EILMELDUNGEN LIVE
🔧 ProgrammierungWould rust have fixed this?(28.08.2026 um 17:55 Uhr)
⚠️ Malware / Trojaner / VirenDas AUR wird angegriffen. Und jetzt? (hackmas2026)(28.08.2026 um 00:00 Uhr)
⚠️ Malware / Trojaner / Virenhackmas2026 - Das AUR wird angegriffen. Und jetzt?(28.08.2026 um 18:55 Uhr)
🕵️ SicherheitslückenThe Threat Intel Workflow is Broken(26.08.2026 um 17:52 Uhr)
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
🕵️ SicherheitslückenHow To Use AI To Become a KiLLER Hacker(29.08.2026 um 02:05 Uhr)
⚠️ Malware / Trojaner / VirenHow North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
⚠️ Malware / Trojaner / VirenUndetected Steam Malware: Sent by Viewer(28.08.2026 um 21:00 Uhr)
🔧 ProgrammierungWould rust have fixed this?(28.08.2026 um 17:55 Uhr)
⚠️ Malware / Trojaner / VirenDas AUR wird angegriffen. Und jetzt? (hackmas2026)(28.08.2026 um 00:00 Uhr)
⚠️ Malware / Trojaner / Virenhackmas2026 - Das AUR wird angegriffen. Und jetzt?(28.08.2026 um 18:55 Uhr)
🕵️ SicherheitslückenThe Threat Intel Workflow is Broken(26.08.2026 um 17:52 Uhr)
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
🕵️ SicherheitslückenHow To Use AI To Become a KiLLER Hacker(29.08.2026 um 02:05 Uhr)
⚠️ Malware / Trojaner / VirenHow North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
⚠️ Malware / Trojaner / VirenUndetected Steam Malware: Sent by Viewer(28.08.2026 um 21:00 Uhr)

6 🕛 kürzlich 2 Min Lesezeit 16 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | Exploiting BLE Re-Pairing with the BLERP Attacks

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
19 YouTube-Aufrufe
Bluetooth Low Energy (BLE) security relies on a Long-Term Key (LTK) that serves as a root of trust. Users implicitly trust their paired devices, such as laptops, mice, and keyboards, assuming that once paired, they are secure. We show that this trust is fragile.

In this talk, we introduce the BLE Re-Pairing Attacks (BLERP), a new class of protocol-level attacks that weaponize the standard re-pairing mechanism to overwrite trusted LTKs with attacker-controlled keys, compromising the BLE security model. We reveal six critical design flaws affecting re-pairing in the latest Bluetooth standard (v6.1), and we show how these flaws enable device impersonation and Man-in-the-Middle (MitM) attacks, even against the most secure BLE configurations. The BLERP attacks are stealthy and practical: they are "0-click" on headless devices, such as keyboards, and require a single unauthenticated interaction on smartphones.

We describe the BLERP Toolkit, an open-source framework built on low-cost nRF52 hardware that enables over-the-air testing of BLE pairing and allows attendees to audit their own devices. The talk includes a live demonstration of a re-pairing Peripheral Impersonation attack against a smartphone and concludes with immediate, actionable mitigations to protect against the BLERP attacks. Attendees will learn about BLE security, how BLERP attacks undermine it, and how to defend against these newly identified threats.

Tommaso Sacchetti | PhD Candidate, EURECOM
Daniele Antonioli | Assistant Professor, EURECOM

https://blackhat.com/asia-26/briefings/schedule/?#exploiting-ble-re-pairing-with-the-blerp-attacks-50164
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
139 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 49%
🟡 In Evaluierung 30%
🟢 Keine Auswirkung 14%
Spannende Innovation 7%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Using AI to Debug the Linux Kernel - BHIS - Talkin' Bout [infosec] News 2026-08-24
1 Quelle
My Life, AI and the Future of LiveOverflow
1 Quelle
How North Korean Hackers end up in your Network