BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Reversing a Recall: From â€˜Noise Triggeredâ€™ to RC
 E\n   Tags: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ›  | Exploit ðŸª²\n
    When: Sunday\, Aug 9\, 10:30 - 11:30 PDT\n   Where: LVCCW Level 1 Hall 
 3 904 (Main Track 4) and DCTV-4 - [1]Map\n\n   Description:\n\n   Heavy-du
 ty trucks move the majority of freight in North America\,\n   making them 
 a critical component of our infrastructure. When a major\n   supplier issu
 ed a recall to address a seemingly harmless noise issue\,\n   the explanat
 ion didn't quite add up.\n\n   This talk follows the reverse engineering j
 ourney that began with a\n   simple question and led to a much larger disc
 overy. By tearing apart\n   firmware\, analyzing the update protocols\, an
 d tracing ECU behavior\, we\n   uncovered evidence that the recall was not
  just remediating noise\n   triggered flaws. Hidden within the recall's fi
 rmware update was a\n   security mitigation addressing undisclosed vulnera
 bilities affecting a\n   critical vehicle system.\n\n   Attendees will see
  how modern tractor ECUs can be analyzed using\n   professional and public
  tools and techniques (IDA Pro\, idapython\,\n   qbindiff)\, the challenge
 s of working with the safety-critical\n   microcontrollers in heavy-vehicl
 es (S12XE)\, and the evidence that\n   revealed security impacts of the pa
 tch. Along the way\, we'll discuss\n   the growing cybersecurity risks fac
 ing commercial vehicles.\n\n   Whether you're interested in automotive hac
 king\, embedded systems\,\n   reverse engineering\, or critical infrastruc
 ture security\, this session\n   offers a look inside the cybersecurity re
 ality of the machines that\n   keep the supply chain moving.\n\n     1. Al
 eph One. (1996). Smashing The Stack For Fun And Profit. Phrack\n       Mag
 azine\, 7(49). http://phrack.org/issues/49/14.html\n\n     2. Intellon Cor
 poration. (1997). SSC P485 PL Transceiver IC Data\n       Sheet.\n\n     3
 . Hunter\, J. D. (2007). Matplotlib: A 2D graphics environment.\n       Co
 mputing in science & engineering\, 9(3)\, 90-95.\n\n     4. NXP Semiconduc
 tors. (2010). HiWave Debugger. Part of CodeWarrior\n       Development Stu
 dio.\n\n     5. Krzywinski\, M.\, Birol\, I.\, Jones\, S. J.\, & Marra\, M
 . A. (2011).\n       Hive plotsâ€”rational approach to visualizing network
 s. Briefings\n       in bioinformatics\, 13(5)\, 627-644.\n\n     6. SAE I
 nternational. (2013). J1587: Electronic Data Interchange\n       Between M
 icrocomputer Systems in Heavy-Duty Vehicle Applications.\n       Warrendal
 e\, PA.\n\n     7. Miller\, C.\, & Valasek\, C. (2014). Adventures in Auto
 motive\n       Networks and Control Units. IOActive.\n       https://www.i
 oactive.com/wp-content/uploads/pdfs/IOActive_Adventures_in_Automotive_Netw
 orks_and_Control_Units.pdf\n\n     8. Behere\, S.\, Zhang\, X.\, Izosimov\
 , V.\, & TÃ¶rngren\, M. (2016). A\n       Functional Brake Architecture fo
 r Autonomous Heavy Commercial\n       Vehicles.\n       https://legacy.sae
 .org/publications/technical-papers/content/2016-01-0134/\n\n     9. SAE In
 ternational. (2016). J1708: Serial Data Communications\n       Between Mic
 rocomputer Systems in Heavy-Duty Vehicle Applications.\n       Warrendale\
 , PA.\n\n     10. TruckHacking organization. (2016). py-hv-networks.\n    
    https://github.com/TruckHacking/py-hv-networks\n\n     11. SAE Internat
 ional. (2018). J1939: Serial Control and\n       Communications Heavy Duty
  Vehicle Network. Warrendale\, PA.\n\n     12. International Organization 
