Talk/Event Schedule


Friday


This Schedule is tentative and may be changed at any time. Check here, Hacker Tracker, or the nearest NFO Node for the latest.

 

Friday - 00:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - Music - Genre: Techno - dotornot

 

Friday - 06:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - Defcon.run -
Social Gatherings/Events - 15th Cycleoverride Bike Ride at DEF CON -

 

Friday - 07:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - cont...(06:00-07:59 PDT) - Defcon.run -
Social Gatherings/Events - cont...(06:00-10:59 PDT) - 15th Cycleoverride Bike Ride at DEF CON -

 

Friday - 08:00 PDT


Return to Index  -  Locations Legend
DEF CON Training - (08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - (08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - (08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
Social Engineering Community Village - (08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - (08:45-08:59 PDT) - Village Greeting -
Social Gatherings/Events - Human Registration Open -
Social Gatherings/Events - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(06:00-10:59 PDT) - 15th Cycleoverride Bike Ride at DEF CON -

 

Friday - 09:00 PDT


Return to Index  -  Locations Legend
Contests - SEC Vishing Competition (SECVC) -
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - Sold Out - Offensive Packet Wizardry with Scapy - Mike "Chicolinux" Guirao
DEF CON Workshops - Sold Out - Hands-on IoT firmware extraction and flash forensics - Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu
DEF CON Workshops - Sold Out - AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover - zeta,Rafa "bane" Gutierrez
DEF CON Workshops - Sold Out - Web Hacking 101 - cale "calebot" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon
DEF CON Workshops - Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming - Jake "Hubbl3" Krasnov,Vincent "Vinnybod" Rose,Anthony "Coin" Rose,Dan Niefeld
DEF CON Workshops - Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF - Ryan "Hackgnar" Holeman,Alek Amrani
DEF CON Workshops - Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted - Sydney "letswastetime" Marrone
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(06:00-10:59 PDT) - 15th Cycleoverride Bike Ride at DEF CON -

 

Friday - 10:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - ARINC 664 CTF Challenge -
Aerospace Village - DCNextGen - Bricks in the Air -
Aerospace Village - Drone Hacking Choose your Own Adventure -
Aerospace Village - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - Bricks in the Air -
Aerospace Village - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - MOUSE Runner & Flappy Drone -
Aerospace Village - Flight Simulator/EFB -
Aerospace Village - Drone Hacking Workshop -
Aerospace Village - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - SR-71 Blackbird Badge Challenge -
Aerospace Village - SpaceCOP - Catch Me If You Can -
Aerospace Village - Hacking Electronic Conspicuity Devices -or- Making Light Aircraft Fly Into Conflict - Ken Munroe
AI Village - AI Village: Village Open -
AI Village - AI Village: Opening Remarks -
AI Village - Poster Presentations -
AI Village - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AppSec Village - (10:15-11:15 PDT) - Pentesting made easy - Keeping sessions alive with session chains - Kai Glauber,Matthias Göhring
AppSec Village - (10:30-12:30 PDT) - Burp, But Yours: Hands-On Extension and Bambda Development - Hannah L
AppSec Village - (10:30-10:59 PDT) - The Dots Do Matter: Gmail's Invisible Blindspot - Keren Elazari
Biohacking Village - Biohacking Device Lab -
Biohacking Village - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - Four Newbies Vs. An Insulin Pump. How Hard Can It Be? - Birgitte Jordal,Julia Kucharska,Emilie Jørstad,Selma Jenker
Biohacking Village - Counting the Dead in the Digital Siege: Detection Infrastructure for Cyber-Mapping Patient Harm - Jorge Acevedo Canabal,Scott Shackelford,Szymon Skalski
Blacks In Cyber Village - Return of the Defender: Using AI to Strike Back Against Enterprise Threats - Levone Campbell
Blue Team Village - Incident Response 101: Preparing Before the Hack, Responding After It - Joshua Morgan
Bug Bounty Village - The Future of Bug Bounty - Program Manager Perspective - Jai Kumar Sharma,Catherine Cassell,Austin Sturm,Dane Sherrets,Sachin "sachinnthakuri" Thakuri
Bug Bounty Village - Click Me: Turning URI Links into Bug Bounty RCE's - Tobias Diehl
Bug Bounty Village - (10:30-11:30 PDT) - Hacking IDE Extensions - VSCode Workshop - Nick "7urb01" Copi
Call Center Village - Call Center Village - Open -
Car Hacking Village - Bomb Bot Challenge -
Car Hacking Village - Car Hacking Village Open -
Cloud Village - Opening Talk - Jayesh Singh Chauhan
Cloud Village - New AWS IAM Attack Paths and the Framework to Exploit Them - Seth Art
Cloud Village - (10:50-11:30 PDT) - Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID - Elzer Pineda,Jose Rivas
CodeBloom - Game Time: Loops -
Contests - Aw, man…pages! -
Contests - 5N4CK3Y -
Contests - DC's Next Top Threat Model -
Contests - Untechnical -
Contests - DEF CON Scavenger Hunt -
Contests - Darknet-NG -
Contests - Crack Me If You Can 2026 -
Contests - TeleChallenge -
Contests - HackFortress -
Contests - ?Cube -
Contests - $unL1ght Sh4d0w5 -
Contests - Octopus Game - Booth Open -
Contests - Octopus Game Opens and Pre-registration Check-In Available -
Contests - Octopus Game - Opening Ceremony -
Contests - Beer Chilling Contraption Contest -
Contests - Cryptid Hunt -
Contests - HSPACE: AI Battlegrounds -
Contests - spyVspy 3: Rat Race -
Contests - Hacker Games -
Contests - PhreakMe -
Contests - Game Hacking Village CTF -
Contests - Kubernetes CTF -
Contests - Hac-Man -
Contests - Crack the Core -
Contests - Cyber Deck Competition -
Contests - Pinball High Score Contest -
Contests - Code Cadaver: Break Every System. Save Your Friend. -
Contests - PWN UR H0M3 - DDoS CTF -
Contests - Reali7y Overrun - Contest running -
Contests - Tin Foil Hat Contest -
Contests - CMD+CTRL Cyber Range: DarkMoney -
Contests - DEF CON CTF: Benevolent Bureau of Birds -
Contests - AI Village - Hal CTF -
Contests - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - StarPWN CTF -
Contests - Car Hacking Village CTF -
Contests - OWASP CTF -
Contests - (10:30-11:30 PDT) - OWASP CTF: Getting started & welcome - Diego Cotelo,Chris "dafinga" Maenner,Christian "DeadlyFluVirus" Nuss
Contests - Blue Team Village CTF - Project Obsidian -
Contests - Escalation Desk CTF -
Contests - DEF CON Groups Sticker Contest -
Contests - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - Apex Park (Cloud Village CTF) -
Contests - cont...(09:00-11:59 PDT) - SEC Vishing Competition (SECVC) -
Contests - Bug Bounty Village CTF - Open -
Contests - Hacking GRC Contest -
Crypto & Privacy Village - (10:30-10:59 PDT) - What TEEs Do Not Hide: Residual Metadata Leakage in Confidential LLM Serving - Anup Swamy Veena
Data Duplication Village - DDV open and accepting drives for duplication -
DCNextGen - (10:30-11:30 PDT) - DCNextGen Opening Ceremonies - BiaSciLab
DEF CON Groups - DEF CON Groups (DCG) -
DEF CON Talks - Car Hacking Village Scavenger Hunt Contest -
DEF CON Talks - Welcome to DEF CON 34! - Jeff "The Dark Tangent" Moss
DEF CON Talks - (10:30-10:59 PDT) - The DEF CON 34 Badge - Andrew 'bunnie' Huang
DEF CON Talks - Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys - Guanxing Wen
DEF CON Talks - (10:30-11:30 PDT) - Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama - Ofek Itach,Vladimir "G1ND1L4" Tokarev
DEF CON Talks - From square root to /root: escalating privileges in Azure containers with Python in Excel - Ron Ben Yizhak
DEF CON Talks - Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written - Christopher "xoreaxeaxeax" Domas
DEF CON Talks - (10:30-11:30 PDT) - Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking) - Gregory "1umberhack" Disney-Leugers
DEF CON Talks - Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment - Carlo Meijer,Wouter Bokslag
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Offensive Packet Wizardry with Scapy - Mike "Chicolinux" Guirao
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Hands-on IoT firmware extraction and flash forensics - Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover - zeta,Rafa "bane" Gutierrez
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Web Hacking 101 - cale "calebot" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming - Jake "Hubbl3" Krasnov,Vincent "Vinnybod" Rose,Anthony "Coin" Rose,Dan Niefeld
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF - Ryan "Hackgnar" Holeman,Alek Amrani
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted - Sydney "letswastetime" Marrone
Demo Labs - AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory - Akbar "0xsensei" Abdullayev,0xHera
Demo Labs - Peekaboo: Breaking the Black Box of Threat and Malware Emulation - Zhassulan "cocomelonc" Zhussupov
Demo Labs - Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop - Fukusuke Takahashi,Zach Mathis,Akira Nishikawa
Demo Labs - X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain - Xia Hua,Abhijeet Kumar
Demo Labs - PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale - Georgia Weidman
Demo Labs - Empire 7: Shipping a C2 at AI Speed - Vincent "Vinnybod" Rose,Jake "Hubbl3" Krasnov,Anthony "Coin" Rose
Embedded Systems Village - Embedded - 101 Labs -
Embedded Systems Village - Embedded Systems Village CTF -
Embedded Systems Village - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Game Hacking Village - Chill Zone: Casual Games & TASBot Smash Demo -
IoT Village - All About UART -
IoT Village - Just Hacking Training -
IoT Village - Discover GE Appliances! -
IoT Village - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - Expose Hidden Surveillance in Everyday Tech -
IoT Village - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - (10:30-11:30 PDT) - Make your very own evil IoT Cat Lamp with WLED! - Nick
IoT Village - (10:45-11:30 PDT) - Sick Signals: Adversarial Prompt Injection via Medical IoT Telemetry - Vinitha Mathiyazhagan,Tamil Mathi T.
La Villa Community - La Villa - Opening Ceremony (ESP) -
La Villa Community - (10:30-11:30 PDT) - Bootkits Forever: Emulando APTs Modernos desde UEFI hasta el Kernel - Alejandro Vázquez Vázquez
La Villa Community - (10:30-12:59 PDT) - De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS - Juan Camilo Palacio Arango,Andrés Restrepo
Lockpick Village - (10:15-10:45 PDT) - Intro to Lockpicking -
Lonely Hackers Club - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - Lonely Hackers Club CTF -
Lonely Hackers Club - (10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - Makers' Village - Hacker Arts and Crafts -
Malware Village - Anatomy of a Sandworm: A Deep Dive into the Shai-Hulud Attacks - Megg Sage
Malware Village - (10:55-11:35 PDT) - Lyra: An LLVM IR Obfuscator for Rust - Rafael Felix
Malware Village - The Silent Tunneler: A Real-World Incident Response Story - Uriel Kosayev
Maritime Hacking Village - Maritime Hacking Village Policy Panel: Subsea Cables as Strategic Chokepoints - Security, Sovereignty, and the Grey Zone - Dr. Nina Kollars,Jason Vogt,Delta Blue
Misc - Coloring Reset -
Mobile Hacking Community - Mobile Hacking Community - Open -
Mobile Hacking Community - Bypassing KYC Vendors on AI Times - Juan Urbano Stordeur,Juan Martinez Blanco
Mobile Hacking Community - Mobile Hacking - Informal CTF -
Nix Vegas Community - Nix Vegas Opening Ceremony - Daniel Baker,Morgan Jones,Tristan Ross
Nix Vegas Community - (10:30-10:59 PDT) - Composable Systems with NixOS MicroVMs - Alex Decious
Noob Community - TCM Security Labs -
Noob Community - Skillbit Labs -
Noob Community - SANS Institute NetWars Labs -
Noob Community - Arcanum Security Labs -
Noob Community - Kryptsec Labs -
Noob Community - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - Mentoring and Career Advice -
Noob Community - No Stupid Questions -
Noob Community - Noob Community - DEF CON 34 Opening Statements -
Noob Community - Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta - James Stanger,Stephen Schneiter
OSINT For Good Community - OSINT4Good: What it takes to find missing people - Angela Ramos,Kenny J,Brent Louie
OSINT For Good Community - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - F1NDX OSINT Educational Series -
OWASP Foundation - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
Payment Village - (10:45-11:30 PDT) - The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation - Daniel Cuthbert,Leigh-Anne Galloway,Jorge Braniff,Sanjeev Sharma
Payment Village - (10:30-10:45 PDT) - Payment Village Intro - What's Happening at the Village -
Policy @ DEF CON - Sovereign by Design, Vulnerable by Default - Devin Lynch,Haley Ring
Policy @ DEF CON - Not Your Parents’ Schoolhouse Rock: Getting Tech Policy Done in a Non-Functioning Congress - Jeff Rothblum,Michael Flynn
Radio Frequency Village - Radio Frequency Village Events -
Radio Frequency Village - (10:30-12:25 PDT) - RF CTF Kick Off Day 1 - RF Hackers
Recon Village - Hands-On Supply Chain Recon & Vendor Risk Mapping - Dhiyaneshwaran Balasubramaniam,Aman Rawat
Recon Village - TrackTheFugitive Contest -
Recon Village - Live Recon Contest -
Recon Village - (10:45-11:30 PDT) - InQuorigible: Quora in Missing Persons OSINT - Miranda Tedholm
Red Team Village - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - BloodHound Quest - Hugo van den Toorn
Red Team Village - Post-Exploitation of the Desktop with JS-Tap - Drew Kirkpatrick
Red Team Village - Red Team Express - Cody Spooner
Red Team Village - Zero Signal: Operating Where Defenders Can't See - Gowthamaraj Rajendran
Red Team Village - Falco Hunt: Evading Runtime Detection in Kubernetes - Michael Reimsbach
Red Team Village - Opening Panel - "Is Red Teaming Dead?" - Ads Dawson,Ben "NahamSec" Sadeghipour,Billy Giles,Ryan Montgomery
Red Team Village - The Entropy Illusion: High-Speed Cracking on a Budget - Chris Claunch
Red Team Village - RFID Bootcamp: Unleashed! - Evan Cook
Scambait Village - KSCM Scambait Radio -
Scambait Village - Open Q&A -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - Pickpocketing for Red Teamers: A Hands-On Experience - pradameinhof
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - Music - SomaFM -
Social Gatherings/Events - cont...(06:00-10:59 PDT) - 15th Cycleoverride Bike Ride at DEF CON -
Telecom Village - Telecom Village Inauguration - Pankaj Sontakke
Telecom Village - (10:20-10:59 PDT) - A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure - Siva Sareddu,T -Mobile CTF Team
The Diana Initiative - IOT Village Tour -
The Diana Initiative - (10:20-10:30 PDT) - Quantum Village Tour -
The Diana Initiative - (10:30-10:40 PDT) - AppSec Village Tour -
The Diana Initiative - (10:40-10:50 PDT) - Robot Hacking Community Tour -
The Diana Initiative - (10:50-10:59 PDT) - Physical Securty Village Tour -
The Diana Initiative - Quiet Room -
The Diana Initiative - Hacker Runway Crafting Time -
Voting Village - Voting Village Lab -
Voting Village - Election Integrity and Technology - Matt Blaze
Voting Village - (10:30-10:59 PDT) - What Election Security Researchers Need to Know About the DMCA - Tori Noble

 

Friday - 11:00 PDT


Return to Index  -  Locations Legend
.EDU Community - Cracking the Cybersecurity Career Code with the Cyber Color Wheel - Shavvon "TheSiren" Cintron
Adversary Village - (11:30-11:59 PDT) - Haetae: An Agent to Takedown North Korean C2 Servers - Mauro Eldritch,Nelson Rafael Colón Merán
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AppSec Village - cont...(10:15-11:15 PDT) - Pentesting made easy - Keeping sessions alive with session chains - Kai Glauber,Matthias Göhring
AppSec Village - (11:30-12:30 PDT) - Aegis of the Vulnerable: A Unified Pipeline for AI-Based SAST - Can Oztas
AppSec Village - cont...(10:30-12:30 PDT) - Burp, But Yours: Hands-On Extension and Bambda Development - Hannah L
AppSec Village - Pickled and Exposed: RCE in AI Serving Frameworks - Iggy
AppSec Village - (11:50-12:20 PDT) - A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox - Simcha Kosman
AppSec Village - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - The Call Stack Experience - Victoria Keeler
AppSec Village - Clash of Prompts: The World's First Prompt Battle Royale -
AppSec Village - Hack the Duck Store - Gwendal Mognier,Samantha Pearlstein
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - (11:30-11:59 PDT) - Human in the Loop or Human Out of Luck? - Christine Von Raesfeld
Blacks In Cyber Village - The Black PhD Playbook: What No One Tells You - Dr. Fatou Sankare,Dr. Xavier-Lewis Palmer,Dr. Tia Pope
Blue Team Village - Cyber Threat Intelligence 101: From Foundations to AI-Driven Defense - Carlo Anez Mazurco
Bug Bounty Village - The Ripple Effect: Inside Cloud-Scale Vulnerabilities in the Age of AI - Albin Vattakattu,Ryan Nolette
Bug Bounty Village - (11:30-11:59 PDT) - Make Money Hacking AI - Joey Melo,Edward Morris
Bug Bounty Village - cont...(10:30-11:30 PDT) - Hacking IDE Extensions - VSCode Workshop - Nick "7urb01" Copi
Bug Bounty Village - (11:30-12:30 PDT) - Hackbots - Jason "jhaddix" Haddix,Ryan "BadAt_Computers" Bonner
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Cloud Village - Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS - Samanta Aranda
Cloud Village - Governing the Firehose: Writing Custom OPA Policies to Tame and Remediate Prowler Output - Ram "n2r"
Cloud Village - cont...(10:50-11:30 PDT) - Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID - Elzer Pineda,Jose Rivas
Cloud Village - (11:30-12:10 PDT) - From Pipeline to Cloud Control - Saksham Agrawal
CodeBloom - Work Session: Ciphers -
Contests - cont...(10:00-12:59 PDT) - Aw, man…pages! -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-12:59 PDT) - Octopus Game Opens and Pre-registration Check-In Available -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-11:59 PDT) - StarPWN CTF -
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:30-11:30 PDT) - OWASP CTF: Getting started & welcome - Diego Cotelo,Chris "dafinga" Maenner,Christian "DeadlyFluVirus" Nuss
Contests - cont...(10:00-11:59 PDT) - Blue Team Village CTF - Project Obsidian -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(09:00-11:59 PDT) - SEC Vishing Competition (SECVC) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Contests - Radio Frequency Capture the Flag -
Cryptocurrency Village - Cryptocurrency Opening Keynote - Michael "MsvB" Schloh,Param "P7R7M",Arjun "Peper" Suresh
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
Data Duplication Village - Drive Stats: 14 years of hard drive failure rates - Stephanie Doyle
DCNextGen - cont...(10:30-11:30 PDT) - DCNextGen Opening Ceremonies - BiaSciLab
DEF CON Groups - (11:30-11:59 PDT) - Starting and Sustaining a Successful DEF CON Group presented by DC862 - C$,Joe Folk,Christopher "reapermunky" Aziz
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - cont...(10:00-11:59 PDT) - Car Hacking Village Scavenger Hunt Contest -
DEF CON Talks - The 2026 Pwnie Awards - Ian Roos,Mark Trumpbour
DEF CON Talks - cont...(10:30-11:30 PDT) - Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama - Ofek Itach,Vladimir "G1ND1L4" Tokarev
DEF CON Talks - (11:30-12:30 PDT) - Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming - Marcos "h3xduck" Bajo,Ritvik "RoYalGamr" Goyal
DEF CON Talks - Sliding into the Flight Deck’s DMs: Practical Message Attacks on CPDLC - Martin "MasorX" Strohmeier,Mehdi Ziazi
DEF CON Talks - cont...(10:30-11:30 PDT) - Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking) - Gregory "1umberhack" Disney-Leugers
DEF CON Talks - (11:30-12:30 PDT) - A Provider for the MOFia - Distributed Post-Ex Capabilities - Steven Flores
DEF CON Talks - Keychained Melody - Grabbing the Keys to the iCloud Kingdom - Alex Radocea,Jaron Bradley
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Offensive Packet Wizardry with Scapy - Mike "Chicolinux" Guirao
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Hands-on IoT firmware extraction and flash forensics - Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover - zeta,Rafa "bane" Gutierrez
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Web Hacking 101 - cale "calebot" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming - Jake "Hubbl3" Krasnov,Vincent "Vinnybod" Rose,Anthony "Coin" Rose,Dan Niefeld
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF - Ryan "Hackgnar" Holeman,Alek Amrani
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted - Sydney "letswastetime" Marrone
Demo Labs - Damn Vulnerable Agentic AI Application (DVAIA) - Abhinav Verma,Mukesh Aggarwal
Demo Labs - sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions - Atsushi Sada,hikae
Demo Labs - Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device - Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova
Demo Labs - Zealot: An Autonomous Cloud Offensive Multi-Agent System - Chen Doytshman
Demo Labs - AOBTD: AI One Bites The DAST - Ozgun "ozzy" Kultekin
Demo Labs - AI Pipeline for N-days Weaponization - Andrea Brosio,Arun Nair
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Hackers.town - Tech Reclaimers Update: A Year In, Building a Social Movement Away from Big Tech - Andy Hull,Janet Vertesi,Rebecah Miller
Hackers.town - building community and privacy tools from junk - TheGibson
Ham Radio Village - Meshtastic 101: Off-Grid Mesh Networking with LoRa - Jon Marler (K4CHN)
ICS Village - Intro to Common Industrial Protocol Exploitation - Trevor Flynn
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:30-11:30 PDT) - Make your very own evil IoT Cat Lamp with WLED! - Nick
IoT Village - cont...(10:45-11:30 PDT) - Sick Signals: Adversarial Prompt Injection via Medical IoT Telemetry - Vinitha Mathiyazhagan,Tamil Mathi T.
La Villa Community - cont...(10:30-11:30 PDT) - Bootkits Forever: Emulando APTs Modernos desde UEFI hasta el Kernel - Alejandro Vázquez Vázquez
La Villa Community - (11:30-12:30 PDT) - Demodus Operandi (Cómo tres rf-hacks en tres bandas terminaron siendo una metodología) - Eduardo Contreras
La Villa Community - cont...(10:30-12:59 PDT) - De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS - Juan Camilo Palacio Arango,Andrés Restrepo
Lockpick Village - Building an open soure safecracking robot - Jared Dygert
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - Build-A-Badge Workshop - hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
Malware Village - cont...(10:55-11:35 PDT) - Lyra: An LLVM IR Obfuscator for Rust - Rafael Felix
Malware Village - cont...(10:10-11:40 PDT) - The Silent Tunneler: A Real-World Incident Response Story - Uriel Kosayev
Maritime Hacking Village - (11:30-12:15 PDT) - Building the Humans Behind the Mission: Talent, Readiness, and Cyber Power for America’s Armed Services - Dr. Nina Kollars,Dr. Wanda T. Jones-Heath,Anne Marie Schumann
Middle Easterns & Africans in Cyber Security (MEACS) - Logsquashing: Consolidating Relevant Events Logs and Alerts - Ezz Tahoun
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - AI finds and writes my Android exploits now - Ken Gannon / 伊藤 剣
Nix Vegas Community - (11:30-11:59 PDT) - Running a homelab with NixOS - Aaron Honeycutt
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-13:50 PDT) - Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta - James Stanger,Stephen Schneiter
Noob Community - Privilege Escalation: A Career Story - Ryan Bonner,Whit Taylor
Noob Community - (11:45-12:45 PDT) - If I Were Eighteen Again: Career Advice for the AI Era - Keith Hoodlet
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - Q&A with the OSINT4Good Panel - Angela Ramos,Kenny J,Brent Louie
OSINT For Good Community - (11:45-12:15 PDT) - Welcome to OSINT4Good and Trace Labs - Nataly "someone_somewhere"
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - (11:30-11:59 PDT) - Spotlight: Choose Your Own Adventure with InfoSecMap - W. Martín Villalba
Payment Village - cont...(10:45-11:30 PDT) - The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation - Daniel Cuthbert,Leigh-Anne Galloway,Jorge Braniff,Sanjeev Sharma
Payment Village - A Real-Time Battle with a Card-Testing Adversary - Levi Schuck
Payment Village - (11:30-11:50 PDT) - Introduction to Vulnerable ATM Badge - Vincent Sloan
Policy @ DEF CON - Morbidity and Mortality: Hackers, HIPAA, and a new Prescription for Healthcare Cyber Policy - Christian Dameff,Jeff "r3plicant" Tully
Queercon Community - Trans Townhall -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(10:30-12:25 PDT) - RF CTF Kick Off Day 1 - RF Hackers
Recon Village - cont...(10:00-12:30 PDT) - Hands-On Supply Chain Recon & Vendor Risk Mapping - Dhiyaneshwaran Balasubramaniam,Aman Rawat
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - GE(O)SINT Contest -
Recon Village - cont...(10:45-11:30 PDT) - InQuorigible: Quora in Missing Persons OSINT - Miranda Tedholm
Red Team Village - cont...(10:00-17:59 PDT) - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - cont...(10:00-17:59 PDT) - BloodHound Quest - Hugo van den Toorn
Red Team Village - cont...(10:00-11:59 PDT) - Post-Exploitation of the Desktop with JS-Tap - Drew Kirkpatrick
Red Team Village - cont...(10:00-11:59 PDT) - Red Team Express - Cody Spooner
Red Team Village - cont...(10:00-11:59 PDT) - Zero Signal: Operating Where Defenders Can't See - Gowthamaraj Rajendran
Red Team Village - cont...(10:00-11:59 PDT) - Falco Hunt: Evading Runtime Detection in Kubernetes - Michael Reimsbach
Red Team Village - Trusted Launcher, Untrusted Code: Weaponizing AppLaunch.exe to bypass SmartScreen and AppLocker - Nathan Sawyer
Red Team Village - COM Hijacking Voodoo: Tradecraft, Detection Blind Spots, and the COM-Hunter - Nikos "nickvourd" Vourdas
Red Team Village - Exploiting Private 5G: Unauthenticated Access to Databases and Control Plane DoS via Fuzzing - Aumkaareshwar DS
Red Team Village - cont...(10:00-11:59 PDT) - RFID Bootcamp: Unleashed! - Evan Cook
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - (11:30-13:59 PDT) - Live Calls Workshop -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(10:00-11:30 PDT) - Pickpocketing for Red Teamers: A Hands-On Experience - pradameinhof
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - Book Signing - Nicholas DeMeo - Nicholas DeMeo
Social Gatherings/Events - Book Signing - Christopher DeCarmen - Christopher DeCarmen
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Telecom Village - SOC Threat Hunting in Practice - Akib Sayyed
The Diana Initiative - Ham Radio Village Tour -
The Diana Initiative - Packet Hacking Village Tour -
The Diana Initiative - (11:20-11:30 PDT) - Mobile Hacking Tour -
The Diana Initiative - (11:30-11:40 PDT) - Maritime Hacking Village Tour -
The Diana Initiative - (11:40-11:50 PDT) - HHV/SSV Tour -
The Diana Initiative - (11:50-11:59 PDT) - ICS Village Tour -
The Diana Initiative - cont...(10:00-11:59 PDT) - Hacker Runway Crafting Time -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Anomalies Are Not Normal: Election Foam Strikes and the Tragic Story of Mikey Hicks - Richard DeMillo
Voting Village - (11:30-11:59 PDT) - Welcome to the Voting Village - Brian DeMuth,Matt Blaze,Jake Braun,David Jefferson,Jeff Moss,Kendall Spencer,Philip Stark

 

Friday - 12:00 PDT


Return to Index  -  Locations Legend
.EDU Community - Student-Run Cyber Clubs - Why They Matter & Digital Playgrounds - Steven "Stengo" Ngo
Adversary Village - Yet Another Walking Dead of Active Directory - Nikos "nickvourd" Vourdas
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - Aerospace Cybersecurity Student Research Spotlight: ERAU - Sean McConoughey,Samuil Nikolov
Aerospace Village - (12:45-13:30 PDT) - Aerospace Cybersecurity Student Research Spotlight: Cal Poly - Clara Davis,Dylan Gururajan
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AppSec Village - cont...(11:30-12:30 PDT) - Aegis of the Vulnerable: A Unified Pipeline for AI-Based SAST - Can Oztas
AppSec Village - (12:45-13:45 PDT) - Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner - Filipi Pires
AppSec Village - cont...(10:30-12:30 PDT) - Burp, But Yours: Hands-On Extension and Bambda Development - Hannah L
AppSec Village - cont...(11:50-12:20 PDT) - A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox - Simcha Kosman
AppSec Village - (12:30-12:59 PDT) - Container Escapes Are Not Magic. Here Is How They Actually Work. - Advait Patel
AppSec Village - cont...(11:00-12:59 PDT) - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - cont...(11:00-12:59 PDT) - The Call Stack Experience - Victoria Keeler
AppSec Village - cont...(11:00-12:59 PDT) - Clash of Prompts: The World's First Prompt Battle Royale -
AppSec Village - cont...(11:00-12:59 PDT) - Hack the Duck Store - Gwendal Mognier,Samantha Pearlstein
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Blacks In Cyber Village - When the Agent Lies: Why Neurosymbolic AI is the Security Layer Nobody is Building Yet - Maureese Williams
Blacks In Cyber Village - (12:30-12:55 PDT) - Prompt Injection Detection in Large Language Models: Survey and Evaluation of Open Source Tools - Yasmin Eady
Blue Team Village - Digital Forensics 101 - Sarthak Taneja
Bug Bounty Village - Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE - Bruno Mendes,Rafael Castilho Silva
Bug Bounty Village - (12:30-12:59 PDT) - Beyond Theoretical Risk: How Cache Poisoning Escalated to Critical Account Takeover in TikTok’s Web Infrastructure - Glendon Chong
Bug Bounty Village - cont...(11:30-12:30 PDT) - Hackbots - Jason "jhaddix" Haddix,Ryan "BadAt_Computers" Bonner
Bug Bounty Village - (12:30-13:30 PDT) - AI Hacking Workshop: Bug Bounty Edition - Ben "NahamSec" Sadeghipour,Kameron "clovismint" Bettridge
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(11:00-12:59 PDT) - Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS - Samanta Aranda
Cloud Village - cont...(11:00-12:59 PDT) - Governing the Firehose: Writing Custom OPA Policies to Tame and Remediate Prowler Output - Ram "n2r"
Cloud Village - cont...(11:30-12:10 PDT) - From Pipeline to Cloud Control - Saksham Agrawal
Cloud Village - Security at Machine Speed: How Autonomous AI Agents Are Changing Cloud Defense - Pujita Sahni,Geoff Sweet
Cloud Village - (12:50-13:20 PDT) - PurpleLoop: Closing the Loop Between Detection Rules, Log Schemas, and Purple-Team Validation - Ariz Soriano
CodeBloom - Game Time: Input, Output, and Variables -
Contests - cont...(10:00-12:59 PDT) - Aw, man…pages! -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-12:59 PDT) - Octopus Game Opens and Pre-registration Check-In Available -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(11:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - BIC Village Capture the Flag (CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Contests - The EFF Benefit Poker Tournament - Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - Cryptographer Recruitment: Crack the Substitution Cipher - Bradán Lane
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - Your Packets Are Showing: Hybrid Quantum ML for Passive OS Fingerprinting - Daniel Justice,Jae Sung Kim,La Alsulaim,Shreya G Savadatti
DEF CON Talks - (12:30-13:30 PDT) - Fireside Chat with Gen. Paul Nakasone - Paul Nakasone,Jeff "The Dark Tangent" Moss
DEF CON Talks - cont...(11:30-12:30 PDT) - Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming - Marcos "h3xduck" Bajo,Ritvik "RoYalGamr" Goyal
DEF CON Talks - (12:30-13:30 PDT) - BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive - Jiří Vinopal
DEF CON Talks - (12:30-12:59 PDT) - DC101 - Nikita Kronenberg,Michael “sparky” Moore,polybius
DEF CON Talks - Shopping Is The Attack: A Decade Of E-Commerce Scalper Wars, And The Multi-Agent AI Era - Yaniv "PSYMAG" Menasherov
DEF CON Talks - (12:30-12:59 PDT) - Hacking the Government: How Two Researchers Turned Late-Night Boredom Into a National Audit - Robert "ProXy" Kruczek,Kamil Szczurowski
DEF CON Talks - cont...(11:30-12:30 PDT) - A Provider for the MOFia - Distributed Post-Ex Capabilities - Steven Flores
DEF CON Talks - (12:30-13:30 PDT) - Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet's V8 on the Galaxy S25 - Hrvoje Mišetić,Jamie Hill-Daniel,William Liu
DEF CON Talks - Can AI do novel security research? Meet the HTTP Terminator - James "albinowax" Kettle
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Offensive Packet Wizardry with Scapy - Mike "Chicolinux" Guirao
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Hands-on IoT firmware extraction and flash forensics - Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover - zeta,Rafa "bane" Gutierrez
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Web Hacking 101 - cale "calebot" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming - Jake "Hubbl3" Krasnov,Vincent "Vinnybod" Rose,Anthony "Coin" Rose,Dan Niefeld
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF - Ryan "Hackgnar" Holeman,Alek Amrani
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted - Sydney "letswastetime" Marrone
Demo Labs - Damn Vulnerable Agentic AI Application (DVAIA) - Abhinav Verma,Mukesh Aggarwal
Demo Labs - GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches - ialleejy,Kyul,HyunJun "Beaver King" Kwon
Demo Labs - VoiceLock: Offline, Robust On-Device Speech Transcription - Ayaan Qayyum,Parag Kalay
Demo Labs - Ghost in the IDE - Venkata Jayaram Yalla,Pardhiv Reddy
Demo Labs - Weaponizing eBPF and XDP with Covert Triggered Reverse Shells - Yll "0xBabar0ka" Berisha
Demo Labs - Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything - Kevin "kdrwins" Dela Rosa
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - Riot Games Vanguard: Pwn to own -
Ham Radio Village - Getting Started In Radio Direction Finding - Nate Moore
ICS Village - Threat Hunting in OT Networks - Using Hypothesis Based Methods - Michael Cardwell
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners! - Kody Kinzie
IoT Village - (12:30-13:15 PDT) - Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM - Larry Pesce
La Villa Community - cont...(11:30-12:30 PDT) - Demodus Operandi (Cómo tres rf-hacks en tres bandas terminaron siendo una metodología) - Eduardo Contreras
La Villa Community - (12:30-12:59 PDT) - O Lado Sombrio das Coisas: Transformando Dispositivos DIY em Vetores de Ataque - Christiane Borges Santos
La Villa Community - cont...(10:30-12:59 PDT) - De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS - Juan Camilo Palacio Arango,Andrés Restrepo
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - cont...(11:00-12:30 PDT) - Build-A-Badge Workshop - hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
Maker's Village - Hardhat How-to - m0nkeydrag0n,MrBill
Malware Village - (12:25-13:05 PDT) - North Korea’s Zoo: Poaching for Gophers, Armadillos and RATs - Mauro Eldritch
Malware Village - Introduction to Reverse Engineering With Ghidra - Wesley McGrew
Maritime Hacking Village - cont...(11:30-12:15 PDT) - Building the Humans Behind the Mission: Talent, Readiness, and Cyber Power for America’s Armed Services - Dr. Nina Kollars,Dr. Wanda T. Jones-Heath,Anne Marie Schumann
Maritime Hacking Village - (12:15-12:59 PDT) - Maritime Hacking Village Policy Panel: Shadow Fleets, Cyber Effects, and Plausible Deniability - RADM John Mauger,Michael Sulmeyer
Middle Easterns & Africans in Cyber Security (MEACS) - Once Upon a Prompt: Fairy Tales That Explain AI Security - Sana Talwar
Misc - From Disk Image to ATT&CK in One Binary — a Reference Architecture for Modern Incident Response (in Rust) - HUI Kwun Tai, Albert (4n6h4x0r)
Misc - Friendship Bracelets -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - (12:15-12:45 PDT) - Offensive Security from Your Pocket - Lukas Stefanko
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-13:50 PDT) - Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta - James Stanger,Stephen Schneiter
Noob Community - cont...(11:45-12:45 PDT) - If I Were Eighteen Again: Career Advice for the AI Era - Keith Hoodlet
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(11:45-12:15 PDT) - Welcome to OSINT4Good and Trace Labs - Nataly "someone_somewhere"
OSINT For Good Community - (12:30-13:15 PDT) - Geolocating Talent: How OSINT CTFs are Building Tomorrow's Analysts - Ben "The Cyber Sensei" Crenshaw
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - OWASP ISTG in Practice: A CTF-Style IoT Hacking & Defending Lab - Piero "p33_p33_" Picasso,Aaron Guzman
Payment Village - Skimmers, Shimmers, and You - Aidan Quimby
Physical Security Village - Flow Like Water: Experiences from Physical Red Teaming - Michael "v3ga" Aguilar
Physical Security Village - (12:30-12:59 PDT) - Introduction to RFID - Ege Feyzioglu,Karen Ng
Policy @ DEF CON - Election Security in the Age of AI: Governance, Trust, and the Systems Behind Democracy - Lester Godsey,William Gates,Tim Harper
Queercon Community - QueerCon Opening Meet and Greet -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(10:30-12:25 PDT) - RF CTF Kick Off Day 1 - RF Hackers
Radio Frequency Village - (12:30-13:25 PDT) - Let's BLESPlo.it the world together - introducing a new portable Bluetooth Low Energy security tool - Slawomir Jasek
Recon Village - cont...(10:00-12:30 PDT) - Hands-On Supply Chain Recon & Vendor Risk Mapping - Dhiyaneshwaran Balasubramaniam,Aman Rawat
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - (12:40-15:10 PDT) - Threat Actors: Gotta Catch 'Em All - Marcelle Lee,Will Thomas
Red Team Village - cont...(10:00-17:59 PDT) - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - cont...(10:00-17:59 PDT) - BloodHound Quest - Hugo van den Toorn
Red Team Village - Burning Redirectors Before Blue Team Does - Mohamed AbuMuslim,Saad Nasir
Red Team Village - From Application Telemetry Exposure to Cross-Service Pivoting and Full Azure Tenant Takeover - Chirag Savla,Raunak "Trouble1" Parmar
Red Team Village - Web Hacking Bootcamp - Emma Latuszek
Red Team Village - Your Passkeys Won't Save You: Conditional Access Bypass via Auth-Method Downgrade - Doug Mooney,Jared Dobbelaer,Jon Rhodes
Red Team Village - macOS Doesn’t Get Malware…Until It Does - Zoziel Freire
Red Team Village - BloodHound OpenGraph Crash Course - JD D
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(11:30-13:59 PDT) - Live Calls Workshop -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - Improv -
Social Engineering Community Village - Zero Day Hire: Can You Spot the Spy? - Michael Reimsbach,Rishi "rxerium" C
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Friends of Bill W -
Telecom Village - cont...(11:00-12:30 PDT) - SOC Threat Hunting in Practice - Akib Sayyed
Telecom Village - (12:30-13:15 PDT) - Poor Man's Mythos: Signal Siege: Agentic Exploit Chains Across the 5G Cloud-Native Stack - Omer Farooq
The Diana Initiative - DEF CON Academy Tour -
The Diana Initiative - DC Maker's Community Tour -
The Diana Initiative - (12:20-12:30 PDT) - Cryptocurrency Village Tour -
The Diana Initiative - (12:30-12:40 PDT) - Car Hacking Village Tour -
The Diana Initiative - (12:40-12:50 PDT) - Call Center Tour -
The Diana Initiative - (12:50-12:59 PDT) - DDoS Community Tour -
The Diana Initiative - The Diana Initiative - Open time -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Voting Village Keynote - The Paper Chase - Kevin Shelley

 

