BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Beyond Normalization: The Expanding Unicode Attack S
 urface\n   Tags: Bug Bounty Village | Creator Talk/Panel\n   When: Friday\
 , Aug 7\, 17:00 - 17:59 PDT\n   Where: LVCCW Level 2 W206-207 (Bug Bounty 
 Village) - [1]Map\n\n   Description:\n\n   Unicode exploitation does not e
 nd with normalization. Modern web\n   applications process input through l
 ayered pipelines: URL decoding\,\n   UTF-8 validation\, WAF transformation
 s\, framework parsing\, surrogate\n   handling\, database collation\, HTML
  entity decoding\, and increasingly\,\n   LLM preprocessing. Each layer im
 plements subtly different assumptions\n   about character validity and equ
 ivalence. When those assumptions\n   diverge\, security boundaries fail. B
 uilding off our popular Black Hat\n   USA 2025 Unicode Briefing\, we have 
 continued our research into the\n   complex world of Unicode processing. T
 his research exposes a new class\n   of Unicode pipeline vulnerabilities t
 hat extend far beyond canonical\n   normalization issues. We demonstrate h
 ow attackers can weaponize\n   illegal UTF-8 sequences to break RE2 valida
 tion\, exploit\n   surrogate-to-replacement conversions (U+FFFD) to alter 
 semantics\,\n   abuse hex overflows to generate filtered characters\, and 
 bypass Host/Secure\n   cookie protections via Unicode whitespace desynchro
 nization. We show\n   how MySQL zero-weight collation rules enable filter 
 bypasses even\n   after normalization\, how WAF/browser canonicalization m
 ismatches lead\n   to XSS and RCE (including analysis of CVE-2025-55182)\,
  and how\n   invisible Unicode variation selectors can jailbreak LLMs or c
 onceal\n   supply chain malware. Using real-world telemetry\, live demonst
 rations\,\n   tooling updates and hands-on lab environments\, this Briefin
 g reframes\n   Unicode as a distributed parsing vulnerability class\, not 
 a character\n   encoding footnote. Unicode is no longer just a normalizati
 on problem.\n   It is an architectural attack surface.\n\n   Speakers:Ryan
  "ryancbarnett" Barnett\,Isabella "4ng3lhacker" Barnett\n\n   SpeakerBio: 
  Ryan "ryancbarnett" Barnett\, Senior Threat Research\n   Manager\, Akamai
 \n\n   Ryan Barnett is a Senior Threat Research Manager leading the Akamai
 \n   App and API Protector (WAF) product. He also acts as s triager on\n  
  Akamai's and customers' bug bounty programs. In addition to his\n   prima
 ry work at Akamai\, he is also a former Faculty Member for the\n   SANS In
 stitute\, a WASC Board Member and OWASP Project Leader for:\n   ModSecurit
 y Core Rule Set (CRS) Web Hacking Incident Database (WHID).\n   Mr. Barnet
 t has also authored two web security books: Preventing Web\n   Attacks wit
 h Apache (Pearson) and The Web Application Defender's\n   Cookbook: Battli
 ng Hackers and Defending Users (Wiley).\n\n   SpeakerBio:  Isabella "4ng3l
 hacker" Barnett\n\n   Isabella Barnett is a Software Engineering Intern at
  Akamai and a\n   junior at George Mason Honor's College studying Cyber Se
 curity\n   Engineering.\n\n   '\n\n   1. #LVCCW_Level2_West\n\n\n
DTEND:20260808T005900Z
DTSTART:20260808Z
LOCATION:Bug Bounty Village - LVCCW Level 2 W206-207 (Bug Bounty Village)
SUMMARY:Beyond Normalization: The Expanding Unicode Attack Surface
END:VEVENT
END:VCALENDAR