 for Standardization. (2018). ISO\n       26262: Road vehicles -- Functiona
 l safety. Geneva\, Switzerland.\n\n     13. International Organization for
  Standardization. (2018). ISO/IEC\n       29147: Information technology --
  Security techniques --\n       Vulnerability disclosure. Geneva\, Switzer
 land.\n\n     14. dfieschko. (2019). RP1210. https://github.com/dfieschko/
 RP1210\n\n     15. MITRE Corporation. (2020). CVE-2020-14514.\n       http
 s://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14514\n\n     16. Inte
 rnational Organization for Standardization. (2020). ISO\n       14229: Roa
 d vehicles -- Unified diagnostic services (UDS). Geneva\,\n       Switzerl
 and.\n\n     17. Gardiner\, B. (2022). Disclosure of confirmed remote writ
 e to\n       J2497 aka PLC4TRUCKS. NMFTA\, Alexandria\, VA\, Letter\, Marc
 h.\n\n     18. National Motor Freight Traffic Association. (2022). Actiona
 ble\n       Mitigations Options v9.\n       https://nmfta.org/wp-content/m
 edia/2022/11/Actionable_Mitigations_Options_v9_DIST.pdf\n\n     19. MITRE 
 Corporation. (2022). CVE-2022-26131.\n       https://cve.mitre.org/cgi-bin
 /cvename.cgi?name=CVE-2022-26131\n\n     20. Pulse Security. (2022). Rever
 sing the Ducati 696 ECU Part 2.\n       https://pulsesecurity.co.nz/articl
 es/ducati-696-part2\n\n     21. Gardiner\, B. (2022). Mitigating PLC4TRUCK
 S Remote Write.\n       Proceedings of the 9th escar USA Conference.\n    
    https://escar.info/downloads\n\n     22. Cybersecurity and Infrastructu
 re Security Agency. (2023).\n       Shifting the Balance of Cybersecurity 
 Risk: Principles and\n       Approaches for Security-by-Design and -Defaul
 t.\n       https://www.cisa.gov/resources-tools/resources/shifting-balance
 -cybersecurity-risk-principles-and-approaches-security-design-and-default\
 n\n     23. Bendix Commercial Vehicle Systems LLC. (2024). 24E086 Chronolo
 gy.\n       https://static.nhtsa.gov/odi/rcl/2024/RMISC-24E086-5355.pdf\n\
 n     24. National Highway Traffic Safety Administration. (2024).\n       
 Technical Service Bulletin 10194446.\n       https://dot.report/bulletins/
 10194446\n\n     25. National Highway Traffic Safety Administration. (2024
 ).\n       Technical Service Bulletin 10176745.\n       https://dot.report
 /bulletins/10176745\n\n     26. National Highway Traffic Safety Administra
 tion. (2024).\n       Technical Service Bulletin 10222229.\n       https:/
 /dot.report/bulletins/10222229\n\n     27. PACCAR Incorporated. (2024). Sa
 fety Recall Report 24V-915.\n       https://static.nhtsa.gov/odi/rcl/2024/
 RCLRPT-24V915-6438.PDF\n\n     28. Navistar\, Inc. (2024). Safety Recall R
 eport 24V-818.\n       https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V818
 -4283.PDF\n\n     29. Volvo Trucks North America. (2024). Safety Recall Re
 port 24V-790.\n       https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V790-
 3386.PDF\n\n     30. Bendix Commercial Vehicle Systems LLC. (2024). Techni
 cal\n       Bulletin TCH-27-007.\n       https://www.bendix.com/media/serv
 ices-and-support/product-action-center-pdfs/tch_27_007_en_000.pdf\n\n     
 31. Bendix Commercial Vehicle Systems LLC. (2024). Technical\n       Bulle
 tin TCH-27-006.\n       https://www.bendix.com/media/services-and-support/
 product-action-center-pdfs/tch_27_006_en_000.pdf\n\n     32. Bendix Commer
 cial Vehicle Systems LLC. (2024). Technical\n       Bulletin TCH-27-008.\n
        https://www.bendix.com/media/services-and-support/product-action-ce
 nter-pdfs/tch-27-008_en_000.pdf\n\n     33. ZF Friedrichshafen AG. (2024).
