Locknote: Highlights & Key Takeaways from Black Hat Asia 2025
Black Hat Asia 2025 · Day 1 · Briefings
Overview
The "Locknote" session at Black Hat Asia 2025 offered a unique, behind-the-scenes perspective from the conference's esteemed review board. Moderated by Daniel Cuthbert, stepping in for Jeff Moss, this panel discussion brought together Auka, Ryan, Pandana, and Vitili to reflect on the hundreds of submissions they evaluated, the prevailing trends in cybersecurity research, and critical advice for aspiring speakers. Unlike typical conference talks that delve into specific vulnerabilities or tools, this session served as a crucial meta-analysis of the industry's direction, the evolution of attack and defense methodologies, and the art of communicating impactful research.

Key moments
- 0:00 Introduction to the Locknote session and its purpose
- 1:50 Daniel Cuthbert takes over, invites review board
- 2:06 Resurgence of old school hacking techniques and trends
- 2:50 Hardware supply chain security: Immaturity and challenges
- 4:30 AI trends and supply chain software (S-BOM) risks
- 6:00 Human creativity and deep technical research beyond AI
- 8:00 E-commerce fraud: A broad perspective on cybercrime
Locknote: Highlights & Key Takeaways from Black Hat Asia 2025
Speakers: Auka, Ryan, Pandana, Vitili (Black Hat Asia Review Board Members), Daniel Cuthbert (Moderator)
Conference: Black Hat Asia
YouTube: https://www.youtube.com/watch?v=Y6_WXVBlMsQ
Overview
The "Locknote" session at Black Hat Asia 2025 offered a unique, behind-the-scenes perspective from the conference's esteemed review board. Moderated by Daniel Cuthbert, stepping in for Jeff Moss, this panel discussion brought together Auka, Ryan, Pandana, and Vitili to reflect on the hundreds of submissions they evaluated, the prevailing trends in cybersecurity research, and critical advice for aspiring speakers. Unlike typical conference talks that delve into specific vulnerabilities or tools, this session served as a crucial meta-analysis of the industry's direction, the evolution of attack and defense methodologies, and the art of communicating impactful research.
This Locknote provided invaluable insights for both seasoned security professionals and emerging researchers. By dissecting the common threads, standout presentations, and frequent pitfalls in submissions, the review board illuminated the current state of cybersecurity innovation. They highlighted areas ripe for further exploration, underscored the enduring relevance of foundational technical skills, and emphasized the necessity of clear, compelling storytelling in disseminating knowledge. The discussion served as a vital compass, guiding the community towards research that is not only technically profound but also effectively communicated and relevant to the ever-changing threat landscape.
The significance of this session extends beyond a mere recap; it’s a strategic briefing on the future of cybersecurity discourse. The board's collective wisdom, drawn from reviewing a vast array of global research, offered a candid assessment of what truly resonates in the security community. Their observations on the resurgence of "old school" hacking, the pervasive influence of AI, and the persistent challenges in supply chain security underscore the complex, multi-faceted nature of modern cyber threats. Furthermore, their practical advice on crafting impactful submissions and leveraging resources like the Speaker Coaching Program provides a direct pathway for researchers to contribute meaningfully to the collective security knowledge base.
Background
▶ Watch: Introduction to the Locknote session and its purpose (0:00)
The Black Hat Asia Locknote functions as a critical concluding session, offering an internal perspective from the individuals responsible for curating the conference's content. The review board members — Auka, Ryan, Pandana, and Vitili — are experts in various domains, tasked with sifting through hundreds of submissions to select the most relevant, innovative, and impactful research. This process is inherently challenging due to the sheer volume of submissions, the diversity of topics, and the need to identify truly groundbreaking work amidst a sea of incremental or poorly articulated research.
The problem this session implicitly addresses is the gap between cutting-edge security research and its effective presentation. Many researchers possess profound technical knowledge but struggle with conveying their findings in a compelling, structured, and accessible manner. This leads to valuable research being overlooked. The Locknote aims to demystify the submission and selection process, providing direct feedback on what the review board values and what common mistakes lead to rejection. It also provides a unique platform for these experts to collectively identify broader industry trends that might not be immediately apparent from individual talks. By sharing their insights, the board empowers future speakers to refine their research and presentation strategies, ensuring that Black Hat continues to showcase the highest caliber of cybersecurity innovation.
