Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2026Living the brand... 010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2026The SIM card taking over your phone via AT Commands and file R/W - "CATana Toolkit". 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026Android's ART caches C++ mirror objects for app-specific Java classes/methods. That file is typically stored in the app’s private directory, writable by the app itself at runtime. Pretty sure there is nothing that can go wrong with that! www.usenix.org/conference/w... 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026Congratulations on your Best Paper Award! 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026Schedule: www.usenix.org/conference/w... Additionally: * Monday 5.30 pm - Birds-of-Feather Sesssions * Tuesday 4.30 pm - Demo/Poster Session and Happy Hour in Harborside Ballroom Cusenix.orgWOOT '26 Technical SessionsThe 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ... 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026"Don't trust your DRAM" -- Jacqueline Henes on attacking ARM TrustZone from userspace with memory aliasing www.usenix.org/conference/w... 021
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026"Insecurity of Cellular Basebands" analyzes prior work on vulnerability discovery and attack surfaces; presenting a taxonomy of vulnerabilities, review state-of-the-art analysis techniques, including static analysis, over-the-air testing, and emulation. Paper: www.usenix.org/system/files... 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/08/2026RTCInspect is an open-source framework for automated analysis of RTC traffic to detect protocol and cryptographic weaknesses; @distrinet.bsky.social conducted a comparative security study of 21 real-world applications, spanning 11 consumer IoT devices and 10 major web platforms. 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/08/2026Finding the right EM probe location is often the tedious, expert-driven part of electromagnetic side-channel attacks. Dev Mehta et al. paper, Swarm in EM Hay, turns this into an adaptive search problem - reducing trace count for AES key recovery by up to 16×. Pre-Print: eprint.iacr.org/2025/2244 010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 07/08/2026Safe travels, everyone! 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 06/08/2026Last year, AIxCC showed that cyber reasoning systems (CRSs) perform vulnerability discovery and patch bugs: most of the 7 open-source CRSs remain largely unusable outside their original infrastructure. This WOOT paper presents an open, local framework with ported components from all finalists. 100
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 06/08/2026What if malware could hide in plain sight? Not by disabling your tools, but by drowning them in data. Telemetry Complexity Attacks generate overwhelming nested telemetry that crashes serializers, breaks database inserts, and freezes dashboards. 18 products tested. 7 affected. 3 CVEs assigned. 010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 27/07/2026Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. What could go wrong? Turns out: a lot. Checkout the upcoming paper "SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode". Preprint: vanbulck.net/files/woot26... 020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 26/07/2026PowerHooK demonstrates that VMs protected by AMD's SEV can still leak secrets through software-based power side channels. By exploiting transient execution to replay victim code paths, a malicious hypervisor can collect clean power traces and recover AES key material @moberhuber.bsky.social 020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 22/07/2026Some rooms at conference rate are again available for WOOT: www.usenix.org/conference/u... 010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 21/07/2026Roudot & Sabt investigate how Widevine, Google's DRM, handles decrypted media inside modern browsers and shows that its output boundary can be intercepted surprisingly easily - on both Linux and Windows - incl. major streaming platforms, namely Netflix and Disney+. hal.science/hal-05648322... 020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 21/07/2026Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated away from the Signal Protocol. @kota-ursgk.bsky.social presents three practical attacks: an impersonation attack, a message timestamp forgery attack, and message dropping and replay attacks 012
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 14/07/2026By reverse engineering AirDrop and building the AIRFUZZ fuzzer, Ebrahim & Tippenhauer uncover six vulnerabilities across macOS, iOS, Android, and Windows, including zero-click DoS bugs, authentication and encryption bypasses, and use-after-free with remote-code-execution impact. 041
