.com/news/signal-developer-explains-why-early-encrypted-messaging-tools-flopped -
#Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
#MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
https://www.pcmag.com/news/signal-developer-explains-why-early-encrypted-messaging-tools-flopped -
#Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
#MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
https://www.pcmag.com/news/signal-developer-explains-why-early-encrypted-messaging-tools-flopped -
Noch kein Patch: Sicherheitsforscher beraubt Windows sämtlicher Schutzfunktionen | Security https://www.heise.de/news/Noch-kein-Patch-Sicherheitsforscher-beraubt-Windows-saemtlicher-Schutzfunktionen-9834479.html #BlackHat2024 #BlackHat24 #BlackHat #DefCon #DefCon32 #DefCon2024
-
Noch kein Patch: Sicherheitsforscher beraubt Windows sämtlicher Schutzfunktionen | Security https://www.heise.de/news/Noch-kein-Patch-Sicherheitsforscher-beraubt-Windows-saemtlicher-Schutzfunktionen-9834479.html #BlackHat2024 #BlackHat24 #BlackHat #DefCon #DefCon32 #DefCon2024
-
Noch kein Patch: Sicherheitsforscher beraubt Windows sämtlicher Schutzfunktionen | Security https://www.heise.de/news/Noch-kein-Patch-Sicherheitsforscher-beraubt-Windows-saemtlicher-Schutzfunktionen-9834479.html #BlackHat2024 #BlackHat24 #BlackHat #DefCon #DefCon32 #DefCon2024
-
Mit Domain-Based Authentication in unternehmensinterne Gruppen eindringen | iX Magazin https://www.heise.de/news/Mit-Domain-Based-Authentication-in-unternehmensinterne-Gruppen-eindringen-9830944.html #BlackHat #BlackHat2024 #BlackHat24
-
Mit Domain-Based Authentication in unternehmensinterne Gruppen eindringen | iX Magazin https://www.heise.de/news/Mit-Domain-Based-Authentication-in-unternehmensinterne-Gruppen-eindringen-9830944.html #BlackHat #BlackHat2024 #BlackHat24
-
Mit Domain-Based Authentication in unternehmensinterne Gruppen eindringen | iX Magazin https://www.heise.de/news/Mit-Domain-Based-Authentication-in-unternehmensinterne-Gruppen-eindringen-9830944.html #BlackHat #BlackHat2024 #BlackHat24
-
Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.
These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.
Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.
Orange Tsai's Research findings: https://blog.orange.tw/2024/08/confusion-attacks-en.html
Blackhat Presentation: https://i.blackhat.com/BH-US-24/Presentations/US24-Orange-Confusion-Attacks-Exploiting-Hidden-Semantic-Thursday.pdf
Akami acknowledgement and mitigations: https://www.akamai.com/blog/security-research/2024-august-apache-waf-proactive-collaboration-orange-tsai-devcore
-
Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.
These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.
Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.
Orange Tsai's Research findings: https://blog.orange.tw/2024/08/confusion-attacks-en.html
Blackhat Presentation: https://i.blackhat.com/BH-US-24/Presentations/US24-Orange-Confusion-Attacks-Exploiting-Hidden-Semantic-Thursday.pdf
Akami acknowledgement and mitigations: https://www.akamai.com/blog/security-research/2024-august-apache-waf-proactive-collaboration-orange-tsai-devcore
-
Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.
These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.
Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.
Orange Tsai's Research findings: https://blog.orange.tw/2024/08/confusion-attacks-en.html
Blackhat Presentation: https://i.blackhat.com/BH-US-24/Presentations/US24-Orange-Confusion-Attacks-Exploiting-Hidden-Semantic-Thursday.pdf
Akami acknowledgement and mitigations: https://www.akamai.com/blog/security-research/2024-august-apache-waf-proactive-collaboration-orange-tsai-devcore
-
Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.
These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.
Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.
Orange Tsai's Research findings: https://blog.orange.tw/2024/08/confusion-attacks-en.html
Blackhat Presentation: https://i.blackhat.com/BH-US-24/Presentations/US24-Orange-Confusion-Attacks-Exploiting-Hidden-Semantic-Thursday.pdf
Akami acknowledgement and mitigations: https://www.akamai.com/blog/security-research/2024-august-apache-waf-proactive-collaboration-orange-tsai-devcore
-
Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.
These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.
Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.
Orange Tsai's Research findings: https://blog.orange.tw/2024/08/confusion-attacks-en.html
Blackhat Presentation: https://i.blackhat.com/BH-US-24/Presentations/US24-Orange-Confusion-Attacks-Exploiting-Hidden-Semantic-Thursday.pdf
Akami acknowledgement and mitigations: https://www.akamai.com/blog/security-research/2024-august-apache-waf-proactive-collaboration-orange-tsai-devcore
-
Black Hat 2024: Secure Shells in Shambles [pdf]
-
Black Hat 2024: Secure Shells in Shambles [pdf]
-
Black Hat 2024: Secure Shells in Shambles [pdf]
-
Blue teamers attending #defcon2024 #blackhat2024 : YEA! AWESOME!
Blue teamers not attending: Ugh...all these new vulns...
-
Blue teamers attending #defcon2024 #blackhat2024 : YEA! AWESOME!
Blue teamers not attending: Ugh...all these new vulns...
-
Blue teamers attending #defcon2024 #blackhat2024 : YEA! AWESOME!
Blue teamers not attending: Ugh...all these new vulns...
