Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
IT Security NachrichtenAI Hallucinations Nearly Triggered a US-China Military Confrontation(20.09.2026 um 16:02 Uhr)
Malware / Trojaner / VirenMalicious npm packages evade install-script defenses at runtime(20.09.2026 um 16:11 Uhr)
IT Security NachrichtenEchtes 'Crossplay': Neuer Emulator startet erste PS5-Spiele auf der Xbox(20.09.2026 um 15:13 Uhr)
IT Security NachrichtenCyberangriff auf LMU München: Daten von Studierenden abgeflossen(20.09.2026 um 15:05 Uhr)
IT Security NachrichtenAI Hallucinations Nearly Triggered a US-China Military Confrontation(20.09.2026 um 16:02 Uhr)
Malware / Trojaner / VirenMalicious npm packages evade install-script defenses at runtime(20.09.2026 um 16:11 Uhr)
IT Security NachrichtenEchtes 'Crossplay': Neuer Emulator startet erste PS5-Spiele auf der Xbox(20.09.2026 um 15:13 Uhr)
IT Security NachrichtenCyberangriff auf LMU München: Daten von Studierenden abgeflossen(20.09.2026 um 15:05 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Black Hat Europe 2025 | Millions of Intranet Devices Are Facing Silent Takeover (On-Demand Only)

Reagiere als Erste:r — dein Feedback zählt!

Author: Black Hat - Bewertung: 2x - Views:22

The shift to cloud-managed IoT has introduced a dangerous blind spot in the security posture of millions of enterprise and residential devices. While vendors focus on web-facing threats, a far more insidious risk has emerged: cloud-device communication channels are becoming the new attack surface. In this presentation, we reveal critical vulnerabilities affecting products from major network equipment manufacturers that enable remote, unauthenticated takeover of intranet devices. Moreover, we demonstrate that security improvements made by vendors—such as enforcing one-to-one cloud–device communication channels—are still insufficient, and can continue to be exploited under real-world conditions.
We present new attack technique that allows attackers anywhere in the world to impersonate target intranet devices, hijack cloud communication channels, spoof the cloud and bypass companion app authentication, and ultimately achieve Remote Code Execution (RCE) with root privileges. Our research exposes flaws in existing cloud-device authentication mechanism, and a widespread absence of proper channel verification mechanisms.
These vulnerabilities silently impact millions of deployed devices worldwide and highlight systemic weaknesses in IoT cloud ecosystem security. Even more concerning, authentication mechanisms are typically finalized during product release and reused across product lines without change. When design flaws exist, they can affect a broad range of devices.
This presentation will describe our reverse engineering, vulnerability exploitation, and ethical disclosure processes. We will provide practical guidance for vendors, enterprise defenders, and cloud architects on how to redesign trust boundaries and secure remote management channels within cloud–device–app ecosystem.

By:
Jincheng Wang | First-year Master Candidate, Nanjing University of Posts and Telecommunications
Nan He | Independent Security Researcher

https://blackhat.com/eu-25/briefings/schedule/?#plug-and-controlled-millions-of-intranet-devices-are-facing-silent-takeover-on-demand-only-49156

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Black Hat Europe 2025 | Millions of Intranet Devices Are Facing Silent Takeover (On-Demand Only)

Thematisch verwandte Begriffe: Black, Europe, 2025, Millions · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93956 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by thi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick