Black Hat Asia 2026 议题列表

April 30, 2026 · View on GitHub

会议信息: April 21-24, 2026 | Marina Bay Sands, Singapore

Thursday (April 23)

Keynote (9:15am)

议题演讲者类型Paper
Privacy is the Captain. Security is the Practice.Violet BlueKeynote-

Session 1 (10:20am)

议题演讲者TrackPaper
AirSnitch: Breaking Client Isolation in Wi-Fi NetworksMathy Vanhoef, Zhiyun QianNetwork Security, CryptographyAsia-26-Vanhoef-AirSnitch-Breaking-Client-Isol.pdf
TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor NetworkYumingzhi Pan et al.IoT, Threat HuntingBHAS26-Pan-TORCHLIGHT-Shedding-LI-REV01.pdf
VsyncBreaker: Subverting Screen Trust via State Disruption and ONE-WAY FloodingWeiMin Cheng et al.Mobile, Platform SecurityBHAS26-WeiminCheng-VsyncBreaker.pdf
Your Number Is Up: When 3.5 Billion Strangers Can Exploit Your WhatsApp DevicesTal Be'eryPrivacy, CryptographyBHAS26-Beery-your-number-is-up.pdf

Session 2 (11:20am)

议题演讲者TrackPaper
AlgoBuster: Systematic Algorithmic Brute-Force Attacks Against UDS Security Access in Automotive ECUsJianwen Ren, Jianchi JiangHardware/IoTBHAS26_Jianchi_AlgoBuster.pdf
Bad Vibes - Pwning Coding Agents 70 Times With The Same BugsPhilip Tsukerman, Nil AshkenaziAI/ML, Exploit Dev❌ No slides
Breaking Hybrid Boundaries Across Azure and WindowsIlan Kalendarov, Ben ZamirCloud, Enterprise-
Practical Attacks Against Smartphone Boot ROMsChristopher WadeMobile, HardwareBHAS26-Wade-Practical-Attacks-REV01.pdf

Session 3 (1:30pm)

议题演讲者TrackPaper
Cast Attack: A New Threat Posed by Ghost Bits in JavaXinyu Bai, Zhihui ChenAppSec:Offense, Exploit DevAsia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf
Exploiting BLE Re-Pairing with the BLERP AttacksTommaso Sacchetti, Daniele AntonioliMobile, IoT❌ No slides
ShadowMQ: Exploiting Message Queue Flaws in AI Inference Servers for Widespread RCEAvi Lumelsky et al.AI/ML, Enterprise❌ No slides
When Flash Reveals Its Secrets: Advanced Glitching Leveraging Hidden CPU–eMMC BehaviorJie Fu et al.Hardware, Reverse EngBHAS26-Zhang-When-Flash-Reveals-Its.pdf

Session 4 (2:30pm)

议题演讲者TrackPaper
Breaking the Illusion of Key Zeroization: How OS, Libraries, and Hardware Keep Your AES Keys AliveToyofumi Sawa, Kuniyasu SuzakiCrypto, PlatformBHA26-Sawa-Breaking-the-Illusion-REV01.pdf
Hidden Telemetry: Uncovering TraceLogging ETW Providers You're Not Using (Yet)Asuka NakajimaDefense, Reverse EngBHAS26-Nakajima-Hidden-Telemetry-REV01.pdf
Qualcomm BootROM: A Journey Through SaharaAlexander Kozlov, Sergey AnufrienkoHardware, Exploit DevBHAS26-Kozlov-Anufrienko-Qualcom-REV01.pdf
Tropic Trooper Reloaded: Unraveling the Invisible Supply Chain MysterySuguru Ishimaru, Satoshi KamekawaThreat Hunting, MalwareAS26-Ishimaru-Tropic-Trooper-Reloaded-REV01.pdf

Session 5 (3:20pm)

议题演讲者TrackPaper
More JVM Memory Shells - JVM Memory Shell Auto Searching ProgramLitong Wan, Fanghai YuMalware, Threat HuntingBHAS26-Wan-More-JVM-Memory-Shells.pdf
Overkill: Hijacking a Wi-Fi 7 Chip for SYSTEM PrivilegesNicola Stauffer, Gürkan GürHardware, Exploit DevBHAS26-Stauffer-Gur-Overkill-slides.pdf
Post-Quantum Cryptography: A Realistic Guide to Manage the TransitionJean-Philippe AumassonPolicy, CryptoBHAS26-Aumasson-Post-Quantum.pdf
When Office Attacks - XLL Chains and Enterprise EDR NightmaresThanmayee RaoEnterprise, Threat HuntingBHAS26-Rao-When-Office-Attacks-Han.pdf

Session 6 (4:20pm)

议题演讲者TrackPaper
Beyond the Golden Image: A Self-Healing Image Supply ChainNeelu Tripathy, Lovlesh MalikAppSec:Defense, CloudBHAS26-Tripathy-BeyondTheGoldenImage.pdf
Graph-Aware LLM for Windows Logon with a Closed-Loop Guarded Detection AgentShusei TomonagaEnterprise, Threat HuntingBHAS26-Tomonaga-Graph-Aware.pdf
RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday ParadoxXiang Li, Yuqi QiuNetwork, Exploit DevBHAS26-Qiu-SessionTitle-RebirthDay.pdf
We'll Eat Your Serial for Breakfast: Exploiting Serial-to-IP Converters in Critical InfrastructureStanislav Dashevskyi, Francesco La SpinaIoT, Exploit Dev-

Friday (April 24)

Keynote (9:00am)