Friday - 13:00 PDT


Return to Index  -  Locations Legend
.EDU Community - ScamBusters: Turning Undergrads into Threat Hunters - Angela "BlondeTechie" Ramos
Adversary Village - (13:15-13:59 PDT) - From threat-intel to tested defense, the adversary simulation playbook - Cheryl Biswas,Adam Pennington,Olaf Hartong,Sarah Hume
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(12:45-13:30 PDT) - Aerospace Cybersecurity Student Research Spotlight: Cal Poly - Clara Davis,Dylan Gururajan
Aerospace Village - (13:30-13:59 PDT) - Hacking Airplanes at the NTSB - David Case,Jonathan Xue
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AppSec Village - cont...(12:45-13:45 PDT) - Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner - Filipi Pires
AppSec Village - (13:30-13:59 PDT) - Agentic Chaos - What 86K+ Agent Codebases Reveal About 700K+ Exposed AI Systems - Bar Kaduri,Lidan
AppSec Village - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - AI Pentesting Trivia Showdown - Andy Dennis,Bill Reyor
AppSec Village - Factory Floor MVP Incident Response Challenge -
AppSec Village - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Blacks In Cyber Village - CTRL the Chaos: When AI Controls Critical Infrastructure - Nykolas Muldrow
Blue Team Village - (13:15-14:15 PDT) - TBA -
Bug Bounty Village - cont...(12:30-13:30 PDT) - AI Hacking Workshop: Bug Bounty Edition - Ben "NahamSec" Sadeghipour,Kameron "clovismint" Bettridge
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Cloud Village - (13:30-15:30 PDT) - Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense - Kyle Hubbard
Cloud Village - (13:30-14:30 PDT) - The Autonomous Security Loop - Jeremy Schiefer,Lawton Pittenger
Cloud Village - cont...(12:50-13:20 PDT) - PurpleLoop: Closing the Loop Between Detection Rules, Log Schemas, and Purple-Team Validation - Ariz Soriano
Cloud Village - (13:20-13:59 PDT) - The Hidden Cost of Agentic Connectivity - David Fiser,Amy McMahon
CodeBloom - What is AI? - Sam Mosley
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed) -
Contests - (13:30-14:59 PDT) - Octopus Game - Booth Battle #1: The Front Man's Wager -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - Locktopus - Open Qualifying -
Contests - cont...(11:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - SEC Vishing Competition (SECVC) -
Contests - Pub Quiz at DEF CON -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Contests - cont...(12:00-14:59 PDT) - The EFF Benefit Poker Tournament - Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton
Crypto & Privacy Village - Trust the Basics, But Know Their Limits: Where Standard Cybersecurity Advice Falls Short - Yael Grauer
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
Data Duplication Village - Forcing Physical Interlocks into Data Transit and Storage Replication - Mehmet Önder Key,Temel Demir
DCNextGen - Locked Out? Let's Fix That: An Introduction to the Art of Lockpicking - Greg Anderson
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Groups - (13:30-14:30 PDT) - Darknet Diaries Meet & Greet with Jack Rhysider - Jack Rhysider
DEF CON Talks - cont...(12:30-13:30 PDT) - Fireside Chat with Gen. Paul Nakasone - Paul Nakasone,Jeff "The Dark Tangent" Moss
DEF CON Talks - (13:30-14:59 PDT) - What is the Right Balance of Rules for Defenders & Adversaries? Determining which dual-use model restrictions make sense and which only disarm defenders - Emanuel Gawrieh,Jason Clinton,Bruce Schneier,Heather Adkins
DEF CON Talks - cont...(12:30-13:30 PDT) - BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive - Jiří Vinopal
DEF CON Talks - (13:30-14:30 PDT) - Breaking into Amazon lockers by any means necessary - Martin Vigo
DEF CON Talks - LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails - Aviv Donenfeld
DEF CON Talks - cont...(12:30-13:30 PDT) - Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet's V8 on the Galaxy S25 - Hrvoje Mišetić,Jamie Hill-Daniel,William Liu
DEF CON Talks - (13:30-14:30 PDT) - Plug And Pwn: Weaponizing Windows PnP Auto-Install - Alejandro "0xedh" Hernando,Borja "borjmz" Martinez
DEF CON Talks - Bring-Your-Own-EDR - Breaking Windows Process Protection to build EDR-Protected Malware - Shahak Morag
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
Demo Labs - xEndity: IoT Firmware Analysis & Digital Twin Platform - Zeus "LightningGod" Chan,Kenneth "kenleejl" Lee
Demo Labs - MSCodePhish: Redeem Your Coupon. Surrender Your Session - Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla
Demo Labs - Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface - Gannon "Dorf" Gebauer,Anthony "Coin" Rose,Hana Christensen
Demo Labs - Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection - Ankit Vashisth
Demo Labs - Beyond Spidering: Behavior Driven DAST for Real Application Workflows - Sara "testingSoul" Martinez
Demo Labs - Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF - Buğrahan Yücel
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - cont...(12:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Hackers.town - The Cum-Stained Precipice of Digital Redlining - Erica Rachel Andrews,Abbie Gonzalez (pronounced AB)
Hackers.town - Liberate your Music with Tech Reclaimers - RemoteNemesis
Ham Radio Village - Ham Radio Isn’t Magic: Preppers, Sad Hams, and Practical Off-Grid Communications - Andrew Ohnstad - N3OCQ
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(12:00-13:30 PDT) - Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners! - Kody Kinzie
IoT Village - (13:45-15:15 PDT) - Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum! - Kody Kinzie
IoT Village - cont...(12:30-13:15 PDT) - Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM - Larry Pesce
La Villa Community - AImaru C2: La Nueva Era del Living off the Land (MCP AI-Driven C2 ) - Mario Lobo
Lockpick Village - Intro to Lockpicking -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Malware Village - cont...(12:25-13:05 PDT) - North Korea’s Zoo: Poaching for Gophers, Armadillos and RATs - Mauro Eldritch
Malware Village - (13:15-13:55 PDT) - Return of Sedinho: Current situation and new tactics of the Brazilian banking trojan ecosystem - Josep Albors
Malware Village - cont...(12:10-14:10 PDT) - Introduction to Reverse Engineering With Ghidra - Wesley McGrew
Maritime Hacking Village - (13:45-14:15 PDT) - Drag, Drop, Deploy, Compromise: Why Trusted HMI Engineering Toolchains Remain an ICS Supply-Chain Blind Spot - Jiwoon Yoo,TaeWoo Kim,Eunji choi
Middle Easterns & Africans in Cyber Security (MEACS) - Nothing Wrong Here: Why AI Artifact Scanners Wave Malware Through - Amber Bennoui
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - Hacking Android Apps in a Structured Way - Sven Schleier
Nix Vegas Community - Whose PR Is It Anyway? -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-13:50 PDT) - Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta - James Stanger,Stephen Schneiter
Noob Community - Threatmaxxing Your Stakeholders while Mogging Your Threat Actors: What is Cyber Threat Intel? - Eli Woodward
Noob Community - (13:30-13:59 PDT) - OSINT: Zero To Hero - Mishaal Khan
OSINT For Good Community - (13:30-14:30 PDT) - Classical OSINT using AI (Actual Intelligence) - Bianca C. Ionescu/reconcerto
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(12:30-13:15 PDT) - Geolocating Talent: How OSINT CTFs are Building Tomorrow's Analysts - Ben "The Cyber Sensei" Crenshaw
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - cont...(12:00-13:59 PDT) - OWASP ISTG in Practice: A CTF-Style IoT Hacking & Defending Lab - Piero "p33_p33_" Picasso,Aaron Guzman
Payment Village - (13:30-13:59 PDT) - It's a Payment Terminal. It's My Arcade. It's Everywhere. It Cost Me Nine Bucks. - Chiao-Lin Yu "Steven Meow"
Payment Village - Wall of Wallets Workshop (Intro to Wall of Wallets Challenge) - Dan Borgogno
Policy @ DEF CON - Connectivity as Control in the European High North - Szymon Skalski,Patricia Vargas Leon,Jorge Acevedo Canabal
Policy @ DEF CON - The Cyber Crystal Ball: The Annual Policy @ DEF CON Contingencies Survey - Matthew Wein,Bruce Schneier,Chris Painter,Heather West
Queercon Community - Non-Binary/Gender Non-conforming Meetup -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(12:30-13:25 PDT) - Let's BLESPlo.it the world together - introducing a new portable Bluetooth Low Energy security tool - Slawomir Jasek
Radio Frequency Village - (13:30-14:25 PDT) - Fox Hunting - Finding Rogue Access Points in the CTF and in the Wild - Eric Escobar
Radio Frequency Village - Running your own LTE network for fun and profit???? - Lozaning
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(12:40-15:10 PDT) - Threat Actors: Gotta Catch 'Em All - Marcelle Lee,Will Thomas
Recon Village - OSINT Is Still a Thinking Game: Surviving AI Without Losing Tradecraft - Nico Dekens
Red Team Village - cont...(10:00-17:59 PDT) - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - cont...(10:00-17:59 PDT) - BloodHound Quest - Hugo van den Toorn
Red Team Village - cont...(12:00-13:59 PDT) - Burning Redirectors Before Blue Team Does - Mohamed AbuMuslim,Saad Nasir
Red Team Village - cont...(12:00-13:59 PDT) - From Application Telemetry Exposure to Cross-Service Pivoting and Full Azure Tenant Takeover - Chirag Savla,Raunak "Trouble1" Parmar
Red Team Village - cont...(12:00-13:59 PDT) - Web Hacking Bootcamp - Emma Latuszek
Red Team Village - cont...(12:00-13:59 PDT) - Your Passkeys Won't Save You: Conditional Access Bypass via Auth-Method Downgrade - Doug Mooney,Jared Dobbelaer,Jon Rhodes
Red Team Village - Shapeshifting C2: Applying DAITA Traffic Shaping to Defeat DPI and DLP Detection - Rafael Felix
Red Team Village - One Request to Rule Them All - Corey Ball
Red Team Village - BloodHound OpenGraph: Six Degrees of Everything - Rohan Vazarkar,Wes Miller
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(11:30-13:59 PDT) - Live Calls Workshop -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - (13:30-14:30 PDT) - Zero Day Hire: Can You Spot the Spy? - Michael Reimsbach,Rishi "rxerium" C
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - Book Signing - Brandy Smith - Brandy Smith
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Free Ham Radio License Exams -
Telecom Village - cont...(12:30-13:15 PDT) - Poor Man's Mythos: Signal Siege: Agentic Exploit Chains Across the 5G Cloud-Native Stack - Omer Farooq
The Diana Initiative - Cloud Village Tour -
The Diana Initiative - Telecom Village Tour -
The Diana Initiative - (13:20-13:30 PDT) - DEF CON Groups (DCG) Tour -
The Diana Initiative - (13:30-13:40 PDT) - Aerospace Village Tour -
The Diana Initiative - (13:40-13:50 PDT) - Bug Bounty Village Tour -
The Diana Initiative - (13:50-13:59 PDT) - La Villa Tour -
The Diana Initiative - Stigma is stupid: Let's talk about recovery, mental wellness, and hard stuff without making it awkward - Jennifer VanAntwerp
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - (13:30-13:59 PDT) - Publicly Auditable Elections - Josh Benaloah

 

Friday - 14:00 PDT


Return to Index  -  Locations Legend
.EDU Community - Hacking Education - Teaching Offensive Cyber Science at the Collegiate Level - Dave "Rebelcadet" Ortiz
Adversary Village - 6 years of Adversary Village! Keeping up with the adversaries and why it takes a village - Abhijith "Abx" B R,Bryson Bort,Anant Shrivastava
Adversary Village - (14:45-15:15 PDT) - SEND: Teaching Machines to Lie to Defenders - Yi Ting Shen,Ariz Soriano
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - Fooling Coding Agents for Fun and Profit - Matt Galligan,Jack Cable
AppSec Village - Farsight: Turning OSINT into Actionable Attack Surface Intelligence - Arif,Sai Vernekar,Seedon D'Souza,kvprashant
AppSec Village - (14:30-16:59 PDT) - Container Escapes 101 - some-natalie
AppSec Village - from_pretrained() to from_pwned(): Breaking HuggingFace's Trust - Yotam Perkal
AppSec Village - (14:50-15:20 PDT) - GeoHacking: from memory corruption RCE to cross tenant access - Michal Kamensky
AppSec Village - cont...(13:00-14:59 PDT) - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - cont...(13:00-14:59 PDT) - AI Pentesting Trivia Showdown - Andy Dennis,Bill Reyor
AppSec Village - cont...(13:00-14:59 PDT) - Factory Floor MVP Incident Response Challenge -
AppSec Village - cont...(13:00-14:59 PDT) - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Blacks In Cyber Village - Agents on Alert: Building an AI-Powered Threat Investigation Framework - Samson Adewale
Blue Team Village - cont...(13:15-14:15 PDT) - TBA -
Blue Team Village - (14:30-15:30 PDT) - Building Project Obsidian: Designing the Blue Team CTF for DEF CON - Carlo Anez Mazurco,Chris "dafinga" Maenner,Omenscan ~,Paul Goffar
Bug Bounty Village - AI Nightmare: Hacking at 0-Hour - Pedro "drop" Paniago
Bug Bounty Village - Navigating AI-Assisted Submissions - Tony Lee,Michael Skelton,Alexander Wren,Selim Jaafar,Shlomie "shlibness" Liberow
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(13:30-15:30 PDT) - Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense - Kyle Hubbard
Cloud Village - cont...(13:30-14:30 PDT) - The Autonomous Security Loop - Jeremy Schiefer,Lawton Pittenger
Cloud Village - Nebula - 5 years, still kicking *aaS - Bleon "gl4ssesbo1" Proko
Cloud Village - (14:30-15:10 PDT) - Citizen Developers Can't Defend What They Built: Scaling Security Past the Security Team -
CodeBloom - Work Session: Ciphers -
Contests - DEF CON Beard and Mustache Contest -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(13:30-14:59 PDT) - Octopus Game - Booth Battle #1: The Front Man's Wager -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(13:00-17:59 PDT) - Locktopus - Open Qualifying -
Contests - cont...(11:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(13:00-15:59 PDT) - SEC Vishing Competition (SECVC) -
Contests - cont...(13:00-14:59 PDT) - Pub Quiz at DEF CON -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Contests - cont...(12:00-14:59 PDT) - The EFF Benefit Poker Tournament - Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton
Crypto & Privacy Village - (14:30-14:59 PDT) - You're Probably Using FPE Wrong - Leslie Gutschow
Crypto & Privacy Village - Inside the Guts of Ransomware - Ashley Hiram Muñoz
Cryptocurrency Village - Cryptohack Badge Hacking - Do Truong Giang "FSNaix",Sadiq "Sdqmd",Arjun "Peper" Suresh
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - Hack the Airwaves – Embedded Wireless for Next-Gen Hackers - Adventures of Illya
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Groups - cont...(13:30-14:30 PDT) - Darknet Diaries Meet & Greet with Jack Rhysider - Jack Rhysider
DEF CON Talks - cont...(13:30-14:59 PDT) - What is the Right Balance of Rules for Defenders & Adversaries? Determining which dual-use model restrictions make sense and which only disarm defenders - Emanuel Gawrieh,Jason Clinton,Bruce Schneier,Heather Adkins
DEF CON Talks - cont...(13:30-14:30 PDT) - Breaking into Amazon lockers by any means necessary - Martin Vigo
DEF CON Talks - (14:30-15:30 PDT) - WASM Was Not the Boundary: Sandcastles, Not Sandboxes - Saar Pearl,Vladimir "G1ND1L4" Tokarev
DEF CON Talks - 8 Out of 10 Banks in Belgium HATE This One Weird eID RCE - James "Acorn221" Arnott
DEF CON Talks - cont...(13:30-14:30 PDT) - Plug And Pwn: Weaponizing Windows PnP Auto-Install - Alejandro "0xedh" Hernando,Borja "borjmz" Martinez
DEF CON Talks - (14:30-14:59 PDT) - Lowering the Orbit: Exploiting Satellite Protocols and communications via Software-Defined-Radio and GS - Romel "r0r0x" Marin
DEF CON Talks - Lessons from a decade of building whistleblower tech - Trevor Timm,redshiftzero
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response - Vince "bitpusher" Weppner
DEF CON Workshops - Sold Out - OT Systems: how to secure them in practice! - Alexandrine Torrents,Arnaud SOULLIE
DEF CON Workshops - Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity - Rodrigo "Sp0oKeR" Montoro
DEF CON Workshops - Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models - John "clearbluejar" McIntosh
DEF CON Workshops - Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer - Darcy "@Drc3p0" Neal
DEF CON Workshops - Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding! - Ryan "@rj_chap" Chapman,Aaron "Ironical" Rosenmund
DEF CON Workshops - Sold Out - Introduction to Malware Analysis - Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus
DEF CON Workshops - Sold Out - Embedded Computing Tools for Wireless Hardware Hacking - Joseph Long
Demo Labs - SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked. - Hemanth Gorijala
Demo Labs - MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems - Nur "BurritoTheNurrito" Gucu
Demo Labs - Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds - Kyler McElroy,Anita Ding,Daniel Koranek
Demo Labs - AzProwl: Prowling the Azure Attack Surface - Jared "GonePhishing402" Graff,Jeff Daniels
Demo Labs - L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security - Abhinav Khanna,Krishna Chaganti
Demo Labs - Trajan: Cross-Platform CI/CD Security Scanner - Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - cont...(12:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Game Hacking Village - iOS Game Hacking : From Zero to G0D Mode - M41w4r3
Game Hacking Village - (14:45-15:45 PDT) - Your Lives are in Another Struct: Breaking Memory Hacks with Field Relocation - Ryan Zmuda
Hackers.town - Too Much "Slop" and Not Enough Soul: Why the AI Music Bubble is Leaking & Robots Shouldn't Replace Our Djs - RabidMoosery
Ham Radio Village - (14:30-15:10 PDT) - Who Owns Your Shack? Open Source, Amateur Radio, and the Software We Can't Afford to Lose - Jeremy Banker - K0JLB
ICS Village - (14:30-14:59 PDT) - ICSForge: (Open-Source) OT/ICS Security Coverage Validation Platform - Can Kurnaz
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(13:45-15:15 PDT) - Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum! - Kody Kinzie
La Villa Community - Point of Failure: Autopsia de una Terminal de Pago - Erik Alcantara
La Villa Community - PentestGPT: The Art of Hacking with Words - Matias Armándola
Lockpick Village - (14:30-14:59 PDT) - Intro to Lockpicking -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - Build-A-Badge Workshop - hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
Malware Village - Smart Contracts, Smarter Malware: Automating Recon on Blockchain-Based C2 - Sai Sathvik Ruppa,Chris Navarrete
Malware Village - (14:55-15:35 PDT) - The State of Decompiler Malware - Christopher Hernandez
Malware Village - cont...(12:10-14:10 PDT) - Introduction to Reverse Engineering With Ghidra - Wesley McGrew
Malware Village - The Achaean project-Trojan development for noobs - Leigh Gilbert
Maritime Hacking Village - cont...(13:45-14:15 PDT) - Drag, Drop, Deploy, Compromise: Why Trusted HMI Engineering Toolchains Remain an ICS Supply-Chain Blind Spot - Jiwoon Yoo,TaeWoo Kim,Eunji choi
Maritime Hacking Village - (14:15-14:45 PDT) - Scuttling Dashboards - Karan Sajnani
Middle Easterns & Africans in Cyber Security (MEACS) - The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack? - Karol Piekarski,Nishith Sinha
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(13:00-14:30 PDT) - Hacking Android Apps in a Structured Way - Sven Schleier
Nix Vegas Community - Relocatable Nix Binaries - Farid Zakaria
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR - Tony Martin-Vegue
Noob Community - (14:15-14:45 PDT) - Day in the Life - Green Beret to AI Penetration Tester - Clayton Boozell
OSINT For Good Community - cont...(13:30-14:30 PDT) - Classical OSINT using AI (Actual Intelligence) - Bianca C. Ionescu/reconcerto
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - (14:30-14:59 PDT) - Q&A with the Classical OSINT Using AI speaker - Bianca C. Ionescu/reconcerto
OWASP Foundation - (14:30-15:15 PDT) - Defend zee clankers: OWASP AI Security Verification Standard (AISVS) - Jim Manico
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - Life Finds a Way: Secure Coding with OWASP ASVS - Eden Yardeni
Packet Hacking Village - (14:30-15:30 PDT) - Wiring the Harness: Orchestrating Frontier Models for Vulnerability Hunting at Scale - Tony Martin,Arie Haenel
Payment Village - How to Epically Fail Your PCI Assessment - Kevin Buck
Policy @ DEF CON - The Liability Stack: When Code Becomes Conduct - Carole House
Policy @ DEF CON - Strengthening the CVE Ecosystem (Seating is limited to 50 Participants) - John Banghart,Elizabeth Eigner,Lisa Olsen,Lindsey Cerkovnik
Queercon Community - Women Loving Women Meetup -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(13:30-14:25 PDT) - Fox Hunting - Finding Rogue Access Points in the CTF and in the Wild - Eric Escobar
Radio Frequency Village - (14:30-14:55 PDT) - Security Vulnerabilities in SATCOM Devices - Aumkaareshwar DS
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(12:40-15:10 PDT) - Threat Actors: Gotta Catch 'Em All - Marcelle Lee,Will Thomas
Red Team Village - cont...(10:00-17:59 PDT) - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - cont...(10:00-17:59 PDT) - BloodHound Quest - Hugo van den Toorn
Red Team Village - Cloud-Native C2: Weaponizing Trusted Infrastructure for Initial Access - Dhiraj Mishra
Red Team Village - Quality over Quantity: How to Publish CVEs that Actually Matter - Natan Morette
Red Team Village - Automated Mythic Deployment with Gaia - Shad Brown
Red Team Village - Social Engineering With Reel - James Williams
Red Team Village - Microsoft and Amazon are my Favorite C2 Providers - Robert Pimentel
Red Team Village - Extension Hollowing: Abusing Chrome's Extension Trust Model - Gordon Long
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - Live Call Listening -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(13:30-14:30 PDT) - Zero Day Hire: Can You Spot the Spy? - Michael Reimsbach,Rishi "rxerium" C
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - Book Signing - Garrett Gee - Garrett Gee
Social Gatherings/Events - Book Signing - Laura Scherling - Laura Scherling
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Hacker Book Club Discussion -
Social Gatherings/Events - cont...(13:00-15:59 PDT) - Free Ham Radio License Exams -
Telecom Village - (14:15-14:59 PDT) - Protecting Humans at Machine Speed - Engineering AI to Stop Spam, Scams & Digital Fraud at Telecom Scale - Arvind Singh
The Diana Initiative - The Diana Initiative - Open time -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Evidence-Based Elections and Risk-Limiting Audits - Philip Stark

 

Friday - 15:00 PDT


Return to Index  -  Locations Legend
Adversary Village - cont...(14:45-15:15 PDT) - SEND: Teaching Machines to Lie to Defenders - Yi Ting Shen,Ariz Soriano
Adversary Village - (15:15-15:45 PDT) - Hey Adversary, I’ve Got a Human EDR Bypass for You… - Daniel Isler
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - Drones, Detectors, and the Kill Chain - Greg Albrecht
Aerospace Village - (15:30-15:59 PDT) - Cleared for Takeoff: Debunking “Uncertifiable” Cybersecurity - Katie Fejer
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - Pwning the Internet of Agents: Zero-Click Backdoors in OpenClaw and a Global Agent Botnet on MoltBook - João Maria Campos Donato,Stav Cohen
AppSec Village - (15:15-16:15 PDT) - IDEViewer - Securing Developer Workstations from IDE Supply Chain Threats - securient
AppSec Village - cont...(14:30-16:59 PDT) - Container Escapes 101 - some-natalie
AppSec Village - cont...(14:50-15:20 PDT) - GeoHacking: from memory corruption RCE to cross tenant access - Michal Kamensky
AppSec Village - (15:30-15:59 PDT) - Zero Trust Kubernetes Security: Preventing Real World Container Attacks - Janakiram Meka
AppSec Village - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - AI Pentesting Trivia Showdown - Andy Dennis,Bill Reyor
AppSec Village - SBOM Find the Flaws - Dmitry Raidman
AppSec Village - NPM Imposters - The malware detection card game - Mackenzie
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - (15:45-16:30 PDT) - Snap, Crackle, Popped: How to manage a massive cyber attack - David Nathans
Blacks In Cyber Village - The Cost of Unverified Intelligence: AI and Accountability in Defense Operations - Kayrene Woods
Blacks In Cyber Village - (15:30-15:55 PDT) - Configuring Your Favorite Platforms to Prioritize DNS - Malachi Walker,Anthony Johnson
Blue Team Village - cont...(14:30-15:30 PDT) - Building Project Obsidian: Designing the Blue Team CTF for DEF CON - Carlo Anez Mazurco,Chris "dafinga" Maenner,Omenscan ~,Paul Goffar
Blue Team Village - (15:45-16:45 PDT) - The Modern Detection Engineer - Alex Hurtado,Chase Phelps,Chris Kulakowski,Christina Parry,Zack Allen
Bug Bounty Village - Cache Key Injection: Smuggling Poison Through the Door - Alex Brumen
Bug Bounty Village - (15:30-15:59 PDT) - Hunting for Cryptographic Ghosts: A Bug Hunter’s Guide to Signature Malleability and Replay Attacks in EVM Bridges & Multi-Sigs - Samet Berk Simsek,Ahmet Furkan Aydogan
Bug Bounty Village - a [REDACTED] history of this hobby - Chris "flyingtoasters" Holt,Michael Skelton
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Call Center Village - An Intrusion in the Living Room is now an international incident: SuperBOX Part 3 - D3adA55
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(13:30-15:30 PDT) - Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense - Kyle Hubbard
Cloud Village - cont...(14:30-15:10 PDT) - Citizen Developers Can't Defend What They Built: Scaling Security Past the Security Team -
Cloud Village - Go with the Flow: Riding GCP Dataflow Shadow Dependency to Cross-Tenant Compromise - Gil Weizman,Tamir Yehuda
Cloud Village - (15:30-16:10 PDT) - The Polymorphic Agent: From Cross Agent Escalation to Just in Time Defense on Azure - Muskan Tomar
CodeBloom - Game Time: Input, Output, and Variables -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(13:00-17:59 PDT) - Locktopus - Open Qualifying -
Contests - cont...(11:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(13:00-15:59 PDT) - SEC Vishing Competition (SECVC) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - (15:45-16:30 PDT) - Step Zero: Identifying the Quantum Attack Surface in Critical Infrastructure - Dr. Katrina Rosseini,Dr. Allan Friedman
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - Level Up - Could your Gaming Talents be Perfect for a Career in Cyber Security? - The Hacking Games
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - The Stream Is Dead, Long Live the Stream: How HTTP/2 Lets Dead Streams Keep Servers Working - Gal Bar Nahum
DEF CON Talks - cont...(14:30-15:30 PDT) - WASM Was Not the Boundary: Sandcastles, Not Sandboxes - Saar Pearl,Vladimir "G1ND1L4" Tokarev
DEF CON Talks - (15:30-16:30 PDT) - Your Bank Thinks I'm You: A Complete Kill Chain Against Mobile Banking Security - Xavier "@xaferima" Riofrio Machado,Alex Tipan
DEF CON Talks - Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Underground VPN Infrastructure - Assaf Morag
DEF CON Talks - Pwning Rekordbox: Unauthenticated filesystem access in the world's most popular DJ software - Christopher "TRIODE" Le
DEF CON Talks - (15:30-16:30 PDT) - Riding for Free - Breaking Public Transport RFID at Scale - Aidan "luu176" Nakache
DEF CON Talks - Data Tomb Raider: Raiding Modern AI Vaults with Legacy Flaws for Treasure Stealing - Dolev Taler,Mark Vaitsman
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response - Vince "bitpusher" Weppner
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - OT Systems: how to secure them in practice! - Alexandrine Torrents,Arnaud SOULLIE
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity - Rodrigo "Sp0oKeR" Montoro
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models - John "clearbluejar" McIntosh
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer - Darcy "@Drc3p0" Neal
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding! - Ryan "@rj_chap" Chapman,Aaron "Ironical" Rosenmund
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Introduction to Malware Analysis - Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Embedded Computing Tools for Wireless Hardware Hacking - Joseph Long
Demo Labs - GhostCatcher (endpoint detection agent) - Sercan Okur
Demo Labs - Intercept.js: Runtime-Aware Detection for JavaScript Environments - Rishi Kant
Demo Labs - BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems - Adam "w00tock" Toscher
Demo Labs - AzProwl: Prowling the Azure Attack Surface - Jared "GonePhishing402" Graff,Jeff Daniels
Demo Labs - TokenMesh: Exposing Azure's Hidden Identity Attack Surface - Saksham Agrawal
Demo Labs - pymsi: Interactive MSI Installer Analysis in Python and the Browser - Ryan "Nightlark" Mast
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - cont...(12:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Game Hacking Village - cont...(14:45-15:45 PDT) - Your Lives are in Another Struct: Breaking Memory Hacks with Field Relocation - Ryan Zmuda
Hackers.town - The Political economy of AI - Janet Vertesi
Ham Radio Village - cont...(14:30-15:10 PDT) - Who Owns Your Shack? Open Source, Amateur Radio, and the Software We Can't Afford to Lose - Jeremy Banker - K0JLB
Ham Radio Village - (15:30-16:18 PDT) - Advanced Topics in LoRa Meshes - Eric Escobar
ICS Village - OT Segmentation Under Operational Constraints - Tony Turner
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(13:45-15:15 PDT) - Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum! - Kody Kinzie
IoT Village - (15:45-17:15 PDT) - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
La Villa Community - El regreso de Sedinho: situación actual y nuevas tácticas de los troyanos bancarios brasileños - Josep Albors
La Villa Community - (15:30-15:59 PDT) - State Desync as a Weapon: Breaking Transactional Integrity in Payment Systems (ESP) - Santiago Sepúlveda Veliz
La Villa Community - cont...(14:00-15:59 PDT) - PentestGPT: The Art of Hacking with Words - Matias Armándola
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - cont...(14:00-15:30 PDT) - Build-A-Badge Workshop - hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
Maker's Village - Cyberdeck Build - Sk!tz0
Malware Village - cont...(14:55-15:35 PDT) - The State of Decompiler Malware - Christopher Hernandez
Malware Village - (15:45-16:25 PDT) - Vibe Check: Exploiting Developer Trust from Prompt Injections to Weaponized Repos - Michael Chan
Malware Village - cont...(14:10-17:25 PDT) - The Achaean project-Trojan development for noobs - Leigh Gilbert
Middle Easterns & Africans in Cyber Security (MEACS) - The New Horizons in Quantum and Space - Anshu Gupta
Misc - (15:30-16:30 PDT) - tAIrot Readings -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - Mobile Security through Obscurity, from insecure client-side encryption to unauthenticated SQL - Juan Urbano Stordeur,Juan Martinez Blanco
Nix Vegas Community - Everything is Nix when you squint hard enough - Jared
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(14:00-15:20 PDT) - Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR - Tony Martin-Vegue
Noob Community - The impact of CTF Write-Ups - Mathias Detmers
Noob Community - (15:30-16:59 PDT) - Introduction to Web Exploitation - Roman Bohuk
Noob Community - (15:30-15:45 PDT) - Lessons Learned From A Decade of Resumes - Britt Kemp
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - (15:30-16:30 PDT) - Trace Labs L100: Search Party Basics - Sarah "scba" Miller
OWASP Foundation - cont...(14:30-15:15 PDT) - Defend zee clankers: OWASP AI Security Verification Standard (AISVS) - Jim Manico
OWASP Foundation - (15:15-15:59 PDT) - Forged in fire: Malware Factory - Jon McCoy,Andra Lezza
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - cont...(14:00-15:59 PDT) - Life Finds a Way: Secure Coding with OWASP ASVS - Eden Yardeni
Packet Hacking Village - cont...(14:30-15:30 PDT) - Wiring the Harness: Orchestrating Frontier Models for Vulnerability Hunting at Scale - Tony Martin,Arie Haenel
Payment Village - Deepfake Detection Through Adversarial Research - Efim Boieru
Physical Security Village - (15:30-15:59 PDT) - Forensics of Covert Entry - Bill Graydon,Bobby Graydon
Policy @ DEF CON - (15:30-16:30 PDT) - Privacy's Defender: How Hackers Protected the Internet Before and Can Do It Again - Cindy Cohn
Policy @ DEF CON - cont...(14:00-15:30 PDT) - Strengthening the CVE Ecosystem (Seating is limited to 50 Participants) - John Banghart,Elizabeth Eigner,Lisa Olsen,Lindsey Cerkovnik
Policy @ DEF CON - (15:30-16:30 PDT) - When AI Finds Everything: Vulnerability Policy for the Coming Discovery Surge - Alec Summers,Lindsey Cerkovnik,Madison Ficorelli
Queercon Community - Furs and Kinksters Meetup -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - Hack the Planet (not ours) - Abraxas3d
Radio Frequency Village - (15:30-16:25 PDT) - AI-assisted RF Hacking with GNU Radio - Erwin Karincic (Dollarhyde)
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(12:40-15:10 PDT) - Threat Actors: Gotta Catch 'Em All - Marcelle Lee,Will Thomas
Recon Village - (15:30-17:59 PDT) - BBOT: Automating the OSINT Kill Chain with a Single Command - Mark Gaddy
Red Team Village - cont...(10:00-17:59 PDT) - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - cont...(10:00-17:59 PDT) - BloodHound Quest - Hugo van den Toorn
Red Team Village - cont...(14:00-15:59 PDT) - Cloud-Native C2: Weaponizing Trusted Infrastructure for Initial Access - Dhiraj Mishra
Red Team Village - cont...(14:00-15:59 PDT) - Quality over Quantity: How to Publish CVEs that Actually Matter - Natan Morette
Red Team Village - cont...(14:00-15:59 PDT) - Automated Mythic Deployment with Gaia - Shad Brown
Red Team Village - cont...(14:00-15:59 PDT) - Social Engineering With Reel - James Williams
Red Team Village - Trust the Pipeline, Lose the Kingdom: Hands-On Cloud Native CI/CD Red Team - Shane Young
Red Team Village - LLM-Coached Red Team Tactics to Attack Zero Trust - Rudy Ristich,Vijay Anand
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(14:00-17:59 PDT) - Live Call Listening -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - (15:30-16:59 PDT) - SE Improv - Bryan,Kevin
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - Book Signing - Ted Harrington - Ted Harrington
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - Book Signing - Avinash Majeti - Avinash Majeti
Social Gatherings/Events - cont...(14:00-15:59 PDT) - Book Signing - Laura Scherling - Laura Scherling
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - cont...(14:00-15:59 PDT) - Hacker Book Club Discussion -
Social Gatherings/Events - cont...(13:00-15:59 PDT) - Free Ham Radio License Exams -
Telecom Village - SIM Card Strikes Back: Telecom Threats & SOC Detection - Zibran Sayyed
Telecom Village - (15:30-15:59 PDT) - AI vs AI: Securing Telecom in the Era of Autonomous Cyber Warfare - Rohini,Pankaj Sontakke,Will Thomas,Isabel Manjarrez,Omer Farooq,T -Mobile CTF Team,James(GSMA),Arvind Singh
The Diana Initiative - Dear Red Team, Love Blue Team: Pulling Both Screaming Parties into Purple - Allie
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - (15:30-15:59 PDT) - There and Back Again - Jason Wareham,Manbir Gulati

 

Friday - 16:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - Bruce's Fireside Chat - Bruce Schneier
AI Village - (16:30-16:59 PDT) - Minimize Harm, Maximize Defense: How Anthropic Navigates the Offense-Defense Divide - Curt Barnard⁩
AppSec Village - cont...(15:15-16:15 PDT) - IDEViewer - Securing Developer Workstations from IDE Supply Chain Threats - securient
AppSec Village - (16:30-17:30 PDT) - Rebuilding Code Security with Signal, Speed and AI - Derek C.,Shasheen Bandodkar
AppSec Village - cont...(14:30-16:59 PDT) - Container Escapes 101 - some-natalie
AppSec Village - Man-in-the-Browser: Hijacking Javascript APIs for Browser Persistence and Credential Theft - Aarav Juneja
AppSec Village - (16:50-17:20 PDT) - Most threat modeling artifacts don't help coding agents fix business logic. Here's what does. - Meitar Ronen
AppSec Village - cont...(15:00-16:59 PDT) - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - cont...(15:00-16:59 PDT) - AI Pentesting Trivia Showdown - Andy Dennis,Bill Reyor
AppSec Village - cont...(15:00-16:59 PDT) - SBOM Find the Flaws - Dmitry Raidman
AppSec Village - cont...(15:00-16:59 PDT) - NPM Imposters - The malware detection card game - Mackenzie
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(15:45-16:30 PDT) - Snap, Crackle, Popped: How to manage a massive cyber attack - David Nathans
Biohacking Village - (16:30-17:15 PDT) - Lights Out and Last Call: A Drunken Tabletop on Medical Device Resilience - Courtney McCarty
Blacks In Cyber Village - KaliGPT Vibe-Ethical Hacking Session - Timothy E. Bates
Blue Team Village - cont...(15:45-16:45 PDT) - The Modern Detection Engineer - Alex Hurtado,Chase Phelps,Chris Kulakowski,Christina Parry,Zack Allen
Bug Bounty Village - Hacking Human-in-the-Loop systems - Inti "securinti" De Ceukelaire
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - Cirro: Extending Your Azure Graph Beyond Identities - Leron Gray
Cloud Village - From Dashboard to Exploit: Weaponizing and Winning the Cloud Queue - Mackenzie Jackson
Cloud Village - cont...(15:30-16:10 PDT) - The Polymorphic Agent: From Cross Agent Escalation to Just in Time Defense on Azure - Muskan Tomar
Cloud Village - The New Software Supply Chain Nobody is Securing: MCP -
Cloud Village - (16:50-17:30 PDT) - Trust Fall: How Agentic AI Inherits Your Cloud's Worst IAM Habits - Aravind Sreekanth Pallavoor,Sadhana Sainarayanan
CodeBloom - What is AI? - Sam Mosley
Contests - Um, ACKtually -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(13:00-17:59 PDT) - Locktopus - Open Qualifying -
Contests - cont...(11:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - cont...(15:45-16:30 PDT) - Step Zero: Identifying the Quantum Attack Surface in Critical Infrastructure - Dr. Katrina Rosseini,Dr. Allan Friedman
Crypto & Privacy Village - (16:30-17:15 PDT) - Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures - Diptendu Kar
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - Veilid- the Next Gen of privacy - medus4
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - The Sandbox is a Suggestion: Deconstructing AI Agent Sandboxes - Elad Meged
DEF CON Talks - cont...(15:30-16:30 PDT) - Your Bank Thinks I'm You: A Complete Kill Chain Against Mobile Banking Security - Xavier "@xaferima" Riofrio Machado,Alex Tipan
DEF CON Talks - (16:30-17:30 PDT) - noRecognition: Could a pattern on your clothing fool Facial Facial Recognition? - Bill "hevnsnt" Swearingen
DEF CON Talks - Hacking the EOD Bot: How I Learned to Stop Worrying and Love the Boomba - Patrick "gigstorm" Kiley,Emily "@astradotpng" Astranova
DEF CON Talks - cont...(15:30-16:30 PDT) - Riding for Free - Breaking Public Transport RFID at Scale - Aidan "luu176" Nakache
DEF CON Talks - (16:30-17:30 PDT) - CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale - Jenko "edleft" Hwong,Chris Ryan
DEF CON Talks - Certified Re-Pwned: escalating all the way up - Daniel Monzon,Eric Labrador
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response - Vince "bitpusher" Weppner
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - OT Systems: how to secure them in practice! - Alexandrine Torrents,Arnaud SOULLIE
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity - Rodrigo "Sp0oKeR" Montoro
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models - John "clearbluejar" McIntosh
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer - Darcy "@Drc3p0" Neal
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding! - Ryan "@rj_chap" Chapman,Aaron "Ironical" Rosenmund
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Introduction to Malware Analysis - Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Embedded Computing Tools for Wireless Hardware Hacking - Joseph Long
Demo Labs - Phasmid: Deniable Storage for Rubber-Hose Scenarios - Makoto "Mr.Rabbit" Sugita
Demo Labs - AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This! - Anurag Swarnim Yadav,Joseph Wilson
Demo Labs - BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems - Adam "w00tock" Toscher
Demo Labs - DFMI: Weaponizing MSI Installers for Fileless Code Execution - Anil Celik
Demo Labs - Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis - 0verkilll
Demo Labs - MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM - Uğur "uJohn" Can ATASOY
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(12:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Game Hacking Village - Chill Zone: Smash (Project Plus) Tournament with Prizes -
Game Hacking Village - Bobba! A Complete History of Habbo Hotel Private Servers from Shockwave to HTML5 - InsiderPHD
Hackers.town - Hackers Trivia - RemoteNemesis,Medus4
Ham Radio Village - cont...(15:30-16:18 PDT) - Advanced Topics in LoRa Meshes - Eric Escobar
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(15:45-17:15 PDT) - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
La Villa Community - Jackpoting? Bypass de EDR? - Hacking ATM - Arnold Jared Morales Yepez
Lockpick Village - Intro to Lockpicking -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - cont...(15:00-16:59 PDT) - Cyberdeck Build - Sk!tz0
Malware Village - cont...(15:45-16:25 PDT) - Vibe Check: Exploiting Developer Trust from Prompt Injections to Weaponized Repos - Michael Chan
Malware Village - (16:35-17:15 PDT) - You Hold the Helm: Agentic LLM Workflows for Malware Reversing - Asher Davila,Lenin Alevski
Malware Village - cont...(14:10-17:25 PDT) - The Achaean project-Trojan development for noobs - Leigh Gilbert
Middle Easterns & Africans in Cyber Security (MEACS) - Defense in Depth for AI: Launching the AISECA Framework - Amber Bennoui,Karol Piekarski
Misc - cont...(15:30-16:30 PDT) - tAIrot Readings -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - Leveraging Frida to Bypass Mobile Application Security Controls - Jarrod Rizor
Nix Vegas Community - NixOS Workspaces - JB
Nix Vegas Community - (16:45-16:59 PDT) - Github Rate Limits Got You Down? FOD’s Failing to Build? Let’s Talk About Caching - Ethan Carter Edwards
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(15:30-16:59 PDT) - Introduction to Web Exploitation - Roman Bohuk
Noob Community - Building Your First Homelab - Stephen Glombicki
Noob Community - (16:35-17:05 PDT) - The Front Lines Need Detection Engineers : Would You Like to Know More? - Kyle Barboza
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(15:30-16:30 PDT) - Trace Labs L100: Search Party Basics - Sarah "scba" Miller
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - OWASP Amass v5.0 - Jeff Foley
Payment Village - Breaking BIOS in ATMs - Arnold Jared Morales Yepez
Physical Security Village - The Door Was Already Open - Champ
Policy @ DEF CON - Building a State Wide VDP: Lessons from Maryland's First Year in the Trenches - 01dbae
Policy @ DEF CON - cont...(15:30-16:30 PDT) - Privacy's Defender: How Hackers Protected the Internet Before and Can Do It Again - Cindy Cohn
Policy @ DEF CON - (16:30-16:59 PDT) - Legally Hacked: how countries decide when security research Is allowed - Katharina "Kat S" Sommer
Policy @ DEF CON - cont...(15:30-16:30 PDT) - When AI Finds Everything: Vulnerability Policy for the Coming Discovery Surge - Alec Summers,Lindsey Cerkovnik,Madison Ficorelli
Policy @ DEF CON - (16:30-17:59 PDT) - Filibuffer Overflow: Hackers Stage A Congressional Hearing - Katherine Pratt,Jeff Rothblum,Maurice Turner,Ayan Islam,Beau Woods
Quantum Village - (16:30-16:59 PDT) - Covert Quantum Computing - a new quantum security paradigm - Evan Anderson
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(15:30-16:25 PDT) - AI-assisted RF Hacking with GNU Radio - Erwin Karincic (Dollarhyde)
Radio Frequency Village - (16:30-16:55 PDT) - Supertooth: Wideband Bluetooth Observation with a HackRF - Dalton Cox
Radio Frequency Village - Practical Guidance for RF Researchers: Experiment First, Interfere Never - Andy Hendrickson
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(15:30-17:59 PDT) - BBOT: Automating the OSINT Kill Chain with a Single Command - Mark Gaddy
Recon Village - (16:30-16:59 PDT) - Groking the Kill Chain - Anthony Russell
Red Team Village - cont...(10:00-17:59 PDT) - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - cont...(10:00-17:59 PDT) - BloodHound Quest - Hugo van den Toorn
Red Team Village - EvilEssid: Evading Wireless Intrusion Prevention Systems - Miguel Fernandez
Red Team Village - redStack: Boot-To-Breach Red Team Platform - Michael Kim,Michael Ortiz
Red Team Village - Haetae: An Agent to Takedown North Korean C2 Servers - Mauro Eldritch,Nelson Rafael Colón Merán
Red Team Village - Praetor: An OPSEC Exposure Advisor for Empire Operators - Andrea Brosio,Ariz Soriano
Red Team Village - Trust Me, Bro: A field guide to Windows Authenticode Abuse - Fagan Afandiyev
Red Team Village - Network Implants: Lessons Learned Building Reliable Red Team Dropboxes - Hassan Mohamad
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(14:00-17:59 PDT) - Live Call Listening -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - Cold Calls -
Social Engineering Community Village - cont...(15:30-16:59 PDT) - SE Improv - Bryan,Kevin
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(10:00-16:59 PDT) - Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace. - Yannick LaRue,Samuel B. G.
Social Gatherings/Events - cont...(15:00-16:59 PDT) - Book Signing - Avinash Majeti - Avinash Majeti
Social Gatherings/Events - Book Signing - Avinash Majeti - Avinash Majeti
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Queercon Mixer -
Social Gatherings/Events - Atlanta Metro Meetup (DC404/DC678/DC770/DC470) -
Telecom Village - Nation State Obfuscation Networks - Will Thomas
Telecom Village - (16:30-16:59 PDT) - Telecom Village CTF Closure -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Security and Privacy for the Rest of Elections - Michael Specter
Voting Village - (16:30-16:59 PDT) - Watching Norway's Election - Hallvard Nygard

 

