Security

The best hacks and security research from Black Hat and Def Con 2024

Comment

a photo showing the entrance of the business hall at the Black Hat security conference in Las Vegas in August 2024
Image Credits: Lorenzo Franceschi-Bicchierai / TechCrunch

Thousands of hackers, researchers and security professionals descended on the Black Hat and Def Con security conferences in Las Vegas this week, an annual pilgrimage aimed at sharing the latest research, hacks, and knowledge across the security community. And TechCrunch was on the ground to report on the back-to-back shows and to cover some of the latest research.

CrowdStrike took center stage, and picked up an “epic fail” award it certainly didn’t want. But the company acknowledged it messed up and handled its scandal several weeks after releasing a buggy software update that sparked a global IT outage. Hackers and security researchers seemed largely willing to forgive, though maybe not easily forget.

As another round of Black Hat and Def Con conferences wrap up, we look back at some of the highlights and the best in research from the show that you might’ve missed.

Hacking Ecovac robots to spy on their owners over the internet

Security researchers revealed in a Def Con talk that it was possible to hijack a range of Ecovacs home vacuum and lawnmower robots by sending a malicious Bluetooth signal to a vulnerable robot within a close proximity. From there, the on-board microphone and camera can be remotely activated over the internet, allowing the attacker to spy on anyone within ear- and camera-shot of the robot.

The bad news is that Ecovacs never responded to the researchers, or TechCrunch’s request for comment, and there is no evidence that the bugs were ever fixed. The good news is that we still got this incredible screenshot of a dog taken from the on-board camera of a hacked Ecovacs robot. 

A dog seen through a hacked Ecovacs device.
A dog seen through a hacked Ecovacs device. Image Credits: Dennis Giese and Braelynn / supplied.
Image Credits: Dennis Giese and Braelynn

The long game of infiltrating the LockBit ransomware game and doxing its ringleader

An intense cat and mouse game between security researcher Jon DiMaggio and the ringleader of the LockBit ransomware and extortion racket, known only as LockBitSupp, led DiMaggio down a rabbit hole of open source intelligence gathering to identify the real-world identity of the notorious hacker. 

In his highly detailed diary series, DiMaggio, spurred on by an anonymous tip of an email address allegedly used by LockBitSupp and a deep-rooted desire to get justice for the gang’s victims, finally identified the man, and got there even before federal agents publicly named the hacker as the Russian national, Dmitry Khoroshev. At Def Con, DiMaggio told his story from his perspective to a crowded room for the first time.

Hacker develops laser microphone that can hear your keyboard taps

Renowned hacker Samy Kamkar developed a new technique aimed at stealthily determining each tap from a laptop’s keyboard by aiming an invisible laser through a nearby window. The technique, demonstrated at Def Con and as explained by Wired, “takes advantage of the subtle acoustics created by tapping different keys on a computer,” and works so long as the hacker has a line-of-sight from the laser to the target laptop itself. 

Prompt injections can easily trick Microsoft Copilot

A new prompt injection technique developed by Zenity shows it’s possible to extract sensitive information from Microsoft’s AI-powered chatbot companion, Copilot. Zenity chief technology officer Michael Bargury demonstrated the exploit at the Black Hat conference, showing how to manipulate Copilot AI’s prompt to alter its output.

In one example he tweeted out, Bargury showed it was possible to feed in HTML code containing a bank account number controlled by a malicious attacker and trick Copilot into returning that bank account number in responses returned to ordinary users. That can be used to trick unsuspecting people into sending money to the wrong place, the basis of some popular business scams

Six companies saved from hefty ransoms, thanks to ransomware flaws in ransomware leak sites

Security researcher Vangelis Stykas set out to scope dozens of ransomware gangs and identify potential holes in their public-facing infrastructure, such as their extortion leak sites. In his Black Hat talk, Stykas explained how he found vulnerabilities in the web infrastructure of three ransomware gangs — Mallox, BlackCat, and Everest — allowing him to get decryption keys to two companies and notify four others before the gangs could deploy ransomware, saving in total six companies from hefty ransoms

Ransomware isn’t getting better, but the tactics law enforcement are using against gangs that encrypt and extort their victims are getting more novel and interesting, and this could be an approach to consider with gangs going forward.

More TechCrunch

When users click on an event on Polymarket, they will now see a summary of news related to the event based on search results from Perplexity.

Prediction marketplace Polymarket partners with Perplexity to show news summaries

The U.K. antitrust regulator has confirmed that it’s carrying out an early-stage inquiry into Synopsys‘s plans to buy Ansys. The Competition and Markets Authority (CMA) has opened an “invitation to…

Synopsys’s plans to buy Ansys for $35B falls on UK regulatory radar

Here is a look back at the top security research from the annual hacker conferences, Black Hat and Def Con 2024.

The best hacks and security research from Black Hat and Def Con 2024
Image Credits: Lorenzo Franceschi-Bicchierai / TechCrunch

Cross-border payments for businesses in emerging markets remain significantly untapped, despite small to large businesses using banks and legacy fintechs to transact trillions of dollars in transaction volume annually.  A…

Conduit’s cross-border payments expand from LatAm into Africa with $6M round

BT, the U.K.’s former incumbent telecoms carrier, is picking up a major new investor today as telecoms companies look for stronger footing in the rapidly-shifting technology and communications market. Bharti,…

Bharti will become BT’s biggest shareholder after buying a 25%, $4B stake from Altice

X, the social media platform owned by Elon Musk, has been targeted with a series of privacy complaints after it helped itself to the data of users in the European…

Elon Musk’s X targeted with nine privacy complaints after grabbing EU users’ data for training Grok

Kazam, an Indian EV charging solution provider, has raised $8 million to expand its footprint in the country and enter Southeast Asian markets.

