Sign in

Usenix WOOT Conference on Offensive Technologies

@wootsecurity.bsky.social
88 followers 96 following 58 posts

WOOT aims to present a broad picture of offense and its contributions, bringing together researchers and practitioners in all areas of computer security. Co-located with USENIX Security Symposium'26 in Baltimore,MD on August 10–11, 2026

PostsRepliesMedia
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2026
Living the brand...
010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2026
The SIM card taking over your phone via AT Commands and file R/W - "CATana Toolkit".
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026
Android's ART caches C++ mirror objects for app-specific Java classes/methods. That file is typically stored in the app’s private directory, writable by the app itself at runtime. Pretty sure there is nothing that can go wrong with that! www.usenix.org/conference/w...
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026
Congratulations on your Best Paper Award!
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026
Schedule: www.usenix.org/conference/w... Additionally: * Monday 5.30 pm - Birds-of-Feather Sesssions * Tuesday 4.30 pm - Demo/Poster Session and Happy Hour in Harborside Ballroom C
usenix.org
WOOT '26 Technical Sessions
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026
"Don't trust your DRAM" -- Jacqueline Henes on attacking ARM TrustZone from userspace with memory aliasing www.usenix.org/conference/w...
021
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026
"Insecurity of Cellular Basebands" analyzes prior work on vulnerability discovery and attack surfaces; presenting a taxonomy of vulnerabilities, review state-of-the-art analysis techniques, including static analysis, over-the-air testing, and emulation. Paper: www.usenix.org/system/files...
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026
RTCInspect is an open-source framework for automated analysis of RTC traffic to detect protocol and cryptographic weaknesses; @distrinet.bsky.social conducted a comparative security study of 21 real-world applications, spanning 11 consumer IoT devices and 10 major web platforms.
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/08/2026
Finding the right EM probe location is often the tedious, expert-driven part of electromagnetic side-channel attacks. Dev Mehta et al. paper, Swarm in EM Hay, turns this into an adaptive search problem - reducing trace count for AES key recovery by up to 16×. Pre-Print: eprint.iacr.org/2025/2244
010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 07/08/2026
Safe travels, everyone!
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 06/08/2026
Last year, AIxCC showed that cyber reasoning systems (CRSs) perform vulnerability discovery and patch bugs: most of the 7 open-source CRSs remain largely unusable outside their original infrastructure. This WOOT paper presents an open, local framework with ported components from all finalists.
100
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 06/08/2026
What if malware could hide in plain sight? Not by disabling your tools, but by drowning them in data. Telemetry Complexity Attacks generate overwhelming nested telemetry that crashes serializers, breaks database inserts, and freezes dashboards. 18 products tested. 7 affected. 3 CVEs assigned.
010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 27/07/2026
Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. What could go wrong? Turns out: a lot. Checkout the upcoming paper "SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode". Preprint: vanbulck.net/files/woot26...
020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 26/07/2026
PowerHooK demonstrates that VMs protected by AMD's SEV can still leak secrets through software-based power side channels. By exploiting transient execution to replay victim code paths, a malicious hypervisor can collect clean power traces and recover AES key material @moberhuber.bsky.social
020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 22/07/2026
Some rooms at conference rate are again available for WOOT: www.usenix.org/conference/u...
010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 21/07/2026
Roudot & Sabt investigate how Widevine, Google's DRM, handles decrypted media inside modern browsers and shows that its output boundary can be intercepted surprisingly easily - on both Linux and Windows - incl. major streaming platforms, namely Netflix and Disney+. hal.science/hal-05648322...
020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 21/07/2026
Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated away from the Signal Protocol. @kota-ursgk.bsky.social presents three practical attacks: an impersonation attack, a message timestamp forgery attack, and message dropping and replay attacks
012
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 14/07/2026
By reverse engineering AirDrop and building the AIRFUZZ fuzzer, Ebrahim & Tippenhauer uncover six vulnerabilities across macOS, iOS, Android, and Windows, including zero-click DoS bugs, authentication and encryption bypasses, and use-after-free with remote-code-execution impact.
041
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 13/07/2026
How are you solving this dilemma?