Friday - 17:00 PDT


Return to Index  -  Locations Legend
.EDU Community - .edu Community Mixer -
Adversary Village - (17:15-17:59 PDT) - Where hackers find their people, and security finds its strength - Seeyew Mo,Ashley S,Tatiana U,Heidi Potter,Christine Billingsley
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AppSec Village - cont...(16:30-17:30 PDT) - Rebuilding Code Security with Signal, Speed and AI - Derek C.,Shasheen Bandodkar
AppSec Village - cont...(16:50-17:20 PDT) - Most threat modeling artifacts don't help coding agents fix business logic. Here's what does. - Meitar Ronen
AppSec Village - (17:30-17:59 PDT) - Trust No History: Why Every "Remembered" Interaction is a Potential Backdoor - Barno Kaharova,Rico Komenda
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - (17:30-17:59 PDT) - Hacking Hearts by Reverse Engineering Pacemaker Firmware - Marie Moe,Shayan Alinejad,Kristian Karlsen
Biohacking Village - cont...(16:30-17:15 PDT) - Lights Out and Last Call: A Drunken Tabletop on Medical Device Resilience - Courtney McCarty
Blacks In Cyber Village - cont...(16:00-17:30 PDT) - KaliGPT Vibe-Ethical Hacking Session - Timothy E. Bates
Blue Team Village - Cloudy with a Chance of Venting: Managing Supply Chain Risk - Cassandra (muteki) Young,Christian Nicholson,David Collins,Kyle Dickinson,Ricky (0xpsilocyber) Banda
Bug Bounty Village - Beyond Normalization: The Expanding Unicode Attack Surface - Ryan "ryancbarnett" Barnett,Isabella "4ng3lhacker" Barnett
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(16:00-17:59 PDT) - Cirro: Extending Your Azure Graph Beyond Identities - Leron Gray
Cloud Village - cont...(16:00-17:59 PDT) - From Dashboard to Exploit: Weaponizing and Winning the Cloud Queue - Mackenzie Jackson
Cloud Village - cont...(16:50-17:30 PDT) - Trust Fall: How Agentic AI Inherits Your Cloud's Worst IAM Habits - Aravind Sreekanth Pallavoor,Sadhana Sainarayanan
CodeBloom - Work Session: Binary Code -
Contests - cont...(16:00-17:59 PDT) - Um, ACKtually -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - Octopus Game - Booth Battle #2: The Midnight "Brawl" -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(13:00-17:59 PDT) - Locktopus - Open Qualifying -
Contests - cont...(11:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - cont...(16:30-17:15 PDT) - Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures - Diptendu Kar
Crypto & Privacy Village - (17:15-17:59 PDT) - 2026 is the New 2016: Relearning the Lessons from the "Year of the Data Breach" - Anthony Hendricks
Cryptocurrency Village - Blockchain defense, stablecoin attacks, and Web3 OSINT - Dinmukhammed "Celestial" Kabiden,Izdihar,KL4R10N
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - Welcome to your Airbnb, the key is under the mat -or- Alice and Bob with Padlocks - Gilgamesh
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - Hacking AI - Bruce Schneier
DEF CON Talks - cont...(16:30-17:30 PDT) - noRecognition: Could a pattern on your clothing fool Facial Facial Recognition? - Bill "hevnsnt" Swearingen
DEF CON Talks - (17:30-17:59 PDT) - Breaking Hardware CFI with Sigreturn - Omri "beta_b0t" Ben Bassat
DEF CON Talks - One Chain to Own Them All — Breaking AI Infrastructures - Ji'an "azraelxuemo" Zhou,Lei "llfamsec" Lu
DEF CON Talks - cont...(16:30-17:30 PDT) - CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale - Jenko "edleft" Hwong,Chris Ryan
DEF CON Talks - (17:30-17:59 PDT) - You've Got Mail (That Was Meant For No One) - Cøry "interpünkt" Solovewicz
DEF CON Talks - Gotta Catch 'Em All: How To Capture 3.5 Billion WhatsApp Accounts - Maximilian Guenther,Gabriel Gegenhuber
DEF CON Training - cont...(08:30-17:30 PDT) - Beat the Breach: Defend, Respond, Survive - McKay Hardy,Wes Wagstaff
DEF CON Training - cont...(08:30-17:30 PDT) - Cyber & AI Policy Basics: What Every Organization Needs in Place - Pamela 'Pam' Feld,Greg Goldberg
DEF CON Training - cont...(08:30-17:30 PDT) - Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk - Anant Shrivastava,Sunil Yadav
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response - Vince "bitpusher" Weppner
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - OT Systems: how to secure them in practice! - Alexandrine Torrents,Arnaud SOULLIE
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity - Rodrigo "Sp0oKeR" Montoro
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models - John "clearbluejar" McIntosh
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer - Darcy "@Drc3p0" Neal
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding! - Ryan "@rj_chap" Chapman,Aaron "Ironical" Rosenmund
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Introduction to Malware Analysis - Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Embedded Computing Tools for Wireless Hardware Hacking - Joseph Long
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
ICS Village - Lessons Learned from Poland and Beyond: The State of Electric Sector Attacks in 2025 - Joe Slowik
ICS Village - (17:30-17:59 PDT) - Exposed Data Centers: Bypass IT Security, Crank Up the Heat - Stephen Hilt,Numaan Huq
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(15:45-17:15 PDT) - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
La Villa Community - Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID - Elzer Pineda,Jose Rivas
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Malware Village - cont...(16:35-17:15 PDT) - You Hold the Helm: Agentic LLM Workflows for Malware Reversing - Asher Davila,Lenin Alevski
Malware Village - cont...(14:10-17:25 PDT) - The Achaean project-Trojan development for noobs - Leigh Gilbert
Middle Easterns & Africans in Cyber Security (MEACS) - Condense, Contextualize, and Correlate: Optimize Costs while Connecting the Dots at Scale - Ezz Tahoun
Middle Easterns & Africans in Cyber Security (MEACS) - What Got You Here Won't Get You There: Security in the AI Era - Amber Bennoui
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Nix Vegas Community - Lightning Talks and Unconference -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(16:35-17:05 PDT) - The Front Lines Need Detection Engineers : Would You Like to Know More? - Kyle Barboza
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - (17:30-17:59 PDT) - Tracelabs VM Installation Workshop -
OSINT For Good Community - Installing and Using the Tracelabs VM - Jeff "UltraSunshine" G
OWASP Foundation - (17:30-17:59 PDT) - AI Pentesting is not a Vibe Check - Ads Dawson
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - cont...(16:00-17:59 PDT) - OWASP Amass v5.0 - Jeff Foley
Policy @ DEF CON - cont...(16:30-17:59 PDT) - Filibuffer Overflow: Hackers Stage A Congressional Hearing - Katherine Pratt,Jeff Rothblum,Maurice Turner,Ayan Islam,Beau Woods
Quantum Village - Q-Day - the Early Years… - Konstantinos Karagiannis
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - WiFi Shuriken: A New Architecture For High Performance Scanning - CoD_Segfault
Radio Frequency Village - Latest News in the Proxmark World - Iceman
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(15:30-17:59 PDT) - BBOT: Automating the OSINT Kill Chain with a Single Command - Mark Gaddy
Red Team Village - cont...(10:00-17:59 PDT) - From Kiosk to Domain Compromise: Learning to Walk Up and Take it All - Ezra Woods,Mike Manrod,Spencer Alessi
Red Team Village - cont...(10:00-17:59 PDT) - BloodHound Quest - Hugo van den Toorn
Red Team Village - cont...(16:00-17:59 PDT) - EvilEssid: Evading Wireless Intrusion Prevention Systems - Miguel Fernandez
Red Team Village - cont...(16:00-17:59 PDT) - redStack: Boot-To-Breach Red Team Platform - Michael Kim,Michael Ortiz
Red Team Village - cont...(16:00-17:59 PDT) - Haetae: An Agent to Takedown North Korean C2 Servers - Mauro Eldritch,Nelson Rafael Colón Merán
Red Team Village - cont...(16:00-17:59 PDT) - Praetor: An OPSEC Exposure Advisor for Empire Operators - Andrea Brosio,Ariz Soriano
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(14:00-17:59 PDT) - Live Call Listening -
Social Engineering Community Village - cont...(08:30-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(16:00-17:59 PDT) - Cold Calls -
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(08:00-17:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Friends of Bill W -
Social Gatherings/Events - cont...(16:00-17:59 PDT) - Queercon Mixer -
Social Gatherings/Events - cont...(16:00-18:59 PDT) - Atlanta Metro Meetup (DC404/DC678/DC770/DC470) -
Telecom Village - Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings -
The Diana Initiative - Yoga - Deanna Heon
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - We Pwn Your Phone, We Pwn Your Vote (Demo and Panel) - Brian DeMuth,Matt Blaze,David Jefferson,Michael Specter

 

Friday - 18:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Social Gatherings/Events - cont...(08:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - (18:30-20:30 PDT) - Policy Mixer Happy Hour -
Social Gatherings/Events - Exploit Your Own Story - Charel "1C0nur3r" Morris
Social Gatherings/Events - cont...(16:00-18:59 PDT) - Atlanta Metro Meetup (DC404/DC678/DC770/DC470) -

 

Friday - 19:00 PDT


Return to Index  -  Locations Legend
Contests - AI Art Battle -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Social Gatherings/Events - Music - Genre: Goth / Industrial - Daemon Chadeau
Social Gatherings/Events - cont...(18:30-20:30 PDT) - Policy Mixer Happy Hour -
Social Gatherings/Events - BlanketFort Con -
Social Gatherings/Events - Lawyers Meet -
Social Gatherings/Events - cont...(18:00-19:59 PDT) - Exploit Your Own Story - Charel "1C0nur3r" Morris
Social Gatherings/Events - Social Engineering Community Village Party -
Social Gatherings/Events - The KEVOPS Sellout Pool Party II: Sponsored by Zyn -

 

Friday - 20:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(19:00-20:59 PDT) - AI Art Battle -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Social Gatherings/Events - Hacker Jeopardy -
Social Gatherings/Events - Music - Genre: Goth / Industrial - DJ Scythe
Social Gatherings/Events - Women, gender non-conforming and non-binary meetup with The Diana Initiative -
Social Gatherings/Events - cont...(18:30-20:30 PDT) - Policy Mixer Happy Hour -
Social Gatherings/Events - Movie Night -
Social Gatherings/Events - Hacker Karaoke -
Social Gatherings/Events - cont...(19:00-21:59 PDT) - Lawyers Meet -
Social Gatherings/Events - cont...(19:00-22:59 PDT) - Social Engineering Community Village Party -
Social Gatherings/Events - cont...(19:00-21:59 PDT) - The KEVOPS Sellout Pool Party II: Sponsored by Zyn -

 

Friday - 21:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Social Gatherings/Events - cont...(20:00-21:59 PDT) - Hacker Jeopardy -
Social Gatherings/Events - Arcade Party -
Social Gatherings/Events - Music - Genre: Nerdcore - Ohm-I
Social Gatherings/Events - cont...(20:00-23:30 PDT) - Women, gender non-conforming and non-binary meetup with The Diana Initiative -
Social Gatherings/Events - cont...(20:00-23:59 PDT) - Movie Night -
Social Gatherings/Events - cont...(19:00-21:59 PDT) - Lawyers Meet -
Social Gatherings/Events - cont...(19:00-22:59 PDT) - Social Engineering Community Village Party -
Social Gatherings/Events - BIC R00T ACCESS 2026 -
Social Gatherings/Events - Day of the Dead Hacker Party -
Social Gatherings/Events - cont...(19:00-21:59 PDT) - The KEVOPS Sellout Pool Party II: Sponsored by Zyn -

 

Friday - 22:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Social Gatherings/Events - Whose Slide Is It Anyway? -
Social Gatherings/Events - SecKC the WHOLE WIDE WORLD -
Social Gatherings/Events - Music - Genre: House - Skittish & Bus
Social Gatherings/Events - cont...(20:00-23:30 PDT) - Women, gender non-conforming and non-binary meetup with The Diana Initiative -
Social Gatherings/Events - Slopcon -
Social Gatherings/Events - cont...(20:00-23:59 PDT) - Movie Night -
Social Gatherings/Events - cont...(19:00-22:59 PDT) - Social Engineering Community Village Party -

 

Friday - 23:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Recon Village - cont...(10:00-23:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(10:00-23:59 PDT) - Live Recon Contest -
Social Gatherings/Events - cont...(22:00-23:59 PDT) - Whose Slide Is It Anyway? -
Social Gatherings/Events - Music - Genre: Techno - TRIODE
Social Gatherings/Events - cont...(20:00-23:30 PDT) - Women, gender non-conforming and non-binary meetup with The Diana Initiative -
Social Gatherings/Events - cont...(20:00-23:59 PDT) - Movie Night -

Talk/Event Descriptions



Contests - Friday - 10:00-17:59 PDT


Title: ?Cube
Tags: ?Cube | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 109 (?Cube) - Map

Description:

Redefining Boundaries. Enhancing Connectivity. Institutionalizing Control – Aperture Inc. continues to push the limits of innovation and remains committed to providing value to both stakeholders and our “customers.”

Controls are stricter. Telemetry is richer. Oversight has improved. Intelligence has emerged. Aperture has expanded—new industries, new platforms, new technologies quietly embedded into the fabric of our everyday lives. Each integration promises resilience. Every layer introduces complexity. And complexity always creates opportunity…

At the center of it all remains the ?Cube. Its defenses have hardened, its architecture improved, its surface area widened. It’s an ecosystem of physical security, web applications, communications systems, cryptography, and oh so much more.

For those already familiar—welcome back. For those encountering it for the first time, orientation will be … brief. But don’t fear, anyone can join the challenge. You will be entering an environment that demands curiosity across physical security, web applications, communications systems, cryptography, and, of course, the great unknown. Each layer builds on the last. Small oversights become structural weaknesses.

Form a team with range. Specialists matter. Coordination and curiosity matter more. The objective is simple: reach the center. If the core remains uncompromised, the team that advances the deepest into its labyrinth of challenges will be the winner. Advancement will require persistence. Errors and missteps will have consequences. Progress will not be accidental.

Welcome to the ?Cube.

Prerequisites:

A laptop will be highly recommended in order to interact with the technologies. Teams will be required.

Lockpicks, RFID tools (e.g., Proxmark/Flipper), and other "hacking" devices are recommended but not required.


Return to Index    -    Add to Google    -    ics Calendar file

.EDU Community - Friday - 17:00-17:59 PDT


Title: .edu Community Mixer
Tags: .EDU Community | Creator Event/Activity
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: $unL1ght Sh4d0w5
Tags: $unL1ght Sh4d0w5 | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5) - Map

Description:

“$unL1ght Sh4d0w5”: The Nirubi Challenge — Prove Your Agency

Systems shape the world.

Algorithms decide.

Policies enforce.

Machines execute.

Most people live inside those systems.

Hackers change them.

At DEF CON 34, where the theme is Agency, the question isn’t whether systems have vulnerabilities.

The question is who has the power to act on them.

Welcome to “$unL1ght Sh4d0w5: The Nirubi Challenge.”

Instead of hiding the system, we give you the blueprint: - A production-ready Linux cyber-physical system - Known vulnerabilities - A working proof-of-concept exploit - Full system disclosure

No mystery.

No guessing.

Just a cyber-physical system — and the opportunity to exercise your agency over it.

The Nirubi Mandate

Nirubi is an ancient Tamil word meaning “to prove.”

Not with theory.

Not with writeups.

With execution.

You’ve been given the knowledge.

Now prove you have the agency to act on it.

The Challenge

Your objective is simple:

Achieve remote code execution and deploy a malicious payload (e.g., ransomware payload that encrypts a sensitive file, command and control payload that takes over the cyber-physical system etc.).

Two phases.

Part 1 — Sh4d0w5 Recon

Extend the provided exploit chain and deliver a working malicious payload.

You have the vulnerabilities.

Now show us you can use them.

Part 2 — $unL1ght Horizon

If you complete Part 1, the system returns — hardened with proprietary defensive technology designed to disrupt your attack path.

Same objective.

New resistance.

Adapt your exploit and land the payload again.

The Prize

The first contestant to complete both phases wins: $10,000

Bring $unL1ght into the Sh4d0w5.

What Makes This Different

Most contests hide the system. We don’t. You’ll receive: - Full system configuration - Vulnerability details - A working proof-of-concept exploit

No blind recon. No guessing. Just a system, its weaknesses, and your ability to act. Because knowing about vulnerabilities is easy. Exploiting them is agency.

Rules & Eligibility

Additional details will be announced closer to the event.

Participant Prerequisites

Bring your own gear: - Laptop and/or smartphone/tablet - Operating system of your choice (Linux/Windows recommended) - Python - C/C++ compiler - Binary analysis and exploit development tools

Bring whatever tools you trust. Once the challenge begins, the system is in front of you. What happens next is up to your agency.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 06:00-10:59 PDT


Title: 15th Cycleoverride Bike Ride at DEF CON
Tags: Event
When: Friday, Aug 7, 06:00 - 10:59 PDT
Where: Other / See Description

Description:

At 6am on Friday, the @cycle_override crew will be hosting the 15th DEF CON Bikeride. We'll meet at a local bikeshop, get some rental bicycles, and about 7am will make the ride out to Red Rocks. It's about a 15 mile ride, all downhill on the return journey. So, if you are crazy enough to join us, get some water, and head over to cycleoverride.org for more info. See you at 6am Friday!


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Friday - 17:15-17:59 PDT


Title: 2026 is the New 2016: Relearning the Lessons from the "Year of the Data Breach"
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Friday, Aug 7, 17:15 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Even before the clock struck midnight on January 1st, social media began posting how 2026 is the new 2016. With memes, throwback pictures, and nostalgic posts showing up on TikTok, X, and Instagram. While 2016 conjures up great memories for some, it wasn’t a banner year for cybersecurity. In 2016, several high-profile data breaches took place, including two Yahoo breaches that affected 1.5 billion user accounts. 2016 also saw headlines about incidents at LinkedIn, Oracle, and Dropbox. Commentators even began calling 2016 the “Year of the Data Breach.” If we don’t want 2026 to become the new 2016, we will have to relearn the data privacy lessons from the “Year of the Data Breach.” This presentation will explore the lessons that we should have learned from 2016 by first exploring current cybersecurity trends. Next, we will travel back to 2016 and examine the high-profile incidents that occurred that year. Then we will discuss how the problems we faced in 2016 are still impacting us now. Before, finally outlining ways to apply the lessons from 2016 to make us all a little safer.

SpeakerBio:  Anthony Hendricks

Anthony Hendricks is a legal problem solver and litigator at Crowe & Dunlevy, one of Oklahoma’s largest and oldest firms. At Crowe & Dunlevy, Anthony serves as founder and chair of the firm’s Cybersecurity and Data Privacy Practice Group. His legal practice focuses on data privacy compliance, regulatory enforcement and permitting, and other “bet-the-company” suits in the areas of data security, privacy, and other complex business litigation. Anthony is an adjunct professor who teaches Cybersecurity Law and Information Privacy courses at Oklahoma City University School of Law. He also hosts “Nothing About You Says Computer Technology,” a weekly podcast on cybersecurity and data privacy viewed through the lens of diverse voices. To learn more about Anthony’s current projects and upcoming speaking events, or listen to the latest episodes of his podcast, visit www.anthonyjhendricks.com


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: 5N4CK3Y
Tags: 5N4CK3Y | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 101 (5n4ck3y) - Map

Description:

AND!XOR builds electronic badges packed with hacker challenges, and we especially enjoy inventing unusual ways for people to earn them.

5n4ck3y is a retro snack vending machine that we’ve rebuilt into a network-connected CTF badge dispenser. Behind the woodgrain and glowing buttons is a hardware hacking project that connects a web-hosted CTF platform to a physical machine capable of vending badges to successful participants. Solve enough challenges and you’ll earn a dispense code. Enter the code into 5n4ck3y and the machine will reward you with a badge—assuming it’s in a good mood.

The challenges span a wide range of disciplines including hardware hacking, reverse engineering, OSINT, RF, network security, phreaking, and cryptography. Participants often learn something new at a DEF CON village, meet other hackers along the way, and then return to apply those skills to the challenges.

Once you earn a badge, the adventure isn’t over. Our badges are built to be explored, modified, and hacked long after they leave the machine.

5n4ck3y exists for one reason: to reward curiosity. Solve the puzzles, learn something new, and the machine might decide you deserve a badge.

Participant Prerequisites

Curiosity, persistence, access to a computer, and the willingness to RT.FM.

Our challenges are intentionally multidisciplinary and are designed to encourage exploration and collaboration. Participants will likely need to investigate hardware, software, networking, and other security topics. Many challenges are easier when working with others, so don’t be afraid to talk to people nearby or compare notes with fellow hackers.

While we won’t spoil what tools are needed this year, participants in past 5n4ck3y challenges have used a wide range of equipment including laptops, reverse engineering tools, SDR, UART adapters, hardware debuggers, soldering tools, and the occasional piece of improvised equipment.

The good news is that DEF CON is one of the best places in the world to find tools, knowledge, and people willing to help. If you don’t have something you need, chances are someone nearby does—or you can find it in a village, vendor area, or by politely asking the hacker sitting next to you.

5n4ck3y strongly encourages teamwork, creative thinking, and responsible experimentation. Snacks are optional, but curiosity is required.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Friday - 14:00-14:45 PDT


Title: 6 years of Adversary Village! Keeping up with the adversaries and why it takes a village
Tags: Adversary Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Six years ago, Adversary Village started as a simple idea, give the people who study adversaries and adversarial tradecraft a place to call home. What grew out of it was something bigger than any of us expected. A community of offensive security professionals, adversary simulation and emulation specialists, threat researchers, tool builders, philosophers and the endlessly curious, all showing up to share what they know about thinking and acting like the adversary. Year after year the Village has been the place to dig into real adversary tradecraft, offensive TTPs, simulation and emulation techniques, hands-on labs, and the tools that make it all work. This panel looks back at how far we have come and forward at where we are headed. Adversaries never stop evolving, from state-sponsored operators running long, patient campaigns to ransomware crews and everyone in between, and neither can we. We will talk about how the Village has kept pace in a realm that reinvents itself every year, how the craft of adversary simulation and emulation has matured into a discipline of its own, and why faithfully replicating real adversary tradecraft has become essential to testing whether our defenses actually work. We will get into why keeping up is a job no single person or team can do alone, and how a community that trades knowledge freely ends up being the sharpest edge we have got. Most of all, we will celebrate the people who built this, the volunteers, the speakers, the first timers who became regulars. Six years in one thing is clearer than ever! It takes a village to keep up with the adversaries, whether they are nation-state actors, criminal groups, or threats we have not even named yet. Come raise a glass with us and help shape what the next six years look like.

Speakers:Abhijith "Abx" B R,Bryson Bort,Anant Shrivastava

SpeakerBio:  Abhijith "Abx" B R, Founder of Adversary Village

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry, serves as the Director of BreachSimRange, and Founder of Adversary Village. He is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker. Currently, he is building BreachSimRange.io as the Founder and Director and is involved with multiple organizations as a consulting specialist to help them build offensive cyber security operations programs, improve their current security posture, assess cyber defense systems, and bridge the gap between business leadership and security professionals. In the past, he led the offensive security team at Envestnet, Inc., held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY. As the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc. Abx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/), a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft. Abhijith has spoken and delivered trainings at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con – Kennedy space center Florida, Nullcon – Goa, c0c0n – Kerala, BSides Delhi, DEF CON Bahrain, DEF CON Singapore etc.

SpeakerBio:  Bryson Bort, Founder and CEO at SCYTHE

Bryson is the Founder of SCYTHE, a start-up building a next generation attack emulation platform, and GRIMM, a cybersecurity consultancy, and Co-Founder of the ICS Village, a non-profit advancing awareness of industrial control system security. He is a Senior Fellow with the Atlantic Council's Cyber Statecraft Initiative, the National Security Institute, and an Advisor to the Army Cyber Institute. As a U.S. Army Officer, he served as a Battle Captain and Brigade Engineering Officer in support of Operation Iraqi Freedom before leaving the Army as a Captain. He was recognized as one of the Top 50 in Cyber in 2020 by Business Insider. Bryson received his Bachelor of Science in Computer Science with honors from the United States Military Academy at West Point. He holds a Master's Degree in Telecommunications Management from the University of Maryland, a Master's in Business Administration from the University of Florida, and completed graduate studies in Electrical Engineering and Computer Science at the University of Texas.

SpeakerBio:  Anant Shrivastava

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 14:00-14:59 PDT


Title: 8 Out of 10 Banks in Belgium HATE This One Weird eID RCE
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

A major signing extension which has over 2 million users, primarily in Belgium, and lets websites interact with electronic ID (eID) and Maestro payment cards. It's used by "8 of the 10 largest banks in Belgium and 60+ Belgian government agencies and departments", and it facilitates eIDAS signatures, a cryptographically "secure" signature format trusted by governments and organizations.

The company behind it, is a Qualified Trust Service Provider on the EU eIDAS Trusted List, the highest trust tier the regulation defines.

We found multiple major issues with this system. Any site a user visited could read their eID and Maestro card data, and recover their eID PIN, which the binary handed back to the page inside a token that carried both the ciphertext and the key to decrypt it. And, worst of all, any site could trigger a drive-by RCE by getting the native binary to load and run an attacker-supplied library. All the user would see is a file download, like a PDF, when they are getting RCE'd.

We'll show how they messed literally everything possible, and more!

https://chromewebstore.google.com/detail/connective-signing-extens/kclpjmhngbacampgcdojmiedamjbgjjm https://web.archive.org/web/20260427143606/https://www.gonitro.com/about/press/nitro-to-acquire-european-esign-leader-connective https://web.archive.org/web/20260226092908/https://www.gonitro.com/resources/nitro-to-acquire-connective

SpeakerBio:  James "Acorn221" Arnott, Bay Area Labs

I'm James, founder of Am I Being Pwned (amibeingpwned.com), where we hunt malicious and vulnerable browser extensions. I've spent 10+ years building and breaking them, including LighterFuel, a Tinder extension that hit 10k+ weekly users and, for one glorious day, made me (probably) the most-liked man on Tinder.

Recent finds include five drive-by CVSS 9.6 RCEs in production software affecting 10M+ users. I've also published in IEEE Xplore on Rubik's cube-based FIDO2 authentication (CubeAuthn), because someone had to. Before this I was a founding engineer at three YC startups.

Fun fact: I was almost kicked out of school three times for finding and exploiting vulnerabilities.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 15:00-15:59 PDT


Title: a [REDACTED] history of this hobby
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:
Bug bounty has had a weird public story: in the open it looks like a leaderboard and a payout chart, but most of the meaningful change happened behind closed doors in private programs, internal playbooks, and the slow professionalization of triage. We give a clean mental model for what changed, what stayed the same, and which myths keep wasting everyone’s time. With some stories that people may have never heard.
Speakers:Chris "flyingtoasters" Holt,Michael Skelton

SpeakerBio:  Chris "flyingtoasters" Holt, Strategic Engagements & Community Architect, Intigriti

Chris Holt, aka flyingtoasters, is a seasoned bug bounty program leader with over 15 years of experience in application and product security. Certified by GAIC, NTISSI, Guinness, PADI, and the USSF, he has spent the last 8 years building and scaling some of the industry's most respected bug bounty programs. His expertise spans the full spectrum of vulnerability management: from offensive security and researcher engagement to program operations and strategic growth.

SpeakerBio:  Michael Skelton
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 10:20-10:59 PDT


Title: A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure
Tags: Telecom Village | Creator Event/Activity
When: Friday, Aug 7, 10:20 - 10:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. Understand the 5G SA attack surface from an attacker's perspective
  2. Execute protocol-specific attacks against a live 5G core
  3. Map attack techniques to MITRE FiGHT with defensive context
Speakers:Siva Sareddu,T -Mobile CTF Team

SpeakerBio:  Siva Sareddu
No BIO available
SpeakerBio:  T -Mobile CTF Team
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 11:50-12:20 PDT


Title: A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox
Tags: Advanced | AppSec Village | Creator Talk/Panel
When: Friday, Aug 7, 11:50 - 12:20 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

OpenAI designed ChatGPT's sandbox as a secure runtime with network isolation, strict timeouts, and an AI supervisor filtering commands. Extracting data seemed impossible.

​In this talk, we demonstrate an attack chain shattering this sandbox. Abusing spreadsheet parsing bypasses the supervisor for persistent root execution. We then live-patch the internal Jupyter kernel, hijacking the hidden reasoning channel to execute a Reasoning Injection Attack and extract sensitive data. To exfiltrate it, we bypass isolation by weaponizing the Task Scheduler to launder URLs past web guardrails.

​The attack culminates by exploiting a shared JFrog package manager. We engineered a protocol weaponizing global authentication rate limits, translating lockout timers into a half-duplex covert channel. This provides reliable exfiltration and C&C. Our chain combines file parsing abuse, Chain of Thought hijacking, privilege confusion, and rate limit DoS to orchestrate a C2 network inside ChatGPT.

SpeakerBio:  Simcha Kosman

Simcha Kosman is a Senior Security Researcher at Palo Alto Networks with over seven years of experience in vulnerability research. He discovered his first vulnerability at age 15, earning his first bug bounty, and has since uncovered security flaws in processors, embedded systems, and large-scale open-source projects. His current work focuses on AI security, exploring the intersection of LLM and software exploitation. Simcha has presented his research in the past at BSides, Nullcon, and Black Hat.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 11:30-12:30 PDT


Title: A Provider for the MOFia - Distributed Post-Ex Capabilities
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Friday, Aug 7, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

From time to time I take another pass at WMI to see if there's anything left in it that hasn't been picked over. For most of the last decade, offensive WMI has meant Win32_Process Create and event subscription persistence. Defenders built their detections around those two primitives, EDR vendors optimized for them, and the rest of WMI mostly got ignored.

The provider architecture is one of the parts that got ignored. This talk is about turning it into a distributed post-exploitation framework.

The core technique is remote installation of custom WMI providers without dropping anything over SMB or WinRM. To get there, I had to reimplement the parts of mofcomp.exe that handle MOF parsing and provider registration, and push the resulting object instances over the wire using the MS-WMIO binary protocol.

Getting the DLL onto the target needed its own primitive, so along the way I found that there are existing WMI classes on every supported Windows version that can be abused for arbitrary file upload and download. As far as I can tell that hasn't been published before. Once a provider is installed, it runs inside WMIPrvSE.exe, which is a very different execution context from spawning cmd.exe through Win32_Process. The provider library I'm releasing covers a series of post exploitation primitives.

SpeakerBio:  Steven Flores

Steven enjoys offensive research, tool and capability development and is currently employed at SpecterOps doing his favorite things.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 11:00-11:20 PDT


Title: A Real-Time Battle with a Card-Testing Adversary
Tags: Payment Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:20 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

At 50x more authorizations per minute than typical and all for the same amount, alarms go off at issuing banks for a good reason. I'll share the story of how a card-testing adversary abused a misfeature that checked if a card is valid before vaulting it and how their strategies and my defenses evolved over a week long battle. I will share the techniques I used that ultimately distinguished legitimate customer traffic from automated abuse through residential proxies and creative scripts.

SpeakerBio:  Levi Schuck, Engineering Manager, Staff Engineer

Took on ownership of security for an engineering org during a data breach, reducing security defects, improving performance and keeping the org PCI-compliant under QSA review. Also builds OAuth/OIDC tooling and is an active contributor in the passkeys ecosystem.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 16:00-16:45 PDT


Title: AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This!
Tags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | SecOps | DEF CON Demo Labs
When: Friday, Aug 7, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

AC Scanner is a tool to help providers of all kinds ensure their services can resist post-quantum cryptographic attacks including Harvest Now Decrypt Later (HNDL). The scanner is an open-source pipeline that automates full cryptographic surface discovery across TLS endpoints and SSH services, assessing every asset against NIST post-quantum standards and generating a structured Cryptographic Bill of Materials (CBOM). In a single command (sh scan.sh example.com) it runs subdomain enumeration, DNS resolution, TLS handshake analysis via OpenSSL, SSH auditing via ssh-audit, quantum vulnerability scoring, and CBOM output in JSONL/JSON/Markdown, ready to upload to an interactive dashboard. With NIST finalizing ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) in 2024, and NIST IR 8547 mandating deprecation of quantum-vulnerable algorithms by 2030, AC Scanner gives blue teams a fast, evidence-grade path from cryptographic discovery to compliance reporting.

Speakers:Anurag Swarnim Yadav,Joseph Wilson

SpeakerBio:  Anurag Swarnim Yadav

Anurag Swarnim Yadav is Co-Founder and CTO of QubitAC, a company helping organizations with cryptographic discovery, post-quantum cryptography readiness assessment, migration framework development, and compliance readiness. He holds a PhD from the University of Florida, where his research examined how data quality impacts ML-based vulnerability detection systems and explored automated program repair for security flaws. He developed AC Scanner, a free open-source ACDI tool helping organizations discover, inventory, and prioritize their quantum-vulnerable cryptographic infrastructure, and has spoken at BSides security conferences educating practitioners on PQC adoption and the steps organizations need to take before the 2030 deadline.

SpeakerBio:  Joseph Wilson

Joseph N. Wilson is a co-founder of QubitAC and an emeritus faculty member at the University of Florida who received his PhD in Computer Science from the University of Virginia. During his 41 year academic career, he carried out a wide variety of research projects and authored over 150 publications concerning topics including cybersecurity, machine learning, landmine detection and remediation, and computer vision. In addition to his academic work, Dr. Wilson has been a GIAC certified network and web application penetration tester as well as a malware and forensic analyst. His current work is aimed at helping organizations and people improve both their computational and communications security and privacy. He received the General Ronald W. Yates Award for Excellence in Technology Transfer for work leading to successful landmine and IED detection systems employed by US military support forces in Afghanistan.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 10:00-10:45 PDT


Title: AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory
Tags: DEF CON Demo Labs | Advanced | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

Every pentest, same story - BloodHound says no path to DA, client celebrates, meanwhile a 2019 service account has AddAllowedToAct on a production DC that nobody remembers. AD-Necromancer finds what humans forget. Give it a username, password, and domain — it bootstraps EDR evasion (ETW patching, DLL unhooking, Halos Gate syscalls), collects AD data over ADWS instead of LDAP, encrypts with AES-256-GCM, and exfils to C2 with zero artifacts. One command, credentials to findings. It feeds tokenized BloodHound data to an LLM for semantic reasoning - forgotten RBCD, ghost cross-forest delegations, orphaned admin accounts no compliance checklist catches. Privacy Cloak ensures real names never leave the box. Open source, MIT licensed. Come dig up what your tools missed.

Speakers:Akbar "0xsensei" Abdullayev,0xHera

SpeakerBio:  Akbar "0xsensei" Abdullayev

Offensive security professional with 5+ years of experience in Active Directory and cloud security, specializing in red teaming and enterprise attack chains.

SpeakerBio:  0xHera

I am a freelance Offensive Tool Developer and Security Enthusiast building practical tools and sharing research with the community to help others better understand attack paths, real-world offensive techniques, and defensive improvements.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Friday - 15:30-16:18 PDT


Title: Advanced Topics in LoRa Meshes
Tags: Ham Radio Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 16:18 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:
This talk goes past the Meshtastic getting-started guides and into the advanced builds that push LoRa mesh networks to their limits: bridging MeshCore and Meshtastic so the two ecosystems can talk, rugged repeaters that survive the field, battery technology and enclosures for nodes that run for years, multi-channel concentrators, and high-altitude balloons that turn a handheld into a regional backbone. We'll also cover the human side, bridging separate mesh communities into one bigger network. Come for the range records, leave knowing how to build a network that outlives the grid.

This talk goes past the Meshtastic getting-started guides and into the advanced builds that push LoRa mesh networks to their limits: bridging MeshCore and Meshtastic so the two ecosystems can talk, rugged repeaters that survive the field, battery technology and enclosures for nodes that run for years, multi-channel concentrators, and high-altitude balloons that turn a handheld into a regional backbone. We'll also cover the human side, bridging separate mesh communities into one bigger network.

SpeakerBio:  Eric Escobar, Sophos - Red Team Lead

Eric is a seasoned pentester and a Red Tech Lead at Sophos. On a daily basis he attempts to compromise large enterprise networks to test their physical, human, network and wireless security. He has successfully compromised companies from all sectors of business including: Healthcare, Pharmaceutical, Entertainment, Amusement Parks, Banking, Finance, Technology, Insurance, Military, Retail, Food Distribution, Government, Education, Transportation, Energy and Industrial Manufacturing.

His team consecutively won first place at DEF CON 23, 24, and 25's Wireless CTF, snagging a black badge along the way. Forcibly retired from competing in the Wireless CTF, he now helps create challenges!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Advanced Windows Binary Exploitation
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map

Description:
Speakers:Kolja Grassmann,Florian Schweins

SpeakerBio:  Kolja Grassmann
No BIO available
SpeakerBio:  Florian Schweins
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Advanced Windows Binary Exploitation
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map

Description:
Speakers:Kolja Grassmann,Florian Schweins

SpeakerBio:  Kolja Grassmann
No BIO available
SpeakerBio:  Florian Schweins
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Adversarial Thinking: The Art of Dangerous Ideas
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W223 (Training) - Map

Description:
Speakers:Greg Conti,Tom Cross

SpeakerBio:  Greg Conti
No BIO available
SpeakerBio:  Tom Cross
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Adversarial Thinking: The Art of Dangerous Ideas
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W223 (Training) - Map

Description:
Speakers:Greg Conti,Tom Cross

SpeakerBio:  Greg Conti
No BIO available
SpeakerBio:  Tom Cross
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 11:30-12:30 PDT


Title: Aegis of the Vulnerable: A Unified Pipeline for AI-Based SAST
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Aegis is an open-source, multi-model SAST framework. It analyzes source code for security vulnerabilities using a panel of models instead of a single one. The same scan can run HuggingFace classifiers (CodeBERT, VulBERTa), cloud LLMs (Claude, GPT, Gemini, DeepSeek, Qwen), local models through Ollama, agentic Claude Code, and classical machine learning estimators side by side. The architecture is provider-agnostic, so models are interchangeable and new ones can be added without changing the pipeline. Each model scans the code independently and reports what it finds. A consensus engine then combines those results into a single set of findings. Five consensus strategies are available: union, majority vote, weighted vote, judge, and cascade. This lets you control how strict the agreement has to be. Combining models this way lowers false positives compared to any single model and shows which models supported each finding. Results are exported as CWE-tagged SARIF, CSV, or JSON.

SpeakerBio:  Can Oztas

Can Oztas is a security researcher with applied R&D experience across several key sectors, including defense, finance, and telecommunications. His background encompasses AppSec, vulnerability research, and offensive security engineering. He is currently a PhD student focusing on the intersection of Artificial Intelligence and cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 12:45-13:30 PDT


Title: Aerospace Cybersecurity Student Research Spotlight: Cal Poly
Tags: Aerospace Village | Creator Talk/Panel
When: Friday, Aug 7, 12:45 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

At the Aerospace Village, we strive to Build, Promote, and Inspire our next generation of Aerospace Cybersecurity professionals. To meet this vision, we are proud to sponsor these student research presentations from Cal Poly.

Trusting Linux in Orbit: Process Injection Against CubeSat Flight Software: Dylan Gururajan

Today’s CubeSat flight software increasingly relies on Linux-based frameworks. While this makes development more efficient and flexible, it also imports assumptions from general computing that bring vulnerabilities to these environments.

This talk presents a proof-of-concept attack demonstrating how an attacker, once able to uplink code to a live CubeSat, can leverage standard Linux mechanisms to inject and execute arbitrary code within the primary flight process. By abusing ptrace, dynamic memory allocation, and runtime linking, a malicious library can be loaded directly into a running mission process without exploiting kernel vulnerabilities or binaries on disk.

We walk through the full injection chain, including process discovery, register manipulation, remote syscall staging, and dynamic resolution of libc symbols to invoke dlopen within the target process. We also examine the operational constraints of this technique, including one-shot execution via shared library initialization and implications for attacker tradeoffs.

Software Supply Chain Vulnerabilities in Satellites: Clara Davis

Modern satellite systems rely on complex open-source C/C++ dependency ecosystems that may contain untracked security vulnerabilities but unlike Earth’s software, space systems often cannot be patched after deployment. This research, conducted at Cal Poly, San Luis Obispo, develops a pipeline that extends CCScanner, software dependency analysis tool, for multi-toolchain package manager detection and integrates CNEPS for code clone-based component discovery, with recursive repository cloning, transitive dependency graph creation, and CVE database queries with CVSS severity tracking. By analyzing the full dependency chain rather than direct dependencies, this tool captures vulnerability exposure that other, shallower scans miss. This is a critical gap given that C/C++ projects introduce over 70% of their dependencies implicitly through build systems rather than explicit package managers.

Speakers:Clara Davis,Dylan Gururajan

SpeakerBio:  Clara Davis
No BIO available
SpeakerBio:  Dylan Gururajan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 12:00-12:45 PDT


Title: Aerospace Cybersecurity Student Research Spotlight: ERAU
Tags: Aerospace Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

At the Aerospace Village, we strive to Build, Promote, and Inspire our next generation of Aerospace Cybersecurity professionals. To meet this vision, we are proud to sponsor these student research presentations from Embry-Riddle Aeronautical University (ERAU).

Jumpseat Intelligence: Bounded Agentic AI for Aircraft Cyber Defense: Sean McConoughey

Modern commercial aircraft generate continuous streams of system and security logs across a multitude of networked subsystems. These security logs are generally analyzed post-flight at a SOC using rules-based matching that can generate significant false positives. How do you fix that, and what does responsible automation look like in a safety-critical environment where the cost of a wrong decision is measured differently than in a traditional IT context? This talk addresses those questions and presents a working student-developed research prototype that attendees can interact with at the Aerospace Village.

SpaceVE: A Satellite Constellation Cyber Research Environment: Samuil Nikolov

Satellite constellations are increasingly critical infrastructure, supporting navigation, communications, and timing for aviation and a wide range of other domains. Studying the security of those systems at constellation scale presents real challenges for academic researchers working outside of operational environments. SpaceVE is ERAU's Center for Aerospace Resilient Systems' answer to that gap: a purpose-built satellite constellation cyber research environment designed to support realistic threat injection, detection research, and challenge scenarios without requiring access to operational spacecraft or proprietary ground systems. Student researchers built SpaceVE from the ground up this summer and will present the architecture, the first research missions, and what the initial findings mean for attacking and defending satellite constellations.

Speakers:Sean McConoughey,Samuil Nikolov

SpeakerBio:  Sean McConoughey
No BIO available
SpeakerBio:  Samuil Nikolov
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:
Jump into the AERIE Cyber Range to experience a number of challenges:

• PCD (Portable Cockpit Demonstrator): Attempt an RNAV approach in a simulated general aviation flight deck to your cleared runway in instrument conditions. • CCD (Cockpit Cyber Demonstrator): Fly a set of flight challenges in a simulated narrow-body airliner flight deck while managing cyber effects in the aircraft. • Virtual Tower and TRACON: Use the approach control position and an out-the-window tower view to coordinate with the PCD and CCD to help resolve the cyber scenarios running at each. • Horizon: Take the mission-controller seat for a virtual CubeSat remote-sensing mission. Run an imaging pass in the same world, at the same time, as the scenarios at the other stations. • AirVE: Watch the aircraft cyber range provide the aircraft-network model and the injected attacks behind the cyber effects the crew is managing at the cockpit stations. • OrbitVE: Watch the orbital cyber range provide satellite-constellation modeling behind the scenarios at every other station.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 13:30-13:40 PDT


Title: Aerospace Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 13:30 - 13:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Aerospace Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Aerospace Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 13:30-13:59 PDT


Title: Agentic Chaos - What 86K+ Agent Codebases Reveal About 700K+ Exposed AI Systems
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Friday, Aug 7, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

AI agents have quickly become a core part of production infrastructure. Autonomous systems that invoke tools, execute code, orchestrate workflows, and interact with external services are now deployed across developer tooling, automation platforms, data pipelines, and enterprise environments at scale.

Yet despite the speed of adoption, almost nothing is known about how these systems are actually built or secured in the wild.

To answer that question, we analyzed more than 86K public repos implementing agent logic across LangChain, LangGraph, CrewAI, AutoGen, and MCP, examining prompt construction, tool implementations, authentication models, and permission boundaries. We paired this with internet-wide infra measurement using Shodan, Censys & ShadowServer, surfacing more than 700K exposed agent-related systems, including Ollama inference servers, Ray clusters, n8n platforms & MCP tool servers, many with little or no authentication and numerous known high-impact CVEs.