  mBSP XBS Factsheet.\n       https://www.zf.com/public/org/ZF_CVS_mBSP_XBS
 _Factsheet_EN_296135.pdf\n\n     34. Technology & Maintenance Council. (20
 24). Position Paper 2024-3:\n       Next Generation Tractor-Trailer Techni
 cal Needs. American Trucking\n       Associations.\n       https://tmc.tru
 cking.org/sites/default/files/TMC_PP-2024_3_NEXTGEN_TRACTOR_TRAILER_TECHNI
 CAL_NEEDS%20.pdf\n\n     35. Gardiner\, B.\, Maag\, J.\, & Tindell\, K. (2
 024). Security\n       Requirements for Vehicle Security Gateways. SAE Int
 ernational.\n       https://www.sae.org/papers/security-requirements-vehic
 le-security-gateways-2024-01-2806\n\n     36. Vehicle Cybersecurity Workin
 g Group (VCRWG)\, National Motor\n       Freight Traffic Association. (202
 4). NMFTA Vehicle Cybersecurity\n       Requirements.\n       https://gith
 ub.com/nmfta-repo/nmfta-vehicle_cybersecurity_requirements\n\n     37. pyt
 hon-can Developers. (2024). python-can.\n       https://python-can.readthe
 docs.io/\n\n     38. Cohen\, R.\, David\, R.\, Mori\, R.\, Yger\, F.\, & R
 ossi\, F. (2024).\n       Improving binary diffing through similarity and 
 matching\n       intricacies. Proc. of the 6th Conference on Artificial\n 
       Intelligence for Defense.\n\n     39. Quarkslab. (2024). Quokka. htt
 ps://github.com/quarkslab/quokka\n\n     40. Bendix Commercial Vehicle Sys
 tems LLC. (2025). Safety Recall\n       Report 25E-073.\n       https://st
 atic.nhtsa.gov/odi/rcl/2025/RCLRPT-25E073-3346.pdf\n\n     41. National Mo
 tor Freight Traffic Association. (2025). Bendix EC80\n       Recall: Safet
 y and Security Implications.\n       https://nmfta.org/bendix-ec80-recall-
 safety-and-security-implications/\n\n     42. Cybersecurity and Infrastruc
 ture Security Agency. (2025). ICS\n       Advisory (ICSA-25-021-03) Bendix
  EC-80.\n       https://www.cisa.gov/news-events/ics-advisories/icsa-25-02
 1-03\n\n     43. National Security Agency. (2025). Ghidra.\n       https:/
 /ghidra-sre.org/\n\n     44. Hiveplotlib Developers. (2025). hiveplotlib.\
 n       https://github.com/hiveplotlib/hiveplotlib\n\n     45. Land Line M
 edia. (2025). Defective Bendix ECUs have prompted\n       recall of nearly
  half a million trucks with latest Paccar recall.\n       https://landline
 .media/defective-bendix-ecus-have-prompted-recall-of-nearly-half-a-million
 -trucks-with-latest-paccar-recall/\n\n     46. SAE Truck and Bus Control a
 nd Communications Network Committee.\n       (2026). J2497 Power Line Carr
 ier Communications for Commercial\n       Vehicles. Work in Progress Draft
  Revision.\n\n     47. Hex-Rays. (2026). IDA Pro. https://hex-rays.com/ida
 -pro/\n\n     48. Python Software Foundation. (2026). Python Programming L
 anguage.\n       https://www.python.org/\n\n     49. Graphviz Authors. (20
 26). Graphviz. https://graphviz.org/\n\n     50. ELDB. XPROG-box. https://
 www.eldb.eu/\n\n     51. PEmicro. PROGS12Z Flash Programmer Software.\n   
     https://www.pemicro.com/\n\n     52. NXP Semiconductors. MC9S12XEQ512 
 Data Sheet.\n       https://www.nxp.com/docs/en/data-sheet/MC9S12XEP100.pd
 f\n\n     53. NXP Semiconductors. MC9S12XE Family Reference Manual.\n     
   https://www.nxp.com/docs/en/reference-manual/MC9S12XERM.pdf\n\n     54. 
