会议信息: April 21-24, 2026 | Marina Bay Sands, Singapore
| 议题 | 演讲者 | 类型 | Paper |
|---|
| Privacy is the Captain. Security is the Practice. | Violet Blue | Keynote | - |
| 议题 | 演讲者 | Track | Paper |
|---|
| AlgoBuster: Systematic Algorithmic Brute-Force Attacks Against UDS Security Access in Automotive ECUs | Jianwen Ren, Jianchi Jiang | Hardware/IoT | BHAS26_Jianchi_AlgoBuster.pdf |
| Bad Vibes - Pwning Coding Agents 70 Times With The Same Bugs | Philip Tsukerman, Nil Ashkenazi | AI/ML, Exploit Dev | ❌ No slides |
| Breaking Hybrid Boundaries Across Azure and Windows | Ilan Kalendarov, Ben Zamir | Cloud, Enterprise | - |
| Practical Attacks Against Smartphone Boot ROMs | Christopher Wade | Mobile, Hardware | BHAS26-Wade-Practical-Attacks-REV01.pdf |
| 议题 | 演讲者 | Track | Paper |
|---|
| Cast Attack: A New Threat Posed by Ghost Bits in Java | Xinyu Bai, Zhihui Chen | AppSec:Offense, Exploit Dev | Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf ⭐ |
| Exploiting BLE Re-Pairing with the BLERP Attacks | Tommaso Sacchetti, Daniele Antonioli | Mobile, IoT | ❌ No slides |
| ShadowMQ: Exploiting Message Queue Flaws in AI Inference Servers for Widespread RCE | Avi Lumelsky et al. | AI/ML, Enterprise | ❌ No slides |
| When Flash Reveals Its Secrets: Advanced Glitching Leveraging Hidden CPU–eMMC Behavior | Jie Fu et al. | Hardware, Reverse Eng | BHAS26-Zhang-When-Flash-Reveals-Its.pdf |
| 议题 | 演讲者 | Track | Paper |
|---|
| Beyond the Golden Image: A Self-Healing Image Supply Chain | Neelu Tripathy, Lovlesh Malik | AppSec:Defense, Cloud | BHAS26-Tripathy-BeyondTheGoldenImage.pdf |
| Graph-Aware LLM for Windows Logon with a Closed-Loop Guarded Detection Agent | Shusei Tomonaga | Enterprise, Threat Hunting | BHAS26-Tomonaga-Graph-Aware.pdf |
| RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox | Xiang Li, Yuqi Qiu | Network, Exploit Dev | BHAS26-Qiu-SessionTitle-RebirthDay.pdf |
| We'll Eat Your Serial for Breakfast: Exploiting Serial-to-IP Converters in Critical Infrastructure | Stanislav Dashevskyi, Francesco La Spina | IoT, Exploit Dev | - |
| 议题 | 演讲者 | 类型 | Paper |
|---|
| From Prompt Tricks to Autonomous Hackers: The Rise of Agentic Offensive Security | Ari Herbert-Voss | Keynote | - |
| 议题 | 演讲者 | Track | Paper |
|---|
| CLOAQ: Ensuring the Cloud Quantum Computer Runs Your Program… But Learns Nothing | Vivek Balachandran, Amal Raj | Reverse Eng, AppSec:Defense | BHAS26-Raj-Cloaq-Where-The-Cloud-Handout.pdf |
| IntentGuard: Securing LLM-Generated Cloud Configurations | Anna Bacher, Chris Wysopal | AppSec:Defense, AI/ML | ❌ No slides |
| The Rentable IoT Meltdown: Mass Scale Hijacking of Shared Mobility and EV-Charging Fleets | Hetian Shi | IoT, Hardware | BHAS26-Shi-The Rentable IoT.pdf |
| WhisperPair: A Security Analysis of Google Fast Pair | Seppe Wyns et al. | Mobile, IoT | BHAS26-Wyns-WhisperPair-A-Securi.pdf |
| 议题 | 演讲者 | Track | Paper |
|---|
| Cyber-Paleontology in the Age of AI | Vitaly Kamluk | Malware, AI/ML | ❌ No slides |
| Remote Server, Local Root. Welcome to MCP. | Jiacheng Zhong et al. | AI/ML, AppSec:Offense | ❌ No slides |
| Silicon Valley's Quiet Leak: Revealing User Activity on macOS for Apple Silicon | Xin Zhang, Zhi Zhang | Platform, Exploit Dev | ❌ No slides |
| The Dark Side of Autonomy: Exploiting DFIR Agents Through Adversarial Manipulation | Yusuke Nakajima | Threat Hunting, AI/ML | BHAS26-Nakajima-The-Dark-Sid.pdf |
| 议题 | 演讲者 | Track | Paper |
|---|
| Capture the Narrative - Social Media Manipulation Wargaming | Hammond Pearce | Human Factors, AI/ML | BHAS26-Pearce-Capture-the-Narrative.pdf |
| Hack the Source, Of the Source | Tsi-Lin Ng | AppSec:Offense | ❌ No slides |
| Lost in Normalization: From URL Quirks to Poisoning the Azure Supply Chain | Nir Ohfeld, Ronen Shustin | Cloud, AppSec:Offense | ❌ No slides |
| One Char to Rule Them All: DNS Silent Vulnerabilities in Domain Name Resolution | Fasheng Miao, Xiang Li | Exploit Dev, Network | BHAS26-Miao-One-Char-to-Rule-The.pdf |
| 议题 | 演讲者 | Track | Paper |
|---|
| AI in the Loop: macOS PID-Domain Vulnerability Discovery with LLM Reasoning | Yinyi Wu et al. | Exploit Dev, AI/ML | ❌ On-Demand Only |
| Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCache | Xiangfan Wu et al. | AI/ML, Exploit Dev | ❌ On-Demand Only |
| IDEsaster 2.0: Another Novel Vulnerability Class in AI IDEs | Ari Marzouk | AI/ML, Exploit Dev | ❌ On-Demand Only |
| Model Files → Memory Corruption → RCE: Triple-Stage AI Attack Chain | Ji'an Zhou, Lei Lu | Exploit Dev, AI/ML | ❌ On-Demand Only |
| The Curious Case About Apple and Its Intelligence | Bhargav Rathod | Threat Hunting, AI/ML | ❌ On-Demand Only |
统计
- 总议题数: 44
- 有 Paper 可下载: 32
- 无 Paper: 12 (含 5 个 On-Demand Only)
重点关注议题
| 议题 | 关键技术 | 价值 |
|---|
| Cast Attack: Ghost Bits in Java | char→byte截断绕过WAF | ⭐⭐⭐ |
| PhantomRPC: Windows RPC提权 | RPC新漏洞类 | ⭐⭐⭐ |
| RebirthDay Attack: DNS缓存投毒 | Birthday Paradox | ⭐⭐⭐ |
| Overkill: Wi-Fi 7芯片劫持 | 硬件漏洞→SYSTEM | ⭐⭐ |
| AlgoBuster: UDS算法暴力破解 | 汽车ECU安全 | ⭐⭐ |
| QualComm BootROM Sahara | BootROM漏洞 | ⭐⭐ |
| VsyncBreaker: 屏幕信任破坏 | 移动设备UI攻击 | ⭐⭐ |