Media Summary: In this talk, we will present a novel timing side-channel attack on the TLB, combined with Recent advancements in OS security from Microsoft such as PatchGuard, Driver Signature Enforcement, and SecureBoot have ... The abundance of memory corruption and disclosure vulnerabilities in

Black Hat Usa 2018 Kernel - Detailed Analysis & Overview

In this talk, we will present a novel timing side-channel attack on the TLB, combined with Recent advancements in OS security from Microsoft such as PatchGuard, Driver Signature Enforcement, and SecureBoot have ... The abundance of memory corruption and disclosure vulnerabilities in In this talk, we perform a systematic assessment of recently proposed mitigation strategies by Apple. We demonstrate that most of ... Writing a working exploit for a vulnerability is generally challenging, time-consuming, and labor-intensive. To address this issue, ... Racing for Privilege: Leaking Privileged Memory From Any Intel System Using a Microarchitectural Race Condition Enhanced ...

In February 2019, I reported to Apple five ways to bypass Virtual Secure Mode, or VSM, on Windows marked the most significant leap in security innovation in quite some time, allowing the ... The security of computer systems fundamentally relies on the principle of confidentiality. Confidentiality is typically provided ... Virtualization based security technologies (VBS) continue to increase the world's dependency on the security of virtualization ...

Photo Gallery

Black Hat USA | Derandomizing the Location of Security-Critical Kernel Objects in the Linux Kernel
Black Hat USA 2025 | Kernel-Enforced DNS Exfiltration Security
Black Hat USA 2018 - Kernel Mode Threats and Practical Defenses
kR^X: Comprehensive Kernel Protection Against Just-In-Time Code Reuse
Eternal War in XNU Kernel Objects
Black Hat USA 2018 - Automating Exploit Generation for Arbitrary Types of Kernel Vulnerabilities
Black Hat USA 2025 | Racing for Privilege
iOS Kernel PAC, One Year Later
Black Hat USA 2025 | How KCFG and KCET Redefine Control Flow Integrity in the Windows Kernel
Black Hat USA 2018 - Meltdown Basics, Details, Consequences
Myth and Truth About Hypervisor-Based Kernel Protector: The Reason Why You Need Shadow-Box
Breaking VSM by Attacking SecureKernel
View Detailed Profile
Black Hat USA | Derandomizing the Location of Security-Critical Kernel Objects in the Linux Kernel

Black Hat USA | Derandomizing the Location of Security-Critical Kernel Objects in the Linux Kernel

In this talk, we will present a novel timing side-channel attack on the TLB, combined with

Black Hat USA 2025 | Kernel-Enforced DNS Exfiltration Security

Black Hat USA 2025 | Kernel-Enforced DNS Exfiltration Security

Kernel

Black Hat USA 2018 - Kernel Mode Threats and Practical Defenses

Black Hat USA 2018 - Kernel Mode Threats and Practical Defenses

Recent advancements in OS security from Microsoft such as PatchGuard, Driver Signature Enforcement, and SecureBoot have ...

kR^X: Comprehensive Kernel Protection Against Just-In-Time Code Reuse

kR^X: Comprehensive Kernel Protection Against Just-In-Time Code Reuse

The abundance of memory corruption and disclosure vulnerabilities in

Eternal War in XNU Kernel Objects

Eternal War in XNU Kernel Objects

In this talk, we perform a systematic assessment of recently proposed mitigation strategies by Apple. We demonstrate that most of ...

Black Hat USA 2018 - Automating Exploit Generation for Arbitrary Types of Kernel Vulnerabilities

Black Hat USA 2018 - Automating Exploit Generation for Arbitrary Types of Kernel Vulnerabilities

Writing a working exploit for a vulnerability is generally challenging, time-consuming, and labor-intensive. To address this issue, ...

Black Hat USA 2025 | Racing for Privilege

Black Hat USA 2025 | Racing for Privilege

Racing for Privilege: Leaking Privileged Memory From Any Intel System Using a Microarchitectural Race Condition Enhanced ...

iOS Kernel PAC, One Year Later

iOS Kernel PAC, One Year Later

In February 2019, I reported to Apple five ways to bypass

Black Hat USA 2025 | How KCFG and KCET Redefine Control Flow Integrity in the Windows Kernel

Black Hat USA 2025 | How KCFG and KCET Redefine Control Flow Integrity in the Windows Kernel

Virtual Secure Mode, or VSM, on Windows marked the most significant leap in security innovation in quite some time, allowing the ...

Black Hat USA 2018 - Meltdown Basics, Details, Consequences

Black Hat USA 2018 - Meltdown Basics, Details, Consequences

The security of computer systems fundamentally relies on the principle of confidentiality. Confidentiality is typically provided ...

Myth and Truth About Hypervisor-Based Kernel Protector: The Reason Why You Need Shadow-Box

Myth and Truth About Hypervisor-Based Kernel Protector: The Reason Why You Need Shadow-Box

Protection mechanisms running in the

Breaking VSM by Attacking SecureKernel

Breaking VSM by Attacking SecureKernel

Virtualization based security technologies (VBS) continue to increase the world's dependency on the security of virtualization ...

Black Hat USA 2012 - A Stitch in Time Saves Nine: A Case of Multiple Operating System Vulnerability

Black Hat USA 2012 - A Stitch in Time Saves Nine: A Case of Multiple Operating System Vulnerability

BlackHat USA