# cfp (blogs) — RSS Amplifier

Recent posts from the 3 feeds in the RSS Amplifier directory that cover cfp.

Page: <https://rssamplifier.com/topics/cfp/blogs>  
Feed: <https://rssamplifier.com/topics/cfp/blogs.md>

---

## [The Zen of Bluetooth Security (ZOBS)](https://francozappa.github.io/post/2026/zobs-init/)

_2026-07-15 · Daniele Antonioli_

Recently, I presented the ZOBS principles in a keynote at ACM WiSec'26 . Thanks again to Vincent Lenders and Gerhard Hancke for the invitation! Keynote abstract: The Zen of Bluetooth Security (ZOBS) is a collection of Bluetooth security principles developed by the speaker to systematize seven years of research on Bluetooth security protocols. The talk explores Bluetooth security research through…

## [ShadowICS: Detecting OT Sandboxes via Passive Industrial Traffic Monitoring](https://francozappa.github.io/publication/2026/shadowics/)

_2026-07-13 · Daniele Antonioli_

## [The Zen of Bluetooth Security](https://francozappa.github.io/publication/2026/zobs/)

_2026-07-06 · Daniele Antonioli_

## [Mastodon Stories for systemd v261](https://0pointer.net/blog/mastodon-stories-for-systemd-v261.html)

_2026-06-25 · Lennart Poettering · Pid Eins_

On June 19 we released systemd v261 into the wild . In the weeks leading up to that release (and since then) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd261 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 27 posts: Post #1: El-Torito/ISO9660 Support in systemd-repart Post #2:…

## [E-Trojans: Ransomware, Tracking, DoS, and Data Leaks on the Xiaomi E-Scooter Ecosystem](https://francozappa.github.io/publication/2026/etrojans/)

_2026-05-04 · Daniele Antonioli_

## [BlueBrothers: Three New Protocols to Secure Bluetooth](https://francozappa.github.io/publication/2026/bbro/)

_2026-04-16 · Daniele Antonioli_

## [HardaBLE: Hardening BLE Against Software Compromise](https://francozappa.github.io/publication/2026/hardable/)

_2026-04-16 · Daniele Antonioli_

## [MaDoS: Matter DoS Attacks via Secure Channel Status Reports](https://francozappa.github.io/publication/2026/mados/)

_2026-03-31 · Daniele Antonioli_

## [Mastodon Stories for systemd v260](https://0pointer.net/blog/mastodon-stories-for-systemd-v260.html)

_2026-03-26 · Lennart Poettering · Pid Eins_

On March 17 we released systemd v260 into the wild . In the weeks leading up to that release (and since then) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd260 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 21 posts: Post #1: NvPCR Measurements for Activated DDIs Post #2: Varlink…

## [BLERP Peripheral Impersonation Attack Demo](https://francozappa.github.io/post/2026/blerp-pidemo/)

_2026-03-23 · Daniele Antonioli_

Here is Tommaso Sacchetti demonstrating the BLERP peripheral impersonation attack against a vulnerable Android 13 build (2024). In this setup, an attacker in proximity impersonates a trusted mouse, triggers an unauthenticated re-pairing, and takes over the input channel. Recent Android versions have addressed this issue.

## [Crypto Payments, No Custody (Sponsored)](https://crawlproof.com/a/a42dRWJwQ5W9)

_2026-03-22 · **Sponsored**_

Send crypto to merchant wallets via API with real-time updates and automatic fees.

## [E-Trojans Black Hat USA 25 Video](https://francozappa.github.io/post/2026/etro-bhusa/)

_2026-03-18 · Daniele Antonioli_

Last summer, Marco Casagrande and I talked about E-Trojans: Ransomware, Tracking, DoS, and Data Leaks on Xiaomi Electric Scooters at Black Hat USA 2025 . Our presentation is online:

## [DCS-CI: Design for Cyber Secure Critical Infra](https://francozappa.github.io/post/2026/dcsci-cfp/)

_2026-03-16 · Daniele Antonioli_

The call for submission for the first edition of the DCS-CI conference is online . The Design of Cyber-Secure Critical Infrastructure (DCS-CI) 26 conference invites researchers, practitioners, and thought leaders to submit original work that advances our collective understanding of how to design, deploy, and maintain secure critical infrastructure systems. We welcome submissions from diverse…

## [WiSec&#39;26 Call for Posters and Demos](https://francozappa.github.io/post/2026/wisec-pd/)

_2026-03-16 · Daniele Antonioli_

I am excited to chair the WiSec Demo and Poster session . Please submit your great posters and demos via this HotCRP instance ! All poster titles must be prefixed with POSTER: and all demo titles with DEMO: . Deadlines: Submission: April 7, 2026 (AOE) Notification: April 21, 2026 Camera-ready: May 5, 2026 Please also share the word!