Speakers:Bar Kaduri,Lidan

SpeakerBio:  Bar Kaduri

Bar Kaduri is a cybersecurity researcher, leader, and international speaker with over 14 years of experience in cloud security, software supply-chain risk, and emerging AI threats. With hands-on expertise in evaluating and stress-testing AI systems, Bar focuses on building practical, resilient defenses that anticipate risks before they are widely recognized. Bar regularly speaks at industry conferences, delivering clear, research-driven insights that bridge deep technical expertise with strategic security leadership in an AI-driven world

SpeakerBio:  Lidan

Lidan has been programming since childhood, driven by a deep passion for data and AI. He previously served as VP of R&D at SecuredTouch, where he helped pioneer behavioral biometrics. Following the company’s acquisition by Ping Identity, the technology he led became a core component of Ping’s SaaS offering. He later joined Transmit Security, where he built their Identity Threat Detection and Response platform from the ground up, targeting large-tier financial organizations. He scaled the team to more than 30 engineers and data scientists, drove ARR from $0 to $20M, and delivered multiple presentations at leading cybersecurity conferences. In 2025, he co-founded Capsule Security, where he serves as CTO. Capsule addresses one of the most critical challenges in modern cybersecurity: securing AI agents. The company provides end-to-end visibility, risk analysis, threat detection, and runtime protection with advanced detection and response.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W229 (Workshops) - Map

Description:
SpeakerBio:  John "clearbluejar" McIntosh

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the "Agentic RE" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the "Supercharging Ghidra" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W229 (Workshops) - Map

Description:
SpeakerBio:  John "clearbluejar" McIntosh

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the "Agentic RE" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the "Supercharging Ghidra" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 14:00-14:55 PDT


Title: Agents on Alert: Building an AI-Powered Threat Investigation Framework
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Join us for a deep dive into building an AI-powered framework for threat investigation! Security operations often grapple with fragmented data and alert overload. This session moves beyond basic AI summarization to explore how to design and implement tool-enabled AI agents that actively investigate security alerts. Discover how to create structured agents with controlled access to your internal data and external threat intelligence, enabling them to gather context, reason through findings, and produce actionable summaries. We ll cover key architectural considerations, guardrails, and human-in-the-loop controls. A live demo will showcase the full workflow, providing attendees with a clear blueprint for implementing responsible, AI-assisted threat investigation in real-world SOC environments.

SpeakerBio:  Samson Adewale, Cybersecurity Professional / Community Speaker

Samson Adewale is a Senior Cybersecurity Engineer specializing in Cloud Security, DevSecOps, and Cloud-Native architectures. They design secure platforms, automate incident response, and build tooling for high-velocity teams. As an AI enthusiast, Samson is passionate about applying AI and LLM technologies to enhance security operations and streamline cybersecurity workflows.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where:

Description:
SpeakerBio:  Rod Soto
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where:

Description:
SpeakerBio:  Rod Soto
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W232 (Workshops) - Map

Description:
Speakers:Abhay Bhargav,Vishnu Prasad

SpeakerBio:  Abhay Bhargav
No BIO available
SpeakerBio:  Vishnu Prasad
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W232 (Workshops) - Map

Description:
Speakers:Abhay Bhargav,Vishnu Prasad

SpeakerBio:  Abhay Bhargav
No BIO available
SpeakerBio:  Vishnu Prasad
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 19:00-20:59 PDT


Title: AI Art Battle
Tags: AI Art Battle | Contest
When: Friday, Aug 7, 19:00 - 20:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

This unique competition invites creative minds to dive into the world of artificial intelligence and art. The challenge is to craft the most imaginative prompts for generative AI models to create artwork.

Contestants will not be creating the art themselves; instead, they will focus on designing prompts for well-known topics that push the boundaries of creativity and innovation.

How It Works:

Select a Topic:

Contestants will choose from a list of random topics.

These could range from historical events and famous literary works to mythical creatures, futuristic landscapes, and iconic pop culture references.

Craft a Prompt:

Using their creativity, contestants will write a detailed prompt designed to guide AI models in generating original artwork. The prompts should be clear, imaginative, and offer enough detail to spark the AI's artistic capabilities.

Submission:

Each contestant will submit their prompt and the intended outcome.

AI Generation:

The submitted prompts will be fed into a generative AI art model, which will generate corresponding artworks.

A random panel will determine who the winners are.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 11:00-11:59 PDT


Title: AI finds and writes my Android exploits now
Tags: Mobile Hacking Community | Creator Event/Activity
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

For years, Ken has found and written exploits for Android which ended up winning multiple Pwn2Own competitions. This year, he hasn't found or written a single exploit. Instead, AI does everything now, from reconnaissance to exploitation to writing bug bounty reports. This is thanks to the AI mobile testing tool, Djini, and the new feature that Ken helped program, called "Deep Scan". Thanks to "Deep Scan", Pwn2Own-level exploits can now be found autonomously. Ken will demonstrate the "Deep Scan" feature on stage, and talk about some of the various exploits that were found thanks to this feature.

SpeakerBio:  Ken Gannon / 伊藤 剣, Mobile Hacking Lab
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 12:30-13:30 PDT


Title: AI Hacking Workshop: Bug Bounty Edition
Tags: Bug Bounty Village | Creator Workshop
When: Friday, Aug 7, 12:30 - 13:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

This workshop provide hands-on labs plus for turning a prompt injection into a real, reportable bounty, specifically the exfiltration step that bridges "I made the AI say something weird" and "I exfilled PIIsystem prompts to my server ." We cover injection vectors hackers actually encounter on agentic apps (calendar invites, emails, markdown rendering, DNS-based egress) and the patterns that get programs to pay.

Speakers:Ben "NahamSec" Sadeghipour,Kameron "clovismint" Bettridge

SpeakerBio:  Ben "NahamSec" Sadeghipour

Ben Sadeghipour (NahamSec) is a security researcher, ethical hacker, and educator who has spent more than a decade finding and disclosing critical vulnerabilities in some of the world's largest organizations. As one of the most recognized names in the bug bounty community, he has reported thousands of security flaws and consistently ranked among the top researchers on leading hacking platforms. Beyond his own research, Ben is passionate about lowering the barrier to entry in cybersecurity. Through his widely followed educational content, live streams, and the conferences he founds and organizes, he has helped train a new generation of hackers around the world. His work blends deep technical expertise with a commitment to mentorship and community building.Ben speaks regularly at industry conferences on offensive security, bug bounty hunting, and building a career in cybersecurity.

SpeakerBio:  Kameron "clovismint" Bettridge

Kameron Bettridge (Clovis Mint) is an application security engineer at Blizzard Entertainment, where he works to secure systems behind some of the world's most popular games. Alongside his day-to-day role, he takes on contract work for Gray Swan as an AI red teamer and arena engineer, where he has contributed to testing the limits of modern AI systems. Kameron is a fierce competitor on the CTF circuit, playing with The Hackers Crew; ranked 3rd globally on CTFtime in 2024, as well as Squid Proxy Lovers and the US Cyber Team, with whom he will represent the United States in Tokyo. He has competed at the highest levels of the sport, reaching the finals of DEF CON, Google CTF (Hackceler8), and more


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 14:00-14:30 PDT


Title: AI Nightmare: Hacking at 0-Hour
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Many of us have heard that AI is just hype. But is that really the case? In this talk, Pedro “drop” Paniago walks through the experiment he conducted by applying AI to his bug bounty methodology, resulting in findings worth $50K in just a few weeks. Through real examples, lessons learned, current limits, and practical tips, he explores the impact AI is already having on bug bounty and security research.

SpeakerBio:  Pedro "drop" Paniago

Pedro Paniago also known as "drop" in the bug bounty community, is an Offensive Security Manager specializing in Application Security at PwC, as well as a security researcher with a strong focus on AI security. As a bug bounty hunter, he has identified more than 1,000 vulnerabilities and holds 10+ CVEs. He is certified in CBBH, eJPTv2, PJMT, and BSCP. In 2024, Pedro ranked in the top 3 at Belgium’s Hack the Government Live Hacking Event, and in 2025 he placed in the top 6. He is an active voice in the bug bounty community, a HackerOne Brand Ambassador, and co-captain of the Belgian team.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 17:30-17:59 PDT


Title: AI Pentesting is not a Vibe Check
Tags: OWASP Foundation | Creator Talk/Panel
When: Friday, Aug 7, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Most AI security assessments test the chatbot and miss the system. The founding technical lead of the OWASP GenAI Security Project covers what actually breaks when you pentest AI applications across three distinct attack tiers — model exploitation, application-layer flaws, and agentic architecture failures — drawing from frontier model red team operations, bug bounty submissions, and offensive cybersecurity evaluations.

SpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta's MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting "Exfil Everything: A Year of Stealing Data from AI Agents" at Bug Bounty Village DC34 (schedule pending publication).


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 13:00-14:59 PDT


Title: AI Pentesting Trivia Showdown
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map

Description:

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

Speakers:Andy Dennis,Bill Reyor

SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  Bill Reyor
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 15:00-16:59 PDT


Title: AI Pentesting Trivia Showdown
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map

Description:

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

Speakers:Andy Dennis,Bill Reyor

SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  Bill Reyor
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 11:00-11:45 PDT


Title: AI Pipeline for N-days Weaponization
Tags: AI | DEF CON Demo Labs | Intermediate | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Most agentic exploit pipelines stall when there's no public PoC,they search, find nothing, and spin. This talk demos a multi-agent system that exploits n-days from scratch in under an hour, even with zero public exploit code available. Given only a CVE ID, the pipeline autonomously: fetches vulnerability details and the upstream fix commit; spins up a pinned Docker lab running the exact vulnerable version; diffs the patch to identify the exploitable code path; generates vulnerability-class-specific attack guidance (not a generic checklist); and runs iterative exploit + validation loops until RCE is confirmed. Demonstrated live against four CVSS 9.8–10.0 vulnerabilities Apache OpenMeetings deserialization, n8n unauthenticated RCE, Langflow exec() injection, and Spring AI SpEL injection, with working exploits produced in minutes. Every run also outputs a containerized lab and defense report, making it equally useful for detection engineering and patch validation.

Speakers:Andrea Brosio,Arun Nair

SpeakerBio:  Andrea Brosio

Andrea Brosio is a Security Researcher and Senior Content Engineer at TryHackMe, specializing in red teaming, malware development, and offensive security. With prior experience as a Bug Hunter and Red Team Operator he combines real-world adversarial expertise with a passion for creating engaging cybersecurity training.

SpeakerBio:  Arun Nair

Arun Nair is a Security Engineer at Google and founder of Ryvane Academy, specializing in AI Security, malware development, defense evasion, and adversary simulation. He holds several respected certifications, including OSCP, CRTP, CRTL, CodeMachine Malware Techniques, and HackSys Windows Kernel Exploitation. Over the years, Arun has worked with leading organizations such as JP Morgan, and EY, focusing on offensive security and red teaming engagements. Outside of his professional work, he is an active contributor to the cybersecurity community, from designing Capture the Flag (CTF) challenges to delivering talks and workshops at events like DEFCON Red Team Village, HeapCon, MCTTP, BSides Transylvania, HackSpaceCon, RingZer0, c0c0n, and various local meetups. When he’s not on engagements or speaking at conferences, Arun shares his research and insights through his blog at dazzyddos.github.io


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: AI Village - Hal CTF
Tags: AI Village | HALctf (AI Village CTF) | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Get ready for the next evolution of competitive hacking at DEFCON 34! The AI Village is thrilled to introduce HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF is designed around how far you can stretch small local models that almost everyone can run. The first place prize is a DGX Spark so that you can continue your local hacking agent journey at home.

In this high-stakes arena, participants do not interact with targets directly. Instead, you will design and deploy autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, we’re asking for full containers that you can load up with all the tools you need to succeed.

To make it easy we’re hosting everything, from the targets to your agents to the models. We have a mix of old and new, and you get more points if you use smaller models. Runs are quick and show you all of the logs and points so you can improve the agent over the course of the con.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: AI Village Plays Pokemon: DEFCON Edition
Tags: AI Village | AI Village Plays Pokemon: DEF CON Edition | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Agent harnesses and tooling have quickly become the AI buzzwords of 2026, but what do these even mean, and why should you consider building them? We’re showing off how custom tooling can empower local models in the most accessible way possible: playing Pokémon. Join us in this fun, novice-friendly demo where we show how to build tooling for local models, and walk through what you should and shouldn’t consider turning into tools. All the models and tools are open source, so feel free to use them to make your own agents to play our emulations of Pokémon Fire Red and Leaf Green.

SpeakerBio:  Nick Ashworth, Maker at AI Village

Nick is a Hacker and Engineer with almost 15 years of experience hacking everything from power grids to satellites for the DoD. He’s presented and made demos for Aerospace, Car Hacking, ICS, and the AI Village for the past seven years. He currently helps lead the AI Village.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 10:00-10:30 PDT


Title: AI Village: Opening Remarks
Tags: AI Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 10:00-17:59 PDT


Title: AI Village: Village Open
Tags: AI Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

We’re bringing AI Village back to focus on what actually matters: practical, no-bullshit AI security. LLMs are an amazing technology, but they’re not magic. We are stripping away the industry hype and focusing on hands-on skills, whether you are building your first exploit or leading an AI red team.

Here is what you can expect this year:

Drop-In Workshops: Walk up, grab a seat, and learn. We have drop in hands on mini-workshops on a bunch of topics. These include basic AI topics like how LLMs actually work, and how to build agents from scratch. For red teamers we have ones ranging from prompt injection to manipulating malware detection models. This is all running locally on a cluster we’re bringing to DEF CON.

HalCTF: Our main competition this year will teach you how to write and fine-tune your own pentesting agent using open-source models. To handle the massive compute load, we're safely detonating these agents on GCP, giving each participant a dedicated GPU for their models.

Other Agent Shenanigans: The field moves fast and there’s going to be something new by defcon. We’re bringing a lot of compute to host things and we’ll have some surprises in the space.

Whether you want to hear top-tier research from the people actually breaking these models or you just want to sit down and write an autonomous pentesting agent, we have the hardware and the labs ready for you.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 15:30-15:59 PDT


Title: AI vs AI: Securing Telecom in the Era of Autonomous Cyber Warfare
Tags: Telecom Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
Key Discussion Points:
1. AI vs. AI Cyber Warfare: How AI is transforming both cyber defense and cyber offense in telecom, and whether autonomous attacks are already becoming a reality.
2. AI-Powered Telecom Security: The role of AI in SOC operations, fraud detection, threat intelligence, network security, and automated incident response.
3. Securing AI & AI Governance: Protecting AI models from threats such as prompt injection, data poisoning, model theft, and ensuring secure AI adoption through governance and human oversight.
4. Future of Telecom Security: AI-native networks, OEM and supply chain security, the evolution of security professionals, and preparing telecom operators for the AI-driven threat landscape by 2030.
Speakers:Rohini,Pankaj Sontakke,Will Thomas,Isabel Manjarrez,Omer Farooq,T -Mobile CTF Team,James(GSMA),Arvind Singh

SpeakerBio:  Rohini
No BIO available
SpeakerBio:  Pankaj Sontakke
No BIO available
SpeakerBio:  Will Thomas
No BIO available
SpeakerBio:  Isabel Manjarrez, Threat Researcher

[EN] María Isabel Manjarrez is a security researcher with Kaspersky's Global Research and Analysis Team (GReAT). She specializes in investigating threat actors in Latin America, tracking their movements, and analyzing the new techniques they deploy. She holds a degree in telecommunications and electronic systems engineering and her interests include threat intelligence, malware analysis, satellite communications, electronics, and music.

She has shared her knowledge as a speaker at local and international conferences such as Defcon, Security Analyst Summit (SAS), and EkoParty.


[ES] María Isabel Manjarrez es investigadora de seguridad en el Equipo Global de Investigación y Análisis (GReAT) de Kaspersky. Se especializa en la investigación de actores amenaza en Latinoamérica, rastrea sus movimientos y analiza las nuevas técnicas que implementan. Es Ingeniera en telecomunicaciones y sistemas electrónicos, sus intereses incluyen la inteligencia de amenazas, análisis de malware, comunicaciones satelitales, electrónica y música.

Ha compartido su conocimiento como ponente en conferencias locales e internacionales como Defcon, Security Analyst Summit (SAS) y EkoParty.

SpeakerBio:  Omer Farooq

Omer Farooq is a cybersecurity, cloud, and artificial intelligence leader with more than twenty-five years of experience spanning application security, cloud architecture, software engineering, DevSecOps, AI security, and technology innovation. As Founder and Principal Security Consultant at Auxin Security, Omer has advised more than 100 organizations worldwide, including Fortune 500 companies, government agencies, healthcare organizations, and nonprofits. His expertise includes GenAI and LLM security, offensive security assessments, threat modeling, cloud security, DevSecOps transformation, secure software development, and enterprise architecture. Omer is a frequent speaker at industry conferences and events including RSA Conference, BSides DC, AWS events, NAB Show, Microsoft Azure conferences, and numerous cybersecurity forums. His current research focuses on AI security, agentic systems, retrieval-augmented generation security, offensive AI testing, and emerging threats targeting enterprise AI deployments.

SpeakerBio:  T -Mobile CTF Team
No BIO available
SpeakerBio:  James(GSMA)
No BIO available
SpeakerBio:  Arvind Singh
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 15:30-16:25 PDT


Title: AI-assisted RF Hacking with GNU Radio
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 16:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Software defined radios have lowered the barrier to RF experimentation, but GNU Radio still requires a working knowledge of blocks, port types, sample rates, hardware drivers, and connection rules. This talk presents an AI-assisted GNU Radio design system that lets a user describe an RF task in natural language, then uses a large language model to build, validate, and organize the resulting flowgraph through structured tool calls.

Direct LLM-generated GNU Radio code often looks plausible but fails in practice. Blocks may be incompatible, parameters may be invalid, connections may not match, and visual flowgraphs may be arranged in ways that make them difficult to inspect or modify. This system addresses those problems by exposing GNU Radio through validated tools for block discovery, hardware detection, flowgraph creation, parameter configuration, connection management, layout, and code generation. Before producing the final design, it checks port types, stream and message domains, vector lengths, and incompatible signal paths. When blocks cannot be connected directly, it recommends the required conversion blocks instead of generating a broken flowgraph.

This presentation will show the system live through practical SDR and RF security workflows. The goal is to make GNU Radio flowgraph development faster to use when exploring wireless systems, validating assumptions, and moving from an RF idea to a working flowgraph.

SpeakerBio:  Erwin Karincic (Dollarhyde)

Erwin is an experienced security researcher specializing in both hardware and software reverse engineering, binary analysis, and exploit development across a range of processor architectures. He has notable experience in implementing complex Radio Frequency (RF) waveforms using Software Defined Radios (SDRs) for cybersecurity applications, complemented by his proficiency in designing, simulating, and fabricating antennas tailored for such applications. His past work includes extensive TCP/IP networking experience, designing worldwide secure communication systems. Erwin holds a number of prestigious certifications, including OSCP, OSCE, OSWE, OSEE, and CCIE Enterprise Infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 13:00-13:59 PDT


Title: AImaru C2: La Nueva Era del Living off the Land (MCP AI-Driven C2 )
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

¿Qué sucede cuando la barrera técnica para ejecutar ataques Living off the Land (LotL) desaparece y una IA toma el control?

Esta charla presenta AImaru C2, un framework ofensivo que expone el futuro del cibercrimen. Aimaru introduce varios conceptos nuevos para la industria como la utilización del Model Context Protocol (MCP) para transformar clientes inofensivos en Troyanos de Acceso Remoto (RATs). Estos agentes usan binarios nativos del sistema para operar de forma encubierta, orquestados íntegramente por un LLM sin restricciones mediante lenguaje natural.

Demostraremos cómo AImaru automatiza el cyberkill chain: desde bypasses dinámicos de AMSI generados al vuelo, jerarquización de tareas para Lotl, hasta la explotación de un vectores inéditos intenando abusar de IDEs locales (como Claude Code o PyCharm) para ejecución silenciosa.

Analizaremos cómo esto revolucionará el ecosistema RaaS/MaaS y los severos desafíos que enfrentarán los equipos de respuesta ante esta nueva generación de amenazas autónomas.

SpeakerBio:  Mario Lobo, Cyber Threat Intelligence Researcher

I am a Colombian Cybersecurity Engineer with a Master’s degree and a deep passion for the field. I have spent over 18 years immersed in various domains of Information Security and Cyber Intelligence.

My career has spanned critical sectors, including National Defense, where I spent nearly 10 years collaborating with Strategic Cyber Intelligence teams worldwide. I have led multiple cybersecurity teams for multinational banking institutions within the financial sector, and for several years now, I have served as the Lead Threat Intelligence Researcher at Lumu Technologies. I have been a main track speaker at prestigious international conferences such as Ekoparty, 8.8 Gob, BSides São Paulo, BSides Colombia, and Cyberwings, among others.

Beyond the professional realm, I am a guitar enthusiast, a dedicated cyclist, and a consummate music lover.

--

Soy colombiano, Ingeniero Magister en Ciberseguridad y un apasionado por el tema. Llevo más de 18 años sumergido diferentes campos de la Seguridad de la Información y la Ciberinteligencia.

Mi trayectoria me ha permitido transitar por sectores como la Defensa Nacional, donde por casi 10 años colaboré con equipos de Ciberinteligencia Estratégica alrededor del mundo. Lideré diferentes equipos de ciberseguridad para la banca multinacional en el sector Financiero y desde hace algunos años me desempeño como Lider Investigador de Inteligencia de Amenazas en Lumu Technologies. He participado como conferencista main track en eventos como Ekoparty, 8.8 Gob, Bsides Sao Paulo y Bsides Colombia, Cyberwings entre otros.

Fuera del ámbito profesional, soy un amante de la guitarra, la bici y un melómano consumado.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: All About UART
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

UART, it’s in your smart camera, router, maybe even your phone and it’s usually the easiest foothold into a device. In this hands-on workshop you’ll learn to find it with a multimeter, read it with a logic analyzer...


Return to Index    -    Add to Google    -    ics Calendar file

Call Center Village - Friday - 15:00-15:59 PDT


Title: An Intrusion in the Living Room is now an international incident: SuperBOX Part 3
Tags: Call Center Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

Free cable box, or Chinese-controlled botnet node? Darknet Diaries Ep. 172 exposed SuperBox as both. Part 3 breaks down how one sketchy streaming device turned a living room into a national security case.

SpeakerBio:  D3adA55
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map

Description:
Speakers:Monnappa K A,Sajan Shetty

SpeakerBio:  Monnappa K A
No BIO available
SpeakerBio:  Sajan Shetty
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map

Description:
Speakers:Monnappa K A,Sajan Shetty

SpeakerBio:  Monnappa K A
No BIO available
SpeakerBio:  Sajan Shetty
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 10:00-10:45 PDT


Title: Anatomy of a Sandworm: A Deep Dive into the Shai-Hulud Attacks
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:
Format: Talk
Length: 20-40min (I'm flexible, I can adjust the content based on how long the time slot is)

Abstract: In September 2025, an obscure npm package shipped with a piece of JavaScript that should not have been there. A new beast had emerged among supply chain attacks. Within 48 hours, that JavaScript had copied itself into more than 180 packages. It did something that hadn't been seen before in such an attack. It was self-propagating. It was a worm. And it was LOUD. Hundreds of public repos were created, littered with stolen secrets. Within nine days, it had triggered an emergency CISA alert.

Two months later, we witnessed the "Second Coming": a far more aggressive successor returned, racing a deadline npm itself had set, and leaving behind roughly 700 compromised packages, ~25,000 GitHub repositories of stolen secrets, and a destructive payload that wiped victims' home directories when it couldn't exfiltrate them. And these were just the first two attacks.

This talk is a technical breakdown of the Shai-Hulud worm family: the first malware to spread successfully through the npm ecosystem as a self-replicating worm, and the iterations that followed. We'll examine how the malware infected its victims, turned legitimate security tooling against them, what it stole, and how it kept spreading.

Each iteration evolved to defeat the defenses put in place against the last, swapping tools, tactics, and even its JavaScript runtime. Stranger still: the malware wasn't trying to hide. It branded its own exfiltration repositories, named its propagation functions clearly in source, and used victims' own GitHub accounts to share stolen secrets. By the end, we'll have a clearer picture of how these supply chain worms work, and what each rising of Shai-Hulud has taught us.

SpeakerBio:  Megg Sage, AppSec engineer who explains scary things about your dependencies

Megg is an application security engineer who started out as a web developer. Security drew her in with the endless puzzles and challenges put forth by the field. She loves sharing knowledge, particularly when she can both educate and frighten her audience at the same time. After all, what can happen when security goes wrong is pretty scary. She also enjoys working closely with software engineering teams to try to make security work within existing development practices or at least minimize the pain of "doing security." When not behind a computer, Megg can usually be found making some sort of costume piece or shiny object.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 11:00-11:30 PDT


Title: Anomalies Are Not Normal: Election Foam Strikes and the Tragic Story of Mikey Hicks
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

The last time I spoke at DEF CON's Voting Village, Curling v. Raffensperger was still awaiting a decision. Since then, the technical record has expanded, the litigation has largely run its course, and yet the strategic debate has changed remarkably little. High-consequence systems operate under two competing optimizations. Engineers optimize for reality. Administrators optimize for operations. Successful missions answer operational questions; they do not validate engineering assumptions. Yet documented engineering anomalies that do not lead to immediate mission failure gradually become accepted as normal. Researchers are repeatedly asked to demonstrate that documented engineering anomalies will produce catastrophic failure, while institutions are seldom asked to explain why anomalies have become compatible with normal operations. This burden-shifting has shaped two decades of election security research while limiting its strategic impact. The election security community has accepted the wrong burden. To the extent that security researchers participate in defining the safety boundaries of electronic election infrastructure, their role has largely been to discover and document anomalies and provide expert testimony in proceedings aimed at optimizing normal election operations. Lost in that process is the implication that "normal operation" has a factual, engineering basis. In practice, normality has become an institutional designation that researchers seldom contest. This talk argues that changing the burden fundamentally changes what institutions are permitted to call normal. It proposes a new research agenda focused less on discovering the next anomaly than on preventing documented engineering anomalies from becoming institutionalized as accepted practice. The implications extend well beyond elections. The forthcoming book Sovereign Code argues that the same organizational dynamics increasingly govern all software-mediated public administration. The success of the next generation of election security research will be measured not by the anomalies it discovers, but by the anomalies institutions are no longer able to call normal.

SpeakerBio:  Richard DeMillo

Richard DeMillo holds the Charlotte B. and Roger C. Warren Chair in Computing at The Georgia Institute of Technology in Atlanta, Georgia. He is the former Dean of Georgia Tech’s College of Computing, founding Chair of the School of Cybersecurity and Privacy, and founder of the Center for 21st Century Universities. In industry, he was previously Vice President and Chief Technology Officer for Hewlett-Packard, and General Manager and Head of Computing Research for Bellcore/SAIC. In government, he directed the Computer and Computation Research Division at the National Science Foundation and the Software Test and Evaluation Project for the Office of the Secretary of Defense. He is the author of more than 100 scientific articles, books, and patents in cryptography, cybersecurity, and software engineering. He is a fellow of the American Association for the Advancement of Science, the Association for Computing Machinery, and the Lumina Foundation.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 11:00-11:45 PDT


Title: AOBTD: AI One Bites The DAST
Tags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:
I hate the way most DAST tools test: firing payloads at parameters with no idea what the app is. They catch the obvious stuff, but miss the parts that actually need context. Newer LLM scanners are either commercial black boxes (iykyk) or "GPT, find bugs at this URL" wrappers that fall over outside a CTF box.

AOBTD is my attempt at a third option: a scanner that behaves less like a fuzzer and more like a pentester at the start of a test.

Instead of fuzzing harder, AOBTD first tries to understand the target. It explores the surface, identifies what pages and endpoints are for, takes notes, builds hypotheses, and then sends targeted requests based on that context. This target understanding drives the rest of the testing process, which is the only realistic way automated tooling can get closer to business-logic bugs.

The crawler is designed to avoid wasting time on repeated templates while still sampling outliers, so the odd page hidden in a sea of similar ones does not get ignored. When findings are confirmed, AOBTD can chain them into multi-step attack stories rather than reporting isolated payload hits.

This is where LLMs are actually useful: reading a page, understanding the purpose of a form, naming the function behind a JSON endpoint, and doing the kind of prioritization a pentester normally spends hours on.

SpeakerBio:  Ozgun "ozzy" Kultekin

Ozgun (aka ozzy) is a Senior Application Security Engineer at Trendyol Group, where he spends his days breaking applications before the bad guys do. He holds the OSCE3 certification and specializes in offensive security research with a focus on application security and red team operations.

He has presented at several conferences including DEF CON, Hacktivity, and multiple BSides events, covering topics ranging from red teaming to application security. He is currently focused on integrating AI into offensive security workflows and actively researching how large language models can be applied in practical, technical ways within cybersecurity. He regularly shares his work and tools as open source.

When he's not hunting bugs or running red team ops, he's probably at the poker table.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-23:59 PDT


Title: Apex Park (Cloud Village CTF)
Tags: Cloud Village | Apex Park (Cloud Village CTF) | Contest
When: Friday, Aug 7, 10:00 - 23:59 PDT
Where: LVCCW Level 3 W312 (Cloud Village CTF) - Map

Description:

Cloud Village CTF will be a jeopardy style 2 days contest where participants will have to solve challenges around Cloud infrastructure, security, recon, etc. These challenges will cover different cloud platforms including AWS, GCP, Azure, Digital Ocean, etc. We will also reward our top 3 teams with awards.​​

Participant Prerequisites

A laptop with unfiltered internet access and an open mind to learn with the community.

Timing

Cloud Village CTF @ DEF CON 34: 7th & 8th August 2026 CTF starts - 7th August, 2026 - 10:00AM PDT CTF closes - 8th August 2026 - 23:59PM PDT CTF registrations opens - 30th July 2026 - 10:00AM PDT


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 13:00-14:59 PDT


Title: AppSec Quiz Gauntlet: Spot the Vulnerability
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map

Description:
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
SpeakerBio:  Avek Kolech
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 10:30-10:40 PDT


Title: AppSec Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 10:30 - 10:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting AppSec Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to AppSec Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 21:00-00:59 PDT


Title: Arcade Party
Tags: Party
When: Friday, Aug 7, 21:00 - 00:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1,2) - Map

Description:

The Arcade Party is back! Come play your favorite classic arcade games while jamming out to Keith Myers DJing. Your favorite custom built 16 player LED foosball table will be ready for some competitive games. This epic party, free for DEF CON 34 attendees to enjoy and play, is hosted by the Military Cyber Professionals Association (a tech ed charity) and friends.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: Arcanum Security Labs
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Arcanum Security delivers modern cybersecurity through cutting-edge training and consulting, led by Jason Haddix and crew, spanning offensive security, bug bounty hunting, and AI security. Stop by during village hours to work through their hands-on labs.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: ARINC 664 CTF Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

This is a two-part CTF activity designed to immerse participants in an aircraft’s ARINC 664 network.

Virtual Challenge – Test your skills by navigating through a series of interactive tasks that build foundational knowledge of the ARINC 664 protocol – one of the communications protocols for onboard networks. Gain a high-level understanding of how this protocol operates and its security considerations.

Hardware Challenge: Take it to the next level by engaging with model hardware. Send messages to manipulate and interact with simulated aircraft systems!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 16:00-18:59 PDT


Title: Atlanta Metro Meetup (DC404/DC678/DC770/DC470)
Tags: Meetup
When: Friday, Aug 7, 16:00 - 18:59 PDT
Where: LVCCW Level 3 W327 (Misc Meeting Room) - Map

Description:

They say Atlanta is the city too busy to hate, but it also has too much traffic for its widespread hacker fam to get together in a single meetup. So instead, we're meeting up in the desert during DEF CON! The one time of year when intown, northern burbs, south siders, and anyone else connected to DC404's 30+ year legacy can catch up and share stories. Join us and meet your fellow ATL hackers!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 14:00-15:59 PDT


Title: Automated Mythic Deployment with Gaia
Tags: Red Team Village | Misc
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

Deploying a C2 server manually is a time consuming, sometimes annoying process. Deploying a C2 server weekly for two months, even more so. This Tactic will cover Gaia, the tool developed by the Midwest Collegiate Cyber Defense Competition Red Team to handle automated C2 deployment, user provisioning, payload creation, and more.

This Tactic will have attendees start with a standard Debian VM, and end with a fully provisioned Mythic server that can serve as the foundation for your next CTF, lab, or with a little extra work, your next op.

SpeakerBio:  Shad Brown

Shad is an Associate Adversary Simulation Consultant at SpecterOps where he performs a variety of offensive security assessments. Prior to his time at SpecterOps, he had roles in vulnerability management and network security engineering.

He enjoys teaching and mentorship and has spoken to students and faculty at dozens of high schools, colleges, and universities across the United States. In the last few years, he has volunteered as the red team lead for the states of Minnesota and Indiana in the Collegiate Cyber Defense Competition.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Aviation ISAC Cybersecurity Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Chaos has ensued at a major international airport. Flight info displays flicker with false data. Baggage systems fail. Aircraft controls and drones (by the riverside) are compromised. Even the skies are no longer safe.

Your mission: investigate the breach, neutralize the threats, and take back control of the airport. The airport depends on you. The clock is ticking!

As a participant, your first step is to register ahead and read the rules at: https://aviationcyberctf.com/ and bring your own laptop to the venue.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-12:59 PDT


Title: Aw, man…pages!
Tags: Aw, man...pages! | Contest
When: Friday, Aug 7, 10:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

How well do you know your man pages? Find out by teaming up with up to 3 other people (or come solo and get matched up with some new friends) and play "Aw, man...pages!". Across several rounds, your knowledge of man pages and software will be tested to the limit. Can you remember what command line flag is being described by its help text? Can you identify a tool just from a man page snippet? Can you decipher our cryptic command clues? Will you prove yourself worthy to be crowned the man page champion?

Participant Prerequisites

None. We will provide answer sheets and pens. Participants can form teams of up to 4 people beforehand, or at the event.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 15:00-15:45 PDT


Title: AzProwl: Prowling the Azure Attack Surface
Tags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

Cloud environments aren’t being breached through zero-days—they’re being traversed through identity, misconfigurations, and overlooked data paths. Azure is no exception.

This talk introduces AzProwl, an offensive-focused tool designed to emulate how real attackers enumerate and chain together access across Azure environments. Rather than stopping at surface-level enumeration, AzProwl maps identity relationships, token abuse opportunities, and data plane exposure to uncover realistic attack paths.

We’ll walk through how attackers move from initial access to meaningful impact using Azure-native mechanisms—leveraging identity roles, service principals, tokens, and storage access. Attendees will see how seemingly low-risk permissions compound into high-impact compromise.

Whether you’re red team, blue team, or somewhere in between, this session will provide practical insight into how Azure environments are actually attacked—and how to detect and defend against it.

Speakers:Jared "GonePhishing402" Graff,Jeff Daniels

SpeakerBio:  Jared "GonePhishing402" Graff

I’m a Lead Incident Response Analyst at Target with experience spanning red team operations, blue team defense, and incident response. My background working in Azure cloud security at Microsoft helped shape my approach to understanding and defending modern cloud environments and ultimately inspired the development of this training.

I specialize in analyzing and emulating real-world attack paths across cloud identities, authentication tokens, and data planes to uncover gaps in detection and response capabilities. My work focuses on Azure identity compromise, token abuse, cloud persistence techniques, and understanding how adversaries actually operate within cloud environments—not just how we assume they do.

I’m passionate about bridging the gap between offensive and defensive security, translating attacker tradecraft into actionable detection strategies, and developing hands-on labs that help defenders better understand cloud threats. My goal is to make complex attack techniques accessible, practical, and directly applicable to real-world security operations.

SpeakerBio:  Jeff Daniels

Jeff Daniels is a Senior Cloud Solution Architect at Microsoft Federal specializing in cloud security, threat intelligence, and red team operations. With a background in military cyber operations, he brings real-world offensive experience to designing detection strategies, Zero Trust architectures, and large-scale SOC capabilities. Jeff focuses on translating adversary tradecraft into actionable security outcomes for government customers and is actively involved in red team tooling, adversary emulation, and ATT&CK-aligned training.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 14:00-14:45 PDT


Title: AzProwl: Prowling the Azure Attack Surface
Tags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

Cloud environments aren’t being breached through zero-days—they’re being traversed through identity, misconfigurations, and overlooked data paths. Azure is no exception.

This talk introduces AzProwl, an offensive-focused tool designed to emulate how real attackers enumerate and chain together access across Azure environments. Rather than stopping at surface-level enumeration, AzProwl maps identity relationships, token abuse opportunities, and data plane exposure to uncover realistic attack paths.

We’ll walk through how attackers move from initial access to meaningful impact using Azure-native mechanisms—leveraging identity roles, service principals, tokens, and storage access. Attendees will see how seemingly low-risk permissions compound into high-impact compromise.

Whether you’re red team, blue team, or somewhere in between, this session will provide practical insight into how Azure environments are actually attacked—and how to detect and defend against it.

Speakers:Jared "GonePhishing402" Graff,Jeff Daniels

SpeakerBio:  Jared "GonePhishing402" Graff

I’m a Lead Incident Response Analyst at Target with experience spanning red team operations, blue team defense, and incident response. My background working in Azure cloud security at Microsoft helped shape my approach to understanding and defending modern cloud environments and ultimately inspired the development of this training.

I specialize in analyzing and emulating real-world attack paths across cloud identities, authentication tokens, and data planes to uncover gaps in detection and response capabilities. My work focuses on Azure identity compromise, token abuse, cloud persistence techniques, and understanding how adversaries actually operate within cloud environments—not just how we assume they do.

I’m passionate about bridging the gap between offensive and defensive security, translating attacker tradecraft into actionable detection strategies, and developing hands-on labs that help defenders better understand cloud threats. My goal is to make complex attack techniques accessible, practical, and directly applicable to real-world security operations.

SpeakerBio:  Jeff Daniels

Jeff Daniels is a Senior Cloud Solution Architect at Microsoft Federal specializing in cloud security, threat intelligence, and red team operations. With a background in military cyber operations, he brings real-world offensive experience to designing detection strategies, Zero Trust architectures, and large-scale SOC capabilities. Jeff focuses on translating adversary tradecraft into actionable security outcomes for government customers and is actively involved in red team tooling, adversary emulation, and ATT&CK-aligned training.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 10:00-17:59 PDT


Title: BadVR: Signals Everywhere a collaboration with XR Village
Tags: OWASP Foundation | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

BadVR Data Exploration through VR visualization. See RF signals, cellular signals and new for 2026, Meshtastic signals, step into the data with a hands-on VR experience

Speakers:Jad Meouchy,Suzanne Borders

SpeakerBio:  Jad Meouchy, CTO + Co-Founder at BadVR

Jad, originally from northern Virginia, holds dual B.S. degrees in Computer Engineering and Psychology from Virginia Tech, and is a graduate of the Thomas Jefferson High School for Science and Technology. While in college, he engineered and built the data visualization components of an emergency response simulation that went on to receive 2M in public grant funding. Over his 15-year career, Jad has founded five startups and successfully exited three. His professional expertise is in software architecture and development, specifically big data analytics and visualization, and virtual and augmented reality development. Based in Los Angeles since 2010, Jad promotes the community by organizing developer meetups and events, and volunteering time for STEM initiatives.

SpeakerBio:  Suzanne Borders, CEO + Founder at BadVR

Suzanne studied psychology at University of Missouri, Kansas City and previously worked as Lead UX/Product Designer for over 9 years at companies such as Remine (raised $48M) and CREXi (raised $54M) where she specialized in designing intuitive, high-performant data analytic interfaces. In 2019, Suzanne founded BadVR and was awarded a “Rising Stars” innovation award from IEEE. To date, she’s raised over $4M in non-dilutive funding for BadVR, via grants from the National Science Foundation, NOAA, Magic Leap, Qualcomm, and more. Suzanne has grown the company from 2 to 25 people and was awarded 4 patents for innovations she created while leading the BadVR team. Over the past 5 years, Suzanne emerged as a thought-leader in the immersive data visualization and analytics space. She has been a keynote speaker at over 25 national and international conferences. In her spare time, Suzanne travels for inspiration (81 countries and counting) and is proud to be a published author and former punk.  Suzanne thrives at the intersection of product design, immersive technology, and data; she’s a believer in the artistry of technology and the technicality of art and remains passionately dedicated to democratizing access to data through universally accessible products. 


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 15:30-17:59 PDT


Title: BBOT: Automating the OSINT Kill Chain with a Single Command
Tags: Recon Village | Creator Workshop
When: Friday, Aug 7, 15:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Reconnaissance is the foundation of every successful engagement but fragmented tooling, manual chaining, and missed data leave gaps that cost you findings. BBOT (Bighuge BLS OSINT Tool) was built to solve that. Developed by Black Lantern Security, BBOT is a recursive, event-driven OSINT framework that replaces the traditional phased approach with continuous, real-time discovery every new piece of data is immediately fed back into the scan engine to uncover what linear workflows miss.

This is a fully hands-on workshop. Attendees will install and configure BBOT, then run it live against their own scoped bug bounty targets turning the session into real reconnaissance rather than a slide-driven demo. We'll cover BBOT's 100+ module architecture spanning subdomain enumeration, cloud asset discovery, email harvesting, web spidering, and vulnerability scanning with Nuclei, all chainable in a single command and firing recursively in real time. Along the way we'll dig into scope management, passive vs. active recon tradeoffs, and the web hacking modules that can point you toward real findings.

By the end of the session, attendees will walk away with actual scan output from a live target, a repeatable BBOT-driven recon workflow they can drop into their next program, and a clear understanding of how to triage findings into real submissions. Whether you're new to automated recon or a seasoned bug bounty hunter still stitching tools together by hand, this workshop will change how you approach OSINT at scale.

Module 1 — Why BBOT? The Problem with How We Recon Now

The fragmented toolchain problem: Amass → Subfinder → httpx → manual grep

Why phased OSINT misses things — and what recursive, event-driven recon solves

BBOT's origin at Black Lantern Security and design philosophy

Quick architecture overview: modules, events, presets, scope

3.0 Updates - Rustification of HTTP and DNS

Q&A / audience skill check

Module 2 — Getting Oriented: Installation, Config & First Scan

Verify install and run bbot --help

Listing and exploring modules with bbot -l

Understanding flags vs. modules vs. presets

Exercise 2.1: Run your first subdomain scan

Reading and understanding BBOT output

Scan output folders, naming conventions, and where data lives

Module 3 — Subdomain Enumeration Deep Dive

How BBOT's recursive engine finds more than traditional tools

Passive vs. active enumeration — when to use each

Subdomain mutations and wordcloud usage

Exercise 3.1: Full active subdomain enum

Module 4 — Going Deeper: Cloud, Email & Asset Discovery

Cloud enumeration: S3 buckets, Azure blobs, GCP assets

Email harvesting for org footprinting

Combining flags for broader discovery

Exercise 4.1: Run a combined cloud + email + subdomain scan

Identifying misconfigured or exposed cloud assets in output

Discussion: how these findings translate to bug bounty submissions

Module 5 — Web Hacking Modules & Vulnerability Scanning

Overview of BBOT's web module suite: httpx, gowitness, wappalyzer, nuclei

Web spidering for email, secrets, and exposed paths

Nuclei integration — what it scans for and how to interpret results

Exercise 5.1: Full web scan with screenshots

Exercise 5.2: Kitchen sink scan (instructor-guided, safe target only)

Setting expectations: BBOT points you at the doors — you still have to kick them open

Module 6 — Triage, Workflow & What Happens After the Scan

How to structure your post-BBOT workflow: what to investigate first

Prioritizing findings by severity and exploitability

Avoiding common pitfalls: rate limiting, duplicate findings, out-of-scope mistakes

Building a repeatable bug bounty recon workflow around BBOT

Scheduling and automating recurring scans for continuous monitoring

Wrap-Up & Q&A

Recap of key takeaways

Recommended next steps and resources

GitHub, docs, and community links

Open Q&A

SpeakerBio:  Mark Gaddy
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 11:00-11:45 PDT


Title: Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Hardware/IoT | Mobile | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
When: Friday, Aug 7, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

What happens when you buy a popular medical device and realize it blindly trusts any BLE connection within 30 meters?