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 13/07/2026How are you solving this dilemma? 020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/07/2026Huber & Schink of Fraunhofer AISEC evaluate BBI-based online and offline manipulations of on-microcontroller flash memory, providing stealthy data manipulation and the ability to re-enable new µC interfaces & features. 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 03/07/2026Models like BLIP can leak training data, unless you rethink the architecture. The authors introduce NEURO(++) topological regularization. The twist: resilience is highly model- & dataset-dependant, i.e., attackers can’t assume one-size-fits-all behavior. #TrustworthyAI github.com/Trust-AI-ua/... 020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 30/06/2026SEMSAN is an eBPF-based, configurable sanitizer that detects semantic bugs – such as a 21-year-old path traversal bug in graphena, command injection, and privilege escalation -- introducing under 1% overhead in real-world systems like Apache and PostgreSQL. 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 29/06/2026GRAPE is cross-context code-pattern scanner that scans the entire Chromium code base in 12 minutes and earned the Authors of "Squeezing Juicy Variant Bugs Out of Modern Browsers" $17k5 for 24 newly-found vulnerabilities. Pre-print: kdsjzh.github.io/assets/pdf/2... 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 25/06/2026Submit a poster to any offensive security topics you'd like to discuss with or show to the WOOT audience! www.usenix.org/conference/w... 100
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 24/06/2026Put a Tesla into a Faraday tent and test its LTE security. It did not end well. See “Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla” at USENIX WOOT’26. Repo & Pre-Print: github.com/Signal-Intel... 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 23/06/2026Microsoft's 6-year-old Zerologon patches use AES-CFB8 incorrectly. The novel Onelogon attack provides two ways to take over a vulnerable AD account in apx 30 minutes. #AESCFB8fail #WONTFIX softsec.link/woot26.onelo... @al3x-n3ff.bsky.social @kevin.borgolte.me @ruhr-uni-bochum.de 020
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 23/06/2026With about $180 of off-the-shelf hardware, HotWire sickcell6000.github.io/HotWire/ steals charging billed to victims, and drains an EV's batteries until they won't start - demonstrated on production cars and live public charging networks. Paper and presentation at WOOT'26. 100
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/06/2026SynthIR tricks deepfake image detectors using a simple optical filter and cardboard. To defend from their attack Ishizue, Rampazzi, & Sugawara propose a detection method based on dual-pixel sensors. tetsuishizue.github.io/BreakingInfr... see the full WOOT'26 lineup: www.usenix.org/conference/w... 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/06/2026Constant time programming is the primary defense against timing attacks, but the meaning of the term actually varies. On a key loading case study, Brumley finds BoringSSL's leak orders of magnitude stronger than OpenSSL's, despite, surprisingly, a stricter threat model. 042
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/06/2026If you have a better poster (or demo), we like to hear from you! Submit by June 25th at www.usenix.org/conference/w... 011
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 24/02/2026The Cycle 2 deadline for the USENIX WOOT Conference is in just one week (March 3, 2026). Full details are available in the Call for Papers: www.usenix.org/conference/w...usenix.orgWOOT '26 Call for PapersThe 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ... 023
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/02/2026The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 3 weeks (March 3, 2026)! WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused). Details are available in the Call for Papers: www.usenix.org/conference/w...usenix.orgWOOT '26 Call for PapersThe 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ... 001
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/12/2025Only 4 days to the WOOT 2026 Cycle 1 submission deadline! Check the CFP for details: www.usenix.org/conference/w...usenix.orgWOOT '26 Call for PapersThe 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ... 011
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/11/2025USENIX WOOT Conference 2026: two submission deadlines this year! - Cycle 1: December 12, 2025 *only one month away* ! - Cycle 2: March 3, 2026 WOOT still has a SoK track and an "Up-and-coming track" (~Industry), CFP for details: www.usenix.org/conference/w... 056
