Find partners
ThinkstScapes

ThinkstScapes

Hosted by Jacob Torrey, research@thinkst.com, haroon meer, marco slaviero

Episodes

20

Latest episode

Jul 2026

Language

EN

About the show

The ThinkstScapes podcast aims to distill and disseminate the cybersecurity research published worldwide. Our researchers track and review hundreds and thousands of talks (so you don't have to) and then bring this to you in small, digestible chunks.

Listen to episodes

20 recent
July 31, 202630 min

ThinkstScapes Research Roundup - Q2 - 2026

Infrastructure under renewed scrutiny Lost in Translation: Text Message Spoofing via Email Sumanth Rao, Ye Shu, Stefan Savage, Aaron Schulman, Geoffrey M. Voelker, and Enze Liu [ Code ] [ Paper ] Hack the Source, Of the Source Tsi-Lin Ng [ Slides ] RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox Xiang Li, Yuqi Qiu, Mingming Zhang, Zuyao Xu, Lu Sun, Baojun Liu, Jia Zhang, Xiaofeng Zheng, Haixin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan, and Fasheng Miao [ Slides ] [ Paper ] Strange Inputs, Critical outputs: Attacking Infrastructure Through Innocuous Network Protocol Fields Sasha Romijn [ Blog post ] [ Video ] Clouds raining data Sub:jugation – Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers Tal Skverer [ Blog post ] [ Video ] Rain: Transiently Leaking Data from Public Clouds Using Old Vulnerabilities Mathé Hertogh, Dave Quakkelaar, Thijs Raymakers, Mahesh Hari Sarma, Marius Muench, Herbert Bos, and Erik van der Kouwe [ Code ] [ Paper ] [ Site ] OCInferno: An Offensive Security Toolkit for OCI Scott Weston [ Code ] [ Lightning Talk Video ] [ Video ] Zapocalypse: Compromising every Zapier user through a Lambda memory leak Yair Balilti [ Video ] [ Website ] Sharp edges in Windows ecosystems Breaking Hybrid Boundaries Across Azure and Windows Ilan Kalendarov and Ben Zamir [ Slides ] PhantomRPC: A New Privilege Escalation Flaw in Windows RPC Haidar Kabibo [ Slides ] [ Code ] Iron Giant: When the vault becomes the victim Erik Egsgard [ Video ] Hunting with models, and models being hunted RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke Inference Qijun Wang, Chunqi Qian, and Huacheng Zeng [ Code ] [ Paper ] [ Site ] Revelio: Blurred Images Can Still Disclose Your Identity Haoyu Zhai, Shuo Wang, Pirouz Naghavi, Qingying Hao, and Gang Wang [ Site ] [ Paper ] Bad Vibes: Pwning Coding Agents 70 Times With The Same Bugs Philip Tsukerman, Nil Ashkenazi, and Alon Zahavi [ Slides ] System Over Model, Tested: Reproducing Mythos's FreeBSD Find on Local Open-Weight Models John McIntosh [ Blog post ] [ Code ] Nifty sundries Protecting Cookies with Device Bound Session Credentials Benjamin Ackerman, Daniel Rubery, and Guillaume Ehinger [ Blog post ] [ Documentation ] Turning Spam Filters Into Your Greatest Enemy: Intrusions Via RCEs in E-Mail Spam Filters Ting-Wei Hsieh and Kai-Ching Wang [ Slides ] AirSnitch: Breaking Client Isolation in Wi-Fi Networks Mathy Vanhoef, Zhiyun Qian, Xin'an Zhou, Juefei Pu, Zhutian Liu, Zhaowei Tan, and Srikanth Krishnamurthy [ Slides ] [ Paper ] [ Code ]