India’s Kazam powers up to roll out EV charging in Southeast Asia

Autonomy founder Scott Painter is spinning out a new company called Autonomy Data Services, or ADS, he tells TechCrunch in an exclusive interview. 

Why Scott Painter is selling a beach house to start a new vehicle software company

Heavy equipment manufacturer CNH Industrial has a long history of mergers and acquisitions, at times supervising legendary brands like Ferrari. But five years ago, as agtech was booming, the global…

How CNH’s ‘black belt’ M&A head makes deals

CrowdStrike’s president said he’ll take the trophy back to headquarters as a reminder that “our goal is to protect people, and we got this wrong.”

CrowdStrike accepts award for ‘most epic fail’ after global IT outage

Featured Article

Open source tools to boost your productivity

TechCrunch has pulled together some open-source alternatives to popular productivity apps that might appeal to prosumers, freelancers, or small businesses looking to escape the clutches of Big Tech.

Open source tools to boost your productivity

The valuation of Oyo, once India’s second-most valuable startup at $10 billion, has dipped to $2.4 billion in a new funding round, multiple sources told TechCrunch. The Gurugram-headquartered startup, which…

Oyo valuation crashes over 75% in new funding

Susan Wojcicki, a longtime Googler who spent nearly a decade as the CEO of YouTube, passed away Friday after a two-year battle with non-small cell lung cancer. Wojcicki, who was…

The tech world mourns Susan Wojcicki

While Amazon has continued releasing Echo devices, including an upgraded Spot announced last month, the company has taken its foot off the gas.

As Alexa turns 10, Amazon looks to generative AI

He really said that: When asked about the company’s “Plan B” if mortgage rates don’t fall, Redfin CEO Glenn Kelman responded, “Plan B is to drink our own urine or…

Redfin CEO promises to ‘drink our own urine’ if mortgage rates don’t fall

Turkey appears to have restored access to Meta-owned Instagram, after blocking the app on August 2.  Abdulkadir Uraloglu, the country’s minister of transport and infrastructure, posted today that the ban…

Turkey restores access to Instagram

Elon Musk doesn’t want Tesla to be just an automaker. He wants Tesla to be an AI company, one that’s figured out how to make cars drive themselves.  Crucial to…

Tesla’s Dojo, a timeline

OpenAI co-founder John Schulman has left the company for rival AI startup Anthropic. In addition, OpenAI co-founder and president Greg Brockman is taking an extended leave after nine years at…

OpenAI faces more leadership shake-ups

Featured Article

Maybe Friend wasn’t crazy for spending $1.8M on a domain after all

Avi Schiffmann, the founder and CEO of Friend, told TechCrunch over email that the purchase has already paid for itself.

Maybe Friend wasn’t crazy for spending $1.8M on a domain after all

Featured Article

One man decided to take on Google Maps, 20 years later OpenStreetMap is still going strong

From internet protocols and operating systems, to databases and cloud services, some technology is so omnipresent most people don’t even know it exists. The same can be said about OpenStreetMap, the community-driven platform that serves companies and software developers with geographic data and maps so they can rely a little…

One man decided to take on Google Maps, 20 years later OpenStreetMap is still going strong

This list only includes major penalties issued to tech firms under the GDPR. In recent years, some significant sanctions have also been issued on Big Tech

The 10 largest GDPR fines on Big Tech

The data breach is the latest security issue to beset CSC ServiceWorks over the past year, after multiple researchers found security bugs.

CSC ServiceWorks reveals 2023 data breach affecting thousands of people

Featured Article

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

CrowdStrike tried to go back to business as usual at one of the world’s largest annual cybersecurity conferences, weeks after its massive global IT crash.

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

Tragedy has again struck a famous Silicon Valley family. Former YouTube CEO Susan Wojcicki just passed away, according to social media posts by her husband, Dennis Troper, and by Google…

Former YouTube CEO Susan Wojcicki has passed away at age 56

This is the second cyberattack targeting the school device management service Mobile Guardian this year.

Student raised security concerns in Mobile Guardian MDM weeks before cyberattack

Featured Article

Smartwatches shipments see sharp decline in India

India’s wearable market declined in Q2, primarily because smartwatch are not attracting consumers.

Smartwatches shipments see sharp decline in India

Anysphere, a two-year-old startup that’s developed an AI-powered coding assistant called Cursor, has raised over $60 million in a Series A financing at a $400 million post-money valuation, two sources…

Anysphere, a GitHub Copilot rival, has raised $60M Series A at  $400M valuation from a16z, Thrive, sources say

The internet is full of deepfakes — and most of them are nudes. According to a report from Home Security Heroes, deepfake porn makes up 98% of all deepfake videos…

How to ask Google to remove deepfake porn results from Google Search

Researchers found flaws that could allow anyone to spy on the owners of Ecovacs home robots by hijacking their cameras and microphones.

Ecovacs home robots can be hacked to spy on their owners, researchers say

When digging into the data to determine how large the exodus everyone on Threads is talking about actually is, we oddly came up short.

The X exodus that wasn’t