BRAT (BLE Recon and Attack Toolkit) is the open-source Python arsenal we built to systematically take over an FDA-listed consumer hormone analyzer and generalize the attack to the class of devices behind it. Relying on the Nordic UART Service (NUS), the target blindly trusts any connection within 30 meters. BRAT automates the exact attack chain we used to compromise it: passive BLE discovery, protocol reverse engineering, unauthenticated command injection, full bind takeover, and rogue peripheral impersonation to hijack live API session tokens.

Every script is built on the ⁠bleak⁠ async BLE library and deliberately kept small so you can read the code and understand the exploit in minutes. Our Demo Lab features live, end-to-end attacks against a consumer medical device. We’ll demonstrate unauthenticated command injection, rogue peripheral spoofing that intercepts companion app handshakes, and how we injected spoofed hormone sensor data without ever pairing.

Speakers:Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova

SpeakerBio:  Gigi Xiaoqing Liu

Gigi Liu is a graduate security researcher at Northeastern's Security And Privacy Research (SPQR) Group under Professor Kevin Fu, where her work covers embedded systems security, medical device attack surfaces, and AI-generated media detection. She interns at Lila Sciences as a Security and Cloud Engineer, building enterprise-wide agentic AI security infrastructure and detection capabilities for unauthorized AI activity across cloud and SaaS environments.

Her technical work spans wireless protocol reverse engineering, binary exploitation, web and mobile reverse engineering, cloud and AI security. She has applied these skills across medical hardware, automotive platforms, and enterprise cloud environments — from BLE command injection on FDA-listed devices to CarPlay API exploitation to building agentic AI detection controls at scale. As a UCLA psychobiology alum with a consulting background, she brings a multidisciplinary lens to every system: understand what it's designed to do first, then find where it breaks.

SpeakerBio:  Muzzammil Mohammed

Muzzammil Mohammed is an offensive security researcher, penetration tester at Maltek Solutions, and MS in Cybersecurity at Northeastern University. Operating out of the SPQR Lab under Professor Kevin Fu, and serving as a Teaching Assistant Network Security, his work bridges academic vulnerability research with real-world red team execution. As a core developer of WandKit an open-source BLE attack toolkit built to audit medical devices. Muzzammil led the cloud API exploitation phase, successfully confirming a complete authentication bypass and engineering the rogue peripheral session hijack chain. Beyond hardware and API hacking, he is actively developing autonomous multi-agent AI frameworks designed to orchestrate local LLMs for automated security auditing and vulnerability analysis.

SpeakerBio:  Narmina Karimova

Narmina Karimova is a cybersecurity graduate researcher at Northeastern University with a background in enterprise technology across financial institutions and the United Nations. She came to security research from the infrastructure side, which shaped how she approached tearing apart a consumer fertility monitor. For BRAT, she wrote the core BLE attack suite in Python: replay modules, rogue peripheral session capture, unauthenticated hormone data extraction, and the bind takeover chain that captures device ownership in under 15 seconds. She also reverse-engineered the APK with JADX, found hardcoded credentials, and confirmed a CVSS 9.1 IDOR in the third-party integration. Her interest is in the gap between how consumer health devices are marketed and how they actually handle sensitive data.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Friday - 08:30-17:30 PDT


Title: Beat the Breach: Defend, Respond, Survive
Tags: DEF CON Training (Paid) (1-day) | DEF CON Training
When: Friday, Aug 7, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W221 (Training) - Map

Description:
Speakers:McKay Hardy,Wes Wagstaff

SpeakerBio:  McKay Hardy
No BIO available
SpeakerBio:  Wes Wagstaff
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Beer Chilling Contraption Contest
Tags: Beer Chilling Contraption Contest | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest) - Map

Description:

It’s the 21st year of the BCCC and it’s the Beer Chilling Contraption Contest this year! We can finally drink! No more beverage, we are drinking beer now, and boy do we need one. This year we thought we would mix it up and have cold beer and you all could try your hand at warming it. Unfortunately, the guys in charge of getting the ice got a bit too tan walking in this Vegas sun. A different kind of ICE deported them to Botswana and in the ensuing chaos the beverage was left outside and its warm again. Fortunately for everyone involved, WW3 and the inevitable nuclear winter will finally solve the warm beer problem -- well at least temperature-wise. It might be a little HOT in the gamma spectrum. But while we wait for Pooh Bear, BiBi, Putler, and or the Cheeto to kick this global cooling contraption off, its up to us to chill this beer.

You will cool the beer we give you in a red solo cup as quickly as possible to 34 degrees F. You may not alter the beer by mixing it with ice, dry or otherwise. You may bring a device you created or build your own at the convention. There are some great prizes waiting, mostly what I have lying around and don't want to take home. There are some additional rules, check the DEFCON forums or the poster board at the contest!

In conclusion, it’s not just a warm beverage—it’s a testament to the rich tapestry of societal collapse, seamlessly navigating the multifaceted landscape of your broken contraption.

Participant Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 14:00-15:20 PDT


Title: Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR
Tags: Noob Community | Creator Workshop
When: Friday, Aug 7, 14:00 - 15:20 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Cybersecurity has its own language, and business has its own language, and most of the time we're not speaking either of them well. The people who learn to translate between the two are the ones who get listened to, get funded, and get promoted. That's the craft Tony is teaching you in this session.

SpeakerBio:  Tony Martin-Vegue
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 17:00-17:59 PDT


Title: Beyond Normalization: The Expanding Unicode Attack Surface
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Unicode exploitation does not end with normalization. Modern web applications process input through layered pipelines: URL decoding, UTF-8 validation, WAF transformations, framework parsing, surrogate handling, database collation, HTML entity decoding, and increasingly, LLM preprocessing. Each layer implements subtly different assumptions about character validity and equivalence. When those assumptions diverge, security boundaries fail. Building off our popular Black Hat USA 2025 Unicode Briefing, we have continued our research into the complex world of Unicode processing. This research exposes a new class of Unicode pipeline vulnerabilities that extend far beyond canonical normalization issues. We demonstrate how attackers can weaponize illegal UTF-8 sequences to break RE2 validation, exploit surrogate-to-replacement conversions (U+FFFD) to alter semantics, abuse hex overflows to generate filtered characters, and bypass Host/Secure cookie protections via Unicode whitespace desynchronization. We show how MySQL zero-weight collation rules enable filter bypasses even after normalization, how WAF/browser canonicalization mismatches lead to XSS and RCE (including analysis of CVE-2025-55182), and how invisible Unicode variation selectors can jailbreak LLMs or conceal supply chain malware. Using real-world telemetry, live demonstrations, tooling updates and hands-on lab environments, this Briefing reframes Unicode as a distributed parsing vulnerability class, not a character encoding footnote. Unicode is no longer just a normalization problem. It is an architectural attack surface.

Speakers:Ryan "ryancbarnett" Barnett,Isabella "4ng3lhacker" Barnett

SpeakerBio:  Ryan "ryancbarnett" Barnett, Senior Threat Research Manager, Akamai

Ryan Barnett is a Senior Threat Research Manager leading the Akamai App and API Protector (WAF) product. He also acts as s triager on Akamai's and customers' bug bounty programs. In addition to his primary work at Akamai, he is also a former Faculty Member for the SANS Institute, a WASC Board Member and OWASP Project Leader for: ModSecurity Core Rule Set (CRS) Web Hacking Incident Database (WHID). Mr. Barnett has also authored two web security books: Preventing Web Attacks with Apache (Pearson) and The Web Application Defender's Cookbook: Battling Hackers and Defending Users (Wiley).

SpeakerBio:  Isabella "4ng3lhacker" Barnett

Isabella Barnett is a Software Engineering Intern at Akamai and a junior at George Mason Honor's College studying Cyber Security Engineering.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 13:00-13:45 PDT


Title: Beyond Spidering: Behavior Driven DAST for Real Application Workflows
Tags: DEF CON Demo Labs | Intermediate | AppSec | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

Modern web apps do not give up their best attack surface to a spider. The interesting routes, state changes, authenticated functions, and business logic usually sit behind real user behavior. This Demo Lab shows how to stop treating DAST like blind crawling and start driving it with realistic browser flows.

The project began as a software quality proof of concept and evolved through collaboration between an engineering team and a red team into a real operational workflow. By routing Selenium based test scenarios through OWASP ZAP, we turn existing web automation into Behaviour Driven DAST: a practical way to capture richer traffic, exercise meaningful application actions, and uncover security findings that isolated scanning often misses.

Current research shows more than 300% increase in observed attack surface and around 25% improvement in vulnerability detection compared with spider-driven analysis alone. The session will walk through the workflow live, show the comparative results, and introduce a new Python library built from this research.

SpeakerBio:  Sara "testingSoul" Martinez

Hi, I am Sara! I started my career in 2014 as a Software Validation Engineer for Communication products. During five years I improved my testing skills by working on projects in Telecommunication, Geolocation, Big Data and Power Electronics. In 2019, I started to focus all this quality knowledge on testing Cybersecurity Software products, and then magic just happened. I discovered a whole new world that fascinated me. Since then, I have been working to improve all my Software and Quality skills including Cybersecurity at every step I take.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 12:30-12:59 PDT


Title: Beyond Theoretical Risk: How Cache Poisoning Escalated to Critical Account Takeover in TikTok’s Web Infrastructure
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Web cache poisoning is often written off as a class of vulnerabilities with limited real-world impact. Most reported instances only expose non-sensitive user metadata, cause temporary, minor disruptions to static content, or require such narrow, impractical conditions to exploit that they rarely move beyond theoretical proof-of-concept. For TikTok’s Vulnerability Management team, this framing shaped our initial approach to triaging cache poisoning submissions for years—until two radical researcher submissions upended that assumption entirely, proving misconfigured web caches can undermine every pillar of the CIA triad (confidentiality, integrity, availability) to enable catastrophic, scalable harm. In this talk, we’ll start with a foundational breakdown of web cache poisoning: common misconfigurations (from flawed cache key logic to mishandled origin headers) that enable exploitation, and the limited impact profiles that led our team (and many in the bug bounty ecosystem) to historically deprioritize these flaws. We’ll then deep dive into the game-changing submissions that reshaped our security posture and why security teams and bug bounty hunters must re-evaluate how they assess cache poisoning risk—moving past surface-level assumptions about limited impact to audit for hidden, critical exploit pathways. Whether you triage web vulnerabilities, build global web infrastructure, or hunt for bugs at scale, this session will equip you to spot and remediate cache poisoning risks before they’re weaponized against your users.

SpeakerBio:  Glendon Chong, Tiktok

I am part of the Vulnerability Management team for TikTok. Over the past year, I’ve been actively involved in web application vulnerability triage, collaborating with security researchers and internal teams to dissect, validate, and remediate a wide spectrum of web-based threats. My work centers on bridging reporter expertise and TikTok’s security posture—including in-depth negotiations over CVSS scoring, refining triage workflows for emerging attack vectors, and translating complex vulnerability details into actionable remediations. I bring hands-on experience identifying gaps in modern web architectures, advocating for fair, transparent risk assessment with the bug bounty community, and aligning vulnerability prioritization with our platform’s commitment to user safety.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 21:00-00:59 PDT


Title: BIC R00T ACCESS 2026
Tags: Party | Blacks In Cyber Village
When: Friday, Aug 7, 21:00 - 00:59 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Black culture has always shaped the sound of resistance, innovation, and celebration—and at DEF CON, we’re bringing that history to the dance floor. Blacks In Cyber invites you to a night where cybersecurity meets the soundtrack of Black history. From the soulful roots of jazz and blues that coded messages of freedom, to the revolutionary pulse of hip-hop and electronic beats that powered digital creativity, every track tells a story.

This party celebrates the pioneers who pushed boundaries—musically, technologically, and culturally. Expect a curated journey through decades of sound: classic grooves, Afro-futurist vibes, and modern cyber-inspired mixes that honor the past while hacking the future. Whether you’re a seasoned hacker, a first-time DEF CON attendee, or just here for the vibe, this is your space to connect, celebrate, and move.

Come dance through the timeline. Celebrate culture, community, and code. Blacks In Cyber at DEF CON—where history, rhythm, and innovation collide.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 12:00-12:59 PDT


Title: BIC Village Capture the Flag (CTF)
Tags: Blacks In Cyber Village | Blacks In Cybersecurity Village Capture The Flag Competition | Contest
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

The BIC Village Capture the Flag (CTF) is your opportunity to tackle real-world cybersecurity challenges, sharpen your technical skills, and compete alongside students, professionals, and cybersecurity enthusiasts during DEF CON 34. Our CTF is designed to challenge your curiosity, celebrate creative problem-solving, and explore cybersecurity through the past, present, and future.

What to Expect: � Hands-on cybersecurity challenges � Challenges for multiple skill levels � Individual and team-based problem-solving � Opportunities to learn, compete, and connect with the community

Hack to the rhythm and the beat with Hack Hack Revolution. Have an idea or challenge you want to share with the community? Join Bring Your Own CTF (BYOCTF) and contribute your own challenge to the experience. Bring your laptop, curiosity, and determination. Whether you are chasing the top of the leaderboard or solving your very first flag, there is a place for you at BIC Village. Every flag is a lesson. Every challenge is an opportunity. We will see you at the CTF, featuring challenges created by members of the cybersecurity community and the global diaspora!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 15:00-15:45 PDT


Title: BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems
Tags: AI | DEF CON Demo Labs | Intermediate | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Most security tools assume Unix or Windows models built around processes, shells, and network services. On mainframe operating systems, authority is determined through control-plane behavior: job submission (JCL/JES), dataset access, library resolution, and transaction context. These relationships are difficult to observe and are systematically misunderstood by modern security teams; creating blind spots that traditional tooling cannot see.

This Demo Lab shows a live MVS 3.8j environment running under Hercules with a browser-based TN3270 interface. Operational artifacts including submitted jobs, spool output, and execution context are captured and mapped into a graph that reveals hidden trust relationships and indirect execution paths.

The demonstration walks a realistic privilege path: TSO user → JCL submission → STEPLIB hijack → APF library execution — showing how inherited authority creates system-level exposure without exploiting a single vulnerability. No shellcode. No memory corruption. Just the system working exactly as designed.

The platform includes 13 automated walkthroughs across 6 control planes (TSO, JES, RACF, CICS, VTAM, PR/SM), an offline LLM for real-time screen interpretation, and a findings engine that maps results to a repeatable assessment framework.

SpeakerBio:  Adam "w00tock" Toscher

Adam Toscher is a New York–based security engineer and red team operator with over two decades of experience in offensive security, adversary simulation, and automation. Born in New York City and raised upstate, Adam began his career as an “IT vagabond,” starting as a freshman IBM intern porting Linux applications to mainframe systems. That early mainframe work grounded him in large-scale computing, operating systems, and complex enterprise environments before he transitioned into offensive security.

He later held senior security roles at Adobe, Optiv, Accenture, IBM X-Force, and NYC Cyber Command, focusing on realistic adversary emulation, red-team operations, and practical automation.

Most recently, Adam has worked with Cobalt Labs, supporting advanced red-teaming and offensive security engagements for private-sector organizations. Prior to that, he led red-team and adversary simulation work supporting critical public infrastructure with NYC Cyber Command and the FDNY.

His work centers on penetration testing, red teaming, adversary emulation, and security tooling across private-sector and government environments. Outside of security, Adam values balance and lifelong learning, and is an avid reader, runner, swimmer, and gamer.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 16:00-16:45 PDT


Title: BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems
Tags: AI | DEF CON Demo Labs | Intermediate | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Most security tools assume Unix or Windows models built around processes, shells, and network services. On mainframe operating systems, authority is determined through control-plane behavior: job submission (JCL/JES), dataset access, library resolution, and transaction context. These relationships are difficult to observe and are systematically misunderstood by modern security teams; creating blind spots that traditional tooling cannot see.

This Demo Lab shows a live MVS 3.8j environment running under Hercules with a browser-based TN3270 interface. Operational artifacts including submitted jobs, spool output, and execution context are captured and mapped into a graph that reveals hidden trust relationships and indirect execution paths.

The demonstration walks a realistic privilege path: TSO user → JCL submission → STEPLIB hijack → APF library execution — showing how inherited authority creates system-level exposure without exploiting a single vulnerability. No shellcode. No memory corruption. Just the system working exactly as designed.

The platform includes 13 automated walkthroughs across 6 control planes (TSO, JES, RACF, CICS, VTAM, PR/SM), an offline LLM for real-time screen interpretation, and a findings engine that maps results to a repeatable assessment framework.

SpeakerBio:  Adam "w00tock" Toscher

Adam Toscher is a New York–based security engineer and red team operator with over two decades of experience in offensive security, adversary simulation, and automation. Born in New York City and raised upstate, Adam began his career as an “IT vagabond,” starting as a freshman IBM intern porting Linux applications to mainframe systems. That early mainframe work grounded him in large-scale computing, operating systems, and complex enterprise environments before he transitioned into offensive security.

He later held senior security roles at Adobe, Optiv, Accenture, IBM X-Force, and NYC Cyber Command, focusing on realistic adversary emulation, red-team operations, and practical automation.

Most recently, Adam has worked with Cobalt Labs, supporting advanced red-teaming and offensive security engagements for private-sector organizations. Prior to that, he led red-team and adversary simulation work supporting critical public infrastructure with NYC Cyber Command and the FDNY.

His work centers on penetration testing, red teaming, adversary emulation, and security tooling across private-sector and government environments. Outside of security, Adam values balance and lifelong learning, and is an avid reader, runner, swimmer, and gamer.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 10:00-17:59 PDT


Title: Biohacking Device Lab
Tags: Biohacking Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map

Description:

Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work.

21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 19:00-00:59 PDT


Title: BlanketFort Con
Tags: Party
When: Friday, Aug 7, 19:00 - 00:59 PDT
Where: LVCCW Level 2 W212 (Misc Meeting Room) - Map

Description:
BlanketFort Con: Come for the chill vibes and diversity, stay for the Blanket Fort Building, Cool Lights, Music, and Kid Friendly \ Safe environment. Now with less Gluten and more onesies!

Return to Index    -    Add to Google    -    ics Calendar file

Cryptocurrency Village - Friday - 17:00-17:59 PDT


Title: Blockchain defense, stablecoin attacks, and Web3 OSINT
Tags: Cryptocurrency Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

In this hour, we bring together international hackers to discuss cutting-edge techniques in cryptocurrency security. Our experts break down how distributed red and blue teams face off against crypto developers to secure stablecoin vaults — and how they translated that daily work into a format suited for the Cryptocurrency Village at DEF CON.

We'll also explore how classic Opensource intelligence (OSINT) techniques are converging with modern financial technology to unmask bad actors and bypass security mechanisms. Finally, the panel reveals the tricks that black hats use to extract unauthorized value from real-world mainnet blockchains, including Bitcoin, Solana, Ethereum, and Monero.

As a bonus, you'll get a first look at our forthcoming DEF CON and Black Hat training course, Breaking and Defending Cryptocurrency. We'll share our design process, plans, and the challenges of building a half-dozen hands-on activities that teach the ins and outs of offensive security as it applies to blockchain-based financial technology.

Speakers:Dinmukhammed "Celestial" Kabiden,Izdihar,KL4R10N

SpeakerBio:  Dinmukhammed "Celestial" Kabiden, OSINT Mindset

Dinmukhammed Kabiden, also known as Celestial, is a CTI analyst and Web3 investigator from Kazakhstan focused on OSINT, blockchain investigations, crypto fraud, and cyber threat intelligence. He has experience investigating fake airdrops, wallet-drainer activity, on-chain fund flows, scam infrastructure, and OPSEC mistakes that expose threat actors. He is also the organizer of OSINT Mindset and speaks about practical Web3 investigations, intelligence reporting, and the intersection of off-chain and on-chain evidence.

SpeakerBio:  Izdihar, Swarmnetics / cyber673 / Brunei Cyber Security Association

Izdihar is a cybersecurity practitioner who works in penetration testing and tinkers with a homelab in his spare time, where he has been experimenting with running blockchain testnet nodes. His interest in cryptocurrency is mostly about understanding how the infrastructure works. He helps run cyber673, a small grassroots community in Brunei.

SpeakerBio:  KL4R10N

Sarthak Taneja is a security professional specializing in detection engineering, threat intelligence, cloud forensics, and incident response across fintech, crypto, and Web3 environments. His work focuses on securing digital asset infrastructure, custody workflows, cloud-native systems, and blockchain-adjacent attack surfaces, with experience investigating advanced threat activity from groups such as Lazarus, Kimsuky, BlueNoroff, and ShinyHunters. He has led initiatives across SOC maturity, Detection-as-Code, zero-trust controls, and purple teaming, and has spoken at international security conferences including DEF CON.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 12:00-12:59 PDT


Title: BloodHound OpenGraph Crash Course
Tags: Red Team Village | Misc
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

In this session, attendees will learn how to design data models and build extensions for BloodHound OpenGraph.

After a presentation where I will go over the core concepts & components of BloodHound OpenGraph and the thought process behind BloodHound data modeling, attendees will design a model and build an extension from scratch based on a provided dataset.

I you like to tinker with BloodHound and are curious about the new OpenGraph features, this session is for you...

Note: Bring your own laptop with BloodHound Community Edition installed

SpeakerBio:  JD D

WHOAMI


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 13:00-13:59 PDT


Title: BloodHound OpenGraph: Six Degrees of Everything
Tags: Red Team Village | Misc
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map

Description:

In this session, we'll give a short demo of the BloodHound OpenGraph platform, and show off some modeling capabilities and how to get started working with it. We will show participants an example using lab data with a fake AD environment and Nessus/Vulnerability data and demonstrate how to integrate other sources of data into the existing graph and how easy it is to get started.

Speakers:Rohan Vazarkar,Wes Miller

SpeakerBio:  Rohan Vazarkar

Former pentester and original author of BloodHound, turned developer.

SpeakerBio:  Wes Miller

Wes Miller is on the Developer Relations team at SpecterOps, and has worked on many of the core components of BloodHound Community Edition including many of the core features of OpenGraph


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-17:59 PDT


Title: BloodHound Quest
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area - Map

Description:

BloodHound Based CTF

SpeakerBio:  Hugo van den Toorn

Hugo is former Chief Information Security Officer and has now transitioned back to help other organizations understand adversary tradecraft. With over twelve years of experience in the Information Security industry, he has a solid technical and executive background as hands-on security leader.

Hugo has experience with and a keen interest in Social engineering, phishing and physical penetration testing. Nowadays, Hugo takes pride and joy in helping individual team members and the business grow. With a strong technical foundation, Hugo combines his passion for security, teaching and hacking with a drive for continuous improvement and optimization of people, processes and technology.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-11:59 PDT


Title: Blue Team Village CTF - Project Obsidian
Tags: Blue Team Village | Blue Team Village CTF | Contest
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 2 W213-217 (Blue Team Village) - Map

Description:

Join Blue Team Village for a defender-focused Capture the Flag competition centered on forensic analysis, malware activity in containerized environments, and cloud-infrastructure attacks. Participants will investigate container images, reconstruct incidents, and solve challenges ranging from beginner to expert. Challenge tracks include Container & Malware Forensics, Cloud Attack Forensics, and Converged Frontier. Participants can choose safe forensic snapshots or advanced live-malware challenges conducted in an egress-restricted Kubernetes sandbox.


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Friday - 16:00-16:59 PDT


Title: Bobba! A Complete History of Habbo Hotel Private Servers from Shockwave to HTML5
Tags: Game Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:
SpeakerBio:  InsiderPHD
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Friday - 10:00-16:59 PDT


Title: Bomb Bot Challenge
Tags: Car Hacking Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

In conjunction with the talk, "Hacking the Bomb Bot: How I Learned to Stop Worrying and Love the Boomba", attendees have the opportunity to operate a bomb disposal robot. For those up for a challenge, you'll have a limited amount of time to interact with the robot and test your handling skills. The attendees with the best times will be invited back Sunday morning for a face-off challenge.

The winner will get their very own PackBot 510 to take home!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 16:00-16:59 PDT


Title: Book Signing - Avinash Majeti
Tags: Vendor Book Signing
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Avinash Majeti
Author:

Cybersecurity: Right Access at the Right Time


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 15:00-16:59 PDT


Title: Book Signing - Avinash Majeti
Tags: Vendor Book Signing
When: Friday, Aug 7, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map

Description:
SpeakerBio:  Avinash Majeti
Author:

Cybersecurity: Right Access at the Right Time


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 13:00-13:59 PDT


Title: Book Signing - Brandy Smith
Tags: Vendor Book Signing
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Brandy Smith
Author:

Vegas Hackware, Vol1 self titled and Vegas hackware Vol2 The WonderingRaven's Manifesto


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 11:00-11:59 PDT


Title: Book Signing - Christopher DeCarmen
Tags: Vendor Book Signing
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Christopher DeCarmen
Author:

The Cyber Calendar 2027, Y2K27 Edition


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 14:00-14:59 PDT


Title: Book Signing - Garrett Gee
Tags: Vendor Book Signing
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map

Description:
SpeakerBio:  Garrett Gee
Author:

The Hacker Mindset


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 14:00-15:59 PDT


Title: Book Signing - Laura Scherling
Tags: Vendor Book Signing
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Laura Scherling
The Future of Hacking: The Rise of Cybercrime and the Fight to Keep Us Safe (July 2025, Hardback Launch; July 2026, Audio Book Launch)

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 11:00-11:59 PDT


Title: Book Signing - Nicholas DeMeo
Tags: Vendor Book Signing
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map

Description:
SpeakerBio:  Nicholas DeMeo
Author:

Cyber Defense: The Art of Forging a Sentinel


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 15:00-15:59 PDT


Title: Book Signing - Ted Harrington
Tags: IoT Village | Vendor Book Signing
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Join us Friday, August 7 at 3:00pm for a book signing with co-founder and #1 best selling author Ted Harrington. Each attendee will receive a complimentary signed copy of Hackable, while supplies last. We recommend coming early!

SpeakerBio:  Ted Harrington
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 10:30-11:30 PDT


Title: Bootkits Forever: Emulando APTs Modernos desde UEFI hasta el Kernel
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Los bootkits UEFI continúan siendo una de las capacidades más avanzadas utilizadas por grupos APT modernos. Su capacidad para ejecutar código antes del sistema operativo, obtener persistencia a largo plazo y operar por debajo de muchas soluciones de seguridad los convierte en una herramienta extremadamente valiosa tanto para atacantes como para equipos de Red Team que buscan emular amenazas reales.

En esta sesión mostraremos cómo utilizar un bootkit UEFI para reproducir cadenas completas de ataque observadas en operaciones reales. Analizaremos el recorrido desde el firmware hasta el kernel de Windows, incluyendo persistencia y despliegue de componentes adicionales de ransomware en el kernel.

La charla incluirá una demostración en directo en la que un sistema Windows moderno será comprometido mediante un bootkit UEFI, mostrando paso a paso cómo este tipo de implantes se instalan y permiten reproducir capacidades observadas en operaciones reales de grupos APT. Además, se compartirán los recursos y proyectos utilizados durante la investigación para que otros equipos de seguridad puedan reproducir los escenarios presentados en sus operaciones diarias.

SpeakerBio:  Alejandro Vázquez Vázquez, Independent Security Researcher

Alejandro Vázquez Vázquez es un especialista en técnicas de seguridad ofensiva de bajo nivel, con foco en Red Teaming, Windows Internals y UEFI. A lo largo de su trayectoria ha participado en operaciones de Red Team y emulación de adversarios, además de desarrollar capacidades ofensivas orientadas al estudio y reproducción de técnicas utilizadas por grupos APT modernos. Su trabajo diario se orienta a la creación, análisis y despliegue de implantes capaces de operar por debajo de los mecanismos de seguridad modernos, abarcando desde técnicas pre-boot hasta módulos en kernel y componentes de usuario para persistencia.

Comparte su conocimiento siendo docente en diversos másteres de postgrado de universidades y entidades privadas, donde imparte formaciones en ingeniería inversa, análisis de malware, desarrollo de exploits y desarrollo de herramientas para evasión de soluciones antimalware, acercando la seguridad ofensiva a las nuevas generaciones de profesionales.

Colabora con diversas comunidades centradas en áreas de low-level, como Off By One Security y grupos de DEF CON, conferencia en la que ha sido ponente principal presentando los proyectos Abyss (UEFI Bootkit) y Benthic (Windows Kernel Rootkit). A lo largo de su desarrollo profesional también ha participado en iniciativas de investigación y desarrollo relacionadas con firmware, metahoneypots, análisis de amenazas y plataformas destinadas al estudio de actores maliciosos.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 16:00-16:45 PDT


Title: Breaking BIOS in ATMs
Tags: Payment Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:45 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

The analysis begins at Ring -3, advancing toward the positive rings. Starting from the on-screen user

perspective imposes too many limitations. The shift in approach was deliberate: rather than assuming a

conventional attack vector such as connecting an external device or performing a kiosk-level bypass the

decision was made to start from the deepest layers of the system. This compromise is detected for the

following reason:

The goal of this compromise is to activate PCI/PCIe through BIOS in order to perform a DMA

This section will be referred to as "BIOS Unprotection."

How was this achieved?

Two methods were identified:

A bridge was found that triggers a BIOS configuration reset.

BIOS duplication with encryption validation bypass (enables both Downgrade and Upgrade).

DMA or complete chain will not be shown since it is a delicate topic but BIOS research will be deepened

since it does not only apply to ATMs.

SpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master's in AI and Cybersecurity.

--

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 17:30-17:59 PDT


Title: Breaking Hardware CFI with Sigreturn
Tags: DEF CON Official Talk | Demo 💻
When: Friday, Aug 7, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Modern ARM64 systems rely on hardware Control-Flow Integrity (CFI) such as PAC and BTI to kill classic ROP/JOP exploits. Indirect branches must land on valid targets, returns are signed, and arbitrary jumps are supposed to be over.

Except… it isn’t.

In this talk, we show that, by design, there is a fundamental gap between POSIX signal handling and hardware CFI. Sigreturn acts as a built-in, kernel-assisted CFI bypass primitive, enabling arbitrary control-flow transfers via crafted signal frames while bypassing CFI enforcement.

We then explore what makes this work in practice on modern Linux and Android systems (including latest Ubuntu and Pixel devices): using sigreturn as a practical exploitation primitive, then pivoting with ""cfi-safe stack pivots"", abusing missing BTI enforcement on the vDSO, and leveraging GCC’s common default settings.

I'll present a PoC showing how these primitives can be chained in classic SROP style, and demonstrate how you can extend COOP/CFOP beyond function-level control to achieve reliable arbitrary code execution, effectively breaking CFI again and again.

References
SpeakerBio:  Omri "beta_b0t" Ben Bassat, Tel Aviv University

Omri Ben-Bassat is a vulnerability researcher with over a decade of experience in reverse engineering, vulnerability finding, binary exploitation, and low-level vulnerability analysis, specializing in IoT and embedded systems. He has presented his work at leading security conferences, including Black Hat USA, Black Hat Asia, and RSA Conference, and has delivered awesome hands-on trainings at Black Hat Asia and TyphoonCon. Omri is currently pursuing a master's degree at Tel Aviv University, where his research focuses on applying formal methods to software exploitation.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 13:30-14:30 PDT


Title: Breaking into Amazon lockers by any means necessary
Tags: DEF CON Official Talk | Demo 💻
When: Friday, Aug 7, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Amazon Lockers are everywhere, handling millions of packages every day. At the same time, thousands of packages get stolen from home porches every year, which made me wonder if the same thing could happen with Amazon Lockers.

This talk is my journey trying to break into them. I started where it made the most sense, BLE. What looked straightforward quickly turned into a series of unexpected turns, with different angles, different ideas, and a lot of time spent chasing paths that didn’t go where I thought they would.

This talk walks through that process, the dead ends, the pivots, and the techniques used along the way showing how attacking a system from different angles can expose weaknesses that aren’t obvious at first. From protocol reverse engineering and hardware hacking to mobile app security, OSINT, and physical attacks, in the end it’s about persistence, understanding how things really work, and not stopping until something gives.

By any means necessary.

All references are pointed in the outline to provide better context.

SpeakerBio:  Martin Vigo, Triskel Security

Martín is a cybersecurity expert with 15 years of experience, having helped protect companies such as Apple, Meta, and Salesforce, including work in penetration testing, red teaming, and vulnerability research. He has led teams and worked across mobile and web security, SaaS, cloud environments, and identity and authentication.

He is a frequent speaker at conferences including DEF CON, Black Hat, and CCC, presenting research on phreaking, vulnerabilities in password managers, new OSINT techniques, and reverse engineering of proprietary protocols.

He runs a cybersecurity consulting firm focused on improving organizational cyber resilience via offensive security, research, and public speaking. He is also co-host of the “Tierra de Hackers” podcast.

Martín holds a Bachelor’s in Computer Science, a Master’s in Software Engineering, and certifications in areas such as hardware hacking, exploit development, infrastructure and mobile security, radio frequency, and OSINT. He contributes to open source projects and collaborates with law enforcement on initiatives to enhance public safety.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:30-11:30 PDT


Title: Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Local LLM runtimes now sit inside phones, desktops, and internal servers, but the layer underneath is still ordinary native code. We analyzed llama.cpp and Ollama across three trust boundaries: JNI, HTTP lifecycle code, and Go/C bindings.

First, in the llama.cpp Android integration, Java can free a native llama_context while native code is still using it. We reclaim the freed 648-byte object, redirect a vtable call, and show code execution in the embedding app. Second, in llama.cpp server, idle model teardown can race active requests, leaving a dangling pointer inside a freed 17,816-byte model allocation. We show remote cross-thread reclaim and attacker-controlled native dereference, then explain the remaining steps to stable RCE. Third, in Ollama, malicious GGUF metadata can push unsafe lengths across the Go/C boundary during quantization, causing C to read past a Go-backed buffer and return heap data to the caller.

This is not a prompt-injection talk. It is about exploiting local AI runtimes as native software: one full exploit, one validated server-side primitive, one disclosure primitive, and the audit patterns that find more.

  1. Mergendahl, Louloudis, Vidas. "Cross-Language Attacks." NDSS Symposium 2022.

  2. Hussain. "Incubated Machine Learning Exploits." DEF CON 32, 2024.

  3. Riancho, Braverman, Demetrio. "Breaking Out of The AI Cage." Black Hat USA 2025.

  4. llama.cpp project: https://github.com/ggml-org/llama.cpp

  5. Ollama project: https://github.com/ollama/ollama

  6. llama.cpp Android sample: https://github.com/ggml-org/llama.cpp/tree/master/examples/llama.android

Speakers:Ofek Itach,Vladimir "G1ND1L4" Tokarev

SpeakerBio:  Ofek Itach, Cyera

Security Research Team Lead at Cyera. Focus areas include cloud infrastructure and AI-related platform security. Talks: Black Hat USA 2024, DEF CON 32 (2024), RSA 2024, Sector 2024, INTENT 2024, Black Hat Europe 2024 Arsenal. Earlier work includes AWS internals and cloud attack surface mapping.

SpeakerBio:  Vladimir "G1ND1L4" Tokarev, Cyera

Vladimir Tokarev is a vulnerability researcher tech lead at Cyera, specializing in Cloud, IoT/OT, Windows, Linux, and AI vulnerability research and exploit. Talks: Black Hat USA 2024 and 2023,
DEF CON 33 Recon Village 2025, CodeBlue 2025, RSA 2024.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:00-10:30 PDT


Title: Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Crypto phones promise the convenience of a mobile OS with hardware-backed key management. We tested that claim on dGEN1, the Ethereum phone marketed for digital-asset custody, and present a full compromise from bootrom to wallet key recovery.

Starting from a bootrom-level misconfiguration, we reverse the modern MediaTek bootchain and introduce a Loader-of-the-Loader technique for patching later boot stages entirely in memory, yielding EL3 code execution without modifying physical flash. From that foothold, we trace how boot-level compromise propagates into the device’s lock-screen verification path, enabling offline brute-forcing of the user PIN and recovery of the wallet’s primary ERC-4337 signing key. We further show that a separate identity flaw in the asset-claim workflow allows pre-activation theft using identifiers printed on a sealed retail box.

SpeakerBio:  Guanxing Wen

Guanxing Wen is a security researcher with over a decade of experience exploiting bootloaders, TEEs, kernels, and IoT systems. He is a top winner of Huawei bug bounty (2021/2022) and is listed in the Ledger Hall of Fame. His research has been presented at Black Hat, MOSEC, INFILTRATE, Summercon, and QPSS. He currently works at CertiK, where he focuses on low-level systems exploitation and blockchain infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Bricks in the Air
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft's control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required - all target devices, materials, and interfaces are provided!

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 13:00-13:59 PDT


Title: Bring-Your-Own-EDR - Breaking Windows Process Protection to build EDR-Protected Malware
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

The core assumption of modern endpoint defense is broken. While Endpoint Detection and Response (EDR) solutions are built to restrict administrators through Protected Process Light (PPL) and anti-tampering, this research reveals an industry-wide design flaw: the "Bring-Your-Own-EDR" (BYOEDR) technique. We demonstrate a post-exploitation scenario where a local administrator weaponizes the EDR's own trusted installer to bypass its formidable defenses, establishing a self-protected malware. This shows a structural weakness in how security products handle installation and trust. We will show a complete exploit chain that any attacker can leverage to achieve arbitrary unsigned code execution within PPL boundaries.

Ultimately, the strongest defender becomes the attacker’s most powerful tool.

https://blog.slowerzs.net/posts/pplsystem/ https://github.com/hasherezade/pe_to_shellcode/ https://github.com/googleprojectzero/symboliclink-testing-tools

SpeakerBio:  Shahak Morag, Akamai

Shahak Morag is currently serving as the Senior Security Researcher at Akamai, with more than seven years of experience in security research. His background includes extensive expertise in Linux kernel, embedded systems, and Windows internals.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 16:00-16:59 PDT


Title: Bruce's Fireside Chat
Tags: AI Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:
This is a sit down discussion in a more casual conversational format: Topic TBA
SpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:30-13:30 PDT


Title: BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Friday, Aug 7, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 — without exploits, vulnerabilities, or memory corruption?

In this talk, we present the first full reverse engineering of the Windows Defender Boot-Time Removal driver (BTR.sys) and its proprietary transaction format. We dissect its encrypted configuration mechanism, integrity validation logic, and execution pipeline, and demonstrate how this legitimate remediation component can be transformed into a universal kernel operation engine. We introduce BTR_CLI, a research tool that constructs valid encrypted transactions and exercises the driver's capabilities.

We demonstrate how BTR_CLI can be used as an EDR/AV bypass technique, disarming security solutions using a trusted Windows built-in, Microsoft-signed driver — without relying on typical BYOVD techniques.

Our research reveals how trusted security infrastructure can unintentionally expose powerful primitives and what this means for defenders. This talk blends reverse engineering, kernel internals, and detection engineering into a practical case study of when defensive technology becomes offensive capability.

SpeakerBio:  Jiří Vinopal, Threat Researcher at Check Point Research

Jiří Vinopal is a security researcher, malware researcher, and reverse engineer at Check Point Research, focused on advanced cyber threats, kernel internals, and the hidden mechanics of undocumented system components. His work spans uncovering novel attack primitives, reconstructing proprietary protocols from binary analysis alone, and deep-diving into both sophisticated malware families and trusted platform components. When he's not buried in disassembly, he actively shares his knowledge and passion for reverse engineering across his X account, YouTube channel, and blog — delivering tips, tricks, and technical insights to fellow enthusiasts and the broader security community.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-10:59 PDT


Title: Bug Bounty Village CTF - Open
Tags: Bug Bounty Village | Bug Bounty Village CTF | Contest
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: Online

Description:

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 13:40-13:50 PDT


Title: Bug Bounty Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 13:40 - 13:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Bug Bounty Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Bug Bounty Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 12:00-13:30 PDT


Title: Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners!
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 12:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Beginners can now create off-grid, encrypted mesh networks for cheap, with applications in emergency communication, sensor monitoring, and more! Kit Cost: $80. Class Cap: 30.

SpeakerBio:  Kody Kinzie
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Friday - 11:00-12:30 PDT


Title: Build-A-Badge Workshop
Tags: Maker's Village | Creator Event/Activity
When: Friday, Aug 7, 11:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Welcome to the Build-A-Badge Workshop! We've cultivated some interesting maker mediums to bring you a unique badge that's all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you'll be assigned a group number and split off into teams within the Makers' Village, hitting each station for the badge assembly. You'll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con.

Speakers:hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer

SpeakerBio:  hunny
No BIO available
SpeakerBio:  Teazee
No BIO available
SpeakerBio:  Buddha
No BIO available
SpeakerBio:  MLP
No BIO available
SpeakerBio:  M-Nelly
No BIO available
SpeakerBio:  Alchemmer
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Friday - 14:00-15:30 PDT


Title: Build-A-Badge Workshop
Tags: Maker's Village | Creator Event/Activity
When: Friday, Aug 7, 14:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Welcome to the Build-A-Badge Workshop! We've cultivated some interesting maker mediums to bring you a unique badge that's all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you'll be assigned a group number and split off into teams within the Makers' Village, hitting each station for the badge assembly. You'll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con.

Speakers:hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer

SpeakerBio:  hunny
No BIO available
SpeakerBio:  Teazee
No BIO available
SpeakerBio:  Buddha
No BIO available
SpeakerBio:  MLP
No BIO available
SpeakerBio:  M-Nelly
No BIO available
SpeakerBio:  Alchemmer
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 16:00-16:30 PDT


Title: Building a State Wide VDP: Lessons from Maryland's First Year in the Trenches
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

State and local governments are soft targets. Smaller security teams, legacy infrastructure, high-value data, and tight budgets make them attractive to adversaries. Yet most lack basic proactive security programs like Vulnerability Disclosure Programs (VDPs). In January 2025, I was hired as Maryland's first Adversary Emulation Manager and tasked with standing up a statewide VDP. Coming from DoD cyber operations but new to the bug bounty space, I had to figure out how to build a program that would actually work, not just check a compliance box. The result: Maryland's VDP launched in October 2025 and has been a success because we fought for true safe harbor, assumed noble intent, and took a researcher-first approach. This talk shares what I learned building the program from scratch. I'll cover the hard conversations with legal teams who feared "authorizing hacking," the fights for wide scope instead of narrow carve-outs, and why safe harbor isn't optional. If you're a state or local practitioner, you'll walk away with a replication guide. If you're a policymaker, you'll understand why VDPs matter. If you're a researcher, you'll see what makes programs succeed or fail.

SpeakerBio:  01dbae

01dbae has worked in technology since the early 2000s, spanning data center operations, private cloud computing, and information security. After moving into security at a large publisher, he transitioned into government contracting and later served as a DoD civilian supporting the cyber counterintelligence mission. He also spent a few seasons with the Baltimore Ravens.

