WOOT aims to present a broad picture of offense and its contributions, bringing together researchers and practitioners in all areas of computer security
Our @wootsecurity'26 paper "CATana" is now available: usenix.org/system/files/woot…!
In the paper, we find that some phones and many IoT devices execute AT commands sent by the SIM, leading to a wide range of consequences from DoS over 2G downgrade to device compromise.
ALT Screenshot of the paper abstract for "CATANA: On the Dangers of SIM-Originating AT Commands".
The text states:
Hostile SIMs have been discussed as an attack vector against Mobile Equipment (ME) connected to cellular networks. One main attack path are proactive commands sent from the SIM to the victim device. In this work, we examine the threats posed by the RUN AT command which are SIM originating requests for the ME to execute a specified AT command, effectively creating a SIM AT interface.
To explore this interface, we introduce the CATANA toolkit and use it to analyze
real-world devices. Despite existing community knowledge on proactive commands and the dangers of AT commands, our investigation shows that SIM AT commands pose a significant security risk for MEs.
We survey 26 different MEs (8 IoT devices and 18 smartphones) and find that 9 expose the SIM AT interface, leading to the discovery of 4 vulnerabilities. [...]
ALT Screenshot from the paper, showing a 2G downgrade attack against a phone initiated by a hostile SIM.
Android's ART caches C++ mirror objects for app-specific Java classes/methods. That file is typically stored in the app’s private directory, writable by the app itself at runtime. Pretty sure there is nothing that can go wrong with that! usenix.org/conference/woot26…
GRAPE is cross-context code-pattern scanner that scans the entire Chromium code base in 12 minutes and earned the Authors of "Squeezing Juicy Variant Bugs Out of Modern Browsers" $17k5 for 24 newly-found vulnerabilities.
Pre-print: kdsjzh.github.io/assets/pdf/…
"Insecurity of Cellular Basebands" analyzes prior work on vulnerability discovery and attack surfaces; presenting a taxonomy of vulnerabilities, review state-of-the-art analysis techniques, including static analysis, over-the-air testing, and emulation.
usenix.org/system/files/woot…
WebRTC security in IoT remains poorly understood. RTCInspect is an automated analysis framework to detect protocol & cryptographic weaknesses. @DistriNet conducted a comparative study of 21 real-world applications, spanning 11 consumer IoT devices and 10 major web platforms.
Finding the right EM probe location is often the tedious, expert-driven part of electromagnetic side-channel attacks. Dev Mehta et al. paper, Swarm in EM Hay, turns this into an adaptive search problem - reducing trace count for AES key recovery by up to 16×.
Last year, AIxCC showed that cyber reasoning systems (CRSs) perform discovery and patch bugs: most of the 7 open-source CRSs remain largely unusable outside their original infrastructure. @TeamAtlanta24 presents an open, local framework with ported components from every finalist.
What if malware could hide in plain sight? Not by disabling tools, but by drowning them in data. Telemetry Complexity Attacks generate overwhelming nested telemetry that crashes serializers, breaks database inserts, and freezes dashboards. 18 products tested. 7 affected. 3 CVEs
Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. The security community spent 20 years asking: what could go wrong? Turns out: a lot.
If you want to learn more, checkout the upcoming paper at WOOT'26 "SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode". Preprint: vanbulck.net/files/woot26-sm…
PowerHooK demonstrates that VMs protected by AMD's SEV can still leak secrets through software-based power side channels. By exploiting transient execution to replay victim code paths, a malicious hypervisor can collect clean power traces and recover AES keys @m_oberhuber
Roudot & Sabt investigate how Widevine, Google's DRM, handles decrypted media inside modern browsers and shows that its output boundary can be intercepted surprisingly easily - on both Linux and Windows - incl. major streaming platforms, namely Netflix and Disney+.
Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated from the extensively studied Signal Protocol. Three practical attacks: an impersonation attack, a message timestamp forgery attack, and message dropping and replay attacks