AMA: Novee researcher who finds pre-auth RCE in enterprise Java, no login required. Black Hat & DEF CON 2026 speaker.

Join Novee vulnerability researcher Lidor Ben Shitrit on Monday, Aug 17 at 12 PM PT.

"Pre-auth RCE" means an attacker who has never logged in, has no account, and clicks nothing can still end up running code on the server.

The targets are enterprise Java platforms, the software quietly running inside large organizations, the kind that has been audited for years and is assumed to be safe.

Lidor finds the chains that get through anyway, and he presented this work at both Black Hat USA and DEF CON this year.

submitted by /u/_clickfix_
[link] [comments]

from hacking: security in practice https://ift.tt/yFo7rjG

Comments