EILMELDUNGEN LIVE
🕵️ SicherheitslückenCase study: ManageWP Blocks 11.9M+ Threats in 6 Months with Patchstack(24.08.2026 um 16:35 Uhr)
📰 IT Security Nachrichtenmarcant Exposes AfD Nazism by Offering Them a Microphone(25.08.2026 um 11:43 Uhr)
📰 IT Security NachrichtenThe History of Webshell(25.08.2026 um 13:30 Uhr)
📰 IT Security NachrichtenDoctorow’s Disinvention of the VCR’s History(26.08.2026 um 10:35 Uhr)
⚠️ Malware / Trojaner / VirenApplying Zero Trust Principles to Agents - Kieran Human - ASW #397(25.08.2026 um 11:00 Uhr)
⚠️ Malware / Trojaner / VirenMeet Manic: The Android Malware With a Sneaky Backup Plan(25.08.2026 um 08:00 Uhr)
⚠️ Malware / Trojaner / VirenCybercriminals Turn GTA VI Leaks Into Malware Bait(24.08.2026 um 19:27 Uhr)
⚠️ Malware / Trojaner / VirenFake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown(25.08.2026 um 09:15 Uhr)
🕵️ SicherheitslückenCase study: ManageWP Blocks 11.9M+ Threats in 6 Months with Patchstack(24.08.2026 um 16:35 Uhr)
📰 IT Security Nachrichtenmarcant Exposes AfD Nazism by Offering Them a Microphone(25.08.2026 um 11:43 Uhr)
📰 IT Security NachrichtenThe History of Webshell(25.08.2026 um 13:30 Uhr)
📰 IT Security NachrichtenDoctorow’s Disinvention of the VCR’s History(26.08.2026 um 10:35 Uhr)
⚠️ Malware / Trojaner / VirenApplying Zero Trust Principles to Agents - Kieran Human - ASW #397(25.08.2026 um 11:00 Uhr)
⚠️ Malware / Trojaner / VirenMeet Manic: The Android Malware With a Sneaky Backup Plan(25.08.2026 um 08:00 Uhr)
⚠️ Malware / Trojaner / VirenCybercriminals Turn GTA VI Leaks Into Malware Bait(24.08.2026 um 19:27 Uhr)
⚠️ Malware / Trojaner / VirenFake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown(25.08.2026 um 09:15 Uhr)

10 🕛 kürzlich 1 Min Lesezeit 9 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | Cast Attack: A New Threat Posed by Ghost Bits in Java

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
617 YouTube-Aufrufe
In modern security defense systems, input validation and data integrity checks are the core to preventing attacks. However, a commonly overlooked source of vulnerabilities has long lurked in the code, not due to complex logic errors, but because of "ghost bits" silently erased during type conversion. This presentation reveals a novel attack technique called Cast Attack, which originates from data loss during Java's type casting process.

In this talk, we will demonstrate how Cast Attack can be used to bypass defenses such as WAFs, as well as introduce four major attack surfaces: privilege/access bypass, arbitrary file read, SMTP injection, and XSS. Affected vendors include, but are not limited to Oracle, Spring, Eclipse, Apache, Atlassian, JetBrains, and others.

The impact of Cast Attack far exceeds expectations. It not only challenges current input validation mechanisms but also provides attackers with a low-cost, stealthy attack vector that can cause unforeseen security vulnerabilities in critical systems. Could this become the next widely exploited attack technique? In this session, we will uncover this hidden threat together.

Xinyu Bai | Security Researcher,
Zhihui Chen | Security Engineer, Alibaba Cloud
Zongzheng Zheng | Independent Researcher, University of New South Wales

https://blackhat.com/asia-26/briefings/schedule/?#cast-attack-a-new-threat-posed-by-ghost-bits-in-java-50444
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
122 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 46%
🟡 In Evaluierung 25%
🟢 Keine Auswirkung 13%
Spannende Innovation 16%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Android-Malware blockiert Google Play per VPN-Trick
1 Quelle
Finger weg vom Schlüsselbund: Dieses Smart Lock übernimmt den Rest
1 Quelle
Brief von Culpa Inkasso – so reagieren Sie richtig