List of DEF CON talks in Tracks 1 thru 5
Villages and other Creators events are listed on the Creator Pages
One page DC Talks Long List with Descriptions
|
1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud DC Talks Info |
|
8 Out of 10 Banks in Belgium HATE This One Weird eID RCE DC Talks Info |
|
A Provider for the MOFia – Distributed Post-Ex Capabilities DC Talks Info |
|
Beyond the Ceremony: The 2026 Passkey Attack Surface DC Talks Info |
|
Bird Hunting Season: The Final Flight DC Talks Info |
|
BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft DC Talks Info |
|
Breaking Hardware CFI with Sigreturn DC Talks Info |
|
Breaking into Amazon lockers by any means necessary DC Talks Info |
|
Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama DC Talks Info |
|
Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys DC Talks Info |
|
Bring Your Own Root Of Trust DC Talks Info |
|
Bring-Your-Own-EDR – Breaking Windows Process Protection to build EDR-Protected Malware DC Talks Info |
|
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive DC Talks Info |
|
C(2)YA: Inside the Adversary’s Inbox DC Talks Info |
|
Can AI do novel security research? Meet the HTTP Terminator DC Talks Info |
|
Car Hacking Village Scavenger Hunt Contest DC Talks Info |
|
Certified Re-Pwned: escalating all the way up DC Talks Info |
|
Chaining Logical Bugs for Reliable Windows LPE DC Talks Info |
|
Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel DC Talks Info |
|
CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale DC Talks Info |
|
Compounding Interest: Exploiting the ATM Supply Chain DC Talks Info |
|
Contest Closing Ceremonies & Awards DC Talks Info |
|
Cracking North Korea’s Information Control: How Smugglers, Defectors, and Technologists are Breaking Open the World’s Most Locked-Down Information System DC Talks Info |
|
Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming DC Talks Info |
|
CRLF-Powered Desync Attacks: Beheading HTTP streams DC Talks Info |
|
CUDA’ve done better – Hacking Nvidia GPUs for container-escape and privilege escalation DC Talks Info |
|
Data Tomb Raider: Raiding Modern AI Vaults with Legacy Flaws for Treasure Stealing DC Talks Info |
|
DC101 DC Talks Info |
|
DEF CON Closing Ceremonies & Awards DC Talks Info |
|
DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers DC Talks Info |
|
Dylib Hijacking on macOS: Dead or Alive? DC Talks Info |
|
ESP32 as a counter-surveillance platform DC Talks Info |
|
Fireside Chat with Gen. Paul Nakasone DC Talks Info |
|
Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services DC Talks Info |
|
From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use-After-Free Vulnerability DC Talks Info |
|
From square root to /root: escalating privileges in Azure containers with Python in Excel DC Talks Info |
|
From Wind Farm to CHP Plant: The Untold Story of Lateral Movement in a Polish Energy Sector Attack DC Talks Info |
|
Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild DC Talks Info |
|
Going the Distance: Long-Range Keystroke Injection via Meshtastic DC Talks Info |
|
Gone in 60 Frames – USB Video Exploitation DC Talks Info |
|
Gotta Catch ‘Em All: How To Capture 3.5 Billion WhatsApp Accounts DC Talks Info |
|
Gotta Phish ‘Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle DC Talks Info |
|
gpwn: Wiretapping fiber (GPON) ISP deployments from the comfort of your home DC Talks Info |
|
Hacking AI DC Talks Info |
|
Hacking Jetskis – from Sea-Don’t to Sea-Doo DC Talks Info |
|
Hacking the EOD Bot: How I Learned to Stop Worrying and Love the Boomba DC Talks Info |
|
Hacking the Government: How Two Researchers Turned Late-Night Boredom Into a National Audit DC Talks Info |
|
Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Underground VPN Infrastructure DC Talks Info |
|
Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design DC Talks Info |
|
Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations DC Talks Info |
|
High Voltage Heist: Turning Your EV into my Power Bank DC Talks Info |
|
How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs? DC Talks Info |
|
Identity Crisis: Novel Vulnerabilities leading to Kerberos Downgrade, DoS, and Full Domain Takeover DC Talks Info |
|
Install Me Maybe: Turning Claimable VS Code Extension IDs into Supply-Chain Attacks DC Talks Info |
|
Keychained Melody – Grabbing the Keys to the iCloud Kingdom DC Talks Info |
|
LaunchBreak: a Sip of Tea, a Click, and a Full Multi-stage Desktop Takeover DC Talks Info |
|
Lessons from a decade of building whistleblower tech DC Talks Info |
|
LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails DC Talks Info |