Key Findings
▶ Watch: Resurgence of old school hacking techniques and trends (2:06)
The review board's discussion revealed several key trends and critical insights into the current state of cybersecurity research and conference submissions:
- Resurgence of Old School Hacking Techniques: Daniel Cuthbert noted a "resurgence of old school hacking techniques" across Black Hat conferences. Vitili echoed this, appreciating "deeply technical talk[s] focusing on like Linux kernel exploitation" that require manual effort and creativity over automation. Auka also observed how techniques like Return-Oriented Programming (ROP), once considered sophisticated, are now "easy technique for like all of like CDF players," highlighting the rapid evolution of attacker capabilities.
- Pervasive Influence of AI: Artificial Intelligence (AI) was undeniably "the talk of the town," with numerous submissions covering AI for malware, AI for quantum computing, and AI for automating Software Bill of Materials (SBOMs) and Vulnerability Exploitability eXchange (VEX). However, the board cautioned against superficial AI-centric talks, with Pandana urging submitters not to "use AI to write that talk." Ryan emphasized that the most interesting submissions were "AI plus something," focusing on practical applications like extracting actionable intelligence or identifying vulnerabilities in AI models and inference platforms. Vitili noted that while AI speeds up development and reversing, "creativity I think it's still up to us to come up with new genius ideas that AI future AI can learn from."
- Immature Hardware Supply Chain Security: Auka highlighted the "keynote talk today's keynote talk about hardware supply chain security" as particularly impactful, expressing surprise at how "immature" this area remains. Both Auka and Daniel discussed the difficulty in tracking hardware-related crimes, often conducted in regions like Shenzhen, where OpSec (Operational Security) is high, and information is scarce. This points to a significant blind spot in current threat intelligence.
- Comprehensive E-commerce Fraud Ecosystems: Ryan found the TikTok session on e-commerce fraud particularly insightful. He described how attackers orchestrate complex fraud schemes involving "fraudulent seller accounts," "army of bots" for fake reviews, and "underground services" for logistics and tracking numbers. This demonstrated a holistic view of cybercrime beyond mere technical exploitation.
- Importance of Software Supply Chain Security: Pandana stressed that SBOMs and VEX remain a "big concern" for software supply chain risks, citing breaches like Log4Shell. She praised research focused on automating these processes, indicating a shift towards practical solutions for a persistent problem.
- Critiques and Advice for Submissions:
- Storytelling: Pandana emphasized the need for researchers to "tell the story" of their work, moving beyond just dumping data.
- Uniqueness: Auka advised submitters to clearly articulate "what's unique about your research" and "why you think it's new."
- Supplementary Material: Ryan highly valued submissions with "supplementary material like... a Google Drive link to the raw data," "screenshots, video recordings" to validate findings.
- Structure and Clarity: Vitili warned against "super short" or "overly complicated" submissions, advocating for a "balanced and structured and very ordered" outline.
- Community Sharing: Vitili encouraged researchers to "give something away to users to other people to to use to leverage," beyond just showing lab results.
- Continuing Research: The board confirmed that submitting updated iterations of previously presented research is encouraged, especially if it includes "new discoveries, new samples, new techniques."
Technical Deep Dive
▶ Watch: Hardware supply chain security: Immaturity and challenges (2:50)
While the Locknote itself was a meta-discussion, it provided a rich tapestry of technical areas that captivated the review board and shaped Black Hat Asia 2025. The insights offered by the speakers point to specific technical challenges and research directions that are currently at the forefront of the cybersecurity landscape.
Hardware Supply Chain Security: An Immature Frontier
A significant technical area highlighted was the immaturity of hardware supply chain security. Auka Nakajima, specializing in exploit development and reverse engineering, expressed surprise at the lack of robust security in this domain. Daniel Cuthbert elaborated on the inherent difficulties, noting that "people doing crime in hardware don't talk about it," leading to a significant lack of threat intelligence compared to software exploits. Unlike software malware, which is quickly analyzed and reported, hardware compromises are often deeply hidden, requiring sophisticated OpSec from attackers. The panel suggested that incorporating zero-trust systems into hardware supply chains and developing specialized "red teams" for hardware could be crucial. Technically, this involves understanding the entire lifecycle of hardware, from design and manufacturing (often in geographically distributed and less transparent environments like Shenzhen, as Pandana pointed out) to deployment, and identifying points where malicious modifications or insertions could occur. This could involve firmware tampering, chip-level backdoors, or counterfeit components, all of which require specialized reverse engineering and hardware-level analysis techniques to detect.
