Conference recordings from TROOPERS26 are now online!
Attack Techniques & Methods2026-08-10, 12:46
Conference recordings from TROOPERS26 are now online!
We've highlighted a few talks worth checking out:
• Popping Microsoft's Sandbox: What Falls Out of a Dataverse Container. The speaker demonstrates how Microsoft Dataverse's built-in capabilities enabled them to obtain maximum privileges in a cloud container, extract credentials and cryptographic keys, and then investigate the possibility of executing code in other customers' environments through an internal unauthenticated interface.
• Confused Recovery: A New Attack Class on Windows Recovery. The talk presents four vulnerabilities in the Windows Recovery Environment and two exploitation methods that allow an attacker to replace the volume being recovered, completely bypass BitLocker, and extract protected secrets.
• Breaking the Backbone of Global ISP Networks. The speaker demonstrates three unauthenticated RCE vulnerabilities in GPON OLTs and another in a cloud management platform. Exploiting them makes it possible to move from compromising an individual device to maintaining control over all OLTs managed by an internet service provider.
• I'm_in_your_cloud_v4_FINAL.pdf — Hacking Everyone's Cloud. The talk covers a years-long study of hybrid AD and Entra ID environments. It led to the discovery of internal Microsoft tokens (Actor Tokens) and a critical flaw in the Azure AD Graph API that allowed attackers to obtain global administrator privileges in other organizations' cloud environments.
• KDS Root Keys: All Secrets Finally Revealed. The speaker shows how, after fully compromising Active Directory, KDS keys can be used to obtain service account passwords, extract LAPS and DSRM passwords at scale, and decrypt DPAPI-NG secrets and BitLocker volumes using the SID Protector mechanism.
• ESC17: Using ADCS to Attack HTTPS-Enabled WSUS Clients. The authors combine ADCS misconfigurations with a MitM attack against WSUS and present a new ESC17 escalation class that enables code execution on Windows machines even when HTTPS and common security recommendations are in use.
• Living Off The Pipeline: Defensive Research, Weaponized. The talk demonstrates an attack chain targeting CI/CD pipelines: finding vulnerable automation scripts, exploiting unsafe handling of change requests, stealing secrets, tampering with releases, and moving from a temporary build environment to persistent cloud administrator privileges.
• A SIM Hacking Odyssey: Can a SIM Hack YOU?. The authors examine attacks using a malicious SIM card: geolocation leaks, cellular modem memory corruption, screen-lock bypasses, and modem control through SIM-issued commands. They also present tools for SIM emulation and automated vulnerability discovery.
Vendors
Products
More