|
Lights Out: Out-of-Band, Out of Mind, Out of Control DC Talks Info |
|
Looking and Peering: Attacking from beyond BGP Adjacency DC Talks Info |
|
Lowering the Orbit: Exploiting Satellite Protocols and communications via Software-Defined-Radio and GS DC Talks Info |
|
Memory Laundering via Metal: What EDR Can’t See on Your Mac DC Talks Info |
|
MSIX’d Up: Weaponizing the Modern Windows App Packaging Ecosystem DC Talks Info |
|
No Prompt Required: Pre-Task RCE in Google Gemini CLI DC Talks Info |
|
No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes DC Talks Info |
|
noRecognition: Could a pattern on your clothing fool Facial Facial Recognition? DC Talks Info |
|
OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise DC Talks Info |
|
One Chain to Own Them All — Breaking AI Infrastructures DC Talks Info |
|
Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet’s V8 on the Galaxy S25 DC Talks Info |
|
Plug And Pwn: Weaponizing Windows PnP Auto-Install DC Talks Info |
|
Pwning Rekordbox: Unauthenticated filesystem access in the world’s most popular DJ software DC Talks Info |
|
Rage Against the Sandbox: Bypassing Apple’s iOS Security to Run Unsigned Code via SSH DC Talks Info |
|
Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking) DC Talks Info |
|
Reversing a Recall: From ‘Noise Triggered’ to RCE DC Talks Info |
|
Riding for Free – Breaking Public Transport RFID at Scale DC Talks Info |
|
Root From Kilometers Away: Ubiquiti AirMax RCE DC Talks Info |
|
Shepherding the Tor network DC Talks Info |
|
Shopping Is The Attack: A Decade Of E-Commerce Scalper Wars, And The Multi-Agent AI Era DC Talks Info |
|
Sliding into the Flight Deck’s DMs: Practical Message Attacks on CPDLC DC Talks Info |
|
Smile, you’re on camera! Livestreaming from North Korea’s IT workers laptop farm DC Talks Info |
|
Stalking the Wily Hacker … 40 years later DC Talks Info |
|
Taking on the Dark Fleet… in Cyberspace! DC Talks Info |
|
Talkers Without Borders: Worldwide Free Speech without an Internet Connection DC Talks Info |
|
Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System DC Talks Info |
|
TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition DC Talks Info |
|
Texas Incidents – How we broke the OMAP-L138 Trusted Execution Environment DC Talks Info |
|
The 2026 Pwnie Awards DC Talks Info |
|
The Compiler That Can’t Read: Crashing Every 5G Phone With One Byte DC Talks Info |
|
The DEF CON 34 Badge DC Talks Info |
|
The Enclave is Lying to You: Breaking TEE Trust Boundaries Through Boot-Time State DC Talks Info |
|
The Ghost Key: Illusions of “Time Management” in TTLock Smart Locks DC Talks Info |
|
The Glass Perimeter: Systematic Bypasses in Biometric Frameworks and the Rise of Synthetic Identity DC Talks Info |
|
The Sandbox is a Suggestion: Deconstructing AI Agent Sandboxes DC Talks Info |
|
The Stream Is Dead, Long Live the Stream: How HTTP/2 Lets Dead Streams Keep Servers Working DC Talks Info |
|
Thin Client? Thin Crypto – Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher DC Talks Info |
|
This Message Was Sent by Microsoft: Turning Microsoft Apps into our Phishing Platform DC Talks Info |
|
Throw Out the Alphabet: Token-Based Markov Chains for Password Cracking DC Talks Info |
|
Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children and Vehicles DC Talks Info |
|
Transformers: Dark Side of the Type – Weaponizing the Conversion Layer DC Talks Info |
|
Very Pwned: Hacking Verifone’s card machine three times in a row DC Talks Info |
|
WASM Was Not the Boundary: Sandcastles, Not Sandboxes DC Talks Info |
|
Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written DC Talks Info |
|
Welcome to DEF CON 34! DC Talks Info |
|
What is the Right Balance of Rules for Defenders & Adversaries? Determining which dual-use model restrictions make sense and which only disarm defenders DC Talks Info |
|
Witchcraft Solver: Automated 0day Discovery in Stripped Binaries DC Talks Info |
|
Wrestling with a Python: Escaping Copilot Studio’s AI-Guarded Sandbox DC Talks Info |
|
Writing to Shadow Stacks DC Talks Info |
|
You’ve Got Mail (That Was Meant For No One) DC Talks Info |
|
Your Bank Thinks I’m You: A Complete Kill Chain Against Mobile Banking Security DC Talks Info |
|
Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet DC Talks Info |
|
Your Packets Are Showing: Hybrid Quantum ML for Passive OS Fingerprinting DC Talks Info |
|
Your WAF Blocked Us, That Was The Exploit – Remote Agent Takeover via Cloudflare, Sentry and Claude Zero-Day for data exfil DC Talks Info |
|
Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks DC Talks Info |