BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Transformers: Dark Side of the Type - Weaponizing th
 e\n   Conversion Layer\n   Tags: DEF CON Official Talk | Demo 💻 | Explo
 it 🪲\n   When: Saturday\, Aug 8\, 13:30 - 14:30 PDT\n   Where: LVCCW Le
 vel 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]Map\n\n   Description:\n\n
    In 2017\, our DEF CON talk "Friday the 13th: JSON Attacks" forced the\n
    industry to confront Insecure Deserialization. Developers responded by\
 n   hardening the configurations of parsers and serializers. But it\n   cr
 eated a dangerous blind spot. Developers and security reviewers now\n   as
 sume that simpler code patterns\, those that do not involve parsers\,\n   
 are inherently safe. We demonstrate that they are not. This talk moves\n  
  the focus away from the serialization format entirely and targets the\n  
  transformation layer: the code that turns a simple string into a\n   comp
 lex object. We expose "Insecure String Transformers": mechanisms\n   that 
 silently resolve types\, trigger complex logic\, and instantiate\n   objec
 ts during what looks like a safe string conversion. This\n   overlooked at
 tack surface remains invisible to the tools and reviews\n   focused on the
  parser-level bugs from 2017. We dissect specific CVEs\n   where string-to
 -object conversion was the root cause of RCE. We\n   release new gadget ch
 ains targeting popular .NET libraries and present\n   a methodology for hu
 nting dangerous conversion patterns across any\n   codebase. The goal is t
 o redefine how the industry classifies this\n   vulnerability: it is not "
 Insecure Deserialization" - it is Insecure\n   Transformation\, and it may
  be hiding in your application even if it\n   does not use any serializati
 on library.\n\n   Alvaro Muñoz & Oleksandr Mirosh\, "Friday the 13th: JSO
 N Attacks" -\n   Black Hat USA 2017\n   https://www.blackhat.com/docs/us-1
 7/thursday/us-17-Munoz-Friday-The-13th-JSON-Attacks-wp.pdf\n   Alvaro Muñ
 oz & Oleksandr Mirosh\, "Room for Escape: Scribbling Outside\n   the Lines
  of Template Security" - Black Hat USA 2020\n   https://i.blackhat.com/USA
 -20/Wednesday/us-20-Munoz-Room-For-Escape-Scribbling-Outside-The-Lines-Of-
 Template-Security-wp.pdf\n\n   SpeakerBio:  Oleksandr Mirosh\, OpenText Fo
 rtify\n\n   Oleksandr Mirosh is a Security Researcher on the Fortify Softw
 are\n   Security Research team at OpenText\, where he focuses on investiga
 ting\n   emerging threats and developing detection and remediation rules f
 or\n   enterprise software. With over 18 years of experience in computer\n
    security\, specializing in vulnerability research\, reverse engineering
 \,\n   and penetration testing\, his work centers on flaws in JNDI\,\n   a
 uthentication protocols\, data serialization\, and transformation logic\n 
   across Java and .NET ecosystems. His research has led to the discovery\n
    of numerous CVEs in widely deployed enterprise applications and\n   fra
 mework libraries. A frequent speaker at Black Hat USA and DEF CON\,\n   he
  has also presented at other security conferences like OWASP Global\n   Ap
 pSec and BSidesLV.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T213000Z
DTSTART:20260808T203000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Transformers: Dark Side of the Type - Weaponizing the Conversion La
 yer
END:VEVENT
END:VCALENDAR