020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/07/2026
Huber & Schink of Fraunhofer AISEC evaluate BBI-based online and offline manipulations of on-microcontroller flash memory, providing stealthy data manipulation and the ability to re-enable new µC interfaces & features.
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 03/07/2026
Models like BLIP can leak training data, unless you rethink the architecture. The authors introduce NEURO(++) topological regularization. The twist: resilience is highly model- & dataset-dependant, i.e., attackers can’t assume one-size-fits-all behavior. #TrustworthyAI github.com/Trust-AI-ua/...
020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 30/06/2026
SEMSAN is an eBPF-based, configurable sanitizer that detects semantic bugs – such as a 21-year-old path traversal bug in graphena, command injection, and privilege escalation -- introducing under 1% overhead in real-world systems like Apache and PostgreSQL.
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 29/06/2026
GRAPE is cross-context code-pattern scanner that scans the entire Chromium code base in 12 minutes and earned the Authors of "Squeezing Juicy Variant Bugs Out of Modern Browsers" $17k5 for 24 newly-found vulnerabilities. Pre-print: kdsjzh.github.io/assets/pdf/2...
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 25/06/2026
Submit a poster to any offensive security topics you'd like to discuss with or show to the WOOT audience! www.usenix.org/conference/w...
100
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 24/06/2026
Put a Tesla into a Faraday tent and test its LTE security. It did not end well. See “Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla” at USENIX WOOT’26. Repo & Pre-Print: github.com/Signal-Intel...
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 23/06/2026
Microsoft's 6-year-old Zerologon patches use AES-CFB8 incorrectly. The novel Onelogon attack provides two ways to take over a vulnerable AD account in apx 30 minutes. #AESCFB8fail #WONTFIX softsec.link/woot26.onelo... @al3x-n3ff.bsky.social @kevin.borgolte.me @ruhr-uni-bochum.de
020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 23/06/2026
With about $180 of off-the-shelf hardware, HotWire sickcell6000.github.io/HotWire/ steals charging billed to victims, and drains an EV's batteries until they won't start - demonstrated on production cars and live public charging networks. Paper and presentation at WOOT'26.
100
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/06/2026
SynthIR tricks deepfake image detectors using a simple optical filter and cardboard. To defend from their attack Ishizue, Rampazzi, & Sugawara propose a detection method based on dual-pixel sensors. tetsuishizue.github.io/BreakingInfr... see the full WOOT'26 lineup: www.usenix.org/conference/w...
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/06/2026
Constant time programming is the primary defense against timing attacks, but the meaning of the term actually varies. On a key loading case study, Brumley finds BoringSSL's leak orders of magnitude stronger than OpenSSL's, despite, surprisingly, a stricter threat model.
042
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/06/2026
If you have a better poster (or demo), we like to hear from you! Submit by June 25th at www.usenix.org/conference/w...
011
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 24/02/2026
The Cycle 2 deadline for the USENIX WOOT Conference is in just one week (March 3, 2026). Full details are available in the Call for Papers: www.usenix.org/conference/w...
usenix.org
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
023
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/02/2026
The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 3 weeks (March 3, 2026)! WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused). Details are available in the Call for Papers: www.usenix.org/conference/w...
usenix.org
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
001
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/12/2025
Only 4 days to the WOOT 2026 Cycle 1 submission deadline! Check the CFP for details: www.usenix.org/conference/w...
usenix.org
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
011
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/11/2025
USENIX WOOT Conference 2026: two submission deadlines this year! - Cycle 1: December 12, 2025 *only one month away* ! - Cycle 2: March 3, 2026 WOOT still has a SoK track and an "Up-and-coming track" (~Industry), CFP for details: www.usenix.org/conference/w...
