About this talk
This talk addresses the ongoing relevance of SOAP in critical systems like billing and document processing. Adobe Senior Offensive Security Researcher Kamalpreet Khurana explores the zero-day XXE vulnerability he discovered in 2025, highlighting how the XML parsing layer in SOAP continues to pose security risks that are often overlooked by developers and security teams. The session delves into how WSDL files can inadvertently provide attackers with a roadmap of a SOAP service, and it outlines a five-stage XXE exploitation methodology that can lead to the extraction of sensitive data. Participants will also learn about practical defense-in-depth strategies for organizations that cannot transition to REST, including methods such as disabling external entities and network isolation.
More from this event
See all 28 talks →
Ai, Deception And Deepfakes When Trust Becomes The Primary Attack Surface
36:15
Cloud Resilience Simplified Less Data, Stronger Security
33:14
Demystifying Driver Research A Systematic Approach For Vulnerability Hunting
25:24
Dpdpa In Action Designing A 72 Hour Breach Response That Actually Works
22:56