议题演讲者类型Paper
From Prompt Tricks to Autonomous Hackers: The Rise of Agentic Offensive SecurityAri Herbert-VossKeynote-

Session 7 (10:20am)

议题演讲者TrackPaper
CLOAQ: Ensuring the Cloud Quantum Computer Runs Your Program… But Learns NothingVivek Balachandran, Amal RajReverse Eng, AppSec:DefenseBHAS26-Raj-Cloaq-Where-The-Cloud-Handout.pdf
IntentGuard: Securing LLM-Generated Cloud ConfigurationsAnna Bacher, Chris WysopalAppSec:Defense, AI/ML❌ No slides
The Rentable IoT Meltdown: Mass Scale Hijacking of Shared Mobility and EV-Charging FleetsHetian ShiIoT, HardwareBHAS26-Shi-The Rentable IoT.pdf
WhisperPair: A Security Analysis of Google Fast PairSeppe Wyns et al.Mobile, IoTBHAS26-Wyns-WhisperPair-A-Securi.pdf

Session 8 (11:20am)

议题演讲者TrackPaper
Discovering React2Shell: JavaScript's Long-Awaited Deserialization Flight-mareLachlan DavidsonExploit Dev, AppSec:OffenseBHAS26-Davidson-Discovering-React2Shell.pdf
Fortifying the Foundation: LLM-Empowered Differential Testing for Ethereum InfrastructureJie Ma, Ningyu HeAppSec:Defense, PlatformBHAS26-Ma-Fortifying-the-Foundation-SLIDES.pdf
Inside Cybercrime Inc: Lessons From Covering the Global Fraud BoomSue-Lin WongEnterprise, Human FactorsBHAS26-Wong-Inside-Cybercrime-Inc.pdf
No Time to Patch: Faster Detection of N-Day Exploits in Chromium-based AppsWenxiang Qian, Zhixin TuDefense, Threat HuntingBHAS26-Wenxiang-Qian.pdf

Session 9 (1:30pm)

议题演讲者TrackPaper
Cyber-Paleontology in the Age of AIVitaly KamlukMalware, AI/ML❌ No slides
Remote Server, Local Root. Welcome to MCP.Jiacheng Zhong et al.AI/ML, AppSec:Offense❌ No slides
Silicon Valley's Quiet Leak: Revealing User Activity on macOS for Apple SiliconXin Zhang, Zhi ZhangPlatform, Exploit Dev❌ No slides
The Dark Side of Autonomy: Exploiting DFIR Agents Through Adversarial ManipulationYusuke NakajimaThreat Hunting, AI/MLBHAS26-Nakajima-The-Dark-Sid.pdf

Session 10 (2:30pm)

议题演讲者TrackPaper
Capture the Narrative - Social Media Manipulation WargamingHammond PearceHuman Factors, AI/MLBHAS26-Pearce-Capture-the-Narrative.pdf
Hack the Source, Of the SourceTsi-Lin NgAppSec:Offense❌ No slides
Lost in Normalization: From URL Quirks to Poisoning the Azure Supply ChainNir Ohfeld, Ronen ShustinCloud, AppSec:Offense❌ No slides
One Char to Rule Them All: DNS Silent Vulnerabilities in Domain Name ResolutionFasheng Miao, Xiang LiExploit Dev, NetworkBHAS26-Miao-One-Char-to-Rule-The.pdf

Session 11 (3:20pm)

议题演讲者TrackPaper
Payload Compromised: Full Key Recovery in Rocket.Chat E2EEHayato Kimura et al.Crypto, AppSec:OffenseBHAS26-Kimura-Payload-Compromised.pdf
PhantomRPC: A New Privilege Escalation Flaw in Windows RPCHaidar KabiboExploit DevBHAS26-Kabibo-PhantomRPC-REV01.pdf
The Gift That Keeps on Giving: Bypassing Auth Reflection Mitigations for SYSTEM ShellsGuillaume AndréPlatform, Reverse EngBHAS26-Andre-Bypass-Auth-Reflect-Mitigations-REV01.pdf

On-Demand Sessions

议题演讲者TrackPaper
AI in the Loop: macOS PID-Domain Vulnerability Discovery with LLM ReasoningYinyi Wu et al.Exploit Dev, AI/ML❌ On-Demand Only
Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCacheXiangfan Wu et al.AI/ML, Exploit Dev❌ On-Demand Only
IDEsaster 2.0: Another Novel Vulnerability Class in AI IDEsAri MarzoukAI/ML, Exploit Dev❌ On-Demand Only
Model Files → Memory Corruption → RCE: Triple-Stage AI Attack ChainJi'an Zhou, Lei LuExploit Dev, AI/ML❌ On-Demand Only
The Curious Case About Apple and Its IntelligenceBhargav RathodThreat Hunting, AI/ML❌ On-Demand Only

统计

  • 总议题数: 44
  • 有 Paper 可下载: 32
  • 无 Paper: 12 (含 5 个 On-Demand Only)

重点关注议题

议题关键技术价值
Cast Attack: Ghost Bits in Javachar→byte截断绕过WAF⭐⭐⭐
PhantomRPC: Windows RPC提权RPC新漏洞类⭐⭐⭐
RebirthDay Attack: DNS缓存投毒Birthday Paradox⭐⭐⭐
Overkill: Wi-Fi 7芯片劫持硬件漏洞→SYSTEM⭐⭐
AlgoBuster: UDS算法暴力破解汽车ECU安全⭐⭐
QualComm BootROM SaharaBootROM漏洞⭐⭐
VsyncBreaker: 屏幕信任破坏移动设备UI攻击⭐⭐