AI's Double-Edged Sword: Applications and Vulnerabilities
Artificial Intelligence (AI) emerged as a dominant theme, not just as a tool but also as a new attack surface. Pandana and Vitili noted a plethora of AI-related talks, ranging from AI for malware analysis and AI for quantum computing security to the automation of Software Bill of Materials (SBOMs) and Vulnerability Exploitability eXchange (VEX). The technical deep dive here revolves around two main aspects:
- AI as an Enabler for Security: Researchers are leveraging AI to accelerate tasks like malware detection, vulnerability discovery, and threat intelligence processing. For instance, AI for quantum computing security likely involves using AI to design quantum-safe cryptographic algorithms or to analyze the security of quantum systems. Automating SBOMs and VEX, as discussed, is a crucial technical step towards proactive software supply chain risk management. This involves AI parsing codebases, identifying dependencies, and mapping known vulnerabilities (CVEs) to components, then generating standardized machine-readable documents.
- Vulnerabilities in AI Systems: Ryan emphasized the importance of "AI plus something," specifically pointing to research on "the platforms that are involved in producing the AI models, AI inference, what are the vulnerabilities in there?" This encompasses a range of technical concerns: data poisoning attacks (manipulating training data to degrade model performance or introduce backdoors), model evasion attacks (crafting inputs that cause a model to make incorrect predictions), model inversion attacks (reconstructing sensitive training data from model outputs), and adversarial attacks against the underlying machine learning (ML) infrastructure. Understanding and securing the entire AI pipeline – from data acquisition and model training to deployment and inference – is a burgeoning field.
E-commerce Fraud: A Systemic Technical Challenge
Ryan Flores highlighted a talk by TikTok on e-commerce fraud, which presented a comprehensive technical view of sophisticated fraud operations. This isn't about traditional software exploits but rather the exploitation of system logic and human behavior on a massive scale. The technical aspects include:
- Bot Networks: Attackers deploy "an army of bots" to create and prop up "fraudulent seller accounts" and generate fake positive reviews. This requires technical expertise in botnet management, anti-anti-bot techniques, and potentially exploiting platform APIs.
- Underground Services: The use of "underground services that would then... for the careers on the tracking numbers" indicates a complex, technically coordinated effort involving logistics manipulation. This could involve generating fake tracking numbers, diverting packages, or exploiting vulnerabilities in shipping carrier systems.
- Data Analysis: Companies like TikTok need advanced data analytics and machine learning to detect these patterns of fraud across vast datasets of user activity, seller behavior, and transaction data.
The Enduring Relevance of Deep Technical Exploitation
Amidst the AI hype, Vitili, a malware analysis expert, stressed the importance of "old school researches... when you don't really cut corners... and you have to do things manually sometimes and be smart and create algorithms." He specifically mentioned "deeply technical talk focusing on like Linux kernel exploitation." This area demands a profound understanding of operating system internals, memory management, processor architectures, and low-level programming. Techniques often involve:
- Memory Corruption Vulnerabilities: Exploiting bugs like buffer overflows, use-after-frees, or race conditions in kernel code.
- Privilege Escalation: Gaining higher privileges (e.g., root) by manipulating kernel structures or exploiting flaws in system calls.
- ROP (Return-Oriented Programming): Crafting exploit chains using existing code snippets (gadgets) to bypass Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR). Auka's observation that ROP is now considered "easy" for CTF players underscores how quickly advanced techniques become commonplace, demanding continuous innovation in exploit development.
Software Supply Chain Automation: SBOMs and VEX
Pandana's enthusiasm for SBOMs and VEX highlighted a critical technical development in managing software supply chain risks. SBOMs provide a complete, nested inventory of all software components used in an application, including open-source libraries, commercial components, and their dependencies. VEX documents the exploitability status of known vulnerabilities within specific software products, helping organizations prioritize patching efforts. Automating these processes, as presented in one talk, involves:
- Static and Dynamic Analysis: Tools to scan source code, binaries, and running applications to identify components and dependencies.
- Vulnerability Mapping: Integrating with vulnerability databases (like NVD) to map CVEs to identified components.
- Contextual Analysis: Using intelligent algorithms to determine if a vulnerability in a component is actually exploitable in the specific context of the application's use. This goes beyond simple presence detection to assess actual risk.
These diverse technical areas, from hardware to AI and low-level exploitation, illustrate the multifaceted nature of modern cybersecurity and the constant need for deep, creative research.
