Conference recordings from BlueHat IL 2026 are now online!
Attack Techniques & Methods2026-07-15, 08:51
Conference recordings from BlueHat IL 2026 are now online!
We've highlighted a few talks worth checking out:
• Recovery Reimagined: Attacking and Securing Windows Recovery. The researchers present their study of Windows Recovery Environment and 11 new vulnerabilities that allow bypassing BitLocker and extracting data from encrypted drives.
• ShadowMQ: Leveraging AI Architecture for RCE Across Leading Inference Servers. The speaker discusses remote code execution flaws in internal channels of popular AI inference servers, including projects from Meta, NVIDIA, Microsoft, vLLM, and SGLang.
• The Stream Is Dead, Long Live the Stream: How HTTP/2 Lets Dead Streams Keep Servers Working. The talk covers the MadeYouReset vulnerability in HTTP/2 that enables request floods and denial of service. The issue affected Tomcat, Netty, F5, and several other implementations.
• Exploiting AI Orchestration Zero-Days via PostgreSQL Internals. The researchers disclose multiple 0-day vulnerabilities in Langflow, n8n, and Activepieces — including remote code execution, sandbox escape, session hijacking, and arbitrary file read via PostgreSQL internals.
• ChainLeak: From AI Framework to Cloud Secrets. This talk examines two vulnerabilities in Chainlit that enable remote file theft, cloud key and secret exfiltration, SSRF exploitation, and eventual server compromise.
• Hybrid Cloud – A Novel Vulnerability Playground. The presenters analyze four remote code execution and privilege escalation vulnerabilities in Azure Arc extensions that link on-prem systems with the cloud.
• VoidLink Internals Inside Chinese Commercial Grade Cloud Native Malware. The researchers dissect the VoidLink cloud-based malware framework, which integrates Linux kernel modules, eBPF, cloud credential theft, and over 30 components for offensive operations.
Vendors
Products
More