## [BLERP: BLE Re-Pairing Attacks and Defenses](https://francozappa.github.io/post/2026/blerp-ndss/)

_2026-02-14 · Daniele Antonioli_

In mid 2024, Tom and I looked at BLE re-pairing, an underlooked attack surface. We uncovered four critical re-pairing attacks and design-level vulnerabilities that allow device impersonation and MitM of arbitrary devices in BLE range. The attacks work even in the most secure BLE modes, like authenticated pairing and Secure Connections Only, and require 0-click or 1-click interactions. As part of…

## [CTRAPS on the DEF CON 33 Hackers&#39; Almanack](https://francozappa.github.io/post/2026/defcon-almanack/)

_2026-02-14 · Daniele Antonioli_

The DEF CON 33 Hackers&rsquo; Almanack just dropped . We would like to thank Paul Chang and their team for featuring CTRAPS in the Right to Repair section. Read and share the Almanack!. Links: CTRAPS paper and DEF CON talk .

## [Introducing Amutable](https://0pointer.net/blog/introducing-amutable.html)

_2026-01-26 · Lennart Poettering · Pid Eins_

Today, we announce Amutable, our ✨ new ✨ company. We – @blixtra@hachyderm.io , @brauner@mastodon.social , @davidstrauss@mastodon.social , @rodrigo\_rata@mastodon.social , @michaelvogt@mastodon.social , @pothos@fosstodon.org , @zbyszek@fosstodon.org , @daandemeyer@mastodon.social @cyphar@mastodon.social , @jrocha@floss.social and yours truly – are building the 🚀 next generation of Linux systems,…

## [PrivacyShield: Relaying BLE Beacons to Counter Unsolicited Tracking](https://francozappa.github.io/publication/2026/pshield/)

_2026-01-05 · Daniele Antonioli_

## [Mastodon Stories for systemd v259](https://0pointer.net/blog/mastodon-stories-for-systemd-v259.html)

_2025-12-30 · Lennart Poettering · Pid Eins_

On Dec 17 we released systemd v259 into the wild . In the weeks leading up to that release (and since then) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd259 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 25 posts: Post #1: systemd-resolved Hooks Post #2: dlopen() everything Post #3:…

## [Mastodon Stories for systemd v258](https://0pointer.net/blog/mastodon-stories-for-systemd-v258.html)

_2025-11-17 · Lennart Poettering · Pid Eins_

Already on Sep 17 we released systemd v258 into the wild . In the weeks leading up to that release I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd258 hash tag. It was my intention to post a link list here on this blog right after completing that series, but I simply forgot! Hence, in case you aren't using Mastodon, but would like…

## [AttackDefense Framework (ADF): Enhancing IoT Devices and Lifecycles Threat Modeling](https://francozappa.github.io/publication/2025/adf/)

_2025-10-15 · Daniele Antonioli_

## [AI QA That Opens Fix PRs (Sponsored)](https://crawlproof.com/a/5lvTaHFMmLXl)

_2025-10-14 · **Sponsored**_

Runs browser QA, files issues with repro evidence, and opens fix PRs.

## [CTRAPS interview on Off By One Security](https://francozappa.github.io/post/2025/ctraps-offbyone/)

_2025-09-22 · Daniele Antonioli_

Marco and I talked about CTRAPS with Stephen Sims from Off By One Security about CTRAPS: CTAP Impersonation and API Confusion on FIDO2 . Thank you Stephen and Randall for inviting us and keep up with the awesome content in your YouTube channel!

## [CTRAPS at Euro S&P&#39;25 and DEF CON 33](https://francozappa.github.io/post/2025/ctraps-eurosp25/)

_2025-07-04 · Daniele Antonioli_

This week we presented at IEEE Euro S&P'25 CTRAPS: CTAP Impersonation and API Confusion on FIDO2 , a paper about the security and privacy of FIDO2, a widespread standard used for single-factor and multi-factor authentication. We focus on the Client to Authenticator Protocol (CTAP) , an application layer protocol spoken by a FIDO2 authenticator (e.g., a YubiKey) and a client (e.g., a smartphone or…

## [CTRAPS: CTAP Client Impersonation and API Confusion on FIDO2](https://francozappa.github.io/talk/ctraps-ctap-client-impersonation-and-api-confusion-on-fido2/)

_2025-06-20 · Daniele Antonioli_

Talk on CTRAPS attacks on FIDO2 as part of ETHZ ZISC seminars.

## [NDSS&#39;26 Artifact Evaluation Committee Self-Nomination](https://francozappa.github.io/post/2025/ae-ndss26/)

_2025-06-13 · Daniele Antonioli_

Mathy Vanhoef and I are co-chairing NDSS'26 Artifact Evaluation (AE) . We are looking for motivated PhD and Postdocs to self-nominate themselves for the NDSS'26 Artifact Evaluation Committee (AEC) . Joining it would offer them practical experience and may ease developing artifact submissions for their papers. The self nomination form is open until June 25th and available here . NDSS'26 AEC call is…

## [ASG! 2025 CfP Closes Tomorrow!](https://0pointer.net/blog/asg-2025-cfp-closes-tomorrow.html)

_2025-06-11 · Lennart Poettering · Pid Eins_

The All Systems Go! 2025 Call for Participation Closes Tomorrow! The Call for Participation (CFP) for All Systems Go! 2025 will close tomorrow , on 13th of June! We’d like to invite you to submit your proposals for consideration to the CFP submission site quickly!