 DARPA. Assured Micropatching (AMP).\n       https://www.darpa.mil/program/
 assured-micropatching\n\n     55. LinkerScope Developers. LinkerScope. Vis
 ualization Tool.\n\n     56. Zynamics. BinDiff. https://www.zynamics.com/b
 indiff.html\n\n     57. hotwolf. HSW12. https://github.com/hotwolf/HSW12\n
 \n     58. National Highway Traffic Safety Administration. NHTSA Recalls b
 y\n       Manufacturer.\n       https://datahub.transportation.gov/Automob
 iles/NHTSA-Recalls-by-Manufacturer/mu99-t4jn\n\n     59. Yapo\, T. FL2K Ex
 periments.\n       https://hackaday.io/project/164346-fl2k-sdr\n\n     60.
  Osmocom. Osmo-FL2k Project.\n       https://osmocom.org/projects/osmo-fl2
 k\n\n     61. National Highway Traffic Safety Administration. Federal Moto
 r\n       Vehicle Safety Standard No. 121\, Air Brake Systems. 49 CFR\n   
     571.121.\n\n     62. Evenchick\, E. CANtact. https://cantact.io/\n\n  
    63. National Motor Freight Traffic Association. j2497-keyhole.\n       
 https://github.com/nmfta-repo/j2497-keyhole\n\n     64. Motorola. Motorola
  S-Record Description (PDF).\n       https://deramp.com/downloads/mfe_arch
 ive/060-Standards%20and%20Specifications/Hex%20Data%20Formats/Motorola%20S
 %20Record.pdf\n\n   SpeakerBio:  Ben Gardiner\, NMFTA Inc.\n\n   Ben is a 
 Senior Cybersecurity Research Engineer contractor at the\n   National Moto
 r Freight Traffic Association\, Inc.Â® (NMFTA)Â®\n   specializing in hardw
 are and low-level software security.\n\n   With more than ten years of pro
 fessional experience in embedded\n   systems design and a lifetime of hack
 ing experience\, Ben has a deep\n   knowledge of the low-level functions o
 f operating systems and the\n   hardware with which they interface.\n\n   
 He has held security assurance and reversing roles at a global\n   corpora
 tion\, as well as worked in embedded software and systems\n   engineering 
 roles at several organizations.\n\n   Ben has conducted workshops and pres
 entations at leading cybersecurity\n   and technical mobility events globa
 lly\, including Black Hat USA\, DEF\n   CON\, NorthSec\, escar USA\, Scapy
 yCon\, the CyberTruck Challenge\, GENIVI\n   Security Sessions\, Hack in P
 aris\, and HackFest.\n\n   In addition to speaking on the main stage at Bl
 ack Hat USA and DEF\n   CON\, Ben is a volunteer at the DEF CON Hardware H
 acking Village (DC\n   HHV) and Car Hacking Village (CHV). He is GIAC -GPE
 N\, and -GICSP\n   certified and a GIAC advisory board member\, serves as 
 the chair of the\n   SAE TEVEES18A1 Cybersecurity Assurance Testing Task F
 orce (responsible\n   for J3322)\, a contributor to ATA TMC task forces\, 
 the ISO/SAE JWG and\n   a voting member of the SAE VESS.\n\n   '\n\n   1. 
 #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T183000Z
DTSTART:20260809T173000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Reversing a Recall: From â€˜Noise Triggeredâ€™ to RCE
END:VEVENT
END:VCALENDAR