-
Sicherheitsforscher verwandeln Sonos-One-Lautsprecher in Wanze | Security https://www.heise.de/news/Sicherheitsforscher-verwandeln-Sonos-One-Lautsprecher-in-Wanze-9830061.html #Hacking #BlackHat #BlackHat2024 #BlackHat24 #Exploit
-
Sicherheitsforscher verwandeln Sonos-One-Lautsprecher in Wanze | Security https://www.heise.de/news/Sicherheitsforscher-verwandeln-Sonos-One-Lautsprecher-in-Wanze-9830061.html #Hacking #BlackHat #BlackHat2024 #BlackHat24 #Exploit
-
Sicherheitsforscher verwandeln Sonos-One-Lautsprecher in Wanze | Security https://www.heise.de/news/Sicherheitsforscher-verwandeln-Sonos-One-Lautsprecher-in-Wanze-9830061.html #Hacking #BlackHat #BlackHat2024 #BlackHat24 #Exploit
-
I've been quiet on here for a while, but wnated to share the blog that details much of UnOAuthorized from my #bhusa talk yesterday.
#blackhat #blackhat2024 #EntraID #azure #microsoft365 #microsoft #infosec
https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/
-
I've been quiet on here for a while, but wanted to share the blog that details much of UnOAuthorized from my #bhusa talk yesterday.
#blackhat #blackhat2024 #EntraID #azure #microsoft365 #microsoft #infosec
https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/
-
I've been quiet on here for a while, but wanted to share the blog that details much of UnOAuthorized from my #bhusa talk yesterday.
#blackhat #blackhat2024 #EntraID #azure #microsoft365 #microsoft #infosec
https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/
-
I've been quiet on here for a while, but wanted to share the blog that details much of UnOAuthorized from my #bhusa talk yesterday.
#blackhat #blackhat2024 #EntraID #azure #microsoft365 #microsoft #infosec
https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/
-
I've been quiet on here for a while, but wanted to share the blog that details much of UnOAuthorized from my #bhusa talk yesterday.
#blackhat #blackhat2024 #EntraID #azure #microsoft365 #microsoft #infosec
https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/
-
The #DCG201 #HackerSummerCamp 2024 for
@blackhatevents is LIVE: https://defcon201.medium.com/hacker-summer-camp-2024-guides-part-fourteen-black-hat-usa-2024-7d7d38c80a79@defcon #defcon32 guide out tomorrow morning!
#BHUSA #BlackHat #BlackHatUSA #BlackHat2024 #BH2024 #CISO @redteamtools @thedarktangent @patrickwardle @signalapp #cisa #omdia @grifter
Still hammering these out. Apologies. Life happens.
-
The #DCG201 #HackerSummerCamp 2024 for
@blackhatevents is LIVE: https://defcon201.medium.com/hacker-summer-camp-2024-guides-part-fourteen-black-hat-usa-2024-7d7d38c80a79@defcon #defcon32 guide out tomorrow morning!
#BHUSA #BlackHat #BlackHatUSA #BlackHat2024 #BH2024 #CISO @redteamtools @thedarktangent @patrickwardle @signalapp #cisa #omdia @grifter
Still hammering these out. Apologies. Life happens.
-
The #DCG201 #HackerSummerCamp 2024 for
@blackhatevents is LIVE: https://defcon201.medium.com/hacker-summer-camp-2024-guides-part-fourteen-black-hat-usa-2024-7d7d38c80a79@defcon #defcon32 guide out tomorrow morning!
#BHUSA #BlackHat #BlackHatUSA #BlackHat2024 #BH2024 #CISO @redteamtools @thedarktangent @patrickwardle @signalapp #cisa #omdia @grifter
Still hammering these out. Apologies. Life happens.
-
The #DCG201 #HackerSummerCamp 2024 for
@blackhatevents is LIVE: https://defcon201.medium.com/hacker-summer-camp-2024-guides-part-fourteen-black-hat-usa-2024-7d7d38c80a79@defcon #defcon32 guide out tomorrow morning!
#BHUSA #BlackHat #BlackHatUSA #BlackHat2024 #BH2024 #CISO @redteamtools @thedarktangent @patrickwardle @signalapp #cisa #omdia @grifter
Still hammering these out. Apologies. Life happens.
-
The #DCG201 #HackerSummerCamp 2024 for
@blackhatevents is LIVE: https://defcon201.medium.com/hacker-summer-camp-2024-guides-part-fourteen-black-hat-usa-2024-7d7d38c80a79@defcon #defcon32 guide out tomorrow morning!
#BHUSA #BlackHat #BlackHatUSA #BlackHat2024 #BH2024 #CISO @redteamtools @thedarktangent @patrickwardle @signalapp #cisa #omdia @grifter
Still hammering these out. Apologies. Life happens.
-
Quite a rock concert intro to a panel about election security. #blackhat2024
-
Quite a rock concert intro to a panel about election security. #blackhat2024
-
Quite a rock concert intro to a panel about election security. #blackhat2024
-
Available at the #BlackHat2024 bookstore. Jus' sayin'
-
Available at the #BlackHat2024 bookstore. Jus' sayin'
-
Available at the #BlackHat2024 bookstore. Jus' sayin'
-
Available at the #BlackHat2024 bookstore. Jus' sayin'
-
Available at the #BlackHat2024 bookstore. Jus' sayin'
-
Zed is having fun at the @TrendMicro booth at #BlackHat2024.
-
Zed is having fun at the @TrendMicro booth at #BlackHat2024.
-
Zed is having fun at the @TrendMicro booth at #BlackHat2024.
-
Zed is having fun at the @TrendMicro booth at #BlackHat2024.
-
Braving the heat for #BlackHat2024? Come find EFF in the Business Hall! We’re in the 4400 section in the AI Zone 🤖 https://www.eff.org/event/eff-black-hat-usa-0