May 29, 202627 min

ThinkstScapes Research Roundup - Q1 - 2026

Pushing browsers to the limit Abusing Modern Browser Features for Phishing Alexander Hurbean [ Blog post ] [ Video ] Committing CSS Crimes for fun and profit Lyra Rebane [ Slides ] [ Blog post ] [ Video ] Improving the Trustworthiness of Javascript on the Web Ezzudin Alkotob, Giulio Berra, Benjamin Beurdouche, Richard Hansen, Daniel Huigens, Dennis Jackson, Cory Francis Myers, and Michael Rosenberg [ Slides ] [ Blog post ] LLMs standing tall Black-hat LLMs Nicholas Carlini [ Video ] [ Slides ] On the Coming Industrialisation of Exploit Generation with LLMs Sean Heelan [ Blog post ] [ Code ] AI Security with Guarantees Ilia Shumailov [ Slides ] [ Paper ] [ Video ] 200 Bugs/Week/Engineer: How We Rebuilt Trail of Bits Around AI Dan Guido [ Slides ] [ Blog post ] [ Video ] Systematic debugging for AI agents: Introducing the AgentRx framework Shraddha Barke, Arnav Goyal, Alind Khare, and Chetan Bansal [ Blog post ] [ Paper ] [ Code ] LLMs taking a fall Trust Me, I Know This Function: Hijacking LLM Static Analysis using Bias Shir Bernstein, David Beste, Daniel Ayzenshteyn, Lea Schönherr, and Yisroel Mirsky [ Slides ] [ Paper ] [ Code ] AI Agent Traps Matija Franklin, Nenad Tomašev, Julian Jacobs, Joel Z. Leibo, and Simon Osindero [ Paper ] Leaking secrets from the claud Niels Hofmans [ Blog post ] [ Code ] Scary Agent Skills: Hidden Unicode Instructions in Skills ...And How To Catch Them wunderwuzzi [ Blog post ] [ Code ] [ Video ] Nifty sundries Data Honeytokens for the Cloud Era Petrus Vasenius [ Blog post ] [ Video ] The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber Defense Volodymyr Styran [ Paper ] The AWS Console and Terraform Security Gap Laurence Tennant [ Blog post ] The Limit Is the Sky… (Or Not)? Antonio Nappa [ Slides ] [ Code ] [ Video ] Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Google Threat Intelligence Group [ Blog post ]

February 12, 202633 min

ThinkstScapes Research Roundup - Q4 - 2025

Networking beyond plug-and-play GET /large file HTTP/1.1: Connection-Based TCP Amplification Attacks Yepeng Pan, Lars Richter, and Christian Rossow [ Paper ] [ Code ] WAFFLED: Exploiting Parsing Discrepancies to Bypass Web Application Firewalls Seyed Ali Akhavani, Bahruz Jabiyev, Ben Kallus, Cem Topcuoglu, Sergey Bratus, and Engin Kirda [ Paper ] [ Code ] Excuse me, what precise time is it? Oliver Ettlin [ Video ] Cut To The QUIC: Slashing QUIC's Performance With A Hash DoS Paul Bottinelli [ Slides ] [ Code ] High-impact security at the foundations Understanding the Security Impact of CHERI on the Operating System Kernel Zhaofeng Li, Jerry Zhang, Joshua Tlatelpa-Agustin, Xiangdong Chen, and Anton Burtsev [ Code ] [ Paper ] CUDA de Grâce: Owning AI Cloud Infrastructure with GPU Exploits Valentina Palmiotti and Samuel Lovejoy [ Video ] Defeating KASLR by Doing Nothing at All Seth Jenkins [ Blog post ] [ Code ] Build a Fake Phone, Find Real Bugs: Qualcomm GPU Emulation and Fuzzing with LibAFL QEMU Romain Malmain and Scott Bauer [ Code ] [ Video ] Rust in Android: move fast and fix things Jeff Vander Stoep [ Blog post ] [ Rust course ] Skynet Starter Kit: From Embodied AI Jailbreak to Remote Takeover of Humanoid Robots Shipei Qu, Zikai Xu, and Xuangan Xiao [ Video ] Wins and losses with LLMs and security Scaling agentic architectures for autonomous security testing and offensive operations Jason Garman, Jake Coyne, and Aaron Brown [ Slides ] [ Code ] Forced Descent: Google Antigravity Persistent Code Execution Vulnerability Aaron Portnoy [ Blog post ] Flaw And Order: Finding The Needle In The Haystack Of CodeQL Using LLMs Simcha Kosman [ Slides ] [ Blog post ] [ Code ] Rescuing the Unpoisoned: Efficient Defense against Knowledge Corruption Attacks on RAG Systems Kim Minseok, Lee Hankook, and Koo Hyungjoon [ Code ] [ Paper ] Whisper Leak: A novel side-channel attack on remote language models Jonathan Bar Or and Geoff McDonald [ Blog post ] [ Paper ] [ Code ] Nifty sundries Format-Preserving Compression-Tolerating Authenticated Encryption for Images Alexandra Boldyreva, Kaishuo Cheng, and Jehad Hussein [ Slides ] [ Paper ] Why Quantum Cryptanalysis is Bollocks Peter Gutmann [ Video ] [ Slides ] Unmasking Organizations' Security Postures: Insights From Phishing-Resistant Authentication Fei Liu [ Slides ] Those Who Do Not Learn from Advisories Are Doomed to Repeat Them Louis Nyffenegger [ Video ]

