WOOT aims to present a broad picture of offense and its contributions, bringing together researchers and practitioners in all areas of computer security

Colocated with Usenix Security
The SIM card taking over your phone via AT Commands and file R/W - "CATana Toolkit".
Our @wootsecurity'26 paper "CATana" is now available: usenix.org/system/files/woot…! In the paper, we find that some phones and many IoT devices execute AT commands sent by the SIM, leading to a wide range of consequences from DoS over 2G downgrade to device compromise.
1
8
864
Android's ART caches C++ mirror objects for app-specific Java classes/methods. That file is typically stored in the app’s private directory, writable by the app itself at runtime. Pretty sure there is nothing that can go wrong with that! usenix.org/conference/woot26…
1
298
Congratulations on your Best Paper Award!
GRAPE is cross-context code-pattern scanner that scans the entire Chromium code base in 12 minutes and earned the Authors of "Squeezing Juicy Variant Bugs Out of Modern Browsers" $17k5 for 24 newly-found vulnerabilities. Pre-print: kdsjzh.github.io/assets/pdf/…
1
2
383
"Don't trust your DRAM" -- Jacqueline Henes on attacking ARM TrustZone from userspace with memory aliasing usenix.org/conference/woot26…
2
11
657
"Insecurity of Cellular Basebands" analyzes prior work on vulnerability discovery and attack surfaces; presenting a taxonomy of vulnerabilities, review state-of-the-art analysis techniques, including static analysis, over-the-air testing, and emulation. usenix.org/system/files/woot…
2
7
577
WebRTC security in IoT remains poorly understood. RTCInspect is an automated analysis framework to detect protocol & cryptographic weaknesses. @DistriNet conducted a comparative study of 21 real-world applications, spanning 11 consumer IoT devices and 10 major web platforms.
2
7
589
Finding the right EM probe location is often the tedious, expert-driven part of electromagnetic side-channel attacks. Dev Mehta et al. paper, Swarm in EM Hay, turns this into an adaptive search problem - reducing trace count for AES key recovery by up to 16×.
1
1
279
Last year, AIxCC showed that cyber reasoning systems (CRSs) perform discovery and patch bugs: most of the 7 open-source CRSs remain largely unusable outside their original infrastructure. @TeamAtlanta24 presents an open, local framework with ported components from every finalist.
1
2
8
744
What if malware could hide in plain sight? Not by disabling tools, but by drowning them in data. Telemetry Complexity Attacks generate overwhelming nested telemetry that crashes serializers, breaks database inserts, and freezes dashboards. 18 products tested. 7 affected. 3 CVEs
2
375
Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. The security community spent 20 years asking: what could go wrong? Turns out: a lot.
8
80
406
31,424
If you want to learn more, checkout the upcoming paper at WOOT'26 "SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode". Preprint: vanbulck.net/files/woot26-sm…
2
34
2,770
PowerHooK demonstrates that VMs protected by AMD's SEV can still leak secrets through software-based power side channels. By exploiting transient execution to replay victim code paths, a malicious hypervisor can collect clean power traces and recover AES keys @m_oberhuber
3
10
870
Roudot & Sabt investigate how Widevine, Google's DRM, handles decrypted media inside modern browsers and shows that its output boundary can be intercepted surprisingly easily - on both Linux and Windows - incl. major streaming platforms, namely Netflix and Disney+.
1
11
449
Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated from the extensively studied Signal Protocol. Three practical attacks: an impersonation attack, a message timestamp forgery attack, and message dropping and replay attacks
1
7
311