Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Black Hat Asia
March 26-29, 2019
Singapore
Black Hat USA
August 3-8, 2019
Las Vegas, NV, USA
Black Hat Europe
December 2-5, 2019
London UK
11/15/2019
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat Europe Brings A Bevy of IoT Security Insights

Attend this London event next month for the latest on how security researchers are finding (and solving) security vulnerabilities in all of your favorite Internet-connected devices.

As the year winds down around us, people around the world are spending more time at home, visiting friends and family. Many of those homes are filled with vulnerable smart devices connected to the Internet of Things, and at Black Hat Europe in London next month you’ll have a prime opportunity to learn about the latest IoT security tricks and techniques.

This year the list of Internet of Things Briefings at Black Hat Europe is packed with practical content like BlueMaster: Bypassing and Fixing Bluetooth-based Proximity Authentication, a Briefing all about the security pitfalls of Bluetooth-based proximity authentication. You’ll hear researchers analyze implementations of Android Smart Lock and Windows Dynamic Lock and demonstrate new attacks on these implementations. Based on their analysis, expect to walk away with a better understanding of the weaknesses in these systems, as well as three new attacks that allow attackers to bypass device proximity authentication.

Experts from Panasonic will present a few Briefings, including Understanding the IoT Threat Landscape and a Home Appliance Manufacturer's Approach to Counter Threats to IoT. As a device manufacturer, Panasonic collected information on IoT threats by connecting its own devices in the development / pre-shipment phases to its own honeypot.

Since its deployment, Panasonic has been able to find 179 million attack cases and 25 thousand malware samples, of which 4,800 were unique samples targeting IoT. You’re going to learn all about it (including insights on some interesting 0-day attacks against the SMB protocol) in this Black Hat Europe Briefing.

For information on how to deal with IoT threats at scale, check out OEM Finder: Hunting Vulnerable OEM IoT Devices at Scale. Researchers developed this new tool to help raise awareness about the threat that vulnerabilities in OEM hardware pose to customers who buy (rebranded) hardware from other companies. OEM Finder can automatically detect OEM device candidates based on the similarity of its appearance between the OEM and original device. In this Briefing you’ll learn how the team achieved fast, automatic and precise OEM device detection by adopting an object recognition algorithm (KAZE) with k-NN. You’ll also learn how to use it effectively to safeguard your devices and those of your clients

Get more information on these and lots of other cutting-edge content in the Briefings schedule for Black Hat Europe, which returns to The Excel in London December 2-5, 2019. For more information on what’s happening at the event and how to register, check out the Black Hat website.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7245
PUBLISHED: 2020-01-23
Incorrect username validation in the registration processes of CTFd through 2.2.2 allows a remote attacker to take over an arbitrary account after initiating a password reset. This is related to register() and reset_password() in auth.py. To exploit the vulnerability, one must register with a userna...
CVE-2019-14885
PUBLISHED: 2020-01-23
A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information...
CVE-2019-17570
PUBLISHED: 2020-01-23
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue...
CVE-2020-6007
PUBLISHED: 2020-01-23
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.
CVE-2012-4606
PUBLISHED: 2020-01-23
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.