Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SecurityWeek’s August 9, 2022 preview selected ten Black Hat USA Briefings it expected to draw attention. The list was an editorial selection—not an objective ranking or a report on talks after they happened. The Briefings took place August 10–11, 2022, during the hybrid Black Hat USA event in Las Vegas. Here is what each session was about and who was most likely to find it useful.

How to read this 2022 selection

The sessions span automotive security, industrial malware, mobile devices, web infrastructure, software supply chains, human rights, and security governance. The descriptions below reflect what the presenters planned to cover, as summarized in SecurityWeek’s preview; they should not be read as independent verification of every research claim or as a current threat assessment. The order follows the preview, not a ranking.

Black Hat’s event page described a hybrid event running August 6–11 at Mandalay Bay in Las Vegas, with the main Briefings scheduled for August 10 and 11. The official schedule said speaker-provided presentations, white papers, or tools would be linked from the relevant session entry after the talk. Whether those materials remain available today is not established by the event information.

The ten presentations

1. “RollBack – A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems”

The researchers described a replay-and-resynchronization attack against rolling-code keyless-entry systems, presenting it as a development beyond RollJam. Its security lesson is that rolling codes are not automatically immune to protocol or state-management weaknesses. The preview framed this as automotive security research, not as instructions for attacking vehicles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. “Industroyer2: Sandworm’s Cyberwarfare Targets Ukraine’s Power Grid Again”

ESET researchers Robert Lipovsky and Anton Cherepanov planned to explain their reverse engineering of Industroyer2, compare it with the 2016 malware, and discuss its use of IEC-104 to communicate with industrial control equipment. SecurityWeek’s preview reported that the 2022 operation did not achieve its intended blackout. The attribution, analysis, and impact are presented here as claims described in that preview.

3. “Déjà Vu: Uncovering Stolen Algorithms in Commercial Products”

Patrick Wardle and Tom McGuire planned to present ways to search for potentially unauthorized reuse of algorithms, followed by a case study involving reverse engineering and binary comparison. The session concerned methods and a particular case; it does not establish that commercial vendors generally steal algorithms.

4. “Monitoring Surveillance Vendors: A Deep Dive into In-the-Wild Android Full Chains in 2021”

Google’s Threat Analysis Group and Android Security teams planned to describe investigations into exploit chains linked to surveillance vendors, including browser and kernel vulnerabilities. This was threat reporting about activity investigated in 2021, as summarized in the 2022 preview—not an assessment of the present-day Android threat landscape.

5. “Attack on Titan M, Reloaded: Vulnerability Research on a Modern Security Chip”

Quarkslab researchers Damiano Melotti and Maxime Rossi Bellom planned to discuss fuzzing and emulation work on Google’s Titan M security chip. The preview said they would explain a vulnerability they had developed into code execution. The talk was a chip-security case study; the preview does not establish that Pixel devices are currently vulnerable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. “The Cyber Safety Review Board: Studying Incidents to Drive Systemic Change”

This discussion was set to cover the board’s first project, its review of the Log4j crisis, and recommendations for organizations and government. The listed participants were Rob Silvers, identified in the preview as DHS Undersecretary for Policy and board chair, and Heather Adkins, identified as Google’s Deputy Chair and Vice President of Security Engineering. It offered a governance and incident-review perspective rather than a technical exploit demonstration.

7. “Charged by an Elephant – An APT Fabricating Evidence to Throw You In Jail”

SentinelLabs researchers Juan Andres Guerrero-Saade and Tom Hegel planned to discuss ModifiedElephant and allegations that fabricated digital evidence had been used to incriminate activists. SecurityWeek presented this as research into alleged abuses with human-rights implications. The allegations and actor characterization should not be mistaken for court findings.

Rank #4
Sale
Black Hat Go: Go Programming For Hackers and Pentesters
  • Book - black hat go: go programming for hackers and pentesters
  • Language: english
  • Binding: paperback

8. “Google Reimagined a Phone. It was Our Job to Red Team and Secure it”

Google’s Android Red Team planned to describe security work on the Pixel 6, including fuzzing, emulation, static analysis, and manual review. The announced demonstrations involved privileged code execution and hardware key attestation. This was the vendor’s account of its product-security process, not independent validation of the phone’s security.

9. “Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling”

PortSwigger researcher James Kettle planned to show how browser behavior could interact with server flaws to broaden the reach of request-desynchronization attacks. The session preview named web servers, content delivery networks, and VPNs as examples. Its focus was the security implications of combining client and server behavior, not a general claim that every such service is exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
I'd Rather Be Phishing Hacker Hacking Cybersecurity Coding Hat Mens Black Hat AllBlack Dad Hat Gifts for Him
  • Easily Adjustment ; Fashion Travel
  • Day Surprise ; Best-loved Hat
  • Professional Stitches, Particulars Exhibition.
  • Birthday Gifts ; Distinctive
  • Everyday For Style

10. “RCE-as-a-Service: Lessons Learned from 5 Years of Real-World CI/CD Pipeline Compromise”

NCC Group researchers Iain Smart and Viktor Gazdag planned to present examples of CI/CD pipeline abuse and argue that highly privileged build systems are a significant software supply-chain attack surface. SecurityWeek reported the researchers’ claim of “several dozen” successful compromises; that figure is their reported work, not an independently established population statistic. For practitioners, the practical implication is to review pipeline permissions, secrets, and build controls.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which sessions fit your interests?

Reader interest Sessions What they emphasize
Automotive and industrial security 1 and 2 Rolling-code keyless entry and malware communicating with industrial control equipment
Mobile and device security 4, 5, and 8 Android exploit-chain investigations, security-chip research, and a vendor red-team account
Web and software supply-chain defense 9 and 10 HTTP request desynchronization and CI/CD pipeline compromise
Policy, incident response, and civil society 6 and 7 Systemic recommendations after Log4j and allegations involving fabricated evidence against activists
Reverse engineering and research methods 3 and 5 Algorithm-reuse detection, binary comparison, fuzzing, and emulation

Finding the event’s materials

Black Hat’s 2022 instructions said speaker-provided presentations, white papers, or tools would appear through the corresponding schedule entry after each session. The event page also described the event as hybrid. These are historical details; current access to recordings or archived speaker files, and any current continuing-education eligibility, are not established by those pages. Black Hat’s overview said eligible ISC2 attendees could earn 14 CPE credits for the two-day Briefings, while Privacy Track Briefings had been pre-approved for IAPP credit with certificate holders self-submitting. Those applied to the 2022 event, not to viewing materials now.

Sources: Black Hat USA 2022 event page; Ryan Naraine, SecurityWeek, August 9, 2022; Black Hat USA 2022 Briefings and attendee resources.

Quick Recap

SaleBestseller No. 4
Black Hat Go: Go Programming For Hackers and Pentesters
Black Hat Go: Go Programming For Hackers and Pentesters
Book - black hat go: go programming for hackers and pentesters; Language: english; Binding: paperback
$34.20
Bestseller No. 5
I'd Rather Be Phishing Hacker Hacking Cybersecurity Coding Hat Mens Black Hat AllBlack Dad Hat Gifts for Him
I'd Rather Be Phishing Hacker Hacking Cybersecurity Coding Hat Mens Black Hat AllBlack Dad Hat Gifts for Him
Easily Adjustment ; Fashion Travel; Day Surprise ; Best-loved Hat; Professional Stitches, Particulars Exhibition.
$10.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.