Your x86 CPU has a hidden mode that no OS can touch, no hypervisor can see, and no security tool can monitor. What could go wrong? Turns out: a lot. Checkout the upcoming paper "SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode". Preprint: vanbulck.net/files/woot26...
Usenix WOOT Conference on Offensive Technologies
@wootsecurity.bsky.social
WOOT aims to present a broad picture of offense and its contributions, bringing together researchers and practitioners in all areas of computer security. Co-located with USENIX Security Symposium'26 in Baltimore,MD on August 10–11, 2026
PowerHooK demonstrates that VMs protected by AMD's SEV can still leak secrets through software-based power side channels. By exploiting transient execution to replay victim code paths, a malicious hypervisor can collect clean power traces and recover AES key material @moberhuber.bsky.social
Some rooms at conference rate are again available for WOOT: www.usenix.org/conference/u...
Roudot & Sabt investigate how Widevine, Google's DRM, handles decrypted media inside modern browsers and shows that its output boundary can be intercepted surprisingly easily - on both Linux and Windows - incl. major streaming platforms, namely Netflix and Disney+. hal.science/hal-05648322...
Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated away from the Signal Protocol. @kota-ursgk.bsky.social presents three practical attacks: an impersonation attack, a message timestamp forgery attack, and message dropping and replay attacks
By reverse engineering AirDrop and building the AIRFUZZ fuzzer, Ebrahim & Tippenhauer uncover six vulnerabilities across macOS, iOS, Android, and Windows, including zero-click DoS bugs, authentication and encryption bypasses, and use-after-free with remote-code-execution impact.
How are you solving this dilemma?
Huber & Schink of Fraunhofer AISEC evaluate BBI-based online and offline manipulations of on-microcontroller flash memory, providing stealthy data manipulation and the ability to re-enable new µC interfaces & features.
Models like BLIP can leak training data, unless you rethink the architecture. The authors introduce NEURO(++) topological regularization. The twist: resilience is highly model- & dataset-dependant, i.e., attackers can’t assume one-size-fits-all behavior. #TrustworthyAI github.com/Trust-AI-ua/...
SEMSAN is an eBPF-based, configurable sanitizer that detects semantic bugs – such as a 21-year-old path traversal bug in graphena, command injection, and privilege escalation -- introducing under 1% overhead in real-world systems like Apache and PostgreSQL.
GRAPE is cross-context code-pattern scanner that scans the entire Chromium code base in 12 minutes and earned the Authors of "Squeezing Juicy Variant Bugs Out of Modern Browsers" $17k5 for 24 newly-found vulnerabilities. Pre-print: kdsjzh.github.io/assets/pdf/2...
Submit a poster to any offensive security topics you'd like to discuss with or show to the WOOT audience! www.usenix.org/conference/w...
Put a Tesla into a Faraday tent and test its LTE security. It did not end well. See “Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla” at USENIX WOOT’26. Repo & Pre-Print: github.com/Signal-Intel...
Microsoft's 6-year-old Zerologon patches use AES-CFB8 incorrectly. The novel Onelogon attack provides two ways to take over a vulnerable AD account in apx 30 minutes. #AESCFB8fail #WONTFIX softsec.link/woot26.onelo... @al3x-n3ff.bsky.social @kevin.borgolte.me @ruhr-uni-bochum.de
With about $180 of off-the-shelf hardware, HotWire sickcell6000.github.io/HotWire/ steals charging billed to victims, and drains an EV's batteries until they won't start - demonstrated on production cars and live public charging networks. Paper and presentation at WOOT'26.
SynthIR tricks deepfake image detectors using a simple optical filter and cardboard. To defend from their attack Ishizue, Rampazzi, & Sugawara propose a detection method based on dual-pixel sensors. tetsuishizue.github.io/BreakingInfr... see the full WOOT'26 lineup: www.usenix.org/conference/w...
Constant time programming is the primary defense against timing attacks, but the meaning of the term actually varies. On a key loading case study, Brumley finds BoringSSL's leak orders of magnitude stronger than OpenSSL's, despite, surprisingly, a stricter threat model.
If you have a better poster (or demo), we like to hear from you! Submit by June 25th at www.usenix.org/conference/w...
The Cycle 2 deadline for the USENIX WOOT Conference is in just one week (March 3, 2026). Full details are available in the Call for Papers: www.usenix.org/conference/w...
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
usenix.org
The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 3 weeks (March 3, 2026)! WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused). Details are available in the Call for Papers: www.usenix.org/conference/w...
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
usenix.org
Only 4 days to the WOOT 2026 Cycle 1 submission deadline! Check the CFP for details: www.usenix.org/conference/w...
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
usenix.org
USENIX WOOT Conference 2026: two submission deadlines this year! - Cycle 1: December 12, 2025 *only one month away* ! - Cycle 2: March 3, 2026 WOOT still has a SoK track and an "Up-and-coming track" (~Industry), CFP for details: www.usenix.org/conference/w...
WOOT 2025 closing Keynote "Escaping Cantor's Find-Fix Cycle" by Falcon Darkstar Momot from Dartmouth College and Aiven.io
Last papers session "Exploit All the Things" (Chair: Cristine Hoepers) - Soufian El Yadmani: SecurePoC—detecting malicious GitHub exploits - Andrea Mambretti: SoK on kernel vuln discovery & auto exploit generation - Junho Lee: BOOTKITTY—stealth bootkit-rootkit for modern OSes
WOOT 2025 late morning session: Application Security (Chair: Yves Younan) - Gabriel Karl Gegenhuber: Prekey Pogo—WhatsApp handshake weaknesses - Manuel Karl: Formula injection in real-world spreadsheets - Jannik Hartung: PHP foot-gun case study (Best paper award !)
WOOT 2025 day 2 starts with another Physical Attacks session (Chair: A. Zonenberg): - Valentin Huber: Deep dive into FRAM fault injection effects - Boyapally Harishma: Side-channel reality check on ARM Cortex-A72 - Wooyeon Jo: PLC memory exploitation in industrial systems
WOOT 2025 last session today Network Security : - Mehrdad Hajizadeh: DeepRed: AI-driven red teaming vs ML-NIDS - Shujie Zhao: Stealth BGP hijacks under uRPF - Anqi Chen: FUZZVPN: Hunting OpenVPN vulns
WOOT 2025 1st session of the afternoon, "Hacking at a Distance" with: - Tommaso Sacchetti on large scale Bluetooth Security Testing - Chengsong Diao: Vulnerabilities in Master Lock Smart Locks - Seyyed Ali Ayati Acoustic Side-Channel on keyboards
WOOT 2025 schedule, all papers are now online open access: usenix.org/conference/w... Talks are recorded, and should be online in a few weeks.
WOOT '25 Technical Sessions
All sessions will be held in Room 611-612 unless otherwise noted.
usenix.org