November 11, 202538 min

ThinkstScapes Research Roundup - Q3 - 2025

Q3’25 ThinkstScapes Microsoft-induced security woes One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens Dirk-jan Mollema [ Blog post ] Turning Microsoft's Login Page into our Phishing Infrastructure Keanu Nys [ Slides ] [ Video ] You snooze you lose: RPC-Racer winning RPC endpoints against services Ron Ben Yizhak [ Slides ] [ Code ] [ Video ] Internal Domain Name Collision 2.0 Philippe Caturegli [ Slides ] [ Video ] Logs are not always as they appear Source IP Spoofing in Cloud Logs: A Hands-On Look Across AWS, Azure, and GCP Eliav Livneh [ Video ] I'm in Your Logs Now, Deceiving Your Analysts and Blinding Your EDR Olaf Hartong [ Slides ] [ Code ] From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion Shu-Hao Tung [ Slides ] [ Paper ] [ Video ] Autobots roll out! Automating software security with LLMs Tyler Nighswander [ Site ] [ Code ] [ Video ] Agents Built From Alloys Albert Ziegler [ Blog post ] [ Dataset ] AI Agents for Offsec with Zero False Positives Brendan Dolan-Gavitt [ Slides ] Are CAPTCHAs Still Bot-hard? Generalized Visual CAPTCHA Solving with Agentic Vision Language Model Xiwen Teoh, Yun Lin, Siqi Li, Ruofan Liu, Avi Sollomoni, Yaniv Harel, and Jin Song Dong [ Site ] [ Paper ] [ Code ] Good vibrations Invisible Ears at Your Fingertips: Acoustic Eavesdropping via Mouse Sensors Mohamad Habib Fakih, Rahul Dharmaji, Youssef Mahmoud, Halima Bouzidi, and Mohammad Abdullah Al Faruque [ Site ] [ Paper ] TimeTravel: Real-time Timing Drift Attack on System Time Using Acoustic Waves Jianshuo Liu, Hong Li, Haining Wang, Mengjie Sun, Hui Wen, Jinfa Wang, and Limin Sun [ Paper ] Nifty sundries Crescent library brings privacy to digital identity systems Christian Paquin, Guru-Vamsi Policharla, and Greg Zaverucha [ Blog post ] [ Paper ] [ Code ] Journey to the center of the PSTN: How I became a phone company, and how you can too Enzo Damato [ Slides ] [ Video ] Safe Harbor or Hostile Waters: Unveiling the Hidden Perils of the TorchScript Engine in PyTorch Ji'an Zhou and Lishuo Song [ Slides ] Ghosts in the Machine Check – Conjuring Hardware Failures for Cross-ring Privilege Escalation Christopher Domas [ Slides ] [ Code ] [ Video ] Machine Against the RAG: Jamming Retrieval-Augmented Generation with Blocker Documents Avital Shafran, Roei Schuster, and Vitaly Shmatikov [ Paper ] [ Code ] Inverting the Xorshift128+ random number generator Scott Contini [ Blog post ] [ Code ]