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025WOOT 2025 closing Keynote "Escaping Cantor's Find-Fix Cycle" by Falcon Darkstar Momot from Dartmouth College and Aiven.io 010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025Last papers session "Exploit All the Things" (Chair: Cristine Hoepers) - Soufian El Yadmani: SecurePoC—detecting malicious GitHub exploits - Andrea Mambretti: SoK on kernel vuln discovery & auto exploit generation - Junho Lee: BOOTKITTY—stealth bootkit-rootkit for modern OSes 010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025WOOT 2025 late morning session: Application Security (Chair: Yves Younan) - Gabriel Karl Gegenhuber: Prekey Pogo—WhatsApp handshake weaknesses - Manuel Karl: Formula injection in real-world spreadsheets - Jannik Hartung: PHP foot-gun case study (Best paper award !) 021
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025WOOT 2025 day 2 starts with another Physical Attacks session (Chair: A. Zonenberg): - Valentin Huber: Deep dive into FRAM fault injection effects - Boyapally Harishma: Side-channel reality check on ARM Cortex-A72 - Wooyeon Jo: PLC memory exploitation in industrial systems 021
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/08/2025WOOT 2025 last session today Network Security : - Mehrdad Hajizadeh: DeepRed: AI-driven red teaming vs ML-NIDS - Shujie Zhao: Stealth BGP hijacks under uRPF - Anqi Chen: FUZZVPN: Hunting OpenVPN vulns 010
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025WOOT 2025 1st session of the afternoon, "Hacking at a Distance" with: - Tommaso Sacchetti on large scale Bluetooth Security Testing - Chengsong Diao: Vulnerabilities in Master Lock Smart Locks - Seyyed Ali Ayati Acoustic Side-Channel on keyboards 031
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025WOOT 2025 schedule, all papers are now online open access: usenix.org/conference/w... Talks are recorded, and should be online in a few weeks.usenix.orgWOOT '25 Technical SessionsAll sessions will be held in Room 611-612 unless otherwise noted. 0128
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025First session, on hardware security: Two talks on attacking the @raspberrypi.com RP2350 by @nsinusr.bsky.social and Andrew D. Zonenberg. One talk on exploiting software using hardware fault injections by Zhenyuan Liu 051
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025WOOT 2025 Conference starting in Seattle. The program prepared by @noopwafel.bsky.social and @naehrdine.bsky.social includes sessions on hardware security, wireless attacks, network security. And tomorrow physical attacks, application security. And Keynote by Falcon Darkstar Momot 242
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 17/07/2025Discounted early bird registration for WOOT '25 is still open until Monday - www.usenix.org/conference/w... - join us in Seattle on Aug 11/12 (right before USENIX Security) for talks and discussions on great cutting-edge offensive security research. Full program at www.usenix.org/conference/w...usenix.orgWOOT '25 Technical Sessions 135
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 06/07/2025Planning to attend WOOT this year? (Seattle on Aug 11/12!) Bring demos or posters of your latest or upcoming offensive security work, or give a lightning talk! Submissions are open and very lightweight (just a couple of sentences will do) - details at www.usenix.org/conference/w...usenix.orgWOOT '25 Call for Lightning Talks, Demos, and Posters 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 19/06/2025Two winners of the RP2350 Hacking Challenge will present their results at WOOT! Muench et al. break its secure boot guarantees through voltage, electromagnetic, and laser fault injection 💥 techniques: www.usenix.org/conference/w...usenix.orgSecurity through Transparency: Tales from the RP2350 Hacking Challenge | USENIXusenix_logo_notag_white 173
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/06/2025The WOOT 2025 conference lineup is live! 👀 www.usenix.org/conference/w...usenix.orgWOOT '25 Technical Sessions 000
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/06/2025Want to go to WOOT and learn about the latest hardware & software attacks? Registrations are now open! If you can't afford traveling ✈️ to Seattle on your own and need financial support for a ticket, apply for a grant until July 7: www.usenix.org/conference/w...usenix.orgWOOT '25 Grant Opportunities 023
Reposted by Usenix WOOT Conference on Offensive TechnologiesUsenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 10/03/2025Reviewer 2 just rejected your latest offensive security paper? Or didn't submit it anywhere yet? There's still more than a day left to (re)submit to USENIX WOOT '25 and get reviews from a community who will appreciate all those clever hacks, weird bugs 👾 and fun exploits! woot25.usenix.hotcrp.comwoot25.usenix.hotcrp.comWOOT '25 088