Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Black Hat USA
August 1-6, 2020
Las Vegas, NV, USA
Black Hat Asia
September 29 - October 2, 2020
Singapore
Black Hat Europe
November 9-12, 2020
London UK
11/15/2019
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat Europe Brings A Bevy of IoT Security Insights

Attend this London event next month for the latest on how security researchers are finding (and solving) security vulnerabilities in all of your favorite Internet-connected devices.

As the year winds down around us, people around the world are spending more time at home, visiting friends and family. Many of those homes are filled with vulnerable smart devices connected to the Internet of Things, and at Black Hat Europe in London next month you’ll have a prime opportunity to learn about the latest IoT security tricks and techniques.

This year the list of Internet of Things Briefings at Black Hat Europe is packed with practical content like BlueMaster: Bypassing and Fixing Bluetooth-based Proximity Authentication, a Briefing all about the security pitfalls of Bluetooth-based proximity authentication. You’ll hear researchers analyze implementations of Android Smart Lock and Windows Dynamic Lock and demonstrate new attacks on these implementations. Based on their analysis, expect to walk away with a better understanding of the weaknesses in these systems, as well as three new attacks that allow attackers to bypass device proximity authentication.

Experts from Panasonic will present a few Briefings, including Understanding the IoT Threat Landscape and a Home Appliance Manufacturer's Approach to Counter Threats to IoT. As a device manufacturer, Panasonic collected information on IoT threats by connecting its own devices in the development / pre-shipment phases to its own honeypot.

Since its deployment, Panasonic has been able to find 179 million attack cases and 25 thousand malware samples, of which 4,800 were unique samples targeting IoT. You’re going to learn all about it (including insights on some interesting 0-day attacks against the SMB protocol) in this Black Hat Europe Briefing.

For information on how to deal with IoT threats at scale, check out OEM Finder: Hunting Vulnerable OEM IoT Devices at Scale. Researchers developed this new tool to help raise awareness about the threat that vulnerabilities in OEM hardware pose to customers who buy (rebranded) hardware from other companies. OEM Finder can automatically detect OEM device candidates based on the similarity of its appearance between the OEM and original device. In this Briefing you’ll learn how the team achieved fast, automatic and precise OEM device detection by adopting an object recognition algorithm (KAZE) with k-NN. You’ll also learn how to use it effectively to safeguard your devices and those of your clients

Get more information on these and lots of other cutting-edge content in the Briefings schedule for Black Hat Europe, which returns to The Excel in London December 2-5, 2019. For more information on what’s happening at the event and how to register, check out the Black Hat website.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11107
PUBLISHED: 2020-04-02
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
CVE-2020-11444
PUBLISHED: 2020-04-02
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
CVE-2020-7617
PUBLISHED: 2020-04-02
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
CVE-2020-8835
PUBLISHED: 2020-04-02
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the intr...
CVE-2020-8423
PUBLISHED: 2020-04-02
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.