August 4, 202534 min

ThinkstScapes Research Roundup - Q2 - 2025

ThinkstScapes Q2’25 Networking is always tricky Beyond the Horizon: Uncovering Hosts and Services Behind Misconfigured Firewalls Qing Deng, Juefei Pu, Zhaowei Tan, Zhiyun Qian, and Srikanth V. Krishnamurthy [ Paper ] 0.0.0.0 Day: Exploiting Localhost APIs From The Browser Avi Lumelsky and Gal Elbaz [ Blog post ] [ Video ] Local Mess: Covert Web-to-App Tracking via Localhost on Android Aniketh Girish, Gunes Acar, Narseo Vallina-Rodriguez, Nipuna Weerasekara, and Tim Vlummens [ Website ] Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer Niklas Niere, Felix Lange, Juraj Somorovsky, and Robert Merget [ Code ] [ Paper ] Language models large and small The road to Top 1: How XBOW did it Nico Waisman [ Blog post ] AI and Secure Code Generation Dave Aitel and Dan Geer [ Blog post ] A look at CloudFlare’s AI-coded OAuth library Neil Madden [ Blog post ] How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation Sean Heelan [ Blog post ] [ Code ] Enhancing Secret Detection in Cybersecurity with Small LMs Danny Lazarev and Erez Harush [ Blog post ] [ Video ] BAIT: Large Language Model Backdoor Scanning by Inverting Attack Target Guangyu Shen, Siyuan Cheng, Zhuo Zhang, Guanhong Tao, Kaiyuan Zhang, Hanxi Guo, Lu Yan, Xiaolong Jin, Shengwei An, Shiqing Ma, and Xiangyu Zhang [ Code ] [ Paper ] When parsing goes right, and when it goes wrong 3DGen: AI-Assisted Generation of Provably Correct Binary Format Parsers Sarah Fakhoury, Markus Kuppe, Shuvendu K. Lahiri, Tahina Ramananandro, and Nikhil Swamy [ Slides ] [ Paper ] GDBMiner: Mining Precise Input Grammars on (Almost) Any System Max Eisele, Johannes Hägele, Christopher Huth, and Andreas Zeller [ Paper ] [ Code ] Parser Differentials: When Interpretation Becomes a Vulnerability Joernchen / Joern Schneeweisz [ Slides ] [ Video ] Inbox Invasion: Exploiting MIME Ambiguities to Evade Email Attachment Detectors Jiahe Zhang, Jianjun Chen, Qi Wang, Hangyu Zhang, Shengqiang Li, Chuhan Wang, Jianwei Zhuge, and Haixin Duan [ Slides ] [ Paper ] [ Code ] Nifty sundries Impostor Syndrome: Hacking Apple MDMs Using Rogue Device Enrolments Marcell Molnár and Magdalena Oczadły [ Slides ] Your Cable, My Antenna: Eavesdropping Serial Communication via Backscatter Signals Lina Pu, Yu Luo, Song Han, and Junming Diao [ Paper ] GoSonar: Detecting Logical Vulnerabilities in Memory Safe Language Using Inductive Constraint Reasoning Md Sakib Anwar, Carter Yagemann, and Zhiqiang Lin [ Paper ] [ Code ] Show Me Your ID(E)!: How APTs Abuse IDEs Tom Fakterman and Daniel Frank [ Slides ] [ Video ] Inviter Threat: Managing Security in a new Cloud Deployment Model Meg Ashby [ Video ] Carrier Tokens—A Game-Changer Towards SMS OTP Free World! Kazi Wali Ullah [ Slides ] [ Code ] [ Video ]

