Conference presentations from DEF CON 34 are now online!
Attack Techniques & Methods2026-08-13, 13:42
Conference presentations from DEF CON 34 are now online!
We've highlighted a few talks worth checking out:
• Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services. The author examines a privilege-escalation vulnerability in GNU telnetd and two Samba flaws, affecting releases spanning more than 25 years, that enabled unauthenticated remote code execution through password-validation and printing mechanisms.
• LaunchBreak: A Sip of Tea, a Click, and a Full Multi-stage Desktop Takeover. Researchers discovered 18 previously unknown vulnerabilities in Electron applications, including the Hyper terminal, the Mailspring email client, and the AI tools DeepChat and Pinokio. In 17 cases, a single click on a crafted link could lead to code execution.
• Zero-Touch Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks. The authors uncovered 17 security issues in TP-Link Omada, a platform for centrally configuring routers, switches, and access points. The attack chains allowed attackers to impersonate controllers and managed devices, steal configuration data and VPN keys, execute commands on gateways, and gain access to internal networks.
• No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes. The authors demonstrate SSRF attacks against internal services, arbitrary file reads and secret theft through Ollama, and a container escape in Docker Model Runner.
• Chaining Logical Bugs for Reliable Windows LPE. The authors combine four Windows logic flaws into two reliable privilege-escalation chains leading to SYSTEM. The attacks use file, process, and registry operations without relying on memory-corruption vulnerabilities.
• OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise. The author demonstrates multiple ways to compromise LiteLLM: an authentication bypass using a junk bearer token, root code execution inside the container under insecure authentication settings, an in-memory backdoor that remains active until the process restarts, and the theft of AWS credentials.
• 8 Out of 10 Banks in Belgium HATE This One Weird eID RCE. The author examines a browser extension used with Belgian electronic identity cards. A malicious webpage could silently read card data, trick the user into entering their PIN and then replay the resulting PIN token, and execute code on the computer through unsafe library loading.
• Plug & Pwn: Weaponizing Windows PnP Auto-Install. The authors show how an emulated USB device can make a fully patched Windows 11 system install vulnerable signed vendor software, leading to code execution as SYSTEM. A remote variant of the attack works through USB redirection in an RDP session.
Vendors
More
Products
More