056
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025
WOOT 2025 closing Keynote "Escaping Cantor's Find-Fix Cycle" by Falcon Darkstar Momot from Dartmouth College and Aiven.io
010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025
Last papers session "Exploit All the Things" (Chair: Cristine Hoepers) - Soufian El Yadmani: SecurePoC—detecting malicious GitHub exploits - Andrea Mambretti: SoK on kernel vuln discovery & auto exploit generation - Junho Lee: BOOTKITTY—stealth bootkit-rootkit for modern OSes
010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025
WOOT 2025 late morning session: Application Security (Chair: Yves Younan) - Gabriel Karl Gegenhuber: Prekey Pogo—WhatsApp handshake weaknesses - Manuel Karl: Formula injection in real-world spreadsheets - Jannik Hartung: PHP foot-gun case study (Best paper award !)
021
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025
WOOT 2025 day 2 starts with another Physical Attacks session (Chair: A. Zonenberg): - Valentin Huber: Deep dive into FRAM fault injection effects - Boyapally Harishma: Side-channel reality check on ARM Cortex-A72 - Wooyeon Jo: PLC memory exploitation in industrial systems
021
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025
WOOT 2025 last session today Network Security : - Mehrdad Hajizadeh: DeepRed: AI-driven red teaming vs ML-NIDS - Shujie Zhao: Stealth BGP hijacks under uRPF - Anqi Chen: FUZZVPN: Hunting OpenVPN vulns
010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025
WOOT 2025 1st session of the afternoon, "Hacking at a Distance" with: - Tommaso Sacchetti on large scale Bluetooth Security Testing - Chengsong Diao: Vulnerabilities in Master Lock Smart Locks - Seyyed Ali Ayati Acoustic Side-Channel on keyboards
031
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025
WOOT 2025 schedule, all papers are now online open access: usenix.org/conference/w... Talks are recorded, and should be online in a few weeks.
usenix.org
WOOT '25 Technical Sessions
All sessions will be held in Room 611-612 unless otherwise noted.
0128
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025
First session, on hardware security: Two talks on attacking the @raspberrypi.com RP2350 by @nsinusr.bsky.social and Andrew D. Zonenberg. One talk on exploiting software using hardware fault injections by Zhenyuan Liu
051
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025
WOOT 2025 Conference starting in Seattle. The program prepared by @noopwafel.bsky.social and @naehrdine.bsky.social includes sessions on hardware security, wireless attacks, network security. And tomorrow physical attacks, application security. And Keynote by Falcon Darkstar Momot
242
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 17/07/2025
Discounted early bird registration for WOOT '25 is still open until Monday - www.usenix.org/conference/w... - join us in Seattle on Aug 11/12 (right before USENIX Security) for talks and discussions on great cutting-edge offensive security research. Full program at www.usenix.org/conference/w...
usenix.org
WOOT '25 Technical Sessions
135
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 06/07/2025
Planning to attend WOOT this year? (Seattle on Aug 11/12!) Bring demos or posters of your latest or upcoming offensive security work, or give a lightning talk! Submissions are open and very lightweight (just a couple of sentences will do) - details at www.usenix.org/conference/w...
usenix.org
WOOT '25 Call for Lightning Talks, Demos, and Posters
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 19/06/2025
Two winners of the RP2350 Hacking Challenge will present their results at WOOT! Muench et al. break its secure boot guarantees through voltage, electromagnetic, and laser fault injection 💥 techniques: www.usenix.org/conference/w...
usenix.org
Security through Transparency: Tales from the RP2350 Hacking Challenge | USENIXusenix_logo_notag_white
173
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/06/2025
The WOOT 2025 conference lineup is live! 👀 www.usenix.org/conference/w...
usenix.org
WOOT '25 Technical Sessions
000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/06/2025
Want to go to WOOT and learn about the latest hardware & software attacks? Registrations are now open! If you can't afford traveling ✈️ to Seattle on your own and need financial support for a ticket, apply for a grant until July 7: www.usenix.org/conference/w...
usenix.org
WOOT '25 Grant Opportunities
023
Reposted by Usenix WOOT Conference on Offensive Technologies
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/03/2025
Reviewer 2 just rejected your latest offensive security paper? Or didn't submit it anywhere yet? There's still more than a day left to (re)submit to USENIX WOOT '25 and get reviews from a community who will appreciate all those clever hacks, weird bugs 👾 and fun exploits! woot25.usenix.hotcrp.com
woot25.usenix.hotcrp.com
WOOT '25
088