April 30, 202529 min

ThinkstScapes Research Roundup - Q1 - 2025

ThinkstScapes Q1’25 Putting it into practice Homomorphic Encryption across Apple features Rehan Rishi, Haris Mughees, Fabian Boemer, Karl Tarbe, Nicholas Genise, Akshay Wadia, and Ruiyu Zhu [ Code ] [ Paper ] [ Video ] Beyond the Hook: A Technical Deep Dive into Modern Phishing Methodologies Alexandre Nesic [ Blog ] How to Backdoor Large Language Models Shrivu Shankar [ Blog ] [ Code ] Buccaneers of the Binary: Plundering Compiler Optimizations for Decompilation Treasure Zion Leonahenahe Basque [ Code ] [ Video ] Software Screws Around, Reverse Engineering Finds Out: How Independent, Adversarial Research Informs Government Regulation Andy Sellars and Michael A. Specter [ Video ] [ Website ] Understanding things all the way down PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR Zizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan, Xiaoyu Ji, and Wenyuan Xu [ Paper ] [ Demo Videos ] Full-stack Reverse Engineering of the Original Microsoft Xbox Markus Gaasedelen [ Video ] Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China Shencha Fan, Jackson Sippe, Sakamoto San, Jade Sheffey, David Fifield, Amir Houmansadr, Elson Wedwards, and Eric Wustrow [ Paper ] Scaling software (in)security Low-Effort Denial of Service with Recursion Alexis Challande and Brad Swain [ Paper ] [ Video ] Is this memory safety here in the room with us? Thomas Dullien (Halvar Flake) [ Slides ] [ Video ] How to gain code execution on millions of people and hundreds of popular apps Eva [ Blog ] Node is a loader Tom Steele [ Blog ] Mixing up Public and Private Keys in OpenID Connect deployments Hanno Böck [ Blog ] [ Code ] Nifty sundries Will It Run? Fooling EDRs With Command Lines Using Empirical Data Wietze Beukema [ Tool site ] [ Code ] [ Video ] Homoglyph-Based Attacks: Circumventing LLM Detectors Aldan Creo [ Paper ] [ Code ] [ Video ] 28 Months Later - The Ongoing Evolution of Russia's Cyber Operations The Grugq [ Slides ] [ Podcast interview ] ‘It's Not Paranoia If They're Really After You’: When Announcing Deception Technology Can Change Attacker Decisions Andrew Reeves and Debi Ashenden [ Paper ] Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel Attack Ziqiang Wang, Xuewei Feng, Qi Li, Kun Sun, Yuxiang Yang, Mengyuan Li, Ganqiu Du, Ke Xu, and Jianping Wu [ Paper ] [ Code ]

February 20, 202537 min

ThinkstScapes Research Roundup - Q4 - 2024

ThinkstScapes Q4’24 Wins and losses in the Microsoft ecosystem Pointer Problems - Why We’re Refactoring the Windows Kernel Joe Bialek [ Video ] Defending off the land Casey Smith, Jacob Torrey, and Marco Slaviero [ Slides ] [ Code ] Unveiling the Power of Intune: Leveraging Intune for Breaking Into Your Cloud and On-Premise Yuya Chudo [ Slides ] [ Code ] From Simulation to Tenant Takeover Vaisha Bernard [ Video ] From Convenience to Contagion: The Libarchive Vulnerabilities Lurking in Windows 11 NiNi Chen [ Slides ] [ Video ] LLM hype continues, as do the security issues Things we learned about LLMs in 2024 Simon Willison [ Blog ] AI Meets Git: Unmasking Security Flaws in Qodo Merge Nils Amiet [ Slides ] [ Video ] [ Blog ] Suicide Bot: New AI Attack Causes LLM to Provide Potential “Self-Harm” Instructions Gadi Evron [ Blog ] Diving deep, then diving deeper Breaking NATO Radio Encryption Lukas Stennes [ Paper ] [ Video ] Exploiting File Writes in Hardened Environments Stefan Schiller [ Blog ] [ Video ] Hacking yourself a satellite - recovering BEESAT-1 PistonMiner [ Video ] IRIS: Non-Destructive Inspection of Silicon Andrew 'bunnie' Huang [ Blog ] [ Paper ] [ Video ] SQL Injection Isn't Dead Paul Gerste [ Slides ] [ Video ] Nifty sundries What Developers Get for Free? Louis Nyffenegger [ Video ] Dialing into the Past: RCE via the Fax Machine – Because Why Not? Rick de Jager and Carlo Meijer [ Video ] Broken isolation - Draining your Credentials from Popular macOS Password Managers Wojciech Reguła [ Slides ] [ Video ] I'll Be There for You! Perpetual Availability in the A8 MVX System André Rösti, Stijn Volckaert, Michael Franz, and Alexios Voulimeneas [ Code ] [ Paper ] Exploring and Exploiting an Android “Smart POS” Payment Terminal Jacopo Jannone [ Video ]

