Conference presentations are now online!

Conference presentations are now online!
We've highlighted a few talks worth checking out:
CAUTION: HIGH VOLTAGE, LOW SECURITY — A Familiar Tale of Cybersecurity Woes. The author examines attacks against electric vehicles and charging stations, including connection hijacking to intercept and modify charging-session traffic, file and network-key extraction, remote control over Modbus, and firmware modification through JTAG. The talk covers three published vulnerabilities.
Don't Look Up: There Are Sensitive Internal Links in the Clear on GEO Satellites. Using a satellite dish, the researchers scanned 411 transponders across 39 geostationary satellites and reconstructed the transmitted network traffic. They found unencrypted phone calls and text messages, cellular-network keys, military asset locations, industrial-control traffic, and payment data.
Extraction of Secrets from 40nm CMOS Gate Dielectric Breakdown Antifuses by FIB Passive Voltage Contrast. The author shows how a focused ion beam and passive voltage contrast can be used to read programmable antifuses in the RP2350 microcontroller. The researchers reconstructed the array layout and demonstrated bulk bit readout, enabling secrets to be extracted from a protected chip.
EVSEFuzz: A Tool for Automated Testing of Protocol Implementations. The authors present a tool for automated black-box testing of electric-vehicle charging protocols. Applying it to EVerest uncovered two vulnerabilities capable of disrupting charging stations, as well as a new flaw introduced while fixing an earlier issue.
The Vehicle May Be Sick: Denial of Diagnostic Services by Exploiting the CAN Transport Protocol. The authors demonstrate eight ways to disrupt vehicle diagnostics by abusing the CAN transport protocol. Given access to the CAN bus, the attacks can suppress or manipulate diagnostic results, alter fault-code readings, and disrupt vehicle configuration programming.
Battle-Testing NIST IR 8473 with Pwn2Own Automotive: Control Coverage of Real-World EVSE Exploit Chains. The author reconstructs real-world charging-station exploit chains from Pwn2Own Automotive, including entry through the charging connector, access to an internal CAN bus and UDS, rollback to vulnerable firmware, recovery of setup access-point credentials, code execution through a debug shell, and an anti-rollback bypass.
Vendors
Escar
Nist
Pwn2Own
Products
Can Bus
Escar Usa 2026
Everest
Evsefuzz
Geo Satellites
Jtag
More