BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//speaker//9MGULV
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251020T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:When Responsible Disclosure Becomes a Criminal Investigation: Unco
 vering CVE-2025-43928 in Law Enforcement Surveillance Systems - Tim Philip
 p Schäfers (TPS)
DTSTART;TZID=Europe/Luxembourg:20261020T114500
DTEND;TZID=Europe/Luxembourg:20261020T121500
DTSTAMP:20261009T050131Z
UID:pretalx-hack-lu-2026-NJFAF3@pretalx.com
DESCRIPTION:In late 2024\, we discovered a critical path traversal vulnera
 bility (CVE-2025-43928) affecting Media Relay Service (MRS)\, a software p
 latform used worldwide in surveillance and reconnaissance systems manufact
 ured by Infodraw. The affected ecosystem includes mobile video surveillanc
 e solutions\, police body cameras\, covert observation equipment\, and dro
 ne-based reconnaissance platforms operated by law enforcement agencies and
  governmental organizations - including the Unité Spéciale de la Police 
 in Luxembourg.\n\nThe vulnerability allowed unauthenticated attackers to a
 ccess arbitrary files on affected Windows and Linux systems and\, under ce
 rtain circumstances\, delete files remotely. Through internet-wide scannin
 g and coordinated vulnerability disclosure efforts\, vulnerable systems we
 re identified across multiple countries\, including systems attributed to 
 specialized police units and operational surveillance teams.\n\nThis prese
 ntation will cover the technical analysis of the vulnerability\, the metho
 dology used to identify exposed systems\, challenges encountered during re
 sponsible disclosure when the vendor remained unresponsive\, and the coord
 ination with national CERTs and affected operators. The talk will further 
 discuss how a successful disclosure process ultimately resulted in a crimi
 nal investigation (in Luxembourg) against the reporting researcher\, despi
 te the affected system being secured following notification.\n\nUsing this
  case study\, we will examine the growing tension between cybersecurity re
 search\, public-interest vulnerability disclosure\, law enforcement operat
 ions\, and outdated computer crime legislation. The presentation aims to p
 rovide practical lessons for vulnerability researchers\, CERT teams\, and 
 policymakers while highlighting the need for legal certainty for security 
 research in Europe.\n\nMore information:\nEnglish: https://mint-secure.de/
 path-traversal-vulnerability-in-surveillance-software/\nGerman: https://mi
 nt-secure.de/ermittlungsverfahren-nach-meldung-von-it-sicherheitsluecken-i
 n-observationssystemen/\nGerman: https://mint-secure.de/path-traversal-sic
 herheitsluecke-aufklaerungsgeraete/
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/NJFAF3/
END:VEVENT
END:VCALENDAR