## [Security and Privacy for Connected Devices](https://francozappa.github.io/publication/2025/hdr-thesis/)

_2025-06-10 · Daniele Antonioli_

## [EmuOCPP: Effective and Scalable OCPP Security and Privacy Testing](https://francozappa.github.io/publication/2025/emuocpp/)

_2025-05-13 · Daniele Antonioli_

## [SimProcess: High Fidelity Simulation of Noisy ICS Physical Processes](https://francozappa.github.io/publication/2025/simprocess/)

_2025-05-13 · Daniele Antonioli_

## [Bluetooth Security Testing with BlueToolkit: a Large-Scale Automotive Case Study](https://francozappa.github.io/publication/2025/btoolkit/)

_2025-04-11 · Daniele Antonioli_

## [KNOB Attack and Crypto 101 by Alfred Menezes](https://francozappa.github.io/post/2025/crypto101-knob/)

_2025-04-01 · Daniele Antonioli_

Alfred Menezes has published a fantastic online course on real-world cryptography called Crypto 101: Real-World Deployments . It is an honor to be featured in the Bluetooth Security Lecture (Lecture 4) which talks about the KNOB attack.

## [Stay updated on your professional world (Sponsored)](https://crawlproof.com/a/N3o3yz5mGt3j)

_2025-03-31 · **Sponsored**_

Keep in touch with people you know, build your career.

## [CheckOCPP: Automatic OCPP Packet Dissection and Compliance Check](https://francozappa.github.io/publication/2025/checkocpp/)

_2025-03-27 · Daniele Antonioli_

## [CTRAPS: CTAP Impersonation and API Confusion on FIDO2](https://francozappa.github.io/publication/2025/ctraps/)

_2025-03-27 · Daniele Antonioli_

## [FP-tracer: Fine-grained Browser Fingerprinting Detection via Taint-tracking and Multi-level Entropy-based Thresholds](https://francozappa.github.io/talk/fp-tracer-fine-grained-browser-fingerprinting-detection-via-taint-tracking-and-multi-level-entropy-based-thresholds/)

_2025-03-18 · Daniele Antonioli_

Talk on FP-tracer and browser fingerprinting at Privasky'25 .

## [On the Insecurity of Vehicles Against Protocol-Level Bluetooth Threats](https://francozappa.github.io/talk/on-the-insecurity-of-vehicles-against-protocol-level-bluetooth-threats/)

_2025-03-14 · Daniele Antonioli_

Talk on Automotive Bluetooth Security at AMUSEC'25 . Cars are some of the most security-critical consumer devices. On the one hand, owners expect rich infotainment features, including audio, hands-free calls, contact management, or navigation through their connected mobile phone. On the other hand, the infotainment unit exposes exploitable wireless attack surfaces. This talk focuses on…

## [CFP: ACSW 2025](https://francozappa.github.io/post/2025/cfp-acsw25/)

_2025-02-03 · Daniele Antonioli_

The call for papers for the 4th Workshop on Automotive Cyber Security (ACSW) co-located with IEEE EuroS&P 2025 is closing today, Feb 3rd AoE. Please submit your automotive security work! For more information see the ACSW website and its past editions .

## [AttackDefense Framework (ADF)](https://francozappa.github.io/project/adf/)

_2024-12-17 · Daniele Antonioli_

The ADF framework is described in a paper published in the ACM TECS journal in 2024 titled AttackDefense Framework (ADF): Enhancing IoT Devices and Lifecycles Threat Modeling and available on GitHub .

## [The AttackDefense Framework (ADF)](https://francozappa.github.io/post/2024/adf-release/)

_2024-12-17 · Daniele Antonioli_

We release the AttackDefense Framework (ADF) , a threat modeling framework for IoT devices and their life cycles. The ADF employs a flexible and generic threat data structure called the AttackDefense (AD) object . An AD can model attack and defense aspects, like attack vectors, surfaces, models and defense policies and mechanisms, at the same time. With the ADF, we can model, among others,…

## [Announcing systemd v257](https://0pointer.net/blog/announcing-systemd-v257.html)

_2024-12-16 · Lennart Poettering · Pid Eins_

Last week we released systemd v257 into the wild . In the weeks leading up to this release (and the week after) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd257 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 37 posts: Post #1: Fully Locked Accounts with systemd-sysusers Post #2:…

## [Andrew Hay’s 2025 Cybersecurity Predictions](https://www.andrewhay.ca/archives/3823)

_2024-12-10 · Andrew Hay · Andrew Hay_

As we approach 2025, the ever-evolving landscape of cybersecurity continues to challenge professionals and organizations alike. Based on observed trends and emerging technologies, here are my predictions for the coming year.

## [E-Trojans: Ransomware, Tracking, DoS, and Data Leaks on Battery-powered Embedded Systems](https://francozappa.github.io/publication/2024/etrojans-preprint/)

_2024-12-09 · Daniele Antonioli_