November 11, 202436 min

ThinkstScapes Research Roundup - Q3 - 2024

Themes covered in this episode Edge cases at scale still matter Works from this theme exploit rarely-occurring issues, but with an internet-wide aperture to end up with impressive results. Look for: mechanising bit-squatting; static code analysis for vulnerabilities across all browser extensions, or across web ecosystems; and how Let’s Encrypt worries about revoking and reissuing 400M certificates in a week. Going above and beyond Talks and papers often use state-of-the-art tooling to measure/detect an interesting phenomenon. This theme highlights four works that could have followed that path, but also built robust tooling/research data to help others push the state-of-the-art forward. Look for: large scale collection and remediation of dangling domains and static secret leaks, preventing memory-corruption vulnerabilities across the Android ecosystem, remote timing attack frameworks, and SSH testing at scale. What goes on behind the curtain can be dangerous Modern IT systems are composed of many layers. Usually the details at lower levels can be abstracted and safely put out of mind. This theme highlights work that shows that what happens in these oft-ignored places can have significant impacts. See: AWS-internal resources built on your behalf, BGP security weaknesses, stealthy hardware backdoors in access control systems spanning over 15 years, Wi-Fi management plane vulnerabilities, VPN-OS interactions, and a legacy file-system hack in Windows. Nifty sundries As always, we wanted to showcase work that didn’t fit into the major themes of this issue. We cover: bypassing voice authentication with only a picture of the victim’s face, racking up bills on locked credit cards, email parsing confusion, scanning IPv6, and a timing attack on remote web clients. Edge cases at scale still matter Flipping Bits: Your Credentials Are Certainly Mine Joohoi and STÖK [ Code ] [ Video ] Universal Code Execution by Chaining Messages in Browser Extensions Eugene Lim [ Blog ] [ Video ] CVE Hunting Made Easy Eddie Zhang [ Blog ] [ Code ] How To Revoke And Replace 400 Million Certificates Without Breaking The Internet Aaron Gable [ Slides ] [ Video ] Going above and beyond Secrets and Shadows: Leveraging Big Data for Vulnerability Discovery at Scale Bill Demirkapi [ Blog ] Eliminating Memory Safety Vulnerabilities at the Source Jeff Vander Stoep and Alex Rebert [ Blog ] Listen to the Whispers: Web Timing Attacks that Actually Work James Kettle [ Slides ] [ Paper ] [ Code ] Secure Shells in Shambles HD Moore and Rob King [ Slides ] [ Code ] [ Video ] What goes on behind the curtain can be dangerous Breaching AWS Accounts Through Shadow Resources Yakir Kadkoda, Michael Katchinskiy, and Ofek Itach [ Slides ] [ Code ] Crashing the Party: Vulnerabilities in RPKI Validation Niklas Vogel, Donika Mirdita, Haya Schulmann, and Michael Waidner [ Slides ] [ Paper ] MIFARE Classic: exposing the static encrypted nonce variant... and a few hardware backdoors Philippe Teuwen [ Blog ] [ Paper ] [ Code ] Fallen Tower of Babel: Rooting Wireless Mesh Networks by Abusing Heterogeneous Control Protocols Xin'an Zhou, Zhiyun Qian, Juefei Pu, Qing Deng, Srikanth Krishnamurthy, and Keyu Man [ Slides ] [ Paper ] [ Code ] Attacking Connection Tracking Frameworks as used by Virtual Private Networks Benjamin Mixon-Baca, Jeffrey Knockel, Diwen Xue, Deepak Kapur, Roya Ensafi, and Jed Crandall [ Paper ] MagicDot: A Hacker's Magic Show of Disappearing Dots and Spaces Or Yair [ Slides ] [ Blog ] [ Video ] [ Code ] Nifty sundries Can I Hear Your Face? Pervasive Attack on Voice Authentication Systems with a Single Face Image Nan Jiang, Bangjie Sun, Terence Sim, and Jun Han [ Paper ] [ Code ] In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping Raja Hasnain Anwar, Syed Rafiul Hussain, and Muhammad Taqi Raza [ Slides ] [ Paper ] Splitting the Email Atom: Exploiting Parsers to Bypass Access Controls Gareth Heyes [ Slides ] [ Paper ] [ Code ] 6Sense: Internet-Wide IPv6 Scanning and its Security Applications Grant Williams, Mert Erdemir, Amanda Hsu, Shraddha Bhat, Abhishek Bhaskar, Frank Li, and Paul Pearce [ Slides ] [ Paper ] [ Code ] SnailLoad: Anyone on the Internet Can Learn What You're Doing Daniel Gruss and Stefan Gast [ Slides ] [ Paper ] Conclusions While we started off 2024 with a modest amount of high-quality works, this has scaled up significantly. As conference publications increase, we do see a slight decline in the number of blogs; there does appear to be some inverse correlation between the two tallies. We highlighted three themes for this quarter: Rare events that happen at internet-scale have big impacts. Going above and beyond in tooling development. Cross-layer gotchas. We’re looking forward to seeing how the year closes out with our year in review and the final quarter of 2024.

