Editor's Picks

Best Talks at 34th USENIX Security Symposium

Hand-picked from in-depth reviewer verdicts — the top 12 talks from this conference. Skip the noise, find the signal.

← All talks at 34th USENIX Security Symposium

  1. 1

    Catch-22: Uncovering Compromised Hosts using SSH Public Keys

    Cristian Munteanu, Georgios Smaragdakis, Anja Feldmann, Tobias Fiebig

    This distinguished paper from USENIX Security 2025 presents a novel, scalable methodology to identify compromised SSH (Secure Shell) servers across the Internet. Authored by researchers from the Max Planck Institute for Informatics and Delft University of Technology, the work…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  2. 2

    Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race Conditions

    Sandro Rüegge, Johannes Wikner, Kaveh Razavi

    This groundbreaking paper from ETH Zurich introduces **Branch Predictor Race Conditions (BPRC)**, a novel class of microarchitectural vulnerabilities that undermine hardware-enforced mitigations against **Spectre v2** attacks on all recent Intel CPUs. The research, which earned…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  3. 3

    Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms

    Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung, Wing Cheong Lau, Julien Lecomte

    This article delves into the critical security vulnerabilities discovered in **integration platforms** that leverage **OAuth 2.0** for **account linking**. The paper, authored by Kaixuan Luo and Xianbo Wang from The Chinese University of Hong Kong, alongside Pui Ho Adonis Fung…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  4. 4

    Tracking You from a Thousand Miles Away! Turning a Bluetooth Device into an Apple AirTag Without Root Privileges

    Junming Chen, Xiaoyue Ma, Lannan Luo, Qiang Zeng

    This groundbreaking research introduces **nRootTag**, a novel attack method that weaponizes Apple's ubiquitous Find My network to maliciously track Bluetooth-enabled devices, transforming them into de facto **AirTags** without requiring root privileges. Presented by researchers…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  5. 5

    LLMmap: Fingerprinting for Large Language Models

    Dario Pasquini, Evgenios M. Kornaropoulos, Giuseppe Ateniese

    The proliferation of Large Language Models (LLMs) into mainstream applications has introduced a new frontier for cybersecurity research, particularly concerning their inherent vulnerabilities. This paper introduces **LLMmap**, a groundbreaking first-generation active…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  6. 6

    Narrowbeer: A Practical Replay Attack Against the Widevine DRM

    Florian Roudot, Mohamed Sabt, Univ Rennes, CNRS

    This technical article delves into the research presented in "Narrowbeer: A Practical Replay Attack Against the Widevine DRM," a paper by Florian Roudot and Mohamed Sabt from IRISA, Univ Rennes, and CNRS, presented at USENIX Security. The work investigates the security of…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  7. 7

    My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers

    Yufan You, Jianjun Chen, Zhongguancun Laboratory, Qi Wang, Haixin Duan, Zhongguancun Laboratory

    The ubiquitous ZIP file format, a foundational component for everything from office documents and Android applications to Java archives and browser extensions, harbors a pervasive and under-explored security vulnerability: **semantic gaps** between its numerous parsing…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  8. 8

    Nothing is Unreachable: Automated Synthesis of Robust Code-Reuse Gadget Chains for Arbitrary Exploitation Primitives

    Nicolas Bailluet, Univ Rennes, Inria, CNRS, Emmanuel Fleury, Univ Bordeaux, CNRS, Isabelle Puaut, Erven Rohou, Univ Rennes, Inria, CNRS

    This groundbreaking paper introduces **ARCANIST**, a novel approach and proof-of-concept tool for the automated synthesis of code-reuse gadget chains. Addressing a critical gap in modern exploit development, ARCANIST distinguishes itself by supporting *arbitrary exploitation…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  9. 9

    Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this Vulnerability

    Chuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu, Jianjun Chen, Haixin Duan, Gang Wang

    This groundbreaking research paper delves into the profound implications of **SMTP smuggling**, a sophisticated email spoofing vulnerability that bypasses established authentication protocols like **SPF** (Sender Policy Framework) and **DMARC** (Domain-based Message…

    0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway MUST SEE ★★★★★
  10. 10

    TDXploit: Novel Techniques for Single-Stepping and Cache Attacks on Intel TDX

    Fabian Rauscher, Luca Wilke, Hannes Weissteiner, Thomas Eisenbarth, Daniel Gruss

    Intel Trust Domain Extensions (**TDX**) represent the second generation of Trusted Execution Environments (TEEs), designed to protect entire virtual machines (VMs), known as trust domains (TDs), from a potentially malicious host system. While TDX aims to provide robust memory…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  11. 11

    Approve Once, Regret Forever: On the Exploitation of Ethereum's Approve-TransferFrom Ecosystem

    Nicola Ruaro, Fabio Gritti, Dongyu Meng, Robert McLaughlin, University of California, Ilya Grishchenko, Christopher Kruegel, Giovanni Vigna, University of California

    This research paper, "Approve Once, Regret Forever: On the Exploitation of Ethereum's Approve-TransferFrom Ecosystem," presented at USENIX Security, delves into a critical class of vulnerabilities in Ethereum smart contracts known as **Approved Controllable TransferFrom…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  12. 12

    I Know What You Said: Unveiling Hardware Cache Side-Channels in Local Large Language Model Inference

    Zibo Gao, Junjie Hu, Feng Guo, Yixin Zhang, Yinglong Han, Siyuan Liu, Haiyang Li, Zhiqiang Lv, Institute of Information Engineering, Chinese Academy of Sciences, School of Cyber Security

    This paper, presented at USENIX Security, unveils a critical and previously unexplored security vulnerability in locally deployed Large Language Models (LLMs): **hardware cache side-channel leakage**. Authored by researchers from the University of Chinese Academy of Sciences…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