Your Honeypots Are Too Boring to Find Zero-Days

No ratings

Presented at Black Hat Asia 2026 by

It seems like every honeypot deployment in 2026 is still logging the same SSH brute-force attempts and Mirai scans it was catching a decade ago. Meanwhile, attackers are burning pre-auth RCEs against enterprise perimeter products within hours of development - and most of the security industry finds out about it from the vendor advisory, days or weeks later.Our research demonstrates that purpose-built, high-fidelity honeypots - designed to convincingly emulate specific enterprise attack surfaces - can catch 0-day exploitation in the wild before a CVE even exists. We used this approach to discover CVE-2026-35616, a CVSS 9.8 pre-authentication remote code execution vulnerability in Fortinet's FortiClient EMS, identified and confirmed entirely from honeypot-captured traffic, leading to an emergency vendor hotfix.In this session, we will walk through the full discovery timeline of CVE-2026-35616 - from the first anomalous request hitting our sensors to a confirmed 0-day and an emergency vendor hotfix. We will show what attacker behavior looks like when a new vulnerability is being actively exploited in the wild, how we distinguished it from background noise, and what the coordinated disclosure process looked like from the researcher's side. Along the way, we will challenge some assumptions about what honeypots are actually capable of when you stop treating them as passive tripwires and start treating them as offensive intelligence tools.You will leave with a new lens on vulnerability discovery and a concrete case study proving it works.Open to Briefings, Business Hall and Trainings Pass Holders.