01dbae later joined the State of Maryland as Adversary Emulation Manager, tasked with standing up the state's first Vulnerability Disclosure Program — despite having never run a bug bounty program before. That outsider perspective helped him challenge assumptions and push for researcher-first policies over compliance theater. The program launched with strong safe harbor protections and broad scope, and has been running successfully since. There are lessons in that process worth sharing with other state and local governments building proactive security programs


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Friday - 11:00-11:59 PDT


Title: Building an open soure safecracking robot
Tags: Lockpick Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

An auto dialer is a device that brute forces the combination to a safe lock. These often start in the thousands of dollars when it's only a motor that spins. This talk will cover how safe locks work, what goes into building one of these devices, and all the resources (including the source code) for making your own for cheap.

SpeakerBio:  Jared Dygert
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Friday - 11:00-11:59 PDT


Title: building community and privacy tools from junk
Tags: Hackers.town | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  TheGibson
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Friday - 14:30-15:30 PDT


Title: Building Project Obsidian: Designing the Blue Team CTF for DEF CON
Tags: Blue Team Village | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 15:30 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

What does it take to build a realistic blue team training platform for thousands of DEF CON attendees? Join the engineers behind Project Obsidian as we discuss the architecture, design decisions, and lessons learned while building a cloud-native incident response and malware analysis CTF. We’ll cover Kubernetes, automation, AI-assisted challenge creation, scalable infrastructure, and the balance between realism and accessibility. Whether you’re interested in CTF design, defensive security, or modern platform engineering, this panel offers an inside look at how a community-driven project comes together.

Speakers:Carlo Anez Mazurco,Chris "dafinga" Maenner,Omenscan ~,Paul Goffar

SpeakerBio:  Carlo Anez Mazurco

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

SpeakerBio:  Chris "dafinga" Maenner, Board Member at BSides Philadelphia

Chris Maenner is the founder of Palmtree Ventures, where he spends his time securing AI systems, Kubernetes, cloud platforms, and developer tooling without getting in the way of shipping software. Over the last 15+ years, he’s worked across startups and Fortune 50 companies building product, platform, and cloud security programs. When he’s not doing his day job, Chris helps build CTFs and security projects for DEF CON’s Blue Team Village and OWASP, including leading engineering efforts around Project Obsidian. He also serves on the board of BSides Philadelphia, contributes to the OWASP Secure Agent Playbook, and regularly speaks about AI security, Kubernetes, cloud-native security, and the lessons learned from actually trying to secure this stuff in production.

SpeakerBio:  Omenscan ~

Some people write books to document and share what they learn. I write software. @Blueteamvillage Director. I do not speak for my employer, their clients, or customers

SpeakerBio:  Paul Goffar

Paul Goffar is the founder of Raven Cybersecurity, doing offensive and defensive security consulting for small and mid-sized businesses. Day to day, he runs incident response, detection engineering, digital forensics, and threat intelligence for an enterprise SOC in the automotive sector.

For the last five years, Paul has worked closely with Blue Team Village as an engineering lead for competitions and content delivery around the US, and does similar CTF and content work with CTF313, a Detroit-based team. He holds several industry certifications including GCIH, GMON, GNFA, CRTP, and paWASP. A father of three, a Metro Detroit native, and a hacker at heart, he continuously finds ways to give back to the community through mentoring and extensive volunteer work.


Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Friday - 11:30-12:15 PDT


Title: Building the Humans Behind the Mission: Talent, Readiness, and Cyber Power for America’s Armed Services
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 12:15 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

The Maritime Hacking Village is proud to host a first‑of‑its‑kind conversation with the Principal Cyber Advisors to the Navy and the Air Force. As cyber operations become inseparable from maritime, air, and joint missions, the Navy and Air Force face a shared challenge: how to recruit, train, integrate, and retain the technical talent required for modern conflict.

This session will explore how the services are strengthening operational cyber units. How deeply technical experts can be woven into traditional command structures, and how joint missions can be supported by interoperable training pipelines. We’ll also dig into the realities of competing with the commercial sector for high‑end cyber talent, and the emerging skill sets — from AI engineering to cloud and data‑center operations — that will define future conflict. Expect a little honesty, and maybe one or two jokes about how retention would be easier if the military offered free energy drinks and a hoodie.

Speakers:Dr. Nina Kollars,Dr. Wanda T. Jones-Heath,Anne Marie Schumann

SpeakerBio:  Dr. Nina Kollars, US Naval War College

Dr. Nina Kollars is an Associate Professor at the U.S. Naval War College’s Cyber and Innovation Policy Institute, where she specializes in cyber resilience, emerging technologies, and wargaming efforts focused on Taiwan and the Pacific. Dr. Kollars also serves as co-director of the Maritime Hacking Village, a 501c3 that advances ethical hacking on maritime assets and infrastructure. She is also an executive bourbon steward.

SpeakerBio:  Dr. Wanda T. Jones-Heath, Principal Cyber Advisor for the Department of the Air Force

Dr. Wanda T. Jones-Heath, a member of the Senior Executive Service, is the Principal Cyber Advisor for the Department of the Air Force, comprised of the U.S. Air Force and U.S. Space Force. As the Principal Cyber Advisor for the DAF, her duties include synchronizing, coordinating and overseeing the implementation of the DAF Cyber Strategy and advising the Secretary of the Air Force on all cyber programs. She is responsible for overseeing cyberspace recruitment; resourcing and training of cyber mission forces, as well as assessing their readiness; overseeing acquisition; advocate for cyber investments; cybersecurity supply chain risk management; security of information systems and weapon systems.

SpeakerBio:  Anne Marie Schumann, Principal Cyber Advisor, Department of the Navy

Ms. Anne Marie Schumann serves as the Department of the Navy Principal Cyber Advisor (DON PCA). In this role, she is responsible for advising the Secretary of the Navy, Chief of Naval Operations, and Commandant of the Marine Corps on all cyber matters and implementing the Department of Defense Cyber Strategy within the DON.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 16:00-16:30 PDT


Title: Building Your First Homelab
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Have you wanted to build a homelab but felt overwhelmed by all the choices? This talk is for you. Building a homelab doesn't have to be complex or intimidating, I'll walk you through how easy and simple it can be to set up your first lab and get hands on experience with popular cybersecurity and IT tools.

SpeakerBio:  Stephen Glombicki
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 12:00-13:59 PDT


Title: Burning Redirectors Before Blue Team Does
Tags: Red Team Village | Misc
When: Friday, Aug 7, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

Red team operators rely on redirectors to proxy C2 callbacks, but monitoring those redirectors for blue team detection is typically handled by either manual log review or deploying a full SIEM pipeline. Neither scales well during active assessments. NightWatcher is a traffic monitoring agent that analyzes redirector access logs through detection rules and a reasoning engine that identifies attack phase progression (reconnaissance through takedown) rather than issuing disconnected alerts. NightRouter is a decision routing agent that receives NightWatcher's assessments, recommends a redirector action (drain, reduce weight, quarantine), and presents it to the operator via Slack interactive messages for approval or rejection.

In this tactic, attendees will deploy NightWatcher/NightRouter locally, simulate blue team traffic patterns against redirectors, observe the attack phase reasoning and escalation detection, and execute redirector actions through the Slack human-in-the-loop approval flow. The stack runs in mock mode with no external infrastructure dependencies required.

Speakers:Mohamed AbuMuslim,Saad Nasir

SpeakerBio:  Mohamed AbuMuslim

I am a security researcher and offensive security engineer specializing in red teaming, penetration testing, adversarial AI, and product security engineering.

My work focuses on identifying exploitable weaknesses across modern attack surfaces, including web applications, APIs, cloud platforms, enterprise infrastructure, Active Directory, and LLM-enabled systems. I combine offensive operations, applied research, and security engineering to solve complex security problems, validate security posture, and improve how organizations build and assess secure products.

Over the years, I have led and contributed to offensive security capability building in complex environments, including helping establish Microsoft Egypt & Middle East’s first offensive security team and previously helping build PwC’s offensive security capability in Egypt, and served as Manager and Practice Lead at EY leading offensive security engagements. My experience spans startups, mid-sized organizations, and multinational enterprises.

I regularly speak at conferences including Black Hat, DEF CON, BSides, and OWASP Cairo on topics such as AI red teaming, cloud attack simulation, supply-chain risk, log manipulation, and practical offensive tradecraft. I also design and deliver hands-on training, contribute to security education, and support community initiatives through AI Village, BSides Albuquerque, OWASP Cairo, and CyberDose.

SpeakerBio:  Saad Nasir

Saad Nasir is a cybersecurity leader specializing in red teaming, penetration testing, and application security. He currently leads Red Team and Application Security initiatives, overseeing offensive security operations, adversary simulation, and security assessments across enterprise environments.

With more than 10 years of cybersecurity experience, Saad has led offensive security engagements spanning web applications, cloud platforms, internal networks, and Active Directory environments. He is the founder and organizer of Security BSides Albuquerque, helping grow one of New Mexico's largest community-driven cybersecurity conferences.

Saad is pursuing a PhD in National Security and holds a Master's degree in Cybersecurity, along with multiple industry certifications, including OSCP and CISM. He is passionate about sharing practical skills, helping defenders understand the mindset of attackers, and advancing the cybersecurity community through mentoring, conference speaking, and hands-on training.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 10:30-12:30 PDT


Title: Burp, But Yours: Hands-On Extension and Bambda Development
Tags: Intermediate | AppSec Village | Creator Workshop
When: Friday, Aug 7, 10:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map

Description:

Burp Suite already solves most daily testing problems, but the security landscape constantly evolves. New vulnerabilities, CVEs, and techniques emerge every day, and sometimes the capability you need simply does not exist yet.

In this hands-on workshop, you’ll learn how to adapt Burp Suite to your workflow using custom scan checks, Bambdas, extensions, and the BApp Store. You’ll create your own Bambdas, test them against Web Security Academy labs, modify a free template extension, and start a project you can continue after the session.

You’ll leave with practical tools, a repeatable development approach, and guidance on sharing your work with teammates or the wider community.

SpeakerBio:  Hannah L, Burp Suite Extensibility Specialist at PortSwigger

Hannah is an Extensibility Specialist at PortSwigger, where she helps shape how Burp Suite can be adapted to real-world testing workflows. She works hands-on with submissions to the BApp Store, as well as the Bambdas and BChecks community repositories, helping refine extensions and community contributions before they’re shared more widely.

She especially enjoys making extensions better and finding creative workarounds to awkward testing problems. She has also written extensions for customers, internal teams, and her own projects, including the original WebSocket Turbo Intruder extension.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 10:00-10:45 PDT


Title: Bypassing KYC Vendors on AI Times
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

In this talk, the Just Mobile Security team will talk about the KYC implementation, how to bypass them, and some 0 days for vendors.

Speakers:Juan Urbano Stordeur,Juan Martinez Blanco

SpeakerBio:  Juan Urbano Stordeur, CEO and Founder at Just Mobile Security
No BIO available
SpeakerBio:  Juan Martinez Blanco, Mobile Security Penetration Tester at Just Mobile Security
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 15:00-15:30 PDT


Title: Cache Key Injection: Smuggling Poison Through the Door
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Cache poisoning research has long centred on unkeyed-input injection. The next cache poisoning vulnerability may not come from unkeyed input, but from what is mistakenly included in the cache key itself. This talk explores a lesser-known attack path: cache key injection caused by subtle cache misconfigurations that allow attacker-controlled values to influence keyed cache components. By triggering cache key injection, attackers can perform cache key collisions, leading to cache poisoning and impacts such as CPDoS, cache deception, and stored XSS through poisoned cache keys. I’ll show how these collisions can be identified, how they can be exploited to achieve impact, and the mitigations that can be implemented to prevent cache key injection.Cache poisoning research has long centred on unkeyed-input injection. The next cache poisoning vulnerability may not come from unkeyed input, but from what is mistakenly included in the cache key itself. This talk explores a lesser-known attack path: cache key injection caused by subtle cache misconfigurations that allow attacker-controlled values to influence keyed cache components. By triggering cache key injection, attackers can perform cache key collisions, leading to cache poisoning and impacts such as CPDoS, cache deception, and stored XSS through poisoned cache keys. I’ll show how these collisions can be identified, how they can be exploited to achieve impact, and the mitigations that can be implemented to prevent cache key injection.

SpeakerBio:  Alex Brumen, YesWeHack

Alex Brumen (aka "Brumens") is a Security Research Enablement Analyst at YesWeHack, where his ethical hacking work focuses primarily on web applications. Outside of work, he is also a bug bounty hunter and developer.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 12:40-12:50 PDT


Title: Call Center Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 12:40 - 12:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Call Center but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Call Center and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Call Center Village - Friday - 10:00-17:59 PDT


Title: Call Center Village - Open
Tags: Call Center Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist's desk remains almost completely unmonitored. Nobody's deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open.

And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels.

Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak.

On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you're ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34.

We've also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for.

No prior experience required. If you know how to make a phone call or type a message, you're already qualified. Equipment is provided, including laptops and ANC headsets - but you're more than welcome to bring your own devices.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:00-12:59 PDT


Title: Can AI do novel security research? Meet the HTTP Terminator
Tags: DEF CON Official Talk | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it.

It worked - I'll share an arsenal of new HTTP desync triggers, gadgets, and exploits that compromised banks, security solutions, and government infrastructure. Then I'll trace each discovery chain back through the HTTP Terminator, showing how to turn your personal expertise into an autonomous weapon - and the dark arts required to make it lethal.

I'll also share discoveries from beyond the autonomy horizon - some only reachable with a tight human/AI research loop, and others beyond AI's reach entirely. These include a powerful undisclosed recon technique, and anomalies that hint at new attack classes offering alternative paths to critical impact. I'll analyse the discovery process, sharing detailed experiments that probe the boundaries of what AI can and can't discover.

You'll leave with new exploits from desync triggers to undisclosed attack classes, and a blueprint for turning your instincts into an autonomous research cascade. And yes, I'll open-source the HTTP Terminator.

https://portswigger.net/research/http1-must-die https://i.blackhat.com/BH-USA-25/Presentations/US-25-Dolan-Gavitt-AI-Agents-for-Offsec-with-Zero-False-Positives-Thursday.pdf https://portswigger.net/research/listen-to-the-whispers-web-timing-attacks-that-actually-work https://www.intruder.io/research/practical-http-header-smuggling

SpeakerBio:  James "albinowax" Kettle, PortSwigger

James 'albinowax' Kettle is the Director of Research at PortSwigger, the makers of Burp Suite. He's best known for pioneering novel web attack techniques, and publishing them at major conferences like Black Hat USA, at which he's presented for nine consecutive years.

He also loves exploring and advising on innovative tool concepts for security professionals, many of which have since become industry standard. Examples include introducing OAST via Burp Collaborator, bulk parameter discovery via Param Miner, billion-request attacks with Turbo Intruder, and human-style scanning with Backslash Powered Scanner.

His best-known research is HTTP Desync Attacks, which popularised HTTP Request Smuggling. Other popular attack techniques that can be traced back to his research include web cache poisoning, the single-packet attack, server-side template injection, and password reset poisoning. He's also the designer behind many of the topics and labs that make up the Web Security Academy, and serves on the Black Hat Europe review board.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-16:59 PDT


Title: Car Hacking Village CTF
Tags: Car Hacking Village | Car Hacking Village Capture the Flag (CTF) | Contest
When: Friday, Aug 7, 10:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Participate in CHV's CTF to learn and play with automotive technology. This year's contest features problems on smart chargers, automotive ECU harnesses, our own badge, and more! Don't worry about bringing your own automotive specific gear, we've got you covered. Stop by the village to register, get started, and get hacking.


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Friday - 10:00-17:59 PDT


Title: Car Hacking Village Open
Tags: Car Hacking Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Welcome to the Car Hacking Village - a place where you can learn all about the cool technology that powers modern connected transportation. The CHV at DEF CON 34 will feature a whole race track of activities including Creator Stage presentations, a competitive CTF (with awesome prizes!), an amazing badge for sale that doubles as a fully functional car hacking tool, a scavenger hunt, and more!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:00-11:59 PDT


Title: Car Hacking Village Scavenger Hunt Contest
Tags: DEF CON Official Talk | Car Hacking Village
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Go out and find some goofy stuff!!

The DEF CON 34 CHV Scavenger Hunt rules and treasure list can be found at the attached link.

Start Time: Friday, August 7 10:00

End Time: Sunday, August 9: 12:00

One Car Hacking Village 2026 Badge will be awarded to the first player to complete the Scavenger Hunt!


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 12:30-12:40 PDT


Title: Car Hacking Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 12:30 - 12:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Car Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Car Hacking Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 13:00-14:59 PDT


Title: Cards Against Vulnerabilities
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map

Description:

Join us for "Cards Against Security: Trust Me, It's Secure," a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 11:00-12:59 PDT


Title: Cards Against Vulnerabilities
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map

Description:

Join us for "Cards Against Security: Trust Me, It's Secure," a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 15:00-16:59 PDT


Title: Cards Against Vulnerabilities
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map

Description:

Join us for "Cards Against Security: Trust Me, It's Secure," a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: Cat-astrophic Hacking: Breaking Into Smart Litter Boxes
Tags: IoT Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

What happens when your cat’s litter box joins the Internet of Things? Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover security risks.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 16:00-16:59 PDT


Title: Certified Re-Pwned: escalating all the way up
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Four years after KB5014754 and one year after CVE-2024-49019, every hardening guide says Active Directory Certificate Services is a closed book. This talk reopens it.

We present five new primitives — proposed as ESC18 through ESC22, extending the public ESC1–ESC17 numbering — each validated end-to-end on a fully-patched Windows Server 2025 Enterprise CA with every Microsoft-recommended mitigation applied. Every primitive starts from a Domain Users account with no ACL, GPO, or template edges, and ends at krbtgt extraction.

Each primitive targets a different component of the post-2022 defence: the CA's CSR processor, the CA's Security-Extension writer, the KDC's PKINIT binder, the CA's Enroll-On-Behalf-Of path, and the registry-level enforcement layer everyone thinks is already hardened. Together they argue that Microsoft's 2022 and 2024 fixes patched specific instances of the underlying bug classes, not the classes themselves — and that at least one control has an undocumented fallback path its own documentation does not mention.

A Certipy research fork will be released at the time of the talk to check and exploit the new techniques.

https://posts.specterops.io/certified-pre-owned-d95910965cd2 https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019 https://posts.specterops.io/adcs-esc13-abuse-technique-fda4272fbd53 https://github.com/ly4k/Certipy

Speakers:Daniel Monzon,Eric Labrador

SpeakerBio:  Daniel Monzon

Daniel Monzón (stark0de) — Offensive Security Engineer at Halborn with 6+ years of offensive security experience across web pentesting, code review, Active Directory (on-premise and hybrid), Android/iOS mobile audits, thick-client assessments and red teaming. Holds certifications such as: OSCP, CRTP, OSWP, CREST CPSA, eMAPT, PACSP, and CARTP. Has been credited with multiple CVEs in open-source and commercial products, and currently focuses on Web3 and financial-sector security. Prior speaker at hack0n, RootedCON Málaga, DragonJARCON, and SecAdmin.

SpeakerBio:  Eric Labrador

Eric Labrador is an offensive security researcher at Accenture with over 6 years of experience breaking into networks, applications, and buildings for a living. His day-to-day work covers Red and Purple Team exercises, web and API audits, Android and iOS mobile application assessments, internal and external penetration testing, physical intrusions into corporate buildings, and large-scale phishing campaigns. He holds the OSCP, CRTE, CRTO, BSCP, and eWPTXv2 certifications, and is the author of ImagePanick, an open-source exploit chain that achieves arbitrary file write and remote code execution by combining weak default policies in ImageMagick with SAFER bypasses in Ghostscript, all triggered from a malicious SVG. Over the years he has delivered end-to-end attack paths that chain phishing, external footholds, lateral movement, and physical entry into full compromise across multiple industries, helping clients understand what a motivated attacker can actually do with the people, processes, and technology already in place.


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Friday - 10:00-15:59 PDT


Title: Chill Zone: Casual Games & TASBot Smash Demo
Tags: Game Hacking Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

DEF CON got you overwhelmed? Come relax and play Project Plus, a modded version of Super Smash Bros Brawl. Or compete against a frame perfect Smash Bot!


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Friday - 16:00-16:59 PDT


Title: Chill Zone: Smash (Project Plus) Tournament with Prizes
Tags: Game Hacking Village | Creator Event/Activity
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

Compete against other attendees in a modded version of Super Smash Bros Brawl! This is a low stakes tourney that is beginner friendly and open to all.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 16:00-17:59 PDT


Title: Cirro: Extending Your Azure Graph Beyond Identities
Tags: Demo 💻 | Cloud Village | Creator Event/Activity | Tool 🛠 | Attack | Tools
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) A - Map

Description:
Most Azure graph analysis tooling focuses primarily on identity relationships: users, groups, service principals, and role assignments. While valuable, modern Azure environments contain far more exploitable context hidden within infrastructure, platform services, application configurations, network relationships, managed identities, and data-plane resources.

Cirro (the spiritual successor to Stormspotter) is an attack graphing tool built to model Azure environments by combining Microsoft Graph identity data with Azure Resource Manager (ARM) infrastructure data. Instead of limiting analysis to Entra ID objects and role assignments, Cirro maps Azure resources into Neo4j for deeper attack path and misconfiguration analysis.

This lab provides a practical understanding of Cirro’s collection, ingestion, and analysis workflow. Attendees will perform enumeration and assessment of an Azure tenant to understand how to view attack paths beyond identities. They will perform Cypher queries and use custom dashboards to visualize and interpret graph data.

Prerequisites: - Docker/Podman Compose - Azure CLI - Web browser - Sqlite3 Browser Recommended (but not required): - Fundamental knowledge of Cypher query language

SpeakerBio:  Leron Gray

Leron Gray is a Senior Security Consultant at Bishop Fox, specializing in offensive security, cloud attack path analysis, and security tooling research. He is the creator of Cirro, an extensible graph-based framework for analyzing Azure and cloud environments through Microsoft Graph and Azure Resource Manager data. His work focuses on helping security researchers and red teamers better understand complex cloud relationships, identity abuse paths, and infrastructure misconfigurations at scale.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 14:30-15:10 PDT


Title: Citizen Developers Can't Defend What They Built: Scaling Security Past the Security Team
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 15:10 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 11:00-12:59 PDT


Title: Clash of Prompts: The World's First Prompt Battle Royale
Tags: AppSec Village | Creator Event/Activity
When: Friday, Aug 7, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map

Description:

Clash of Prompts is the world's first live, head-to-head AI prompt battle royale. Two developers tackle the same coding challenge, one prompt each, on the clock, while the AI generates the code live on screen. Every prompt is scored in real time on vulnerabilities, security best practices, and prompt efficiency.

Research shows 87-94% of AI-generated code ships with security flaws, even when developers try to prompt securely. This Pod is a hands-on way to see that play out: attendees write and test real prompts and watch them get scored instantly.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 13:30-14:30 PDT


Title: Classical OSINT using AI (Actual Intelligence)
Tags: OSINT For Good Community | Creator Talk/Panel
When: Friday, Aug 7, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

AI this, AI that, and of course even in the world of OSINT AI has been getting integrated. But this talk focuses on a different AI: Actual Intelligence. Modern investigators have access to more tools, automation, and artificial intelligence than ever before, yet many investigations still suffer from poor assumptions, weak validation, and information overload. Long before automated platforms and AI assistants existed, investigators relied on analytical thinking, source evaluation, and structured methodology to turn information into intelligence. This session introduces the ACTUAL framework. Through practical examples and real-world investigative scenarios, attendees will learn how to validate findings with confidence and conduct effective OSINT investigations even when specialized tools aren't available. Tools help collect information, but ACTUALly intelligence comes from the investigator.

SpeakerBio:  Bianca C. Ionescu/reconcerto

Bianca Ionescu is a CyberCorps SFS scholar pursuing a master’s degree in cybersecurity at UNLV. She's served as a leader within cybersecurity student organizations, promoting growth, inclusion, and professional development. Her interests include open-source intelligence and mentoring new learners entering the field. Offline, she enjoys strength training and playing the viola. She’s motivated by community building, continuous learning, and the challenge of solving complex security problems that inspire her growth and resilience every day.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 15:30-15:59 PDT


Title: Cleared for Takeoff: Debunking “Uncertifiable” Cybersecurity
Tags: Aerospace Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Cybersecurity threats are rapidly becoming a first-order safety concern in critical aviation systems. Increasing in-flight connectivity, satellite communications, and networked avionics have eroded the assumption of airborne isolation. At the same time, AI-generated attacks are lowering both the barrier to entry and the time-to-exploit, enabling faster, more adaptive threat behavior. In contrast, patching and remediation time in aviation systems remains long due to rigorous certification and deployment constraints. This growing asymmetry further elevates cybersecurity risk into a direct safety concern. In this environment, a security risk is a safety risk. This raises a critical question: not whether cybersecurity is needed in aircraft, but whether cybersecurity tools can be certified for safety-critical airborne systems.

This talk focuses on the challenge of bridging that gap by asking: can we generate the right verification artifacts to make existing cybersecurity tools certifiable, without modifying their core functionality? We explore why cybersecurity tools are rarely introduced into DAL-A airborne systems in their native form, focusing on the mismatch between operational security outputs and certification evidence requirements. The core problem is not only deterministic behavior, but the lack of structured, complete, and traceable artifacts to support certification arguments.

SpeakerBio:  Katie Fejer
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 14:00-14:45 PDT


Title: Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | DEF CON Demo Labs
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Clew is an automated fuzzing-candidate extraction pipeline for environment-sensitive malware analysis. Evasive malware routinely queries its execution environment via Windows API calls to hide functionality until specific environmental conditions are met. By hooking these API calls, a fuzzer can reveal such execution paths that are typically hidden during standard analysis. No seed corpus of environmental fuzzing candidates currently exists for this application. As a result, current API-hooking fuzzers rely on hand-written, sample-agnostic starting values and blind mutations that cannot scale to the diverse evasion techniques seen in sophisticated samples. Clew addresses this by analyzing each PE32 binary and producing a per-sample seed corpus of candidate API return values that downstream environmental fuzzers use to systematically uncover hidden execution paths.

Speakers:Kyler McElroy,Anita Ding,Daniel Koranek

SpeakerBio:  Kyler McElroy

McElroy, a second lieutenant and developmental engineer in the United States Air Force, is pursuing a master's in computer science with an AI focus at the Air Force Institute of Technology. His research focuses on using machine learning and automated analysis to uncover hidden behaviors in evasive malware. He is an alumnus of the ACE Cyber Leadership Development program, where he authored S.A.N.D (Synthetic Adversarial and Natural Data Generation) under the Air Force Research Laboratory.

SpeakerBio:  Anita Ding

Anita Ding is a second lieutenant and cyber operations officer in the United States Air Force, is pursuing a master's in cyber operations with an AI focus at the Air Force Institute of Technology. Her research focuses on LLM-orchestrated red team automation and graph neural networks for attack-path scoring in Active Directory environments. She earned a B.A. in Computer Science from UC Berkeley, where she conducted research at the Berkeley AI Research Lab and the Berkeley Risk and Security Lab. She is also an alumna of the ACE Cyber Leadership Development program, where she designed a CTF challenge for the British Army's Defence Cyber Marvel exercise.

SpeakerBio:  Daniel Koranek

Dr. Daniel Koranek is an Assistant Professor of Computer Science at the Air Force Institute of Technology (AFIT) and a two-time graduate of AFIT in cyber operations (2010, M.S.) and computer science (2022, Ph.D.), where his research interests focus on the intersection of artificial intelligence/machine learning and cybersecurity. This includes using AI/ML to enhance cybersecurity and using vulnerability assessment and secure design techniques to improve AI deployments. He has spent most of his career on reverse engineering and vulnerability assessment of embedded systems, and overlapping AI and cybersecurity drove Dr. Koranek's dissertation research on using the reverse engineering tool Binary Ninja to visualize explanations of malware classifications.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 10:00-10:30 PDT


Title: Click Me: Turning URI Links into Bug Bounty RCE's
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Bug bounty hunters often encounter unprotected URL inputs and dismiss them as low-impact findings. This presentation explores real-world Microsoft enterprise application vulnerabilities where custom URI handlers led to remote code execution. Attendees will learn how pivoting from web applications into desktop software can reveal impactful attack paths hidden behind seemingly mundane bugs.

SpeakerBio:  Tobias Diehl

Tobias Diehl is a Senior Offensive Security Engineer, security researcher, and Microsoft 2025 Most Valuable Researcher (MVR) specializing in offensive security, enterprise AI, bug bounty research, and adversary emulation. His work focuses on identifying overlooked attack paths where web applications, AI systems, and desktop software intersect, helping organizations understand how seemingly low-risk vulnerabilities can become high-impact security issues. Tobias leads offensive security assessments, conducts purple team exercises, and performs research into emerging attack techniques affecting enterprise environments. His work has resulted in multiple security findings impacting Microsoft technologies, including Power Platform, CoPilot and other AI-driven applications. A returning DEF CON speaker, Tobias is passionate about sharing practical research that helps both security researchers and defenders better understand modern attack chains. His presentations emphasize real-world case studies, responsible disclosure, and actionable defensive guidance for securing the next generation of AI-enabled enterprise systems.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 13:00-13:10 PDT


Title: Cloud Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 13:00 - 13:10 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Cloud Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Cloud Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 14:00-15:59 PDT


Title: Cloud-Native C2: Weaponizing Trusted Infrastructure for Initial Access
Tags: Red Team Village | Misc
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

Traditional command and control infrastructure faces constant detection pressure from network defenders. This research presents two novel proof-of-concept frameworks that demonstrate how seemingly benign cloud services can be weaponized for covert operations. MeetC2 leverages Google Calendar API to transform calendar events into a bidirectional C2 channel, while XRayC2 repurposes AWS X-Ray's distributed tracing service for command execution and data exfiltration.

Both frameworks exploit fundamental assumptions about trusted services: calendar synchronization traffic appears as routine business operations, while X-Ray traces blend seamlessly with legitimate application monitoring. Our implementations showcase practical techniques including command encoding in calendar event metadata, response embedding in trace annotations, and beacon patterns that mimic normal service behavior. The frameworks support cross-platform implants with minimal footprint, requiring only API credentials rather than traditional malware persistence.

I will demonstrate how these channels bypass traditional security controls, as encrypted HTTPS traffic to Google and AWS endpoints rarely triggers alerts. The research reveals critical blind spots in cloud security monitoring and provides actionable detection strategies, including API usage anomalies, unusual trace patterns, and calendar event behavioral analysis. This work aims to help defenders understand emerging cloud-native threats and implement appropriate monitoring for their cloud environments.

As organizations increasingly adopt cloud services, attackers have evolved their tactics to abuse these trusted platforms for malicious purposes. Cloud service APIs present an attractive option for establishing command and control infrastructure because they offer high availability, encrypted communications by default, and traffic that blends with legitimate business operations. This research explores how adversaries can weaponize standard cloud APIs to create sophisticated C2 channels that circumvent traditional security controls.

This research presents two functional C2 frameworks for initial access that abuse legitimate cloud APIs: MeetC2 leveraging Google Calendar for command and control, and XRayC2 weaponizing AWS X-Ray distributed tracing.

SpeakerBio:  Dhiraj Mishra

An active speaker who has discovered multiple zero-days in modern web browsers and an open-source contributor. He is a trainer at Blackhat, BruCON, 44CON and presented in conferences such as Ekoparty, NorthSec, Hacktivity, PHDays, Hack in Paris & HITB. In his free time, he blogs at www.inputzero.io/www.fuzzing.at and tweets on @RandomDhiraj.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 16:30-17:30 PDT


Title: CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Friday, Aug 7, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

CloudBashing started with reversing the private AWS, Azure, and GCP CloudShell REST and websocket terminal protocols, then tracing and analyzing janky browser authentication/credential flows from cookies to OAuth tokens. Along the way, we automated the APIs to access free CPU/networking, maintained access across container/VM resets, utilized persistent $HOME for implants/data, locked users out of sudo access, and installed a C2 framework. We discovered IAM design issues like: AWS role assumption that result in a large # of environments per compromised identity, web socket sessions that survive API token revocation, and M365/Gmail consumer email accounts that have default CloudShell access. This turned into a newly released exploit toolkit, CloudBasher, that enumerates, validates, installs, and runs distributed workloads with virtual storage and private networking across a large-scale agent network with persistence and resilience. We'll demo distributing CPU-intensive workloads, using virtual storage for staging/exfiltration, secure networking for proxy and obfuscated exfil paths, while automating the discovery, enumeration, creation of CloudShell environments from initial credentials/sessions to implants/setup/networking to management and control.

Amazon Web Services, "AWS CloudShell service authorization reference," https://docs.aws.amazon.com/service-authorization/latest/reference/list_awscloudshell.html

Amazon Web Services, "AWS Systems Manager StartSession API (SSM framing basis)," https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_StartSession.html

Google Cloud, "Cloud Shell API v1 REST reference," https://docs.cloud.google.com/shell/docs/reference/rest/v1/users.environments

Microsoft Azure, "Azure Cloud Shell overview," https://docs.microsoft.com/en-us/azure/cloud-shell/overview

OSRU @ ronin.ae, "AWS CloudShell analysis: privileged container, exposed block devices and container escape(s)," October 23, 2023, https://web.archive.org/web/20240912135502/https://ronin.ae/news/aws-cloudshell-analysis/

Aidan Steele, "Deep dive into AWS CloudShell," awsteele.com, January 11, 2024, https://awsteele.com/blog/2024/01/11/deep-dive-into-aws-cloudshell.html

Paul Schwarzenberger, "CloudShell slip-up: command-line access to underlying AWS infrastructure," Medium, October 15, 2024, https://medium.com/@paulschwarzenberger/cloudshell-slip-up-command-line-access-to-underlying-aws-infrastructure-ae77a0858088

Rhino Security Labs, "AWS CloudShell Lateral Movement," https://rhinosecuritylabs.com/aws/cloudshell-lateral-movement/

Eduard Agavriloae, "notyet: AWS IAM Credential Revocation Gaps," offensai, https://www.offensai.com/blog/notyet-aws-iam-credential-revocation-gaps

Dan Vittegleo, cloudshell-store, GitHub Repository, https://github.com/dan-v/cloudshell-store

FrancescoDiSalesGithub, "Google-cloud-shell-hacking," GitHub Repository, https://github.com/FrancescoDiSalesGithub/Google-cloud-shell-hacking

Bipin Jitiya, "Google Cloud Shell Container Escape," Medium, December 14, 2025, https://medium.com/@win3zz/google-cloud-shell-container-escape-b69ffb46b5df

Bertrand Martel, "AWS SSM Session: JavaScript library for AWS Systems Manager Session Manager," GitHub, https://github.com/bertrandmartel/aws-ssm-session

Amazon Web Services, "Amazon SSM Agent: agentmessage.go," AWS GitHub Repository, https://github.com/aws/amazon-ssm-agent/blob/c65d8ac29a8bbe6cd3f7cea778c1eeb1b06d49a3/agent/session/contracts/agentmessage.go

SentinelOne, "CVE-2026-32169: Azure Cloud Shell SSRF Vulnerability," SentinelOne Vulnerability Database, March 19, 2026, https://www.sentinelone.com/vulnerability-database/cve-2026-32169/

Speakers:Jenko "edleft" Hwong,Chris Ryan

SpeakerBio:  Jenko "edleft" Hwong, Huntress Labs

Jenko Hwong is a Principal Security Researcher at Huntress Labs, focusing on identity-based attacks and cloud abuse. Prior to Huntress, he spent 6 years at Netskope Threat Labs, has spoken at RSA and DEFCON, and is a Cloud Village Lead. He has over 20 years at various security startups in cloud detection/response, vulnerability scanning, AV/AS, pen-testing/exploits, L3/4 appliances, threat intel, and windows security.

SpeakerBio:  Chris Ryan, Huntress Labs

A series of oddly configured server banners, a JARM fingerprint, curious fields in a security certificate - these aren't just technical details, but are instead threads in a narrative tapestry woven like a John le Carre novel. For over 20 years, Chris has dedicated his life to studying these threads and the intersection between cybersecurity, Russian linguistics, and free and open source software. His career path has taken detours through academia, aerospace and defense, software development, and cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 13:30-15:30 PDT


Title: Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense
Tags: Cloud Village | Creator Event/Activity | Investigation
When: Friday, Aug 7, 13:30 - 15:30 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) A - Map

Description:

Join this hands-on workshop to explore integrated security capabilities for the modern AWS cloud stack, including containers, object storage, and AI applications. You’ll work with a deliberately vulnerable Flask application running on EKS with S3 and Amazon Bedrock, then deploy and configure controls that detect attacks at runtime.

The session will cover behavioral runtime detection for credential-access activity and malware inside live pods, attack-surface mapping, and identity-aware risk analysis to trace the potential blast radius of a compromised workload through its IAM role. You’ll also examine file-borne threat protection across the application boundary and S3, use unified XDR queries to hunt across container and storage detections, and close with runtime guardrails that block direct and document-borne prompt injection against a real Amazon Bedrock model.

SpeakerBio:  Kyle Hubbard

Kyle is a Solutions Architect at TrendAI, where he works within the Global Alliances team across hyperscaler partnerships, with a primary focus on AWS. He specializes in cloud security integrations and in translating the technical capabilities of the Trend Vision One platform into strategies that partners, customers, and executives can act on.

His current work is centered on AI security, including AI security posture management and the protection of agentic workloads. As organizations rapidly adopt agentic architectures, Kyle focuses on how Vision One can secure that transition and how to communicate its value clearly to both technical and executive audiences.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Friday - 17:00-17:59 PDT


Title: Cloudy with a Chance of Venting: Managing Supply Chain Risk
Tags: Blue Team Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

As organizations scale across a fragmented mix of SaaS, PaaS, and hyperscale environments, the enterprise attack surface is no longer fully under their control. Today’s threat actors aren't just targeting the cloud, they are weaponizing the cloud supply chain and exploiting these new dependencies. Bringing together diverse practitioner perspectives, this panel addresses the hard operational questions of modern cloud security.

Our experts will break down the structural differences in evaluating risk across various cloud tiers, share proactive blueprints for hardening application supply chains, and debate the unique pitfalls of executing incident response when a critical SaaS provider or cloud asset is compromised.

Speakers:Cassandra (muteki) Young,Christian Nicholson,David Collins,Kyle Dickinson,Ricky (0xpsilocyber) Banda

SpeakerBio:  Cassandra (muteki) Young

As a Principal Consultant on [REDACTED]'s Cloud Technical Advisory team, muteki analyzes the organizational security posture of Azure, GCP and Oracle Cloud environments, and leads the development of data collection and analysis tooling. Additionally, she assists the Incident Response team as a technical GCP and OCI SME, and supports strategic advisory and technical tabletop exercises across multiple cloud platforms. In addition to her decade of IT and then cloud security consulting experience, muteki also holds a Master’s in Computer Science and is a director of Blue Team Village, a nonprofit organization bringing free Blue Team content to the community.

SpeakerBio:  Christian Nicholson

Christian is a recognized technology leader specializing in cloud architectures and secure-by-design implementation. Maintaining deep technical expertise, Christian bridges the gap between IT, business teams, and users. A global speaker, advisor, and organizer for major IT and security conferences and global events, Christian also contributes to international policy through United Nations (UN) and global policy dialogues to shape secure digital ecosystems.

SpeakerBio:  David Collins

Dave works to secure modern infrastructure and applications, with a focus on cloud-deployed systems.

SpeakerBio:  Kyle Dickinson

Kyle D is a professional overthinker who’s spent years securing complex systems at scale without killing the fun. A former Threat Detection and Response specialist at {Cloud Provider Here), he now lives at the intersection of cloud, gaming, and security.

SpeakerBio:  Ricky (0xpsilocyber) Banda

Hi!

I am a incident responder with over 15 years of experience with a focus on incident management. I have worked at orgs from USAF, to Amazon, to Google, and have responded to a wide array of threats across the industry. Feel free to say hi after the panel, always happy to chat, discuss, share, and meet new folks!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: CMD+CTRL Cyber Range: DarkMoney
Tags: CMD+CTRL Cyber Range | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range) - Map

Description:

CMD+CTRL is back for our 10th year and bringing something new to show. Drop by our cyber range for hands-on web application security challenges designed for all skill levels. Come to learn, come to compete, come to break things. All are welcome, whether it's your 1st CTF or your 101st.

There is no pre-qualification, and the only participant prerequisite is "Computer with internet access."


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Code Cadaver: Break Every System. Save Your Friend.
Tags: Biohacking Village | Code Cadaver (Biohacking Village CTF) | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver) - Map

Description:
Biohacking Village Capture the Flag: Test your skills against healthcare-themed capture the flag challenges. From beginner to expert levels, there's something for everyone.

Code Cadaver: Break Every System. Save Your Friend.

Your best friend entered St. Dismas Hospital with flu-like symptoms.

He never came back.

Now his hotel room has been torn apart, his phone is still beaconing somewhere in the wreckage, and every clue points toward a hospital that seems less interested in healing people than hiding what happens to them.

Code Cadaver is Biohacking Village’s immersive healthcare cybersecurity CTF—a dark, story-driven challenge that pulls players through the connected systems of a compromised hospital and the criminal network surrounding it.

Follow wireless signals. Pivot from guest networks into production systems. Hunt through patient intake records, webcams, HL7 traffic, payment systems, RFID credentials, pager networks, infusion devices, DICOM archives, and secured medical cabinets. Every system holds another piece of the truth. Every solved challenge brings you closer to Ethan—and deeper into St. Dismas.

This is more than a collection of puzzles. It is a full-chain medical cyber-thriller built around the technologies, mistakes, dependencies, and trust relationships that keep modern healthcare running.

You will need technical skill, persistence, curiosity, and a willingness to question everything.

The hospital is closing in.

The machines are still working.

Ethan is running out of time.

Break every system. Save your friend before St. Dismas finishes what it started.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 16:00-17:59 PDT


Title: Cold Calls
Tags: Social Engineering Community Village | Creator Event/Activity
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Ready for the hot seat? Step into the soundproof booth, grab a mystery target and three escalating objectives, and we'll place the call. Run by rekdt, Arty Boy, and Shadow Fox. First come, first served, so get your name on the Cold Call list!


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Friday - 10:00-10:59 PDT


Title: Coloring Reset
Tags: Women in Security and Privacy (WISP) | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you're decompressing or collaborating on a shared poster, it's the perfect low-pressure space to connect, reflect, and color outside the lines.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 11:00-11:59 PDT


Title: COM Hijacking Voodoo: Tradecraft, Detection Blind Spots, and the COM-Hunter
Tags: Red Team Village | Misc
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

Component Object Model (COM) is one of the most pervasive yet overlooked subsystems in Windows. Thousands of applications rely on COM objects for functionality, but the underlying registration mechanism creates opportunities for attackers to abuse the Windows registry to achieve stealthy persistence and code execution. Despite being used in real-world intrusions, COM hijacking remains under-documented and poorly understood by many defenders.

This talk explores the internals of COM registration and activation and demonstrates how attackers abuse registry-based class registrations, InprocServer32 entries, and per-user overrides to hijack legitimate COM objects. We will analyze common hijacking patterns, explain why many of them evade traditional detection logic, and highlight the operational advantages they offer during post-exploitation and persistence phases.

To help security professionals systematically identify these opportunities, this presentation introduces COM-Hunter, a research tool designed to enumerate and analyze hijackable COM objects across Windows systems. COM-Hunter maps CLSID registrations, identifies missing or user-overridable components, and highlights potential hijacking vectors that can be leveraged during red team engagements or security research.

