#HackLu has opened their #CfP. There is a vast list of topics of interest, thus opening the floor to researchers of various #cybersecurity, #threatintel and #internetmeasurement disciplines. Much of their work has a European, or even global impact. These folks are a bunch of great minds working […]
Call for papers is now open for hack.lu 2026 (the 20th edition!)
#hacklu #conference #cybersecurity #luxembourg #europe
2026.hack.lu/blog/hack.lu...
Revisiting Widevine L3: DRM As A Playground For Hackers - Felipe Custodio Romero
youtu.be/T3Xo4C6vIto
#HackLu
To wrap up our presentations at #HackLu, @bluesheeet.bsky.social and @butanol.bsky.social tackled a scary subject: Post-quantum cryptography. 🤯
They demonstrated that it is not as complicated at it seems and why it is crucial to begin integrating it in your products.
Still at #HackLu, @remsio.bsky.social and @w0rty.bsky.social shared their research on Livewire's unmarshalling mechanism at #nullcon Berlin. They demonstrated how to achieve RCE with the APP_KEY and extended their laravel-crypto-killer tool to automate the process. 💪
Later this month, at #HackLu in Luxembourg, @aeinot.bsky.social and @cybiosity.bsky.social demonstrated how Blue team tooling can be used by attackers for reconnaissance and post exploitation. They also gave insights on detection opportunities. 🧑🎓
At hack.lu I gave a presentation about "How to better identify (weaponized) file formats":
- Why do we need to identify file formats accurately?
- Why can the current tools (libmagic, magika) sometimes be bypassed?
- How can we do better?
You can now see it here: youtu.be/Qp5GDh2sj6A
#HackLu
How To Better Identify (Weaponized) File Formats With Ftguess - Philippe Lagadec
youtu.be/Qp5GDh2sj6A
#HackLu
French Stealer Ecosystem: The Resurgence Skid Gangs In Cybercrime Space - 0xSeeker
youtu.be/-3dF0zWtO_o
#HackLu
RE: infosec.exchange/@ministraitor/1154300499...
This talk from @wr is a masterpiece if you want to dive into all the gory details of the X.509 certificate format.
#hacklu #cybersecurity #certificate #threatintel
CLI Ambush - William Robinet
youtu.be/2ogJ6LkvNGw
#HackLu
Beyond Post-quantum Stereotypes - Antoine Gicquel & Benjamin Sepe
youtu.be/WqFrNRgBpEM
#HackLu
DCOM Turns 20: Revisiting A Legacy Interface In The Modern Threatscape - Julien Bedel
youtu.be/QSOjcQzLMA0
#HackLu
Automotive Security Analyzer For Exploitability Risks: An Automated And Attack Graph-Based Evaluation Of On-Board Networks - Martin Salfer
youtu.be/LseD22_ph78
#HackLu
Lightning Talk:
Revisiting RAND’s Lost Monte Carlo Simulations: Sharla Perrine, Paul Baran, And The True Business Case For The Internet - Trey Darley
youtu.be/FCdEhYVHvzw
#HackLu
Lightning Talk:
Threat Actor Tripping On The Finish Line - Rasmus
youtu.be/YXfTAXtSQYE
#HackLu
Lightning Talk:
Pwn2Own: Hacking IoT Devices - Adam
youtu.be/eESkBe0kOKw
#HackLu
Lightning Talk:
4-Byte Hell: When Unicode Enters The Stage - Jonas Hess
youtu.be/IJ0C1lEz-S0
#HackLu
Lightning Talk:
Reverse Engineering, For Real - Henri Ahola
youtu.be/TQUVg_XHC38
#HackLu @hack_lu
Lightning Talk:
Bugs In The Human Code: Help Timo - Paul Hirtz
youtu.be/ITkT05McR6E
#HackLu
Lightning Talk:
Fake Likes, Real Risks: Mapping Fake Social Activity Shops in Europe - Sviatlana Höhn & Anastasia "Asya" Sergeeva
youtu.be/BHhk0tdAdXY
#HackLu
Best Paper Award
youtu.be/2VlvIWedKDE
#HackLu
CTF Challenge Prize
youtu.be/ARGWj2-zDY0
#HackLu
Exploiting Legit APIs For Covert C2: A New Perspective On Cloud-based Malware Operations - Cocomelonc
youtu.be/l2G2TZvzj0E
#HackLu
Lethal Language Models: From Bit Flip To RCE In Ollama - Paul Gerste
youtu.be/YjCHGWIGxbU
#HackLu
Russian-speaking Underground:- Changes In - Vladimir Kropotov
youtu.be/vvbozBgfWSI
#HackLu
From YAML To Root: CI/CD Pipeline Attacks And Countermeasures - Hugo
youtu.be/YUbN6MuiuFM
#HackLu
Palo Alto GlobalProtect: Remote Full Compromise Exploit Chain - Maxime Escourbiac
youtu.be/3lQ5gxKTmw4
#HackLu
The Russian underground has ads for “arson” “surveillance” and more types of #hybridwarfare capabilities.
It seems there’s some (not unexpected, not the first time) connection between Russians Gov and the underground…
#hacklu #hacklu2025
Breaking Android IPC: A Deep Dive Into AIDL Fuzzing - Rajanish Pathak & Hardik Kamlesh Mehta
youtu.be/aNS6cScjKQA
#HackLu