An Azure Sphere Security Breakdown | Lilith Wyatt | Nullcon Conference March 2021
Title: An Azure Sphere Security Breakdown by Lilith Wyatt | Nullcon International Security Conference March 2021 Abstract: ----------------- The Azure Sphere IoT platform is Microsoft's ambitious answer to IoT Security, and includes a number of lightweight security features inside its custom SoC and patched Linux kernel. Previously simple tasks like connecting to an arbitrary IP or running non-rop shellcode have been locked down and now require their own distinct vulnerabilities to perform. On May 15th, 2020, Microsoft kicked off the (Azure Sphere Security Research Challenge), a three month bug hunt on the Azure Sphere platform. Among the teams and individuals selected, we (Cisco Talos) conducted a three-month sprint of research into the platform and submitted 16 vulnerabilities of various severity, including a privilege escalation chain to acquire Azure Sphere Capabilities (the most valuable Linux normal world permissions in the Azure Sphere context) by installing an app. Speaker Bio: ------------------------ Lilith Wyatt is a Senior Research Engineer with the Cisco Talos Vulndev Team, and is tasked with finding 0-day vulnerabilities in third party products. Her focus is usually in IoT devices and networking, and has found vulnerabilities in targets such as Vmware, Azure Sphere, and the Google Nestcam IQ. Before Talos, Lilith assembled burgers at McDonald's, trained to be a boxer while unemployed, and crafted pizzas for minimum wage. #azure #IoT #Microsoft #Infosec --------------------------------------------------------- Follow nullcon on Facebook: / nullcon Twitter: / nullcon LinkedIn: / nullcon Website: https://nullcon.net

Attacking AI - Jason Haddix - NDC Security 2026

Arbitrary code execution on RISC-V using fault injection | Praveen Vadnala & Nils Wiersma | Nullcon

CockroachDB: Architecture of a Geo-Distributed SQL Database | Cockroach Labs

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

The French Do Not Care About Work

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

Complete CYBERSECURITY Fundamentals: Everything You Need to Know

Something is jamming GPS over Europe. Here's what we found

Inside the Mind of Anthropic CEO Dario Amodei | The Circuit | Extended Interview

She’s 12. She Sings Aretha Franklin… Until Simon TELLS Her to Do It Acapella! 😳

'Listen Like You Might Be Wrong': Harvard Student Goes Viral For Stunning Speech On Trump Amid Feud

Golden Retriever Meets Completely Broken Rescue for the First Time

Secret Agent: How To Detect A Lie Instantly! - Evy Poumpouras

Spine Surgeon Drowns for 30 Minutes —Comes Back With a List

Germany’s army chief on AI, drones and the future of the tank | The Economist

40Hz Binaural Gamma Waves - Ultra Deep Concentration

What to teach when AI writes the code | Rainer Stropek | TEDxLinz

What Nobody Tells You About Being a Quant

Rory Sutherland's 2026 Predictions