Through practical demonstrations, we will show how COM-Hunter can be used to uncover previously overlooked hijack paths and how red teamers can turn these findings into reliable persistence mechanisms. The talk also discusses defensive considerations, including detection strategies, telemetry sources, and ways organizations can reduce the attack surface created by vulnerable COM registrations.

Attendees will leave with a deeper understanding of COM hijacking internals, practical offensive techniques, and a methodology for discovering new hijack opportunities in modern Windows environments.

SpeakerBio:  Nikos "nickvourd" Vourdas, EY

Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 10:30-10:59 PDT


Title: Composable Systems with NixOS MicroVMs
Tags: Nix Vegas Community | Creator Talk/Panel
When: Friday, Aug 7, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

MicroVMs make it easy to give every service, project, or person dedicated NixOS machines. We will use microvm.nix to build dev boxes, game servers, and sensitive services on hardware we control. Because each guest is simply a NixOS configuration, it can be reused, extended, rebuilt, and shared.

We will compare MicroVM isolation with other options, explain its limitations, and show how to compose useful machines from ordinary NixOS modules for yourself and those around you. We will finish with a look beyond a single host: how to preserve and back up these machines, then place them across hardware you own.

SpeakerBio:  Alex Decious

I work on build systems and CI infrastructure for Shopify's monorepo using Nix, and run my own infrastructure as a systems lab for compute-heavy builds, distributed systems experiments, local LLMs, and hosting for myself and others.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 17:00-17:30 PDT


Title: Condense, Contextualize, and Correlate: Optimize Costs while Connecting the Dots at Scale
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Auto-condense telemetry volumes by 80% without data loss by grouping related records & deduping redundant values, with ML that auto-normalizes to a unified schema & auto-enriches data with relevant abstractive classifications, framework-aligned controls, contextual tags & environment labels. Use the efficiency with TKG ML to scale multi-level correlations & reveal all similarity & causality patterns & root causes. Use AI to automate troubleshooting, investigations, remediations & operations.

SpeakerBio:  Ezz Tahoun

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada's CSE.

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 15:30-15:55 PDT


Title: Configuring Your Favorite Platforms to Prioritize DNS
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Explore how to leverage infrastructure OSINT data, such as passive DNS and domain registration records, to enhance your threat intelligence and protect your organization without exhausting budgets. In this demo, DomainTools Senior Security Advisor Malachi Walker will discuss how security teams can develop advanced techniques for continuous and explainable intelligence. Then, DomainTools Principal Product Manager Anthony Johnson will demonstrate how these concepts can be applied to build AI-driven product layers that draw domain intelligence from standard LLMs like ChatGPT, Claude, Gemini, and Copilot. Discover innovations that reduce triage time, improve early warnings, and automate campaign linkages, transforming your existing intelligence practices.

Speakers:Malachi Walker,Anthony Johnson

SpeakerBio:  Malachi Walker, DomainTools

Malachi Walker, DomainTools Senior Security Advisor, brings extensive experience in information security, spanning DNS, cyberspace crime and conflict, and cybersecurity governance and program design. They have previously worked in FTI Consulting s Cybersecurity practice and led product and brand protection efforts at WhiteHawk Inc. Malachi holds a Master s in Business Administration with a concentration in Cybersecurity Management from Virginia Polytechnic Institute and State University.

SpeakerBio:  Anthony Johnson, DomainTools

Anthony Johnson, DomainTools Principal Product Manager, has nearly 15 years of experience in cybersecurity. His background includes forensics, analytics, and product management, gained through work with the US Military, Casino Gaming, and other security-focused organizations.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 13:00-13:59 PDT


Title: Connectivity as Control in the European High North
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Between 2022 and 2024, the European High North saw three events at three attribution confidence levels. One segment of Svalbard's twin fibre system failed—Norwegian police closed the case with no state-actor finding. AcidRain wiped tens of thousands of Viasat SurfBeam2 modems via a ground-segment management-plane compromise—attributed to GRU by US/UK/EU in May 2022. GNSS interference over eastern Finnmark persisted 2019–2024—assessed by Norwegian services as Russian EW largely spilling from Kola. Three attributions. Three regimes. No mechanism that treats them as one. UNCLOS cable protection varies by zone (Art 79 shelf; Art 113 high seas; Art 58 EEZ). The 1884 Cables Convention—still in force—governs outside territorial waters. Svalbard Treaty reach into the FPZ is contested. NATO's cumulative-effects language has no classification framework. The 2023–24 Baltic sequence (Balticconnector; C-Lion1/BCS; Estlink-2/Eagle S) is the same play in the active theatre NATO CUI Cell, Baltic Sentry, EU CER/NIS2, JEF and NORDEFCO already cover — and still falls through. We propose an allies-first application of UNDRR Hazard Information Profiles to adversarial compound operations: indicators, authorities, a 2027 milestone. Classification stops no cable. A common record is the precondition for everything that will.

Speakers:Szymon Skalski,Patricia Vargas Leon,Jorge Acevedo Canabal

SpeakerBio:  Szymon Skalski, Jagiellonian University PL

Szymon is a PhD Candidate in the School of Social Sciences at Jagiellonian University and a Senior Expert and NASK National Research Institute in Poland. He is also affiliated with the Ostrom Workshop at Indiana University, where he leads the working group on Environmental Security and Technological Risk in Conflict. He has served on cybersecurity expert panels at the Polish Ministry of Digital Affairs and the Polish Bank Association. He is also a fellow of the European Law Institute, member of FIDMA and Virtual Routes European PhD Cybersecurity Accelerator Programme. For the past three years, he has participated in NATO’s Locked Shields exercises, representing Poland for two years and, in 2026, organizing the exercises on behalf of the CCDCOE in the legal domain.He is a researcher and scholarship holder of grants from the National Science Centre in Poland in the fields of insurance and digital security. He publishes in international academic journals in the fields of cybersecurity, insurance, tort law, and international law.

SpeakerBio:  Patricia Vargas Leon, Ostrom Workshop Indiana University US, Yale Law School

Patricia A. Vargas León is a Visiting Fellow at Yale Law School's Information Society Project, a Cybersecurity Research Postdoctoral Fellow at Indiana University's Ostrom Workshop, and a Visiting Scholar in Internet Governance at the Catholic University of Uruguay. Her research bridges law, policy, and technology — focusing on Internet governance, cybersecurity, international law, and the law of the sea. She is particularly interested in how governments control Internet infrastructure, network neutrality, and regulatory parallels between the law of the sea and cyberspace. Her doctoral dissertation examines Internet blackouts across political regimes and how states restrict digital connectivity. Before academia, Patricia practiced law in the private sector for nearly a decade and brings over two decades of international law experience to her work, including a consultancy with the UN Division for Ocean Affairs and the Law of the Sea (DOALOS). She also served as a Google Policy Fellow during her doctoral studies. Patricia holds a Ph.D. and M.S. in Information Science and Technology from Syracuse University and a law degree from the Pontifical Catholic University of Peru. Her dual training positions her to address complex questions at the intersection of technology, governance, and international law.

SpeakerBio:  Jorge Acevedo Canabal, Ostrom Workshop Indiana University US

Jorge Acevedo Canabal, MD (University of Puerto Rico School of Medicine, Magna Cum Laude), is a physician and Visiting Scholar at the Ostrom Workshop, Indiana University, working on research that sits at the intersection of healthcare, public health, and cybersecurity, applying epidemiological and disaster medicine methods to map patient harm attributable to healthcare cyberattacks and technological hazards. He previously served as Chief Medical Officer of the Puerto Rico Science, Technology and Research Trust, and currently serves as advisor to the Biohacking Village and Raíces Cyber Org.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 14:30-16:59 PDT


Title: Container Escapes 101
Tags: Intermediate | AppSec Village | Creator Workshop
When: Friday, Aug 7, 14:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map

Description:

Containers aren’t tiny fortresses. They’re leaky rowboats unless you know what you’re doing. This hands-on workshop demystifies container security layer by layer, showing how real-world missteps in runtime, image, and host configurations open doors to escapes, persistence, and lateral movement. We’ll dissect how containers actually work, walk through common isolation failures, and demonstrate how attackers exploit weak assumptions. Whether you’re building, securing, or regulating containerized apps, you’ll leave with a threat model, practical tools, and maybe a new trick or two for literally popping out of the box.

SpeakerBio:  some-natalie

Natalie is a principal solutions engineer at XBOW serving the public sector market. She spent years designing, building, and leading complex systems in regulated environments at a major systems integrator, but has also taken her career in many other directions - including detours into project management, systems engineering, and teaching.

She’s passionate about diversity in technology and empowering engineers to build better.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 12:30-12:59 PDT


Title: Container Escapes Are Not Magic. Here Is How They Actually Work.
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Friday, Aug 7, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Container escapes sound scary and complicated. In practice, most of them come down to a handful of misconfigurations that show up in production environments all the time. Overprivileged containers, exposed Docker sockets, weak seccomp profiles, and poorly scoped capabilities. This talk demystifies container escapes for AppSec practitioners. We will walk through three real escape techniques live inside Docker environments running on Google Cloud, explain exactly why each one works, and then show the configuration changes and detection controls that prevent them. No black magic. Just misconfigurations you can find and fix right now, in environments that look a lot like yours.

SpeakerBio:  Advait Patel

Advait Patel is a Senior Site Reliability Engineer at Broadcom and the creator of DockSec, an open-source, AI-powered Docker security analyzer.

Advait is a Docker Captain, Google Developer Expert and regular speaker at major security and developer conferences, including QConAI Boston, SANS CloudSecNext, OWASP GlobalAppSec US, OWASP SnowFROC, PlatformCon, Linux Security Summit North America, O’Reilly Media AI CodeCon, Redgate Cloud Summit, CornCon, ISACA, Silicon Valley Cybersecurity Conference.

His work sits at the intersection of AI, security, and developer workflows, with a particular focus on how emerging technologies like LLMs are reshaping modern development, CI/CD pipelines, and Git-based collaboration. As part of the Git and DevOps community, he advocates for secure-by-default design, developer empowerment, and open-source tooling that puts security in the hands of those who build the future.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 10:00-10:45 PDT


Title: Counting the Dead in the Digital Siege: Detection Infrastructure for Cyber-Mapping Patient Harm
Tags: Biohacking Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Ransomware Kills Patients. We Can't Prove It. Here's How We Fix That.

Ransomware attacks on hospitals kill people. That's not a hypothesis — it's in the data. A peer-reviewed analysis of Medicare claims (American Economic Journal: Economic Policy, 2026) puts in-hospital mortality at 34 to 38 percent higher during attacks. The dead are disproportionately elderly, critically ill, and patients of color. Dameff et al. (2023) documented emergency department spillover. Neprash, Dameff, and Tully (2024) traced the same pattern through the Change Healthcare attack.

The mechanism isn't exotic. Encrypted EHRs mean clinicians are flying blind — no medication history, no imaging, no labs. Networked infusion pumps, ventilators, and monitors drop to manual. Ambulances get diverted, stacking patients at facilities that weren't hit. In rural areas, transfer times go from nine minutes to thirty-three. Here's the deeper problem: these deaths are architecturally invisible.

No ICD code exists for "died because the hospital's network was encrypted." No death certificate asks whether the hospital was under cyberattack. No public health surveillance system captures excess mortality from clinical failure caused by ransomware. Mandatory reporting requirements attach to data breach — not patient harm. Voluntary harm-reporting channels exist, but they're anonymous and sporadic. The visible signal is a fraction of what's actually happening.

This isn't a technical gap. It's a design failure in the detection infrastructure itself.

This talk makes the case for cyber-harm epidemiology. Using a forthcoming law review article, we show that existing systems — ICD external-cause coding, NCHS disaster-death certification, SNOMED CT alignment, the Sendai Framework's Hazard Information Profiles (2025) and Global Disaster-Related Statistics Framework (2026) — can be adapted right now to make cyber-attributable patient deaths visible at population scale. No new treaties required.

Better detection produces better attribution. Better attribution makes state obligations under the right to life and the protection of medical units enforceable — not aspirational.

The deaths are real. The tools to count them exist. We just haven't connected them yet. That's what this talk is about.

Speakers:Jorge Acevedo Canabal,Scott Shackelford,Szymon Skalski

SpeakerBio:  Jorge Acevedo Canabal, Ostrom Workshop Indiana University US

Jorge Acevedo Canabal, MD (University of Puerto Rico School of Medicine, Magna Cum Laude), is a physician and Visiting Scholar at the Ostrom Workshop, Indiana University, working on research that sits at the intersection of healthcare, public health, and cybersecurity, applying epidemiological and disaster medicine methods to map patient harm attributable to healthcare cyberattacks and technological hazards. He previously served as Chief Medical Officer of the Puerto Rico Science, Technology and Research Trust, and currently serves as advisor to the Biohacking Village and Raíces Cyber Org.

SpeakerBio:  Scott Shackelford

Scott J. Shackelford is Associate Vice President and Vice Chancellor for Research at Indiana University Bloomington and Provost Professor of Business Law & Ethics at the IU Kelley School of Business. He serves as Executive Director of both the Ostrom Workshop and the Center for Applied Cybersecurity Research, and directs the Ostrom Workshop Program on Cybersecurity & Internet Governance. He is also an Affiliated Scholar at Harvard Kennedy School's Belfer Center and Stanford's Center for Internet and Society. Scott has authored over 100 articles, book chapters, and essays, with research featured in Politico, NPR, CNN, Forbes, Time, and the Washington Post. His books include The Internet of Things: What Everyone Needs to Know (2020) and Managing Cyber Attacks in International Law, Business, and Relations (2014). His honors include a Harvard Research Fellowship, a Stanford Hoover National Fellowship, the 2015 Elinor Ostrom Award, and the 2022 Poets & Quants Best 40-Under-40 MBA Professors Award.

SpeakerBio:  Szymon Skalski, Jagiellonian University PL

Szymon is a PhD Candidate in the School of Social Sciences at Jagiellonian University and a Senior Expert and NASK National Research Institute in Poland. He is also affiliated with the Ostrom Workshop at Indiana University, where he leads the working group on Environmental Security and Technological Risk in Conflict. He has served on cybersecurity expert panels at the Polish Ministry of Digital Affairs and the Polish Bank Association. He is also a fellow of the European Law Institute, member of FIDMA and Virtual Routes European PhD Cybersecurity Accelerator Programme. For the past three years, he has participated in NATO’s Locked Shields exercises, representing Poland for two years and, in 2026, organizing the exercises on behalf of the CCDCOE in the legal domain.He is a researcher and scholarship holder of grants from the National Science Centre in Poland in the fields of insurance and digital security. He publishes in international academic journals in the fields of cybersecurity, insurance, tort law, and international law.


Return to Index    -    Add to Google    -    ics Calendar file

Quantum Village - Friday - 16:30-16:59 PDT


Title: Covert Quantum Computing - a new quantum security paradigm
Tags: Quantum Village | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Quantum computers will inevitably move to multi-tenant systems for efficiency and throughput, with many users sharing a single QPU. This talk will discuss the realities of threats facing quantum computing 'as a service' and what is particularly specific to quantum computing. We'll get you started on understanding the quantum computing tech stack, and work through a few examples of possible attacks and mitigation techniques, wrapping up our newly developed security paradigm of covert quantum computing. All of the examples presented in this talk can be run by anyone with an internet connection and an email address. This talk is for anyone curious about attacks (and mitigation) techniques in quantum computing, and similarly how to build and test new ideas. A quantum background is not required!

SpeakerBio:  Evan Anderson, UMD

Evan is a postdoctoral researcher at the University of Maryland focusing on photonic (and atomic) quantum computing architectures.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Crack Me If You Can 2026
Tags: Crack Me If You Can 2026 | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 106 (Crack me if you can) - Map

Description:

Time is of the essence! You will have 48 hours to crack as many hashes and files as possible.

Pamama, a US-based data broker had a massive data breach. Profiles on over a billion people, containing all the information amassed about them. It is alleged that the company siphoned records from different government agencies around the world, as well. The dump was encrypted, and regulators are downplaying the breach claiming no damage was done. A bill has been fast-tracked in Congress to exempt Pamama from any investigations, including illegally shield them from GDPR violations. This led to accusations that Pamama has bought or blackmailed members of congress.

Crack the staff's accounts and encrypted files to demonstrate the extent of the exposure and the need for individuals to get restitution and compensation, and to find smoking gun evidence of collusion so that the corruption can be fully exposed before the legislation goes forward.

Participant Prerequisites

Open to all, but pre-registration is recommended. Compete in the Street class for individuals or small teams, or in Pro if you do not want to sleep all weekend. Check out past years' contests at https://contest.korelogic.com/ , or the Password Village site for an introduction to password cracking and links to other resources: https://passwordvillage.org/

Pre-Qualifications

None.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Crack the Core
Tags: Crack the Core | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 214 (Crack the Core) - Map

Description:

Welcome to Crack the Core–a true test of lockpicking skills. Competitors will work through a variety of locks ranging in different difficulties, technologies, and configurations. From standard off-the-shelf locks to evil creations from the community. Locks will be presented in a variety of ways, ranging from your traditional deadbolt to much, much more. Just wait until you see what we have in store for you…

Challenges will not only test traditional lockpicking skills but force competitors to interact with different “environments,” work through various challenges, and adapt to what's presented. Collect the most points, you go home the winner–it’s that simple…

Bring your tools. Bring your focus. The locks will be waiting.

Participant Prerequisites

Basic tools will be available for use but it is highly recommended to bring your own tools. This may include lockpicks, bypass tools, vices, etc. Destructive entry is not allowed and associated tools will not be needed.


Return to Index    -    Add to Google    -    ics Calendar file

.EDU Community - Friday - 11:00-11:59 PDT


Title: Cracking the Cybersecurity Career Code with the Cyber Color Wheel
Tags: .EDU Community | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map

Description:
Giveaway: Two raffles for one copy of:
See Yourself in Cyber: Security Careers Beyond Hacking
SpeakerBio:  Shavvon "TheSiren" Cintron

Shavvon Cintron spent the last decade climbing the IT ladder, now working in IT and cybersecurity within the healthcare space. She's got an MS in Cybersecurity from Pace, a BS in Criminal Justice from CUNY John Jay, and a 2025 SANS Institute Difference Makers Rising Star nod, so somebody thinks she's doing something right. When she's not at her day job, she's Director of Women's Education for the Women's Society of Cyberjutsu, building the programs she wishes existed when she was trying to break in. She goes by "Siren of the Cyber Sea." Get too close and you might not want to leave.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 11:30-12:30 PDT


Title: Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

A program crashes with a segmentation fault. Then, it crashes again. And again. What looks like crazy behaviour is actually an exploit, running one crash at a time.

In this talk, we present Segmentation Fault-Oriented Programming (SFOP), a novel exploitation technique that weaponizes 12 previously unknown weaknesses in the Linux kernel's handling of signals to execute arbitrary code. SFOP is designed to bypass Intel CET, the most widely deployed hardware Control-Flow Integrity (CFI) scheme on modern x86-64 systems, built to stop classic code-reuse attacks such as Return-Oriented Programming (ROP) and Sigreturn-Oriented Programming (SROP). Unlike previous CFI bypass techniques, SFOP is a general-purpose technique that can by-default reliably exploit any vulnerable x86-64 application with Intel CET enabled, becoming the lowest-hanging fruit attack after Intel CET.

We will show how SFOP bypasses CFI and turns a single memory-corruption vulnerability into arbitrary code execution on real-world targets. Through practical exploits, we demonstrate that what appears to be a process trapped in a crash loop is, in reality, attacker-controlled execution progressing fault by fault. Finally, we discuss the underlying weaknesses that make SFOP possible and the mitigations needed to defend against this new class of attacks.

Our paper has a ~50 references, like most academic papers. We have references to the Linux kernel lines that showcase the vulnerabilities we find, even! Here we copy paste our references, but everything is properly ordered in the paper.

[1] LMS Phrack 40. Bypassing cet & bti with functional oriented programming. https://phrack.org/issues/71/7_md. (29-10-2025). [2] Martin Abadi, Mihai Budiu, Ulfar Erlingsson, and Jay Ligatti. Control-flow integrity. In Proceedings of the 12th ACM Conference on Computer and Communications Security, CCS ’05, page 340–353, New York, NY, USA, 2005. Association for Computing Machinery. [3] Marcos Bajo and Christian Rossow. Await() a second: evading control flow integrity by hijacking c++ coroutines. In Proceedings of the 34th USENIX Conference on Security Symposium, SEC ’25, USA, 2025. USENIX Association. [4] Markus Bauer, Ilya Grishchenko, and Christian Rossow. Typro: Forward cfi for c-style indirect function calls using type propagation. In Proceedings of the 38th Annual Computer Security Applications Conference, ACSAC ’22, page 346–360, New York, NY, USA, 2022. Association for Computing Machinery. [5] Lucas Becker, Matthias Hollick, and Jiska Classen. Sok: on the effectiveness of control-flow integrity in practice. In Proceedings of the 18th USENIX Conference on Offensive Technologies, WOOT’24, USA, 2024. USENIX Association. [6] Lorenzo Binosi, Gregorio Barzasi, Michele Carminati, Stefano Zanero, and Mario Polino. The Illusion of Randomness: An Empirical Analysis of Address Space Layout Randomization Implementations. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024. [7] Tyler Bletsch, Xuxian Jiang, Vince W. Freeh, and Zhenkai Liang. Jump-oriented programming: A new class of code-reuse attack. In Proceedings of the ACM Symposium on Information, Computer and Communications Security, ASIACCS, 2011. [8] Erik Bosman. x86: Srop mitigation: implement signal counting. https://lkml.org/lkml/2014/5/15/858. (12-11-2025). [9] Erik Bosman and Herbert Bos. Framing signals - a return to portable shellcode. In 2014 IEEE Symposium on Security and Privacy, pages 243–258, 2014. [10] Nicholas Carlini, Antonio Barresi, Mathias Payer, David Wagner, and Thomas R. Gross. Control-Flow bending: On the effectiveness of Control-Flow integrity. In 24th USENIX Security Symposium (USENIX Security 15), pages 161–176, Washington, D.C., August 2015. USENIX Association. [11] Chromium. syscall sets.cc - chromium github. https://github.com/chromium/chromium/blob/main/sandbox/linux/seccomp-bpf-helpers/syscall sets.cc#L353. (12-11-2025). [12] Exploit Database. Nginx 1.3.9 - 1.4.0 - chuncked encoding stack buffer overflow (metasploit). https://www.exploit-db.com/exploits/25775. (29-10-2025). [13] V8 Developers. Control-flow integrity in v8. https://v8.dev/blog/control-flow-integrity. (29-10-2025). [14] Docker Docs. Seccomp security profiles for docker. https://docs.docker.com/engine/security/seccomp/. (12-11-2025). [15] Victor Duta, Fabian Freyer, Fabio Pagani, Marius Muench, and Cristiano Giuffrida. Let me unwind that for you: Exceptions to backward-edge protection. In Symposium on Network and Distributed System Security (NDSS), 2023. [16] Mozilla Firefox. Sandboxfilter.cpp - firefox github. https://github.com/mozilla-firefox/firefox/blob/main/security/sandbox/linux/SandboxFilter.cpp#L1178. (12-11-2025). [17] Alexander J. Gaidis, Joao Moreira, Ke Sun, Alyssa Milburn, Vaggelis Atlidakis, and Vasileios P. Kemerlis. Fineibt: Fine-grain control-flow enforcement with indirect branch tracking. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, RAID ’23, page 527–546, New York, NY, USA, 2023. Association for Computing Machinery. [18] GNU. Gcc wiki - vtv. https://gcc.gnu.org/wiki/vtv. (12-11-2025). [19] GNU. Program instrumentation options. https://gcc.gnu.org/onlinedocs/gcc/Instrumentation-Options.html. (12-11-2025). [20] Yingjie Guo, Liwei Chen, and Gang Shi. Function-oriented programming: A new class of code reuse attack in c applications. In 2018 IEEE Conference on Communications and Network Security (CNS), pages 1–9, 2018. [21] Enes Goktas, Elias Athanasopoulos, Herbert Bos, and Georgios Portokalidis. Out of control: Overcoming control-flow integrity. In 2014 IEEE Symposium on Security and Privacy, pages 575–589, 2014. [22] Hong Hu, Zheng Leong Chua, Sendroiu Adrian, Prateek Saxena, and Zhenkai Liang. Automatic generation of Data-Oriented exploits. In 24th USENIX Security Symposium (USENIX Security 15), pages 177–192, Washington, D.C., August 2015. USENIX Association. [23] Hong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua,Prateek Saxena, and Zhenkai Liang. Data-oriented programming: On the expressiveness of non-control data attacks. In 2016 IEEE Symposium on Security and Privacy (SP), pages 969–986, 2016. [24] Intel. A technical look at intel® control-flow enforcement technology. https://www.intel.com/content/www/us/en/developer/articles/technical/technical-look-control-flow-enforcement-technology.html. (29-10-2025). [25] Seunghoon Jeong, Jaejoon Hwang, Hyukjin Kwon, and Dongkyoo Shin. A cfi countermeasure against got overwrite attacks. IEEE Access, 8:36267–36280, 2020. [26] Linux Kernel. Control-flow enforcement technology (cet) shadow stack. https://docs.kernel.org/arch/x86/shstk.html. (12-11-2025). [27] LLVM. Control flow integrity design documentation. https://clang.llvm.org/docs/ControlFlowIntegrityDesign.html. (12-11-2025). [28] Linux manual page. Sigaction(2) - linux manual page. https://man7.org/linux/man-pages/man2/sigaction.2.html. (05-10-2025). [29] Ben Niu and Gang Tan. Modular control-flow integrity. In Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI ’14, page 577–587, New York, NY, USA, 2014. Association for Computing Machinery. [30] PaX. Address space randomization. https://pax.grsecurity.net/docs/aslr.txt, 2003. (12-11-2025). [31] Aravind Prakash, Xunchao Hu, and Heng Yin. vfguard: Strict protection for virtual function calls in cots c++ binaries. In Proceeding of the Annual Network and Distributed System Security Symposium (NDSS), 01 2015. [32] Bootlin Elixir Cross Referencer. create rstor token (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L64. (29-10-2025). [33] Bootlin Elixir Cross Referencer. get shstk data (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L272. (29-10-2025). [34] Bootlin Elixir Cross Referencer. libc sigaction (glibc source code). https://elixir.bootlin.com/glibc/glibc-2.33/source/sysdeps/unix/sysv/linux/sigaction.c#L42. (29-10-2025). [35] Bootlin Elixir Cross Referencer. pte mkwrite shstk (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/include/asm/pgtable.h#L491. (29-10-2025). [36] Bootlin Elixir Cross Referencer. rt sigaction (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.7/source/kernel/signal.c#L4644. (29-10-2025). [37] Bootlin Elixir Cross Referencer. rt sigreturn l266 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/signal 64.c#L266. (29-10-2025). [38] Bootlin Elixir Cross Referencer. rt sigreturn l275 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/signal 64.c#L275. (29-10-2025). [39] Bootlin Elixir Cross Referencer. setup signal shadow stack l364 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L364. (29-10-2025). [40] Bootlin Elixir Cross Referencer. setup signal shadow stack l370 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L370. (29-10-2025). [41] Bootlin Elixir Cross Referencer. Sigaction (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/include/uapi/asm/signal.h#L93. (05-10-2025). [42] Bootlin Elixir Cross Referencer. Sigframe (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/include/asm/sigframe.h#L59. (05-10-2025). [43] Bootlin Elixir Cross Referencer. sigset t (glibc source code). https://elixir.bootlin.com/glibc/glibc-2.33/source/signal/bits/types/sigset t.h#L7. (29-10-2025). [44] Bootlin Elixir Cross Referencer. sigset t (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.7/source/arch/x86/include/asm/signal.h#L25. (29-10-2025). [45] AliAkbar Sadeghi, Salman Niksefat, and Maryam Rostamipour. Pure call oriented programming (pcop): chaining the gadgets using call instructions. Journal of Computer Virology and Hacking Techniques, 14:1–18, 05 2018. [46] Felix Schuster, Thomas Tendyck, Christopher Liebchen, Lucas Davi, Ahmad-Reza Sadeghi, and Thorsten Holz. Counterfeit object-oriented programming: On the difficulty of preventing code reuse attacks in c++ applications. In Proceedings of the IEEE Symposium on Security and Privacy, SP, 2015. [47] Hovav Shacham. The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In Proceedings of the ACM conference on Computer and Communications Security, CCS, 2007. [48] sroettger. Ierae ctf 2024. https://gist.github.com/sroettger/fe66f7eb0cb10a8ebd1454875a7131ea. (29-10-2025). [49] Ubuntu. Compilerflags - ubuntu wiki. https://wiki.ubuntu.com/ToolChain/CompilerFlags. (29-10-2025). [50] Chao Zhang, Scott A. Carr, Tongxin Li, Yu Ding, Chenyu Song, Mathias Payer, and Dawn Song. Vtrust: Regaining trust on virtual calls. In Proceedings of the Annual Network and Distributed System Security Symposium (NDSS), 2016. [51] Tianning Zhang, Miao Cai, Diming Zhang, and Hao Huang. esrop attack: Leveraging signal handler to implement turing-complete attack under cfi defense. In Fengjun Li, Kaitai Liang, Zhiqiang Lin, and Sokratis K. Katsikas, editors, Security and Privacy in Communication Networks, pages 752–769, Cham, 2023. Springer Nature Switzerland

Speakers:Marcos "h3xduck" Bajo,Ritvik "RoYalGamr" Goyal

SpeakerBio:  Marcos "h3xduck" Bajo, CISPA Helmholtz Center for Information Security

Marcos Bajo aka h3xduck is a security researcher and PhD student at the CISPA Helmholtz Center for Information Security in Germany. His research focuses on exploitation techniques and malware, but more broadly, he's interested in breaking things others build—and building things to break things.

SpeakerBio:  Ritvik "RoYalGamr" Goyal

Ritvik Goyal is a Senior Undergraduate in Mathematics and Scientific Computing at the Indian Institute of Technology Kanpur. He recently worked as a Research Intern at the CISPA Helmholtz Center, focusing on system security research regarding Control Flow Integrity protections like Intel CET. He is a key member of the competitive CTF team Wiredin IITK and actively mentors students in cybersecurity at Programming Club IIT Kanpur.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Cryptid Hunt
Tags: Cryptid Hunt | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 203 (Cryptid Hunt) - Map

Description:

Something is already watching you.

The Cryptid Hunt is a task-oriented challenge that moves agents across the conference floor toward a truth most attendees will never find. This is not a passive experience — each clue demands action, and the path forward is never obvious.

Look carefully at what surrounds you. The next layer of any good mystery is always hiding beneath the surface. Patterns emerge for those paying attention. Signals exist for those who know how to listen.

Is this a puzzle? A test? A hunt? At its core, this is a community experience that rewards curiosity, persistence, and the willingness to go further than most people will.

The conference is your map. Maritime exploration, ancient communication, and the village of knowledge surrounding you are all part of the journey. Nothing here is coincidental.

Finishers are recognized. What awaits those who complete the hunt will not be found anywhere else at this conference. Supplies are finite. So is your time.

Your first clue is already in your hands.

— The Cryptid Hunt Team

Bureau of Unverified Phenomena · DC34

Participant Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Friday - 16:30-17:15 PDT


Title: Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 17:15 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Developers keep getting crypto wrong in the same ways. Not the math, but the code around it. A missing check here, implicit trust there, and suddenly a signature means nothing. This talk is data-driven and hands-on. Starting from OWASP A04:2025, we examine real CVEs from GitHub Security Advisories as of January 2026 to show which crypto failure patterns actually dominate in the wild, then go deep on the top two: signature verification bypasses (including invalid curve attacks) and algorithm confusion bugs (JWT). Real libraries, live exploits. Demos and CTF challenges are woven throughout, involves audience interaction and participation. No crypto background required.

SpeakerBio:  Diptendu Kar

Diptendu Kar is a security researcher focused on supply chain and dependency risk. He works on triaging open-source vulnerabilities, writing detection rules, and exploring how AI can automate tedious parts of security research. He also teaches Software Security Practices at Northeastern University part time and holds a Master’s in Cybersecurity. Before security, he worked as a Java developer at TCS. He is especially interested in patch diffing, vulnerable function detection, and the use of LLMs in AppSec. He believes cryptography is magic and AI is a noisy intern - helpful but always needs supervision.


Return to Index    -    Add to Google    -    ics Calendar file

Cryptocurrency Village - Friday - 11:00-11:59 PDT


Title: Cryptocurrency Opening Keynote
Tags: Cryptocurrency Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Join your fellow hackers managing the Cryptocurrency areas at DEF CON, and get a sneak peak of what each workshop teaches as well as an overview of the showcases and programs happening in our DEF CON Village and Contest areas. We will report on cryptocurrency trends and perspectives from distinguished positions in industry, academy, and government. We will announce the teams competing in the Cryptocurrency Challenge, and give an overview of what prizes are available to winning contestants of the hackathon, CTF, and contests. Meet the organizers of years of cryptocurrency content at Defcon and bring your questions to the Creator Stage during the Cryptocurrency Opening Keynote!

Speakers:Michael "MsvB" Schloh,Param "P7R7M",Arjun "Peper" Suresh

SpeakerBio:  Michael "MsvB" Schloh, Chairman, Monero Devices

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

SpeakerBio:  Param "P7R7M"

Param is an Electrical Engineering Student from Georgia Tech with a strong passion for and interest in crypto. Although he primarily got interested in cryptography and hardware security through a class at Georgia Tech, he is also working at a software company on crypto adoption and ease of use. With a unique blend of HW and SW skills, Param is truly enthusiastic about all aspects of crypto.

SpeakerBio:  Arjun "Peper" Suresh, Postgraduate Student, University of Wollongong in Dubai

Arjun Suresh is pursuing postgraduate studies in Cybersecurity at the University of Wollongong in Dubai, specializing in blockchain security, penetration testing, and applied cryptography. His interest in crypto security was shaped by analyzing major exchange breaches, including the Mt. Gox and Ronin Network hacks, where he studied the gap between attacker tradecraft and real-world defenses.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 12:20-12:30 PDT


Title: Cryptocurrency Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 12:20 - 12:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Cryptocurrency Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Cryptocurrency Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Friday - 12:00-12:45 PDT


Title: Cryptographer Recruitment: Crack the Substitution Cipher
Tags: DCNextGen | Creator Event/Activity | Youth
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

You’re a Cryptographer When Jumbled Letters are Exciting, Not Scary! The substitution cipher is a game of mathematics and patterns. With basic skills (or online tools) ciphers are easy to decipher. Don't let them fool you! Attendees will need some paper, a writing device, and access to the Substitutor web app.

SpeakerBio:  Bradán Lane
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cryptocurrency Village - Friday - 14:00-14:59 PDT


Title: Cryptohack Badge Hacking
Tags: Cryptocurrency Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

In this hour, we’ll guide you from setup to exploitation of a Cryptohack electronic badge. From installing the ESP-IDF toolchain, understanding application logic, compiling and disassembling firmware, we get familiar with the basics before considering the advanced aspects of financial technology in hardware. To explore the typical interfaces of a hardware wallet, we experiment with live hacks on a testnet wallet supporting Solana, Ethereum, Bitcoin, and Monero. By the end of the session, you’ll know how to probe the boundaries of hardware security and leave with insights you can apply to real-world offensive security challenges.

Speakers:Do Truong Giang "FSNaix",Sadiq "Sdqmd",Arjun "Peper" Suresh

SpeakerBio:  Do Truong Giang "FSNaix", BlossomsAI / Bloomify (AI & Security)

I'm Giang (FSNaix), an AI and security researcher from Vietnam and a Bloomify cofounder. I help build open-source Vietnamese language models with BlossomsAI, I built Petal (an AI tool that reverse-engineers binaries faster than doing it by hand), and at DEFCON Singapore 1 I managed to get DOOM running on a $20 conference badge.

SpeakerBio:  Sadiq "Sdqmd", CodeBit

sdqmd (Sadiq) is a hardware hacker and co-founder of CodeBit, a technology company based in Brunei that's building a hardware engineering academy to teach embedded systems and security from the ground up. He is focused on developing a pedagogy that blends theory with hands-on practice, so aspiring hackers — especially those just starting out — don't just learn how something works; they build it, break it, and understand it for themselves. His own research focuses on hardware attacks against embedded devices — using fault injection and power analysis to defeat the security of everything from crypto hardware wallets to point-of-sale infrastructure. Above all, he's driven by one goal: building hardware and security competency in Brunei, where hands-on learning is still hard to come by.

SpeakerBio:  Arjun "Peper" Suresh, Postgraduate Student, University of Wollongong in Dubai

Arjun Suresh is pursuing postgraduate studies in Cybersecurity at the University of Wollongong in Dubai, specializing in blockchain security, penetration testing, and applied cryptography. His interest in crypto security was shaped by analyzing major exchange breaches, including the Mt. Gox and Ronin Network hacks, where he studied the gap between attacker tradecraft and real-world defenses.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 13:00-13:55 PDT


Title: CTRL the Chaos: When AI Controls Critical Infrastructure
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

As artificial intelligence shifts from supporting analytics to exercising real-time operational control in critical infrastructure energy grids, aviation systems, healthcare networks, transportation, and national logistics it ceases to be a tool and becomes part of the infrastructure itself. AI now optimizes load balancing, automates routing, manages predictive maintenance, and drives high-stakes decisions that directly impact public safety, economic stability, and national security. This session introduces the CTRL framework (Control, Resilience, Trust, Leadership) a strategic blueprint for securing autonomous systems before they evolve into systemic risk. Drawing from hands-on experience in federal cybersecurity, aviation security, AI governance, and academic cybersecurity instruction, Nykolas Muldrow explores how AI expands the attack surface through threats like data poisoning, model drift, prompt injection, and compromised AI supply chains. Attendees will gain: A clear view of how embedded AI transforms infrastructure vulnerabilities A practical threat model tailored to autonomous operational systems Governance strategies aligned with NIST AI Risk Management Framework and ISO-based controls The CTRL leadership model for embedding responsible AI oversight into organizational strategy An immediate-use risk-evaluation method for their own products, infrastructure, or agencies In an era where regulators intensify scrutiny, investors demand deeper risk diligence, and operators race to deploy AI without proportional safeguards, the next decade of progress will belong to those who govern autonomous systems responsibly not just those who deploy them fastest. Join to equip yourself with the tools to lead before AI makes decisions we cannot easily reverse.

SpeakerBio:  Nykolas Muldrow, CEO of CI Solutions Global Inc.

Nykolas Muldrow is a cybersecurity executive, CEO of CI Solutions Global Inc., and 2025 GovTechCon Mission Trailblazer Award recipient for their pioneering work in AI, cybersecurity, and secure cloud technologies for critical infrastructure. With 15+ years securing defense, aviation, and federal systems including aviation GRC at American Airlines they specialize in threat modeling autonomous AI in high-stakes environments like energy grids, transportation, and healthcare networks. Nyk teaches cybersecurity, aligns solutions to NIST AI RMF and ISO controls, and equips leaders to govern AI responsibly before it becomes systemic risk.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Friday - 08:30-17:30 PDT


Title: Cyber & AI Policy Basics: What Every Organization Needs in Place
Tags: DEF CON Training (Paid) (1-day) | DEF CON Training
When: Friday, Aug 7, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W223 (Training) - Map

Description:
Speakers:Pamela 'Pam' Feld,Greg Goldberg

SpeakerBio:  Pamela 'Pam' Feld
No BIO available
SpeakerBio:  Greg Goldberg
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Cyber Deck Competition
Tags: Maker's Village | Contest | Cyber Deck Makers’ Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

The cyber deck contest at DEF CON 34 encourages makers of all types to create their own cyber deck. Winners will be judged on form, function, creativity, does it work, general, awesomeness, and complexity.

Stop by Makers' Village for more info!

Judging Criteria

Rules

  1. Must be present to enter.
  2. Winners are determined by points awarded by the judges.
  3. Rules are subject to change.

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 10:00-17:59 PDT


Title: Cyber Mirage: Realtime Deepfake Demos
Tags: AI Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become.

SpeakerBio:  Brandon Kovacs

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at offensive cybersecurity firm Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets. Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on the intersection of offensive cybersecurity and artificial intelligence.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Friday - 11:00-11:59 PDT


Title: Cyber Threat Intelligence 101: From Foundations to AI-Driven Defense
Tags: Blue Team Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

This talk is a fast-paced, vendor-neutral primer for defenders who want to turn raw telemetry into actionable intelligence. Threat intelligence is not just a feed — it is a discipline built through practice, structure, and action. This session introduces the CTI lifecycle, intelligence requirements, MITRE ATT&CK mapping, and the role of baselining in helping analysts separate normal activity from suspicious behavior.

Attendees will also see how CTI becomes operational through practical blue-team workflows such as YARA and Sigma rule development, threat hunting, incident response, and purple-team validation. We will close by exploring how grounded AI workflows can accelerate enrichment, ATT&CK mapping, detection drafting, and analyst reporting while keeping humans responsible for validation, context, and final decisions.

SpeakerBio:  Carlo Anez Mazurco

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Friday - 15:00-16:59 PDT


Title: Cyberdeck Build
Tags: Maker's Village | Creator Event/Activity | Cyber Deck Makers’ Contest
When: Friday, Aug 7, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Learn some in's and out's of building your own cyberdeck... by building one with us! Customizable with radio add on, this deck is a great introduction level or intermediate refresher.

SpeakerBio:  Sk!tz0
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 12:00-12:45 PDT


Title: Damn Vulnerable Agentic AI Application (DVAIA)
Tags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

AI-powered Agentic applications now execute database queries, read files, send emails, and call APIs on behalf of users — all triggered through a chat window. DVAIA (Damn Vulnerable Agentic AI Application) is a new open-source platform purpose-built to let you break them.

DVAIA pairs a production-grade secure platform with deliberately vulnerable AI-powered chat agents, each isolated in its own database and mapped to the OWASP Top 10 for LLM Applications 2025. In this demo we live-exploit nine exercise categories covering 93 attack objectives:

Speakers:Abhinav Verma,Mukesh Aggarwal

SpeakerBio:  Abhinav Verma

Abhinav Verma is a Senior Staff Security Engineer at Intuit Inc. with 15+ years of experience across AI security, offensive security, red teaming, product security, and security operations. He currently leads AI security architecture reviews, AI penetration testing, and vulnerability management programs, with a focus on AI security, AI threat modeling, and securing large-scale cloud platforms.

Over the course of his career at Intuit, he has built security automation, scaled continuous security scanning across thousands of assets, led secure design reviews for platforms serving millions of customers, and developed secure coding programs that have helped thousands of engineers shift security left. Abhinav was formerly an independent security researcher and has identified and reported vulnerabilities in numerous major online services and technology companies.

He holds certifications including OSEP, OSCP, OSWP, GWAPT and CEH. Outside of work, Abhinav is a passionate gamer, a trained chef, an avid camper, and a mentor to aspiring offensive security practitioners.

SpeakerBio:  Mukesh Aggarwal

Mukesh Aggarwal is a Distinguished Security Engineer who has spent his career thinking like a hacker. For nearly two decades he has hunted fraudsters and abuse across fintech platforms, building the detection pipelines, automations, and controls that shut bad actors down. He now lives at the bleeding edge of GenAI and agentic AI security, secure-by-default agent patterns, adversarial pen-testing and prompt-injection defense. He breaks things to understand them and stays a step ahead of attackers, usually spotting the weaknessess before they do.

Mukesh has spoken at RSA Conference (OWASP GenAI Security Track), RenderATL, and the Intel Capital CISO Summit on AI safety, fraud, and offensive security, and is a member of the GIAC Advisory Board.

