Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

The court denied requests to suspend awards regarding Apple's App Store payment fees

June 6, 2025

Circle IPOs are giving hope to more startups waiting to be published to more startups

June 5, 2025

Perplexity received 780 million questions last month, the CEO says

June 5, 2025
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    The court denied requests to suspend awards regarding Apple's App Store payment fees

    June 6, 2025

    Perplexity received 780 million questions last month, the CEO says

    June 5, 2025

    Bonfire's new software allows users to build their own social communities free from platform control

    June 5, 2025

    x Test to highlight posts that users with dissent

    June 5, 2025

    Google says the updated Gemini 2.5 Pro AI model is excellent at coding

    June 5, 2025
  • Crypto

    Circle IPOs are giving hope to more startups waiting to be published to more startups

    June 5, 2025

    GameStop bought $500 million in Bitcoin

    May 28, 2025

    Vote for the session you want to watch in 2025

    May 26, 2025

    Save $900 + 90% from 2 tickets to destroy 2025 in the last 24 hours

    May 25, 2025

    Only 3 days left to save up to $900 to destroy the 2025 pass

    May 23, 2025
  • Security

    Humanity unveils custom AI models for US national security customers

    June 5, 2025

    Unlock phone company Cellebrite to acquire mobile testing startup Corellium for $170 million

    June 5, 2025

    Ransomware Gangs claim responsibility for Kettering Health Hack

    June 4, 2025

    Former CTO of CrowdStrike's cyber-rivals and how automation can undermine security for early-stage startups

    June 4, 2025

    Data breaches at newspaper giant Lee Enterprises impact 40,000 people

    June 4, 2025
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Less than 48 hours left until display at TC at all stages

    June 5, 2025

    TC Session: AI will be on sale today at Berkeley

    June 5, 2025

    North America accounts for the majority of AI VC investment despite the harsh political environment

    June 5, 2025

    3 days left: Charge all your locations in stages on TC Expo Floor

    June 4, 2025

    From $5 to Financial Empowerment: Why Stash co-founder Brandon Krieg is a must-see for TechCrunch All Stage 2025

    June 4, 2025
TechBrunchTechBrunch

Best Hacking and Security Research from Black Hat and Def Con 2024

TechBrunchBy TechBrunchAugust 12, 20244 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


This week, thousands of hackers, researchers, and security professionals gathered in Las Vegas for the security conferences Black Hat and Def Con, annual pilgrimages aimed at sharing the latest research, hacks, and knowledge across the security community. TechCrunch was on-site to report on the back-to-back shows and bring you some of the latest research.

CrowdStrike got the attention and the “big fail” award it didn't want, but the company addressed the scandal and admitted it screwed up just weeks after releasing a buggy software update that caused a global IT outage. Hackers and security researchers may not forget easily, but they seem mostly willing to forgive.

As another round of Black Hat and Def Con conferences comes to an end, we're looking back at some of the show's highlights and best research that you may have missed.

Hacking Ecovac robots to spy on their owners over the internet

Security researchers revealed in a talk at Def Con that it's possible to take over Ecovacs home vacuums and lawnmower robots by sending malicious Bluetooth signals to vulnerable nearby robots. From there, the on-board microphones and cameras can be remotely activated over the internet, allowing the attacker to spy on anyone within the robot's ears and camera's field of view.

Unfortunately, Ecovacs did not respond to the researchers or to TechCrunch's request for comment, and there is no evidence that the bug has been fixed. The good news is that we still have some great screenshots of the dog captured by the hacked Ecovacs robot's onboard camera.

A dog seen through a hacked Ecovax device.A dog seen through a hacked Ecovacs device. Image courtesy of Dennis Guise and Braelyn / Courtesy. Image courtesy of Dennis Guise and Braelyn

The long-term battle to break into LockBit ransomware and expose the identity of its masterminds

A wild chase between security researcher John DiMaggio and the mastermind behind the LockBit ransomware and extortion ring, known only as LockBitSupp, led DiMaggio into a maze of open-source intelligence gathering to discover the notorious hacker's actual identity.

In a series of highly detailed diaries, DiMaggio was driven by an anonymous tip about an email address allegedly used by RockBitsap and a deep-seated desire to deliver justice for the gang's victims, and he eventually identified the man — and he did so before federal agents publicly named the hacker as Russian national Dmitry Khoroshev. At DEFCON, DiMaggio told his story from his perspective for the first time in front of a packed audience.

Hackers develop laser microphone that can listen to keyboard keystrokes

Famed hacker Sammy Kamkar has developed a new technique for surreptitiously identifying taps on a laptop keyboard by shining an invisible laser through a nearby window. Demonstrated at Def Con and explained by Wired, the technique “uses the subtle acoustic sounds produced by tapping various keys on a computer,” and works as long as the hacker can maintain a line of sight from the laser to the target laptop itself.

Prompt injection can easily trick Microsoft Copilot

A new prompt injection technique developed by Zenity has been shown to allow for the extraction of sensitive information from Copilot, Microsoft's AI-powered chatbot companion. Zenity Chief Technology Officer Michael Bargury demonstrated the exploit at the Black Hat conference, showing how to manipulate Copilot AI prompts to change their output.

In one example, Burglee tweeted, he showed how a malicious actor could enter HTML code containing a bank account number they control and trick CoPilot into returning that bank account number in a response to a consumer. This can be used to trick unsuspecting people into sending money to the wrong place, a common business fraud technique.

Sending an email caused an RCE in M365 Copilot

~RCE means complete remote control
The action – Search for sensitive content (SharePoint, Mail, Calendar, Teams), run plugins
And output – bypassing DLP controls, manipulating referrals, social engineering users… pic.twitter.com/r1yMRLXKAG

— mbg @ Defcon (@mbrg0) August 8, 2024

Ransomware leak site's ransomware flaw saves six businesses from hefty ransoms

Security researcher Vangelis Stikas set out to investigate dozens of ransomware gangs and identify potential holes in their public infrastructure, such as extortion leak sites. In his Black Hat talk, Stikas described how he discovered vulnerabilities in the web infrastructure of three ransomware gangs (Mallox, BlackCat, and Everest), obtained decryption keys for two of them before the gangs deployed their ransomware, and notified four others, saving a total of six gangs from paying high ransoms.

While ransomware has not improved, the tactics used by law enforcement against gangs who encrypt and blackmail their victims are becoming more innovative and interesting, and this may be an approach to consider against gangs in the future.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Humanity unveils custom AI models for US national security customers

June 5, 2025

Unlock phone company Cellebrite to acquire mobile testing startup Corellium for $170 million

June 5, 2025

Ransomware Gangs claim responsibility for Kettering Health Hack

June 4, 2025

Former CTO of CrowdStrike's cyber-rivals and how automation can undermine security for early-stage startups

June 4, 2025

Data breaches at newspaper giant Lee Enterprises impact 40,000 people

June 4, 2025

Phone Chipmaker Qualcomm fixes 3 zero-days exploited by hackers

June 3, 2025

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

The court denied requests to suspend awards regarding Apple's App Store payment fees

June 6, 2025

Circle IPOs are giving hope to more startups waiting to be published to more startups

June 5, 2025

Perplexity received 780 million questions last month, the CEO says

June 5, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2025 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.