The most impactful vulnerabilities are not always the ones that look severe at first glance.
At BlueHat Asia, Asem Eleraky (@Melotover) challenged attendees to rethink how client-side vulnerabilities are evaluated, arguing that the real question is not "What can I steal?" but "What can I make the application do?" Through two real-world case studies, the session showed how seemingly limited injection flaws can be chained into much larger security outcomes.
The first case study showed how a client-side vulnerability could be leveraged into a full account takeover by exploiting trust assumptions around identity workflows and OTP-based authentication. The second explored how application-layer weaknesses could be used to hijack Microsoft 365 Copilot interactions, highlighting the importance of securing not only AI models but also the platforms, frameworks, and trust boundaries surrounding them.
A key theme throughout the talk was that understanding context matters. By digging deeper into how applications work, researchers can uncover unexpected paths to impact that go far beyond the original bug. As security architectures evolve, proving real-world impact remains one of the most important parts of effective research.
Sep 17, 2026 · 6:20 AM UTC
2
3
14
2,774



