Infrastructure under renewed scrutinyLost in Translation: Text Message Spoofing via EmailSumanth Rao, Ye Shu, Stefan Savage, Aaron Schulman, Geoffrey M. Voelker, and Enze Liu

[Code] [Paper]

Hack the Source, Of the SourceTsi-Lin Ng

[Slides]

RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday ParadoxXiang Li, Yuqi Qiu, Mingming Zhang, Zuyao Xu, Lu Sun, Baojun Liu, Jia Zhang, Xiaofeng Zheng, Haixin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan, and Fasheng Miao

[Slides] [Paper]

Strange Inputs, Critical outputs: Attacking Infrastructure Through Innocuous Network Protocol FieldsSasha Romijn

[Blog post] [Video]

Clouds raining dataSub:jugation – Hijacking Cloud Identities by Recycling Namespaces in Global OIDC IssuersTal Skverer

[Blog post] [Video]

Rain: Transiently Leaking Data from Public Clouds Using Old VulnerabilitiesMathé Hertogh, Dave Quakkelaar, Thijs Raymakers, Mahesh Hari Sarma, Marius Muench, Herbert Bos, and Erik van der Kouwe

[Code] [Paper] [Site]

OCInferno: An Offensive Security Toolkit for OCIScott Weston

[Code] [Lightning Talk Video] [Video]

Zapocalypse: Compromising every Zapier user through a Lambda memory leakYair Balilti

[Video] [Website]

Sharp edges in Windows ecosystemsBreaking Hybrid Boundaries Across Azure and WindowsIlan Kalendarov and Ben Zamir

[Slides]

PhantomRPC: A New Privilege Escalation Flaw in Windows RPCHaidar Kabibo

[Slides] [Code]

Iron Giant: When the vault becomes the victimErik Egsgard

[Video]

Hunting with models, and models being huntedRadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke InferenceQijun Wang, Chunqi Qian, and Huacheng Zeng

[Code] [Paper] [Site]

Revelio: Blurred Images Can Still Disclose Your IdentityHaoyu Zhai, Shuo Wang, Pirouz Naghavi, Qingying Hao, and Gang Wang

[Site] [Paper]

Bad Vibes: Pwning Coding Agents 70 Times With The Same BugsPhilip Tsukerman, Nil Ashkenazi, and Alon Zahavi

[Slides]

System Over Model, Tested: Reproducing Mythos's FreeBSD Find on Local Open-Weight ModelsJohn McIntosh

[Blog post] [Code]

Nifty sundriesProtecting Cookies with Device Bound Session CredentialsBenjamin Ackerman, Daniel Rubery, and Guillaume Ehinger

[Blog post] [Documentation]

Turning Spam Filters Into Your Greatest Enemy: Intrusions Via RCEs in E-Mail Spam FiltersTing-Wei Hsieh and Kai-Ching Wang

[Slides]

AirSnitch: Breaking Client Isolation in Wi-Fi NetworksMathy Vanhoef, Zhiyun Qian, Xin'an Zhou, Juefei Pu, Zhutian Liu, Zhaowei Tan, and Srikanth Krishnamurthy

[Slides] [Paper] [Code]