LONDON–(BUSINESS WIRE)–Black Hat, the producer of the cybersecurity industry’s most established and in-depth security events, today announced the release of its content lineup for Black Hat Europe 2023. The live, in-person event will take place at ExCeL London from December 4 to December 7, and feature 40 Briefings hand selected by the Black Hat Europe Review Board, four days of Trainings, over 50 Sponsored Sessions, and 50 Arsenal tool demos.
On December 6 and December 7, attendees will gain insight into the latest in information security risks, developments, and trends. Briefings highlights include:
- Sweet QuaDreams or Nightmare Before Christmas? Dissecting an iOS 0-Day – This talk will explore private sector offensive actors (PSOAs) and how they have become one of the latest sophisticated threats, as well as cover the discovery of QuaDream’s spyware, outline the zero-click exploit likely used to deliver it, and share experiences from reversing engineering the attack surface from the ground up.
- TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers – This talk will present a Domain Name System (DNS) amplification attack named TsuKing, and discuss that with TsuKing, an initial small amplification factor can increase exponentially through the internal layers of coordinated amplifiers, resulting in an extremely powerful amplification attack.
- Indirect Prompt Injection Into LLMs Using Images and Sounds – This talk will discuss multi-modal Large Language Models (LLMs) as advanced artificial intelligence models that can produce contextually rich responses that combine inputs of various types (text, audio, pictures), along with possible threat models (and their significance with respect to existing threat models), the two types of attacks that can be applied (targeted output attack and dialog poisoning), and the method’s technical implementation.
- My Invisible Adversary: Burnout – This talk will highlight burnout as an invisible member of every operational security team, and discuss how to recognize burnout, what types of burnout are most applicable to security response teams, and ways to operate that actively monitor and reduce burnout across teams.
Two- and four-day Trainings will take place from December 4 to December 7 and feature a variety of in-person and virtual courses in application security (AppSec), defense, Internet of Things (IoT), malware, pentesting, and more. All participants will also receive a Certificate of Completion.