July 29, 202431 min

ThinkstScapes Research Roundup - Q2 - 2024

AI/ML in security Injecting into LLM-adjacent components Johann Rehberger [ Blog 1 ] [ Blog 2 ] Teams of LLM Agents can Exploit Zero-Day Vulnerabilities Richard Fang, Rohan Bindu, Akul Gupta, Qiusi Zhan, and Daniel Kang [ Paper ] Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models Sergei Glazunov and Mark Brand [ Blog ] LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and Benchmarks Saad Ullah, Mingji Han, Saurabh Pujar, Hammond Pearce, Ayse Kivilcim Coskun, and Gianluca Stringhini [ Paper ] [ Code ] The Impact of Backdoor Poisoning Vulnerabilities on AI-Based Threat Detectors Dmitrijs Trizna, Luca Demetrio, Battista Biggio, and Fabio Roli [ Slides ] [ Paper ] [ Code ] Looking at the whole system Systems Alchemy: The Transmutation of Hacking Thaddeus grugq [ Video ] The Boom, the Bust, the Adjust and the Unknown Maor Shwartz [ Slides ] Poisoning Web-Scale Training Datasets is Practical Nicholas Carlini, Matthew Jagielski, Christopher A. Choquette-Choo, Daniel Paleka, Will Pearce, Hyrum Anderson, Andreas Terzis, Kurt Thomas, and Florian Tramèr [ Paper ] Intercloud Identities: The Risks and Mitigations of Access Between Cloud Providers Noam Dahan and Ari Eitan [ Video ] New modalities with which to inflict pain GPU.zip: On the Side-Channel Implications of Hardware-Based Graphical Data Compression Yingchen Wang, Riccardo Paccagnella, Zhao Gang, Willy R. Vasquez, David Kohlbrenner, Hovav Shacham, and Christopher W. Fletcher [ Paper ] AquaSonic: Acoustic Manipulation of Underwater Data Center Operations and Resource Management Jennifer Sheldon, Weidong Zhu, Adnan Abdullah, Sri Hrushikesh Varma Bhupathiraju, Takeshi Sugawara, Kevin Butler, Md Jahidul Islam, and Sara Rampazzi [ Paper ] [ Video ] Video-Based Cryptanalysis: Extracting Cryptographic Keys from Video Footage of a Device’s Power LED Captured By Standard Video Cameras Ben Nassi, Etay Iluz, Or Cohen, Ofek Vayner, Dudi Nassi, Boris Zadov, and Yuval Elovici [ Site ] [ Paper ] [ Video ] Old components showing the strain Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi Networks Yuxiang Yang, Xuewei Feng, Qi Li, Kun Sun, Ziqiang Wang, and Ke Xu [ Blog ] [ Paper ] Reliable Payload Transmission Past the Spoofed TCP Handshake Yepeng Pan and Christian Rossow [ Paper ] [ Code ] Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials David Klein and Martin Johns [ Paper ] [ Code ] Practical Exploitation of Registry Vulnerabilities in the Windows Kernel Mateusz Jurczyk [ Blog ] [ Video ] Nifty sundries An Analysis of Recent Advances in Deepfake Image Detection in an Evolving Threat Landscape Sifat Muhammad Abdullah, Aravind Cheruvu, Shravya Kanchi, Taejoong Chung, Peng Gao, Murtuza Jadliwala, and Bimal Viswanath [ Code ] [ Paper ] Tracking illicit phishermen in the deep blue Azure Jacob Torrey [ Slides ] [ Code ] SEVeriFast: Minimizing the root of trust for fast startup of SEV microVMs Benjamin Holmes, Jason Waterman, and Dan Williams [ Paper ] [ Code ] Certiception: The ADCS Honeypot We Always Wanted Balthasar Martin and Niklas van Dornick [ Blog ] [ Code ] [ Slides ]

June 14, 202425 min

ThinkstScapes Research Roundup - Q1 - 2024

Revealing more than anticipated, and preventing prying eyes PrintListener: Uncovering the Vulnerability of Fingerprint Authentication via the Finger Friction Sound Man Zhou, Shuao Su, Qian Wang, Qi Li, Yuting Zhou, Xiaojing Ma, and Zhengxiong Li [ Paper ] ModelGuard: Information-Theoretic Defense Against Model Extraction Attacks Minxue Tang, Anna Dai, Louis DiValentin, Aolin Ding, Amin Hass, Neil Zhenqiang Gong, Yiran Chen, and Hai Li [ Paper ] [ Code ] RECORD: A RECeption-Only Region Determination Attack on LEO Satellite Users Eric Jedermann, Martin Strohmeier, Vincent Lenders, and Jens Schmitt [ Code ] [ Paper ] Private web search with Tiptoe Alexandra Henzinger, Emma Dauterman, Henry Corrigan-Gibbs, and Nickolai Zeldovich [ Slides ] [ Paper ] [ Video ] [ Code ] Can Virtual Reality Protect Users from Keystroke Inference Attacks? Zhuolin Yang, Zain Sarwar, Iris Hwang, Ronik Bhaskar, Ben Y. Zhao, and Haitao Zheng [ Website ] [ Paper ] Backtrace in Time: Revealing Attackers’ Sleep Patterns and Days Off in RDP Brute-Force Attacks with Calendar Heatmaps Andréanne Bergeron [ Code ] [ Blog ] [ Video ] Taking another look with a fresh perspective Breaking HTTP Servers, Proxies, and Load Balancers Using the HTTP Garden Ben Kallus and Prashant Anantharaman [ Code ] [ Video ] Compiler Backdooring For Beginners Marion Marschalek [ Video ] Revisiting 2017: AI and Security, 7 years later Thomas Dullien [ Video ] Automated Large-Scale Analysis of Cookie Notice Compliance Ahmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini, and David Basin [ Paper ] [ Code Access ] Turning Windows into doors LSA Whisperer Evan McBroom [ Slides ] [ Blog ] [ Code ] Wishing: Webhook Phishing in Teams Matthew Eidelberg [ Blog ] [ Code ] Misconfiguration Manager: Overlooked and Overprivileged Duane Michael and Chris Thompson [ Slides ] [ Blog ] [ Code ] Smoke and Mirrors: How to hide in Microsoft Azure Aled Mehta and Christian Philipov [ Video ] Nifty sundries Backdoor in XZ Utils allows RCE: everything you need to know Andres Freund, Merav Bar, Amitai Cohen, Danielle Aminov, and Russ Cox [ Initial Disclosure ] [ Wiz Blog ] [ Timeline ] More Money, Fewer FOSS Security Problems? The Data, Such As It Is John Speed Meyers, Sara Ann Brackett, and Stewart Scott [ Video ] MUDding Around: Hacking for gold in text-based games Unix-ninja [ Blog ] DeGPT: Optimizing Decompiler Output with LLM Peiwei Hu, Ruigang Liang, and Kai Chen [ Paper ]

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts