Conference presentations and recordings are now online!
Attack Techniques & Methods2026-08-12, 09:01
Conference presentations and recordings are now online!
We've highlighted a few talks worth checking out:
• Pre-auth RCE in Enterprise Java: When Middleware Becomes the Exploit. Researchers have discovered 12 vulnerabilities in enterprise Java platforms and demonstrate two unauthenticated RCE chains in Bonita BPM and Apache OFBiz.
• Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover. The author presents two Active Directory vulnerabilities. KerberLoss can disrupt Kerberos services and force authentication to fall back to NTLM, while ResetNightmare allows an attacker with permission to modify or create a user or computer object to obtain domain administrator privileges.
• Pass-the-Passkey Family of Attacks. The talk categorizes more than 20 attacks against WebAuthn and FIDO2, including authentication request reuse, relay, and tampering, and examines three vulnerabilities in Windows 11 and Entra ID.
• Handle With Care: Chaining Azure Automation Flaws for Cross-Tenant Identity Takeover. The author shows how an insecure configuration and two Azure Automation flaws allowed an attacker to impersonate another tenant's service account and act with its privileges in a different cloud environment.
• Turning Enterprise Update Servers Into Backdoor Factories. The author shows how, when the WSUS database is hosted on a separate SQL server, NTLM authentication relay can provide access to the database, enable the creation of malicious updates, and deploy them to selected computers.
• When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers. Researchers discovered five memory corruption flaws in Cloudflare's execution environment and used them to escape the sandbox and obtain other customers' secrets.
• No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks. The authors found 12 vulnerabilities in popular AI agent platforms. A malicious document could lead to code execution through internal data-processing mechanisms - even without directly invoking external tools.
• A 0-Click Exploit Chain for the Pixel 10. The authors demonstrate a zero-click compromise of the Pixel 10: a flaw in the Dolby audio decoder enables code execution in a system process, while a VPU driver vulnerability provides root privileges and access to kernel memory.
• Root From Kilometers Away: Ubiquiti AirMax RCE. Researchers reverse-engineered Ubiquiti AirMax's proprietary wireless protocol and discovered two vulnerabilities that allow unauthenticated remote code execution with kernel privileges over the radio link on devices located several kilometers away.
Vendors
Products
More