Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Black Hat USA
August 1-6, 2020
Las Vegas, NV, USA
Black Hat Asia
September 29 - October 2, 2020
Singapore
Black Hat Europe
November 9-12, 2020
London UK
11/15/2019
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat Europe Brings A Bevy of IoT Security Insights

Attend this London event next month for the latest on how security researchers are finding (and solving) security vulnerabilities in all of your favorite Internet-connected devices.

As the year winds down around us, people around the world are spending more time at home, visiting friends and family. Many of those homes are filled with vulnerable smart devices connected to the Internet of Things, and at Black Hat Europe in London next month you’ll have a prime opportunity to learn about the latest IoT security tricks and techniques.

This year the list of Internet of Things Briefings at Black Hat Europe is packed with practical content like BlueMaster: Bypassing and Fixing Bluetooth-based Proximity Authentication, a Briefing all about the security pitfalls of Bluetooth-based proximity authentication. You’ll hear researchers analyze implementations of Android Smart Lock and Windows Dynamic Lock and demonstrate new attacks on these implementations. Based on their analysis, expect to walk away with a better understanding of the weaknesses in these systems, as well as three new attacks that allow attackers to bypass device proximity authentication.

Experts from Panasonic will present a few Briefings, including Understanding the IoT Threat Landscape and a Home Appliance Manufacturer's Approach to Counter Threats to IoT. As a device manufacturer, Panasonic collected information on IoT threats by connecting its own devices in the development / pre-shipment phases to its own honeypot.

Since its deployment, Panasonic has been able to find 179 million attack cases and 25 thousand malware samples, of which 4,800 were unique samples targeting IoT. You’re going to learn all about it (including insights on some interesting 0-day attacks against the SMB protocol) in this Black Hat Europe Briefing.

For information on how to deal with IoT threats at scale, check out OEM Finder: Hunting Vulnerable OEM IoT Devices at Scale. Researchers developed this new tool to help raise awareness about the threat that vulnerabilities in OEM hardware pose to customers who buy (rebranded) hardware from other companies. OEM Finder can automatically detect OEM device candidates based on the similarity of its appearance between the OEM and original device. In this Briefing you’ll learn how the team achieved fast, automatic and precise OEM device detection by adopting an object recognition algorithm (KAZE) with k-NN. You’ll also learn how to use it effectively to safeguard your devices and those of your clients

Get more information on these and lots of other cutting-edge content in the Briefings schedule for Black Hat Europe, which returns to The Excel in London December 2-5, 2019. For more information on what’s happening at the event and how to register, check out the Black Hat website.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Introducing 'Secure Access Service Edge'
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  7/3/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5607
PUBLISHED: 2020-07-10
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2020-15001
PUBLISHED: 2020-07-09
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code is not checked when u...
CVE-2020-15092
PUBLISHED: 2020-07-09
In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most T...
CVE-2020-15093
PUBLISHED: 2020-07-09
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A ...
CVE-2020-15299
PUBLISHED: 2020-07-09
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is execu...