Usenix WOOT Conference on Offensive Technologies :verified:
Make a deal with Usenix WOOT Conference on Offensive Technologies :verified:
🔒 Paid proposals held safely in escrow — released only when the work's approved.
Known for
12 views
PowerHooK demonstrates that confidential VMs protected by AMD's SEV technologies can still leak secrets through software-based power side
channels. By exploiting transient execution to replay victim code
paths, a malicious hypervisor can collect clean power traces and recover secrets, such as AES key material, even from SEV-SNP-protected Workloads. @moberhuber @isec_tugraz
11 views
Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. The security community spent 20 years asking: what could go wrong? Turns out: a lot. If you want to learn more, checkout the upcoming paper at WOOT'26 "SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode".
Preprint: https://vanbulck.net/files/woot26-smm.pdf
8 views
"Protocol Prying: Systematic Vulnerability Research in the AirDrop and Android Quick Share Proximity Transfer Protocols" presents the first cross-platform security analysis of Apple AirDrop and Android Quick Share, two proximity file-transfer protocols used by over five billion devices. By reverse engineering AirDrop’s application-layer stack and building the AIRFUZZ protocol-aware fuzzer, @Micros
4 views
Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated away from the Signal Protocol. The paper presents three practical attacks: an impersonation attack, a message timestamp forgery attack, and message dropping and replay attacks
📊 Post engagement
🔥 Top post: PowerHooK demonstrates that confidential VMs protected by AMD's · 12 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
🔥 Top post
PowerHooK demonstrates that confidential VMs protected by AMD's SEV technologies can still leak secrets through software-based power side
channels. By exploiting transient execution to replay victim code
paths, a malicious hypervisor can collect clean power traces and recover se…
WebRTC security in IoT remains poorly understood. RTCInspect is an open-source framework for automated analysis of RTC traffic
to detect protocol and cryptographic weaknesses. Using this
framework, Goeman et al. conducted a comparative sec…
Finding the right EM probe location is often the tedious, expert-driven part of electromagnetic side-channel attacks. Dev Mehta et al. paper, Swarm in EM Hay, turns this into an adaptive search problem: a particle swarm follows mutual-info…
Last year, DARPA’s AI Cyber Challenge (AIxCC) showed that cyber reasoning systems (CRSs) perform vulnerability discovery and patch bugs: most of the 7 open-source CRSs remain largely unusable outside their original infrastructure that no l…
What if malware could hide in plain sight? Not by disabling your tools, but by drowning them in data. Telemetry Complexity Attacks generate overwhelming nested telemetry that crashes serializers, breaks database inserts, and freezes dashbo…
Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. The security community spent 20 years asking: what could go wrong? Turns out: a lot. If you want to learn more, checkout the upco…
Some rooms at conference rate are again available for WOOT: https://www.usenix.org/conference/usenixsecurity26/venue-hotel-and-travel
Roudot & Sabt investigate how Widevine, Google's DRM, handles decrypted media inside modern browsers and shows that its output boundary can be intercepted surprisingly easily - on both Linux and Windows - incl. major streaming platforms, n…
Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated away from the Signal Protocol. The paper presents three practical attacks: an impersonation attack, a message timestamp forgery at…
"Protocol Prying: Systematic Vulnerability Research in the AirDrop and Android Quick Share Proximity Transfer Protocols" presents the first cross-platform security analysis of Apple AirDrop and Android Quick Share, two proximity file-trans…
How are you solving this dilemma?
Huber & Schink of #FraunhoferAISEC evaluate BBI-based online and offline manipulations of on-microcontroller flash memory, providing stealthy data manipulation and the ability to re-enable new µC interfaces & features.
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 97% real, active audience · Low fake-follower risk.
- Strong engagement (~2.2% of followers engage each post) — an active, real audience.
- Established account (3+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message Usenix WOOT Conference on Offensive Technologies :verified:
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with Usenix WOOT Conference on Offensive Technologies :verified:
Booking an event / appearance is a Pro feature. Upgrade to book Usenix WOOT Conference on Offensive Technologies :verified: for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ Usenix WOOT Conference on Offensive Technologies :verified: gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.
Auto-generated from Mastodon's public data — no affiliation with or endorsement by SocialDB. Is this you? Claim it · Remove