EILMELDUNGEN LIVE
🔧 AI Nachrichten LLM & AI Agent Benchmarks vs Reality: Why AI Applications Break(27.08.2026 um 13:00 Uhr)
🎥 PodcastsEven China’s done with Windows(25.08.2026 um 02:25 Uhr)
🔧 AI Nachrichten That’s It?(27.08.2026 um 02:55 Uhr)
🎥 PodcastsSLOP FILTER TIME!(29.08.2026 um 01:30 Uhr)
🎥 PodcastsPixel 11 vs. Pixel 11 Pro | Choose WISELY!(28.08.2026 um 17:45 Uhr)
🎥 PodcastsWho Watches the Pixel Watch?(28.08.2026 um 22:43 Uhr)
🔧 AI Nachrichten LLM & AI Agent Benchmarks vs Reality: Why AI Applications Break(27.08.2026 um 13:00 Uhr)
🎥 PodcastsEven China’s done with Windows(25.08.2026 um 02:25 Uhr)
🔧 AI Nachrichten That’s It?(27.08.2026 um 02:55 Uhr)
🎥 PodcastsSLOP FILTER TIME!(29.08.2026 um 01:30 Uhr)
🎥 PodcastsPixel 11 vs. Pixel 11 Pro | Choose WISELY!(28.08.2026 um 17:45 Uhr)
🎥 PodcastsWho Watches the Pixel Watch?(28.08.2026 um 22:43 Uhr)

10 🕛 kürzlich 2 Min Lesezeit 11 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
2.2k YouTube-Aufrufe
The rapidly expanding Internet of Things (IoT) landscape is shifting toward cloudless architectures, removing reliance on centralized cloud services but exposing devices directly to the internet and increasing their vulnerability to cyberattacks. Our research revealed an unexpected pattern of substantial Tor network traffic targeting cloudless IoT devices, suggesting that attackers are using Tor to anonymously exploit undisclosed vulnerabilities (possibly obtained from underground markets). To delve deeper into this phenomenon, we developed TORCHLIGHT, a tool designed to detect both known and unknown threats targeting cloudless IoT devices by analyzing Tor traffic. TORCHLIGHT filters traffic via specific IP patterns, strategically deploys virtual private server (VPS) nodes for cost-effective detection, and uses a chain-of-thought (CoT) process with large language models (LLMs) for accurate threat identification.

Our results are significant: for the first time, we have demonstrated that attackers are indeed using Tor to conceal their identities while targeting cloudless IoT devices. Over a period of 12 months, TORCHLIGHT analyzed 26 TB of traffic, revealing 45 vulnerabilities, including 29 zero-day exploits with 25 CVE-IDs assigned (5 CRITICAL, 3 HIGH, 16 MEDIUM, and 1 LOW) and an estimated value of approximately $312,000. These vulnerabilities affect around 12.71 million devices across 148 countries, exposing them to severe risks such as information disclosure, authentication bypass, and arbitrary command execution. The findings have attracted significant attention, sparking widespread discussion in cybersecurity circles, reaching the top 25 on Hacker News, and generating over 190,000 views.

Yumingzhi Pan | Ph.D. Student, Southeast University
Zhen Ling | Professor, Southeast University
Yue Zhang | Professor, Shandong University
Hongze Wang | Ph.D. Student, Southeast University
Guangchi Liu | Professor, Southeast University
Junzhou Luo | Professor, Southeast University

https://blackhat.com/asia-26/briefings/schedule/?#torchlight-shedding-light-on-real-world-attacks-on-cloudless-iot-devices-concealed-within-the-tor-network-50017
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
43 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 55%
🟡 In Evaluierung 29%
🟢 Keine Auswirkung 12%
Spannende Innovation 5%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
How North Korean Hackers end up in your Network
1 Quelle
BHIS - Talkin' Bout [infosec] News 2026-08-31
1 Quelle
Undetected Steam Malware: Sent by Viewer