EILMELDUNGEN LIVE
🔧 AI Nachrichten Slopsquatting in the Supply Chain: Weaponized AI Hallucinations(23.08.2026 um 11:23 Uhr)
🐧 Linux TippsZwei Probleme in libnet-dns-perl (Debian)(23.08.2026 um 00:22 Uhr)
⚠️ Malware / Trojaner / VirenToxicPanda Android malware uses VPN permissions to block Google Play(23.08.2026 um 16:23 Uhr)
🕵️ SicherheitslückenSchwachstelle: Forscher reaktivieren abgelaufene Visa-Kreditkarten(23.08.2026 um 06:54 Uhr)
🔧 AI Nachrichten In Pekinger KI-Bar gibt es DeepSeek-Zugang gratis zum Bier dazu(23.08.2026 um 08:43 Uhr)
🪟 Windows TippsMicrosoft untersucht Spieleprobleme nach August-Windows-Updates(23.08.2026 um 11:54 Uhr)
📰 IT Security NachrichtenKI-Abhängigkeit als Risiko(23.08.2026 um 18:37 Uhr)
🔧 AI Nachrichten Slopsquatting in the Supply Chain: Weaponized AI Hallucinations(23.08.2026 um 11:23 Uhr)
🐧 Linux TippsZwei Probleme in libnet-dns-perl (Debian)(23.08.2026 um 00:22 Uhr)
⚠️ Malware / Trojaner / VirenToxicPanda Android malware uses VPN permissions to block Google Play(23.08.2026 um 16:23 Uhr)
🕵️ SicherheitslückenSchwachstelle: Forscher reaktivieren abgelaufene Visa-Kreditkarten(23.08.2026 um 06:54 Uhr)
🔧 AI Nachrichten In Pekinger KI-Bar gibt es DeepSeek-Zugang gratis zum Bier dazu(23.08.2026 um 08:43 Uhr)
🪟 Windows TippsMicrosoft untersucht Spieleprobleme nach August-Windows-Updates(23.08.2026 um 11:54 Uhr)
📰 IT Security NachrichtenKI-Abhängigkeit als Risiko(23.08.2026 um 18:37 Uhr)

📂 26 🕛 kürzlich ⏱️ 2 Min Lesezeit 29 Leser online 🛡️ CVE-RADAR
0

Black Hat Asia 2026 | More JVM Memory Shells: JVM Memory Shell Auto Searching Program

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
👁️ 104 YouTube-Aufrufe
A Java memory shell is a fileless backdoor that resides entirely in JVM memory, leaving no trace on disk. Attackers exploit code execution vulnerabilities—such as ScriptEngine injection or deserialization flaws—to use Java reflection to replace legitimate objects in web frameworks with malicious classes. Once implanted, specially crafted HTTP requests (mimicking normal traffic) trigger arbitrary command execution within the JVM, with results exfiltrated via standard HTTP responses. This stealthy technique blends seamlessly into legitimate traffic and bypasses firewalls that only allow ports 80/443, rendering traditional reverse shells ineffective.

Over the past eight years, common variants have included Tomcat Filter, Tomcat Listener, and Spring Controller memory shells—all dynamically injected at runtime. However, the discovery of new types has largely stalled in recent years, relying almost exclusively on manual source code audits.

We have developed an automated framework for discovering Java memory shells, integrating SAST (Static Application Security Testing), Java Agent–based hooking, JVM runtime memory introspection, and AIpowered PoC generation and validation capabilities. This framework dramatically accelerates the discovery of novel memory shells: in a very short time, it expanded the number of known Spring memory shell variants from just 2 to 9. Moreover, it is adaptable to any Java web framework for uncovering new memory shell techniques, significantly enhancing the efficiency of Java memory shell research and surpassing years of manual efforts.

Litong Wan | Cyber Security Engineer, Alibaba Holding - Risk & Security Dept
Fanghai Yu | Independent Security Researcher,
Yang Jing | Cyber Security Engineer, Alibaba Holding - Risk & Security Dept
Dongyan Zhang | Senior Security Engineer, Alibaba Holding - Risk & Security Dept
Huan Zeng | Senior Security Engineer, Alibaba Holding - Risk & Security Dept

https://blackhat.com/asia-26/briefings/schedule/?#more-jvm-memory-shells---jvm-memory-shell-auto-searching-program-50558
📰 Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
💡 Wie bewertest du diesen Beitrag?
1 Klick Feedback
149 Fachleser & IT-Security Experten haben diesen Report heute geteilt
🔗 Teilen mit Netzwerk & Team:
✍️

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf „✍️ Eigene Analyse verfassen“!
📊 Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 40%
🟡 In Evaluierung 32%
🟢 Keine Auswirkung 11%
💡 Spannende Innovation 17%
⚡ Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
4 Quellen
Black Hat Asia 2026 | Ensuring the Cloud Quantum Computer Runs Your Program… But Learns Nothing
1 Quelle
That App Isn't Native. It's Windows.
1 Quelle
Claude Code + Codex = AI GOD MODE! (Open source + Free)
🧠
KI-Empfehlungen & Semantisch verwandte Analysen
384-Dim Vektor-Match
🎯 100% Match ⏱️ 2 Min
Black Hat Asia 2026 | More JVM Memory Shells: JVM Memory Shell Auto Searching Program
📂 26 Lesen ↗
🎯 100% Match ⏱️ 2 Min
Black Hat Asia 2026 | More JVM Memory Shells: JVM Memory Shell Auto Searching Program
📂 26 Lesen ↗
🎯 100% Match ⏱️ 2 Min
Black Hat Asia 2026 | More JVM Memory Shells: JVM Memory Shell Auto Searching Program
📂 26 Lesen ↗