ThinkstScapes Research Roundup - Q2 - 2026
Infrastructure under renewed scrutiny Lost in Translation: Text Message Spoofing via Email Sumanth Rao, Ye Shu, Stefan Savage, Aaron Schulman, Geoffrey M. Voelker, and Enze Liu [ Code ] [ Paper ] Hack the Source, Of the Source Tsi-Lin Ng [ Slides ] RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox Xiang Li, Yuqi Qiu, Mingming Zhang, Zuyao Xu, Lu Sun, Baojun Liu, Jia Zhang, Xiaofeng Zheng, Haixin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan, and Fasheng Miao [ Slides ] [ Paper ] Strange Inputs, Critical outputs: Attacking Infrastructure Through Innocuous Network Protocol Fields Sasha Romijn [ Blog post ] [ Video ] Clouds raining data Sub:jugation – Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers Tal Skverer [ Blog post ] [ Video ] Rain: Transiently Leaking Data from Public Clouds Using Old Vulnerabilities Mathé Hertogh, Dave Quakkelaar, Thijs Raymakers, Mahesh Hari Sarma, Marius Muench, Herbert Bos, and Erik van der Kouwe [ Code ] [ Paper ] [ Site ] OCInferno: An Offensive Security Toolkit for OCI Scott Weston [ Code ] [ Lightning Talk Video ] [ Video ] Zapocalypse: Compromising every Zapier user through a Lambda memory leak Yair Balilti [ Video ] [ Website ] Sharp edges in Windows ecosystems Breaking Hybrid Boundaries Across Azure and Windows Ilan Kalendarov and Ben Zamir [ Slides ] PhantomRPC: A New Privilege Escalation Flaw in Windows RPC Haidar Kabibo [ Slides ] [ Code ] Iron Giant: When the vault becomes the victim Erik Egsgard [ Video ] Hunting with models, and models being hunted RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke Inference Qijun Wang, Chunqi Qian, and Huacheng Zeng [ Code ] [ Paper ] [ Site ] Revelio: Blurred Images Can Still Disclose Your Identity Haoyu Zhai, Shuo Wang, Pirouz Naghavi, Qingying Hao, and Gang Wang [ Site ] [ Paper ] Bad Vibes: Pwning Coding Agents 70 Times With The Same Bugs Philip Tsukerman, Nil Ashkenazi, and Alon Zahavi [ Slides ] System Over Model, Tested: Reproducing Mythos's FreeBSD Find on Local Open-Weight Models John McIntosh [ Blog post ] [ Code ] Nifty sundries Protecting Cookies with Device Bound Session Credentials Benjamin Ackerman, Daniel Rubery, and Guillaume Ehinger [ Blog post ] [ Documentation ] Turning Spam Filters Into Your Greatest Enemy: Intrusions Via RCEs in E-Mail Spam Filters Ting-Wei Hsieh and Kai-Ching Wang [ Slides ] AirSnitch: Breaking Client Isolation in Wi-Fi Networks Mathy Vanhoef, Zhiyun Qian, Xin'an Zhou, Juefei Pu, Zhutian Liu, Zhaowei Tan, and Srikanth Krishnamurthy [ Slides ] [ Paper ] [ Code ]