Demo / Proof of Concept
▶ Watch: Human creativity and deep technical research beyond AI (6:00)
This Locknote session, being a panel discussion, did not feature a live demonstration or proof of concept (POC) of a specific vulnerability or tool. However, the review board members extensively discussed the critical role of demos and supplementary material in the submission process. Ryan, for instance, explicitly stated that it "makes me really happy if a submission has supplementary material like if a submission could contain a Google Drive link to the raw data that they had, screenshots, video recordings to to show what they what they really found." This highlights the board's expectation for concrete evidence that validates research findings.
Vitili further emphasized the importance of sharing tangible outputs with the community, encouraging future submitters "not only to show how you did this but also to give something away to users to other people to to use to leverage so that it's not just like this is how we did this in the lab." This implies a desire for open-source tools, methodologies, or datasets that allow the community to replicate, verify, and build upon the presented research. While no demo was presented, the discussion underscored that a strong, verifiable demonstration, either live or through supplementary evidence, is a crucial component of a successful and impactful Black Hat talk submission.
Defensive Implications
▶ Watch: E-commerce fraud: A broad perspective on cybercrime (8:00)
The trends and insights discussed by the Black Hat Asia review board carry significant defensive implications for organizations and security professionals:
- Strengthen Hardware Supply Chain Security: The acknowledged immaturity of hardware supply chain security demands immediate attention. Defenders should push for greater transparency from hardware vendors, implement stricter procurement policies, and consider hardware-level attestation mechanisms. As Auka suggested, adopting a zero-trust approach to hardware components, even from trusted suppliers, is crucial. This means verifying the integrity of firmware, chips, and components at every stage, potentially through advanced hardware reverse engineering or independent validation. Organizations should also be aware that traditional threat intelligence sources may not cover hardware-specific attacks, necessitating a broader intelligence gathering strategy.
- Prudent and Informed AI Adoption: While AI offers powerful defensive capabilities, its pervasive use also introduces new attack surfaces. Defenders must:
- Secure the AI Pipeline: Understand and mitigate vulnerabilities in their own AI systems, including data poisoning, model evasion, and model inversion attacks. This requires securing training data, validating model integrity, and implementing robust access controls for AI infrastructure.
- Defend Against AI-Powered Attacks: Recognize that attackers are leveraging AI for malware generation, automated vulnerability discovery, and sophisticated fraud. Defensive AI systems must be resilient to these advanced tactics.
- Prioritize "AI + X" Solutions: Focus on AI applications that provide tangible, actionable security improvements, such as AI for threat intelligence correlation, anomaly detection, or automating critical security tasks like SBOM and VEX generation, rather than superficial AI integrations.
- Embrace Software Supply Chain Automation (SBOMs & VEX): The emphasis on SBOMs and VEX highlights their critical role in managing software supply chain risk. Defenders should actively implement and automate the generation and consumption of SBOMs to gain comprehensive visibility into their software components. Integrating VEX data will enable organizations to accurately assess the exploitability of known CVEs within their specific deployments, allowing for prioritized patching and more efficient resource allocation. This moves beyond reactive vulnerability management to a proactive risk assessment framework.
- Maintain Foundational Technical Skills: The resurgence of "old school" hacking techniques and the appreciation for deep technical research (e.g., Linux kernel exploitation) underscore that fundamental vulnerabilities remain a significant threat. Defenders must ensure their teams retain and continuously develop skills in:
- Low-Level Exploitation Analysis: Understanding how memory corruption vulnerabilities, privilege escalation techniques, and ROP chains work is crucial for effective incident response and preventative measures.
- Reverse Engineering: The ability to analyze malware, identify root causes of exploits, and understand complex system interactions without relying solely on automated tools is indispensable.
- Creative Problem Solving: As Vitili noted, human creativity is still paramount for discovering novel attack vectors and developing truly innovative defenses that AI cannot yet replicate.
- Develop Comprehensive Fraud Detection Systems: Ryan's insights into e-commerce fraud highlight the need for multi-layered defensive strategies that go beyond technical exploits. Organizations, particularly those with online platforms, must implement sophisticated fraud detection systems that:
- Monitor User and Seller Behavior: Detect anomalous patterns in account creation, review generation, and transaction history.
- Combat Bot Activity: Employ advanced bot detection and mitigation techniques to prevent automated account manipulation and fake engagement.
- Integrate with External Data: Understand and monitor underground markets for services related to their platform (e.g., fake tracking numbers, stolen credentials) to preemptively identify emerging fraud schemes.
By integrating these defensive implications, organizations can build more resilient security postures that are adaptable to both established threats and the rapidly evolving landscape of cyber attacks.
Key Takeaways
- Black Hat Asia 2025 revealed a compelling duality in cybersecurity research, showcasing both a resurgence of "old school" deep technical exploitation (e.g., Linux kernel vulnerabilities) and the pervasive, yet often superficial, influence of Artificial Intelligence (AI) across various domains.
- Supply chain security remains a critical concern, encompassing both the immature and opaque hardware supply chain and the ongoing challenges in software supply chain risk management, with a growing emphasis on automating SBOMs and VEX for better visibility and exploitability assessment.
- Successful AI-centric research moves beyond buzzwords, focusing on "AI plus something" – demonstrating actionable intelligence, practical applications (e.g., AI for quantum computing, malware analysis), or addressing vulnerabilities within AI models and inference platforms themselves.
- Effective Black Hat submissions require a clear, compelling narrative, highlighting the unique aspects of the research, providing robust supplementary material (raw data, screenshots, videos), and ideally, sharing tools or products to benefit the wider community.
- The industry's rapid evolution means that past "sophisticated" techniques (like ROP) quickly become commonplace, underscoring the continuous need for human creativity, manual effort, and foundational technical skills to discover and defend against novel threats.
- Resources like the Black Hat Speaker Coaching Program are invaluable for researchers, particularly first-time speakers, in honing their storytelling abilities and presentation skills to effectively communicate complex technical findings to a diverse audience.
About the Speaker(s)
The Locknote panel featured several distinguished members of the Black Hat Asia Review Board, each bringing their unique expertise to the discussion, along with an experienced moderator.
Daniel Cuthbert (Moderator): Stepping in for Jeff Moss, Daniel Cuthbert moderated the session, guiding the discussion and offering his own insights as a veteran in the security industry. His questions often steered the conversation towards forward-looking trends and practical advice for researchers.
Auka Nakajima (Black Hat Asia Review Board Member): Auka primarily reviews submissions for the exploit development track and reverse engineering track. She expressed particular interest in hardware supply chain security, highlighting its current immaturity. Her perspective emphasized the importance of unique research findings in submissions.
Pandana (Black Hat Asia Review Board Member): Pandana (likely Vandana Sharma, a known Black Hat contributor) played a key role in reviewing the AI track, which had the most submissions for the conference. She is also deeply invested in software supply chain security, particularly SBOMs (Software Bill of Materials) and VEX (Vulnerability Exploitability eXchange), advocating for their automation. She stressed the importance of storytelling in research submissions.
Vitili (Black Hat Asia Review Board Member): Vitili (likely Vitaly Kamluk, a prominent figure in malware analysis) has focused on malware analysis for decades. He appreciates deeply technical, manual research that requires creativity over pure automation. Vitili is also a dedicated volunteer and coach in the Speaker Coaching Program, helping new speakers overcome stage fright and structure their talks effectively. He shared a memorable (and physically dramatic) past presentation experience.
Ryan (Black Hat Asia Review Board Member): Ryan (likely Ryan Flores, often associated with incident response and operations) brings expertise in malware, breaches, and security operations. He found the TikTok talk on e-commerce fraud particularly insightful due to its comprehensive view of cybercrime ecosystems. Ryan emphasized the value of supplementary material in research submissions for validation.
Together, these individuals represent the diverse expertise and critical judgment that shapes the Black Hat conference content, offering a collective vision for the future of cybersecurity research.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This Locknote delivers rare, invaluable insider signal directly from the Black Hat Asia Review Board. It functions as a critical strategic briefing, laying bare the prevailing trends in cybersecurity research, the board's expectations for submissions, and the crucial areas demanding deeper technical exploration. For any researcher, CISO, or security professional aiming to understand where the cutting edge is, what truly resonates, and how to contribute meaningfully, this session is a non-negotiable watch, offering a candid assessment that goes far beyond surface-level platitudes.
Heather Calloway (CISO) — STRONG ACCEPT
This Locknote session offers a vital strategic overview for any CISO or security leader, moving beyond individual technical findings to provide a critical meta-analysis of the cybersecurity landscape. By synthesizing trends from hundreds of research submissions, the Black Hat review board illuminates key areas of institutional risk—from the immature state of hardware supply chain security to the nuanced challenges of AI adoption and the enduring importance of foundational technical skills. It delivers actionable insights for refining security programs and informs board-level discussions on real-world business exposure and accountability.