Conference recordings from OrangeCon 2026 are now online!
Attack Techniques & Methods2026-07-17, 10:41
Conference recordings from OrangeCon 2026 are now online!
We've highlighted a few talks worth checking out:
• The Gift That Keeps On Giving: Bypassing Authentication Reflection Mitigations For SYSTEM Shells. The talk presents new techniques to bypass CVE-2025-33073 patches, enabling NTLM and Kerberos reflection attacks once again to escalate privileges and achieve RCE in domain environments.
• Abusing ASP.NET Trust Levels For Covert C2 Communications Channels. The speaker demonstrates how to establish covert C2 channels on IIS via allowed ASP.NЕТ mechanisms, even under restricted trust levels. This is achieved without invoking cmd.exe or spawning child processes.
• Strange Inputs, Critical Outputs: Attacking Infrastructure Through Innocuous Network Protocol Fields. This research explores attacks that leverage fields in DNS, TLS, WHOIS, and other network protocols to gain root on OpenWRT, take over hosting accounts, and disrupt ISP routing.
• 0-days on a Shoestring: Breaking Embedded Systems with LLMs and Junk Hardware. The session covers building a semi‑autonomous framework to discover and exploit 0-days in embedded devices using LLMs and inexpensive hardware.
• Bars of Shame: How Carriers Got Pwned, And What's Coming For The Rest Of Us. The presenter shows how telecom CRM data can be exploited for SIM swaps, SS7 and Diameter attacks, and roaming fraud.
Vulnerabilities
Researchers
Vendors
Products
More