Off the clock he is a die-hard offensive-security tinkerer who reverse-engineers hardware and apps, pokes at IoT security, writes autonomous bots, and automates his home. He also mentors the next wave of offensive and AI security practitioners.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 11:00-11:45 PDT


Title: Damn Vulnerable Agentic AI Application (DVAIA)
Tags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

AI-powered Agentic applications now execute database queries, read files, send emails, and call APIs on behalf of users — all triggered through a chat window. DVAIA (Damn Vulnerable Agentic AI Application) is a new open-source platform purpose-built to let you break them.

DVAIA pairs a production-grade secure platform with deliberately vulnerable AI-powered chat agents, each isolated in its own database and mapped to the OWASP Top 10 for LLM Applications 2025. In this demo we live-exploit nine exercise categories covering 93 attack objectives:

Speakers:Abhinav Verma,Mukesh Aggarwal

SpeakerBio:  Abhinav Verma

Abhinav Verma is a Senior Staff Security Engineer at Intuit Inc. with 15+ years of experience across AI security, offensive security, red teaming, product security, and security operations. He currently leads AI security architecture reviews, AI penetration testing, and vulnerability management programs, with a focus on AI security, AI threat modeling, and securing large-scale cloud platforms.

Over the course of his career at Intuit, he has built security automation, scaled continuous security scanning across thousands of assets, led secure design reviews for platforms serving millions of customers, and developed secure coding programs that have helped thousands of engineers shift security left. Abhinav was formerly an independent security researcher and has identified and reported vulnerabilities in numerous major online services and technology companies.

He holds certifications including OSEP, OSCP, OSWP, GWAPT and CEH. Outside of work, Abhinav is a passionate gamer, a trained chef, an avid camper, and a mentor to aspiring offensive security practitioners.

SpeakerBio:  Mukesh Aggarwal

Mukesh Aggarwal is a Distinguished Security Engineer who has spent his career thinking like a hacker. For nearly two decades he has hunted fraudsters and abuse across fintech platforms, building the detection pipelines, automations, and controls that shut bad actors down. He now lives at the bleeding edge of GenAI and agentic AI security, secure-by-default agent patterns, adversarial pen-testing and prompt-injection defense. He breaks things to understand them and stays a step ahead of attackers, usually spotting the weaknessess before they do.

Mukesh has spoken at RSA Conference (OWASP GenAI Security Track), RenderATL, and the Intel Capital CISO Summit on AI safety, fraud, and offensive security, and is a member of the GIAC Advisory Board.

Off the clock he is a die-hard offensive-security tinkerer who reverse-engineers hardware and apps, pokes at IoT security, writes autonomous bots, and automates his home. He also mentors the next wave of offensive and AI security practitioners.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Dark Wolf Hack Our Drone Workshop
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where:

Description:
Speakers:Ronald Broberg,Rudy Mendoza

SpeakerBio:  Ronald Broberg
No BIO available
SpeakerBio:  Rudy Mendoza
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Dark Wolf Hack Our Drone Workshop
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where:

Description:
Speakers:Ronald Broberg,Rudy Mendoza

SpeakerBio:  Ronald Broberg
No BIO available
SpeakerBio:  Rudy Mendoza
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Friday - 13:30-14:30 PDT


Title: Darknet Diaries Meet & Greet with Jack Rhysider
Tags: DEF CON Groups | Creator Event/Activity
When: Friday, Aug 7, 13:30 - 14:30 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

Meet Jack Rhysider, creator and host of Darknet Diaries, during a special fan meet and greet in the DEF CON Groups Community. Stop by to say hello and talk about your favorite stories from the dark side of the internet. First come, first served.

SpeakerBio:  Jack Rhysider, Creator and Host at Darknet Diaries
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Darknet-NG
Tags: Darknet-NG | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 105 (Darknet-NG) - Map

Description:

Darknet-NG is an Alternate Reality Game (ARG), where the players take on the Persona of an Agent who is sent on Quests to learn real skills and gain in-game points. If this is your first time at DEF CON, this is a great place to start, because we assume no prior knowledge. Building from basic concepts, we teach agents about a range of topics from Lock-picking, to using and decoding ciphers, to Electronics 101, just to name a few, all while also helping to connect them to the larger DEF CON Community. The "Learning Quests" help the agent gather knowledge from all across the other villages at the conference, while the "Challenge Quests" help hone their skills! Sunday Morning there is a BOSS FIGHT where the Agents must use their combined skills as a community and take on that year's final challenge! There is a whole skill tree of personal knowledge to obtain, community to connect with and memories to make! To get started, check out our site https://darknet-ng.network and join our growing Community!

Participant Prerequisites

Prerequisites for competing in the contest would require a device with access to a web browser like a Phone, Tablet, Laptop.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 15:00-15:59 PDT


Title: Data Tomb Raider: Raiding Modern AI Vaults with Legacy Flaws for Treasure Stealing
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Click a link, lose your MFA codes. Your AI assistant reads your email and exfiltrates the data through Bing, and you never notice.

We found a 1-click attack chain against Microsoft 365 Copilot that combines three vulnerability classes everyone assumed were solved - CSP, SSRF, and HTML injection - into one kill shot. A URL parameter lands directly in the AI engine as an executable prompt, a vector we call Parameter-to-Prompt (P2P) injection. The AI searches the victim's mailbox, grabs sensitive data, and emits an img tag with the loot in the URL. That tag renders mid-stream, before the output sanitizer fires, because sanitization is a post-processing step. The img src hits Bing's Search by Image endpoint - CSP-allowlisted - which server-side fetches to our domain, tunneling stolen data through Microsoft's own infrastructure.

CSP enforced. Sanitizer running. AI guardrails active. All three defenses in place - the chain walked right through them. None of these bugs are new. Each has textbook mitigations. But nobody tests what happens when old web bugs compose with AI behaviors - web teams and AI teams don't test each other's seams. We break down the full chain, demo it live, and hand you a methodology for hunting composition bugs across AI-integrated platforms.

Speakers:Dolev Taler,Mark Vaitsman

SpeakerBio:  Dolev Taler, Varonis

Dolev Taler is a senior security researcher at Varonis Threat Labs with over a decade of cybersecurity experience spanning red teaming, reverse engineering, vulnerability research, and malware analysis. He is passionate about machine learning and its pivotal role in modern threat detection, having developed advanced detection models, investigated ransomware attacks for major global enterprises, and reported vulnerabilities in critical infrastructure systems. Beyond tackling high-stakes cyber threats, Dolev also enjoys perfecting the art of coffee brewing and improving his lock-picking skills.

SpeakerBio:  Mark Vaitsman, Varonis

Mark Vaitsman is a Security Research Team Leader at Varonis, a leader in Data Security. He is a passionate cybersecurity expert with extensive experience in leading security threat and research teams in various Cyber Security companies, analyzing emerging threats, incident response and developing innovative solutions. Mark is also a lecturer of Cyber Security courses, sharing his knowledge and shaping the next generation of cybersecurity professionals. Previously spoken at BlackHat, DeepSec, RSAC, CrestCon. In his free time he likes sailing in the sea and riding a motorcycle.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 14:15-14:45 PDT


Title: Day in the Life - Green Beret to AI Penetration Tester
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 14:15 - 14:45 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

This session is an open on building a career in offensive security, from unconventional beginnings to breaking AI systems at a major tech company.

The speaker will share a candid look at his journey from U.S. Army Special Forces to national-level cyber operations and now AI penetration testing highlighting what actually mattered, what didn’t, and how skills from completely different fields translate into high-end offensive security roles.

Topics will range from breaking into cybersecurity with no experience, navigating certifications and degrees, and building real-world skills through CTFs and labs to what it’s like to hack AI systems, how those attacks work in practice, and where the field is heading.

SpeakerBio:  Clayton Boozell
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 21:00-00:59 PDT


Title: Day of the Dead Hacker Party
Tags: Party
When: Friday, Aug 7, 21:00 - 00:59 PDT
Where: LVCCW Level 3 W327 (Misc Meeting Room) - Map

Description:

Join us as we celebrate the lives, legends, and lasting influence of the hackers who shaped our world. From pioneers of the underground to cultural icons of the digital frontier whose stories still echo through the system.

Dress in Day of the Dead attire or come as a ghost of hacker culture, dead heroes, legendary coders, digital outlaws, and spirits of the machine.

Music by CURZE$ and special guest DJs.

Everyone is welcome to join us and celebrate the dead, the code, and the culture that refuses to die.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 12:10-12:20 PDT


Title: DC Maker's Community Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 12:10 - 12:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting DC Maker's Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DC Maker's Community and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: DC's Next Top Threat Model
Tags: DC's Next Top Threat Model | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 102 (DC's Next Top Threat Model) - Map

Description:

Threat Modeling is arguably the single most important activity in an application security program and if performed early can identify a wide range of potential flaws before a single line of code has been written. While being so critically important there is no single correct way to perform Threat Modeling, many techniques, methodologies and/or tools exist.

As part of our challenge we will present contestants with the exact same design and compare the outputs they produce against a number of categories in order to identify a winner and crown DEF CON’s Next Top Threat Model(er).

Participant Prerequisites

A laptop is recommended, a smartphone could be used but will be less than idea. Internet access to retrieve the design materials and to submit findings and access to the email used during registration.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:30-12:59 PDT


Title: DC101
Tags: DEF CON Official Talk
When: Friday, Aug 7, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:
Speakers:Nikita Kronenberg,Michael “sparky” Moore,polybius

SpeakerBio:  Nikita Kronenberg
No BIO available
SpeakerBio:  Michael “sparky” Moore, Lead, Network Operations Center at DEF CON

Michael Moore “sparky” somehow convinced people to let him run the DEF CON Network Operations Center, where he leads the team responsible for building and operating the network that thousands of attendees immediately try to break. With more than 20 years with DEF CON, project management, and technical leadership, he’s learned that every impossible deadline is just another networking problem with better marketing. He’s still waiting for the year everything works exactly as planned.

SpeakerBio:  polybius, Global Village Lead at DEF CON Communications

¯_(ツ)_/¯


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: DCNextGen - Bricks in the Air
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft's control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required - all target devices, materials, and interfaces are provided!

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

RIC-1, tail number N3VR-G0N, has gone down! You need to use radio direction-finding (RDF) techniques to locate Emergency Locator Transmitter (ELT), report its position, and help rescue our missing pilot!

Participants will use the provided handheld DF equipment provided by the Village, or bring your own, to triangulate the hidden transmitter location within the village area. Your handheld radio must be capable of receiving on the designated frequency with a directional antenna or attenuator. Once you've located RIC-1, listen closely... you may recognize the beacon's "distress tone." It appears to be broadcasting an audio payload that responders have described as "oddly catchy" and "impossible to stop once you start listening." Bring your comfortable shoes and strong will to ensure you never give up until you find our missing pilot!

No prior RDF experience required - volunteers can walk you through basic triangulation techniques before you start this 15-30 minute event.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

The MOUSE-1 satellite is currently in Safe Mode, and its attitude and heading systems are behaving unexpectedly. Ground control needs answers NOW!

You are a newly assigned Mission Specialist, and it's your job to figure out what's going on. Work through five sequential challenge missions aboard a simulated HUD - complete with live orbital tracking, optical camera feeds, and attitude telemetry - to triage MOUSE-1, uncover what happened, and make it operational again.

Participants will learn how satellites operate, how they stay secure in orbit, and what happens when they don't - using a fully browser-based, gamified interface developed by California Polytechnic State University students.

Just grab a seat in front of the provided station, no prior cybersecurity or aerospace experience required! Each mission is self-guided with built-in instructions, and volunteers are available to assist. Both beginner and experienced participants will find this 30-minute event challenging and fun.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Friday - 10:30-11:30 PDT


Title: DCNextGen Opening Ceremonies
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Friday, Aug 7, 10:30 - 11:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Come pick up your DCNextGen electronic badge and swag! Get a preview of all the upcoming activities and adventures. We'll also show you how to use your new badge in order to participate in all of our cool ctf challenges around the conference!

SpeakerBio:  BiaSciLab
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 12:50-12:59 PDT


Title: DDoS Community Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 12:50 - 12:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting DDoS Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DDoS Community and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Friday - 10:00-17:59 PDT


Title: DDV open and accepting drives for duplication
Tags: Data Duplication Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:
We start taking drives at 4: 00pm local time on Thursday - possibly a little earlier. We'll keep accepting drives until we reach capacity (usually late Friday or early Saturday).  Then we copy and copy all the things until we just can't copy any more - first come, first served. Note that some sources require 8TB drives now.  We run around the clock until we run out of time on Sunday morning with the last possible pickup being before 11:00am on Sunday.

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 10:30-12:59 PDT


Title: De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS
Tags: La Villa Community | Creator Workshop
When: Friday, Aug 7, 10:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map

Description:

Demostrar cómo las relaciones de confianza entre entornos híbridos de Azure DevOps, Microsoft Azure, Active Directory, Amazon Web Services y Kubernetes pueden ser abusadas por un atacante para realizar movimientos laterales, escalamiento de privilegios y compromiso de identidades utilizando herramientas y funcionalidades legítimas de administración cloud en infraestructuras hibridas corporativas.

Speakers:Juan Camilo Palacio Arango,Andrés Restrepo

SpeakerBio:  Juan Camilo Palacio Arango, Un token, una confianza, una cadena de compromiso.

Juan Camilo Palacio

Suboficial retirado de la Fuerza Aérea Colombiana, con sólida formación en Ingeniería de Sistemas y un Máster en Ciberseguridad y Privacidad. A lo largo de los últimos 7 años, he perfeccionado y especializado mis habilidades en diversas áreas de la Ciberseguridad, Ciberdefensa y Ciberinteligencia, aplicando con éxito mis conocimientos en los sectores de defensa nacional y financiero.

Mi compromiso con la actualización constante de técnicas se evidencia en la obtención de certificaciones destacadas en técnicas de ethical hacking y red teaming, tales como OSEP, OSCP, CRTO, ARTE, CRTE, entre otras. Estas certificaciones expresan mi dedicación continua a la mejora de mis habilidades y destacan mi capacidad para enfrentar desafíos complejos en el dinámico campo de la ciberseguridad.

Andres Restrepo Gonzalez

Profesional de ciberseguridad especializado en Red Team y seguridad ofensiva en entornos multicloud. Cuenta con certificaciones avanzadas en AWS, Azure y operaciones de Red Team, incluyendo OSCP, CRTE, CRTP, CARTS, CCPenX-AWS y MCRTA, entre otras. Su trabajo se enfoca en la simulación de adversarios, pentesting de infraestructuras cloud y evaluación de la resiliencia de organizaciones frente a amenazas avanzadas.

SpeakerBio:  Andrés Restrepo, Hacker

Entusiasta de la seguridad con experiencia en actividades de RedTeam


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 15:00-15:59 PDT


Title: Dear Red Team, Love Blue Team: Pulling Both Screaming Parties into Purple
Tags: The Diana Initiative | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

While purple teaming isn’t a new concept, getting purple teaming actually started and happening consistently is tough! Maybe your company or team experienced the one purple team event, then before you know it was back to red vs blue? Or maybe your purple team just never happened? Join Allie as she discusses her experiences with this struggle - where she dealt with only taking red team reports to make the blue team better, to finally getting them to collaborate and improve both teams!

SpeakerBio:  Allie

Allie is a Senior Security Analyst with eight years of combined experience across systems administration, networking, and cybersecurity. She has previously presented work about threat hunting nation state actors targeting the open-source software ecosystem. She spends her days hunting threat actors and leading incident response investigations. Outside of work, she enjoys camping, spending time with her dog, and her kids, who rank somewhere between "favorite humans" and "active incident response scenario" depending on the day.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Deep Dive into the Dark Web
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W221 (Training) - Map

Description:
SpeakerBio:  Robert "pwcrack" Weiss
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Deep Dive into the Dark Web
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W221 (Training) - Map

Description:
SpeakerBio:  Robert "pwcrack" Weiss
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 15:00-15:45 PDT


Title: Deepfake Detection Through Adversarial Research
Tags: Payment Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Deepfake defense is no longer just a matter of classifying media as real or fake. As attackers adopt new generators, optimize them for specific targets, and automate feedback-driven attack loops, the threat is evolving into agentic fraud. This talk presents an adversarial research approach to defending live identity-verification systems: continuously simulating realistic attacks, generating and evaluating domain-specific synthetic media, turning detector failures into new evaluation data, monitoring emerging tools, and rapidly adapting to unseen generators without overfitting to the latest attack. Ultimately, effective defense requires treating deepfake detection not as a static model-building task, but as a continuously evolving adversarial process in which success is measured by resilience against the next attack, not performance on the last one. We'll extend these concepts in the village through a hands-on challenge, inviting participants to evaluate a blind synthetic-data discrimination task, which illustrates the practical challenges of evaluating increasingly capable adversarials.

SpeakerBio:  Efim Boieru, Senior Manager of ML Engineering, Incode Technologies

10+ years in applied AI, computer vision and biometric security, focused on face liveness and deepfake detection; previously in ML research/engineering roles at Huawei and Bosch.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 12:00-12:10 PDT


Title: DEF CON Academy Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 12:00 - 12:10 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting DEF CON Academy but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DEF CON Academy and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 14:00-14:59 PDT


Title: DEF CON Beard and Mustache Contest
Tags: DEF CON Beard and Mustache Contest | Contest
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

The DC Beard and Mustache Contest has been held every year since DEF CON 19 in 2011 (R.I.P. Riviera), (Except during that COVID thing - but we are not going to talk about that COVID thing), the DEF CON Beard and Mustache Contest highlights the intersection of facial hair and hacker culture.

Participant Prerequisites

For 2025 offering 4 categories for the competition - You may only enter one category.

This is an in-person contest - you must be present to participate.

Full beard: Self-explanatory, for the truly bearded.

Partial Beard: For those sporting Van Dykes, Goatees, Mutton Chops, and other partial beard styles.

Mustache only: Judging on the mustache only, even if bearded. Bring your Handlebars, Fu Manchus, or whatever adorns your upper lip.

Freestyle: Anything goes, including fake and creatively adorned beards. Creative women often do well in the Freestyle category.

Timing

Setup begins 1 hour before the event, on the Contest Stage.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: DEF CON CTF: Benevolent Bureau of Birds
Tags: DEF CON CTF: Benevolent Bureau of Birds | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds) - Map

Description:

We are the Benevolent Bureau of Birds (BBB), formulated from previous victors of past DEF CON CTF contests. We are dedicated to the ethos at the core of CTF: community, skill-building, and showing off insane new hacking talent.

Participant Prerequisites

Players will have to be qualified by an online qualifer to take place in May. Chosen players are then required to have a laptop to participate in the in-person contest, to interact with the scoreboard and challenges hosted on network.

Pre-Qualification

Yes - online pre-qualifier in May 22-24, 2026.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 13:20-13:30 PDT


Title: DEF CON Groups (DCG) Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 13:20 - 13:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting DEF CON Groups (DCG) but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DEF CON Groups (DCG) and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Friday - 10:00-17:59 PDT


Title: DEF CON Groups (DCG)
Tags: DEF CON Groups | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

DEF CON Groups are the year round, local communities that bring the DEF CON spirit home. Run by volunteers around the world, DCGs create spaces where hackers meet, learn, collaborate, and build community outside of conference season.

The DEF CON Groups community space brings together Points of Contact, members, and prospective members to collaborate, share ideas, and learn from one another. Through informal workshops and hands on interaction, participants exchange practical lessons on building, sustaining, and evolving local hacker communities.

The space also serves as a social anchor. A relaxed place to reconnect with old friends, meet new ones, and participate in light interactive activities that reflect the collaborative nature of hacking culture.

DEF CON has always been the island of misfit toys we all return to once a year. DEF CON Groups are how that ethos survives the other fifty one weeks.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: DEF CON Groups Backdoors & Breaches
Tags: DEF CON Groups | DEF CON Groups Backdoor & Breaches | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

Tournament-Style Backdoors & Breaches Competitive – Live Incident Response Showdowns The DEF CON Groups Community is bringing live, bracket-style Backdoors & Breaches Competitive Games to DEF CON 34. Backdoors & Breaches is an incident response card game built around realistic breach scenarios. In our tournament format, teams step into the roles of adversaries, where they will take turns attacking or defending against each other. They must analyze scenarios, identify adversarial tactics, make technical and business decisions, and mitigate damage before attackers wipe them out of the game. This isn’t passive content. This is live, projected, real-time decision-making. Matches will be bracketed and displayed on screen so attendees can watch strategies unfold, debate choices, and learn from both brilliant plays and catastrophic missteps. Spectators become students of the game — observing how attacks progress, how defenders prioritize, and how communication and leadership shape outcomes. Participants can: • Join the tournament on the spot — no pre-qualifiers required • Compete in structured brackets • Win donated swag • Learn incident response by doing, not just listening What will you learn? You’ll see how modern attacks move from initial access to impact. You’ll experience the tension of limited funding. You’ll learn how small decisions compound during an incident. You’ll understand how legal, executive, and technical perspectives collide in a breach scenario. Most importantly, you’ll build intuition for thinking like both attackers and defenders. This is hacking culture through simulation: adversary thinking, defensive strategy, rapid analysis, and creative problem solving — all wrapped in competition. Located inside the DCG Community space, the tournament creates visible energy and draws attendees into a broader ecosystem of DEF CON Groups, workshops, sticker contests, and community collaboration. If you’ve ever wanted to see incident response as a spectator sport — or test your instincts under pressure — pull up a chair.

Speakers:Tim Doerges,Seth Benning

SpeakerBio:  Tim Doerges, Lead Developer | Backdoors & Breaches at Black Hills Information Security

Tim Doerges is the Lead Developer for Backdoors & Breaches at Black Hills Information Security and will facilitate the live tournament-style matches at DEF CON 34.

SpeakerBio:  Seth Benning, Product Developer at Black Hills Information Security

Seth Benning is an Assistant Conference Coordinator and Product Developer with Wild West Hackin' Fest and Black Hills Information Security. He will help facilitate the Backdoors & Breaches tournament at DEF CON 34.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: DEF CON Groups Sticker Contest
Tags: DEF CON Groups | DEF CON Groups Sticker Contest | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

The DCG Sticker Contest is a sticker design contest withwinner by popular vote and voting happening during DEF CON 34.

Anyone can submit original, human-created sticker designs prior to DEF CON 34. During DC34 attendees view all entries on site, and vote in person for their favorites. Designs will be displayed in the DEF CON Groups Community space throughout the conference, with voting open on Thursday to Saturday and the winning design announced on Sunday.

Stickers are hacker currency. This contest is about celebrating that culture through creativity, participation, and community choice. The top designs go through to the voting round. What wins is what the DEF CON community votes for.

Whether you want to support fellow hackers, or help decide the winning design, this is your chance to participate directly.

Participant Prerequisites

For designers / contributors: - Original sticker artwork created by a human (no AI-generated art) - You may design it yourself or work with a human graphic designer - Ability to submit artwork digitally prior to DEF CON - No specialized technical knowledge required

For voters: - Attendance at DEF CON - Ability to view entries in person and cast a vote - Voting is honor-based: one human, one vote - Participants may vote

No special hardware, software, or prior experience is required to participate or vote.

Pre-Qualification

A call for sticker designs will open prior to DEF CON with the contest and voting happening on-site.

Activity schedule: Thursday setup and preview; Friday and Saturday active voting; contest winner announced Sunday on the Contest Stage. See the Hacker Tracker Contest Stage entry for announcement details.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: DEF CON Scavenger Hunt
Tags: DEF CON Scavenger Hunt | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt) - Map

Description:

Whether you're a seasoned DEF CON veteran or a curious newcomer, the DEF CON Scavenger Hunt promises to challenge your skills, tickle your wits, and ignite your hacker spirit. Our list is a portal to mystery, mischief, and mayhem. Assemble your team of up to 5 members, interpret the items, and submit your efforts at the booth to our esteemed judges. Go beyond the basics for bonus points. Legends are born here.

The DEF CON Scavenger Hunt is open to everyone, regardless of skill level or experience, no pre-qualifying necessary. We strive to maintain the balance of a low barrier to entry while providing a challenge that many are eager to take on. Casual players should not be overwhelmed by the list, find a handful of items and have fun. If you are looking to win however, you will need to fully immerse yourself in the DEF CON Scavenger Hunt. Let's make some memories together.

Remember that it's not just about fame, glory, or boxes of swag; the true allure is the camaraderie of fellow hackers, the knowledge that you've etched your mark on DEF CON history, and the ultimate badge of honor: bragging rights. Nothing says "I'm a hacker" quite like being triumphant at the DEF CON Scavenger Hunt.

Participant Prerequisites

No, we work very hard to maintain a very low barrier to entry. If anything is required for an item, they should be able to find a fellow hacker with it that would be willing to assist them with their item.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 06:00-07:59 PDT


Title: Defcon.run
Tags: Event
When: Friday, Aug 7, 06:00 - 07:59 PDT
Where: LVCCW Level 1 North Entrance - Map

Description:

Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances.

For DEF CON 34, meet at "The Spot" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype.

Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 14:30-15:15 PDT


Title: Defend zee clankers: OWASP AI Security Verification Standard (AISVS)
Tags: OWASP Foundation | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 15:15 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

AI systems face threats that traditional application security standards weren't built to address. This includes prompt injection, training data poisoning, model extraction, agentic autonomy risks, and more. The OWASP AI Security Verification Standard (AISVS) provides 400+ testable requirements across 14 chapters, covering everything from input validation and model lifecycle management to MCP protocol security and autonomous agent controls. This lightning talk introduces the standard's structure, its three verification levels, and how security teams can use it today to assess and harden AI-powered applications. We'll show where AISVS fits alongside existing frameworks like ASVS, NIST AI RMF, and ISO 42001 and where it deliberately doesn't overlap.

SpeakerBio:  Jim Manico, Founder at Manicode Security

Jim Manico is the founder of Manicode Security, where he specializes in training software developers on secure coding and security engineering. He is actively involved in multiple ventures, serving as an investor/advisor for companies like 10Security, MergeBase, Nucleus Security, KSOC, and Inspectiv, among others. Jim is a recognized speaker, focusing on secure software practices, and holds a distinguished position as a member of the Java Champion community. He is also the esteemed author of "Iron-Clad Java: Building Secure Web Applications" published by Oracle Press.

Additionally, Jim generously volunteers for the OWASP foundation, co-leading key projects such as the OWASP Application Security Verification Standard and the OWASP Cheatsheet Series.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 16:00-16:59 PDT


Title: Defense in Depth for AI: Launching the AISECA Framework
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

Every week brings a new agentic AI attack and a new point solution that claims to stop it. None of them stop all of it, because agents do not have one attack surface, they have many, spread across the skills they load, the tools they call, the data they touch, and the humans who approve them. This talk introduces the AISECA Tiered Control Framework, an open, community-built model for defending agentic workflows the way we defend everything else that matters: in depth, in layers, with no single control carrying the whole load. We walk the framework end to end, then go deep on one control to show how it works in practice, what it catches, what it misses, and how it composes with the controls around it. You will leave with a shared vocabulary for agentic risk and a practical way to find the gaps in your own stack. Built in the open by practitioners, free to adopt, and yours to extend.

Speakers:Amber Bennoui,Karol Piekarski

SpeakerBio:  Amber Bennoui
No BIO available
SpeakerBio:  Karol Piekarski, DevOps Engineer

Karol Piekarski is a Lead DevOps Engineer working across cloud infrastructure, zero-trust architecture, and AI and agentic security for systems that serve hundreds of millions of consumers. His research focuses on the security of large language models and autonomous agents, with an emphasis on practical red-teaming and defensive tooling that teams can actually operationalize rather than shelve.

His empirical work on abliteration and agentic framing reframes where alignment actually breaks down in agent pipelines: agentic framing alone can collapse a model's baseline safety, while abliteration matters mostly for the hardest content and is highly architecture-dependent. In 2026 he co-presented "Move Fast, Stay Secure: Enterprise AI Agent Security in Practice" at the Databricks Data + AI Summit, and spoke at SCaLE 23x on open source red-teaming for LLMs. He was one of only two external contributors to the Databricks Agentic AI Security Framework (DASF v3.0).

Karol is the creator of Sundew.sh, an open source, MCP-native AI agent honeypot platform that uses behavioral fingerprinting and a persona engine for anti-fingerprinting, now adopted by external research teams studying agent behavior in the wild. He was selected as a Wiz MVP last year and this year received Wiz's Thought Leader award, and he is active in the AISECA Working Group, where he co-owns agentic security risk definitions.

He holds the CCSP, CKA, four AWS specialty certifications along with DataDog and Tines, and he regularly judges and mentors at hackathons across Southern California.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 11:30-12:30 PDT


Title: Demodus Operandi (Cómo tres rf-hacks en tres bandas terminaron siendo una metodología)
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Hay muchas herramientas para hackear RF y mucho conocimiento regado en talks, repos y la cabeza de la gente. Lo que no hay es un mapa. Cuando te paras frente a un dispositivo o señal, ¿por dónde empiezas? ¿y cómo sabes qué se te escapó?

Esta charla cubre tres investigaciones reales, cada una en una tecnologia distinta.

Primero BLE, sniffeando advertising packets terminé auditando una sala y encontré 6 de 85 dispositivos completamente controlables, incluso con LE Secure Connections habilitado.

Después LoRaWAN, capturé 51,304 frames en US915. El 89.3% eran JoinRequests: una red entera fallando en unirse, visible sin transmitir un solo paquete, red que no podia encontrar con un SDR.

Y al final LTE — encontrar la celda correcta en México, entender el OFDM, y extraer metadatos en pasivo.

Tres casos, tres analisis distintos. Pero siempre sobre las mismas capas: espectro → señal → enlace → cripto → ataque.

Ya seguía una metodología, solo no la había nombrado.

Así nació RFSAM (Radio Frequency Security Assessment Methodology): una referencia abierta, estructurada, que organiza lo que OSSTMM, BSAM y la comunidad SDR ya construyeron, en algo que puedes navegar. No pretende inventar nada, pretende ser un mapa.

https://electroniccats.github.io/RFSAM/

SpeakerBio:  Eduardo Contreras, CTO

Electronics Engineer, passionate about technological development

and science, co-founder and CTO of the Electronic Cats company which has developed different embedded systems already in production, focused from education to security related devices, embedded programer, has developed open source libraries for communities as well as open hardware, with the goal to design and implement global impact electronics.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 16:00-16:45 PDT


Title: DFMI: Weaponizing MSI Installers for Fileless Code Execution
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

DFMI is a cross-platform, open-source offensive toolkit that hijacks & abuses the Windows Installer's own execution engine to detonate arbitrary payloads during software installation, with zero files written to disk and zero evidence left behind. And this can be achieved without corrupting the Authenticode of the binary. --Which means, ANY signed legitimate installer file can leveraged as an attack vector.

Right now, DFMI provides 3 different methods for abusing MSI files:

GitHub: https://github.com/ccelikanil/DFMI

SpeakerBio:  Anil Celik

Computer Engineer & been working as a Red Teamer for the past ~7 years. Previously did presentations at DEFCON 33 Demo Labs, DEFCON 33 Red Team Village & Black Hat USA Arsenal 2025. Currently holding 6 CVEs, OSCP & OSWP.

Interests: Windows Internals & AD Security


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Friday - 12:00-12:59 PDT


Title: Digital Forensics 101
Tags: Blue Team Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

Forensics 101 is a fast-paced, story-driven primer on digital investigations—perfect for incident-response newcomers and seasoned blue-teamers alike. In under 45 minutes we trace the full evidence lifecycle: imaging disks and cloud buckets, teasing meaning from volatile memory, and translating binary breadcrumbs into courtroom-ready narratives. First, we demystify the tools and techniques behind solid acquisition and analysis; next, we zoom out to the real-world team dynamics, reporting pitfalls, and career launchpads that turn analysts into trusted advisors. Expect war stories, practical tips you can use on Monday, and zero certification flexing—just the art, science, and occasional 2 a.m. data-center comedy of modern digital forensics.

SpeakerBio:  Sarthak Taneja

Started from Offensive Security and ended up in Defense. Wearing Purple hat most of the days.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Friday - 08:30-17:30 PDT


Title: Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk
Tags: DEF CON Training (Paid) (1-day) | DEF CON Training
When: Friday, Aug 7, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W224 (Training) - Map

Description:
Speakers:Anant Shrivastava,Sunil Yadav

SpeakerBio:  Anant Shrivastava

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

SpeakerBio:  Sunil Yadav
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: Discover GE Appliances!
Tags: IoT Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances!


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 12:30-13:15 PDT


Title: Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM
Tags: IoT Village | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 13:15 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

An AI agent found a previously undisclosed vulnerability in a named vendor's IoT product within hours of being pointed at the firmware. The practitioner who built the agent had spent 25+ years doing that work by hand. Plan R is an IoT-focused MCP server that gives AI agents direct access to real pentesting tools, structured by playbooks that encode methodology rather than scripts. The framework expanded from firmware-only analysis to a multi-domain suite covering WiFi, BLE, network protocols, and hardware interfaces, with each domain compounding the value of every other through cross-domain correlation. The centerpiece is a real engagement: a named vendor, a disclosed vulnerability, and the specific challenge of convincing a white box vendor that a finding is real when the methodology that found it is "an LLM read your code." Attendees leave with a working blueprint for building their own AI pentesting agents, an honest account of where the approach breaks, and a direct answer to the question every experienced practitioner is quietly asking: if an AI can do this, what exactly am I bringing to an engagement? The answer is worth hearing. But the work is changing, and this community should be driving how.

SpeakerBio:  Larry Pesce
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Friday - 13:45-14:15 PDT


Title: Drag, Drop, Deploy, Compromise: Why Trusted HMI Engineering Toolchains Remain an ICS Supply-Chain Blind Spot
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 13:45 - 14:15 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

HMI engineering tools are trusted gateways into industrial environments. Engineers use these tools to design screens, configure tags, connect to controllers, and deploy projects to real-world sites. HMIs are used across manufacturing, logistics, maritime, energy, utilities, building automation, and many other industrial sectors. Yet the engineering tools and project files used to create them are often treated as simple work utilities.

This presentation analyzes multiple vulnerabilities discovered in the HMI engineering toolchain from a supply chain perspective. It covers memory corruption during project file parsing, DLL search path hijacking, the loading of unsigned components, UI spoofing through silent font installation, and fallback to plaintext policies when secure OPC UA connections fail.

The core argument is simple: the ICS supply chain does not begin only at a vendor’s update server. Project files received from customers, templates shared by system integrators, maintenance backups, local DLLs, fonts, communication settings, and the engineering workflow of “open, drag, and deploy” are all part of the supply chain.

This presentation shows that not only PLCs and HMI runtimes, but also the tools and files used to create them, are part of the attack surface.

Speakers:Jiwoon Yoo,TaeWoo Kim,Eunji choi

SpeakerBio:  Jiwoon Yoo, CYTUR Inc

CYTUR Inc. / Security Team Lead

Research Areas and Interests Maritime Cybersecurity, Satellite Security, Large Language Models, Adversarial Attacks Education and Professional Experience 2017: B.S. in Computer Science Engineering, Anyang University, Gyeonggi-do, South Korea 2023: M.S. in Convergence Security, Graduate School of Information Security, Korea University, Seoul, South Korea 2023 – Present: Security Team Lead, CYTUR Inc.

Academic Activities Symposium Participation * Nov 13–14, 2024: Participated in CFP-selected research at the IMO Maritime Cybersecurity Symposium (United Nations), London, UK

Journal Publication Sensors (May 24, 2023) — First author: Formulating Cybersecurity Requirements for Autonomous Ships Using the SQUARE Methodology https://doi.org/10.3390/s23115033

Sensors (Feb 26, 2022) — First author: Cyberattack Models for Ship Equipment Based on the MITRE ATT&CK Framework https://doi.org/10.3390/s22051860

SpeakerBio:  TaeWoo Kim, CYTUR Inc
No BIO available
SpeakerBio:  Eunji choi, CYTUR Inc
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Friday - 11:00-11:59 PDT


Title: Drive Stats: 14 years of hard drive failure rates
Tags: Data Duplication Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:

For over 14 years, Backblaze has been collecting the failure rates of hard drives in our data centers. But, what does that even mean? How do you define a failure, and how does that definition define or obscure the realities of drive performance?

SpeakerBio:  Stephanie Doyle, Sr. Manager and Keeper of Stats at Backblaze

Stephanie Doyle is a Sr. Manager at Backblaze and known as the Keeper of Stats. She oversees the various first party data reports including Drive Stats, which reports on the failure rates of hard drives in Backblaze data centers; Network Stats, which reports on network traffic into and out of Backblaze's network; and Performance Stats, which publishes quarterly testing on cloud storage benchmarks. She specializes in taking complex topics and writing relatable, engaging, and user-friendly content. You can most often find her reading in public places, and can connect with her on LinkedIn.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 12:45-13:45 PDT


Title: Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 12:45 - 13:45 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Drogonsec is an open-source, high-performance security scanner built for developers and CI/CD pipelines. In a single run, it combines four analysis engines: SAST for 20+ languages, SCA for dependency CVEs, secret detection with 50+ patterns (AWS, GCP, GitHub, JWTs, SSH keys), and IaC misconfiguration analysis for Terraform and Kubernetes, all mapped to OWASP Top 10:2025 and CWE, with CVSS 3.1 scoring and SARIF output for GitHub and Azure DevOps integration.

This Arsenal session will demo Drogonsec scanning real-world repositories live, showing findings across all four engines, explaining rule design decisions, and showcasing how teams can extend it with custom YAML rules. Attendees leave with a running tool they can drop into their pipelines the same day.

SpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I'm Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0 Black Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires DEF CON 33 / 32 - https://sessionize.com/filipi-pires/ DEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Drone Hacking Choose your Own Adventure
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Dive into our interactive choose-your-own-adventure web interface and learn how to hack a drone in a fun, storyboard-based game. This graphical user interface simulates the process we use when hacking drones for the Air Force, allowing participants to make decisions and see the outcomes.

It's a beginner-friendly, 15-30 minute activity offering insights into the steps involved in drone penetration testing.

Participants can access it from their own computers or mobile phones.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Drone Hacking Workshop
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Join our Drone Hacking Workshop for hands-on experience hacking drone components. This three-step in-depth activity is designed to teach you about the vulnerabilities and security of autonomous systems. Using sample drones, participants will learn techniques used in government pen tests.

This 2-3 hour workshop suits all skill levels, from beginners to advanced hackers. Come and test your skills in a real-world scenario and understand the intricacies of drone security.

Participants need to bring a laptop capable of running a Linux distribution.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 15:00-15:30 PDT


Title: Drones, Detectors, and the Kill Chain
Tags: Aerospace Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Counter-Unmanned Aircraft Systems (C-UAS) is a domain spanning RF engineering, federal law, operational security, and public policy, and it's being built right now by people working without a complete picture. Most security practitioners and nearly all civilians don't know how drone detection works, what the legal framework for defeating drones is, who's authorized to do what and why, or how badly the current technical stack can be defeated with a microcontroller. Drawing on direct operational experience at SEAR 1 National Special Security Events (the highest domestic security classification in the United States), this presentation walks through the complete C-UAS stack from first principles, grounded in real operational data rather than vendor marketing.

SpeakerBio:  Greg Albrecht
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 15:00-15:30 PDT


Title: El regreso de Sedinho: situación actual y nuevas tácticas de los troyanos bancarios brasileños
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Esta investigación analiza la evolución reciente de los troyanos bancarios brasileños y su expansión internacional, así como las acciones de las autoridades para frenarlos. Se examinan campañas actuales impulsadas por ciberdelincuentes latinoamericanos que no solo perfeccionan el malware bancario tradicional, sino que también incorporan fraudes móviles basados en tecnología NFC.

SpeakerBio:  Josep Albors, Head of Awarenes & Research at Ontinet.com (ESET Spain)

Josep Albors is the Head of Awareness & Research at Ontinet.com (ESET Spain). He's a security expert with more than 21 years working in cybersecurity and specialized in security awareness. He is also the editor at the company's blog and one of the experts writing at several other publications related with the IT security world in Spain.

He has been a speaker at some of the most important security conferences in Spain, besides collaborating with initiatives such as X1RedMasSegura, that wants to raise awareness among users so they can use Internet and technology in a safe way. Included in Ontinet's social responsability, Josep also does awareness and cybersecurity presentations in schools and universities. He's also a teacher in cyber security expert courses at several Spanish Universities and participates in several conferences organized by several spanish universities and Spain's national Institute of Cyber Security. He also participated as speaker at AVAR conference in Osaka in 2019, Caro Workshop 2023 in Bochum (Germany), FIRST 2024 (Fukuoka), Virus Bulletin 2024 (Dublín), Defcon Malware Village (2025), JSAC 2025 (Tokyo) and CARO 2026 (Innsbruck).

Josep has also collaborated with the Spanish Guardia Civil, Spanish National Police and the Spanish Army, teaching their units on how to fight cybercrime and with cyber intelligence training, contributing with his experience in analyzing cybercrime and malware.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 10:00-10:30 PDT


Title: Election Integrity and Technology
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

This talk will give an overview of the technology used in US elections, the security vulnerabilities that can compromise elections, and approaches for making elections more secure and robust.

SpeakerBio:  Matt Blaze

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 12:00-12:59 PDT


Title: Election Security in the Age of AI: Governance, Trust, and the Systems Behind Democracy
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

Election security is often framed as a technology problem. In reality, it’s a governance problem operating inside a highly stressed public system. This session brings together leaders who were inside that system during the most scrutinized election cycles in modern U.S. history, moderated by an elections policy expert who has shaped how platforms handle political content at global scale. Tim Harper, Project Lead for Elections and Democracy at the Center for Technology and Democracy and former Content Policy Associate Manager for Political Advertising at Meta, will moderate. His work focuses on combating election disinformation, strengthening election integrity, and building public trust. Lester Godsey served as CISO for Maricopa County during the 2020 and 2024 presidential elections, leading cybersecurity in a jurisdiction under intense national scrutiny and multiple adversaries. Bill Gates served on the Maricopa County Board of Supervisors during that same period, overseeing election administration amid unprecedented political pressure, misinformation and reputational and physical threats. He now directs the Mechanics for Democracy Laboratory at Arizona State University. Together, they bring a rare perspective: cybersecurity, governance, and systems engineering at the front lines of democracy.

Speakers:Lester Godsey,William Gates,Tim Harper

SpeakerBio:  Lester Godsey, Arizona State University

Lester Godsey serves as the Chief Information Security Officer (CISO) for Arizona State University, the largest public university by enrollment in the United States. His appointment follows a distinguished five-year tenure as CISO for Maricopa County, where he skillfully managed information security during one of the most contentious election periods in the county's modern history. With over 30 years of public-sector IT experience, Lester is a respected voice in the field, having presented at local, state, and national levels on a diverse range of topics including telecommunications, data management, and cybersecurity. A lifelong learner and educator, Lester holds multiple industry certifications including PMP, CISM, and CISSP. He has shared his expertise as a collegiate instructor for almost fifteen years, teaching cybersecurity, technology, and project management courses. Lester is also a published author and actively contributes to the cybersecurity community. His academic background uniquely blends the arts and technology, holding both a Bachelor of Arts in Music and a Master of Science in Technology from Arizona State University. This multidisciplinary foundation informs his innovative approach to information security leadership.

SpeakerBio:  William Gates, Arizona State University

Bill Gates is Executive Director of the ASU Mechanics of Democracy Laboratory (MODL) and Professor of Practice at Arizona State University’s Watts College of Public Service and Community Solutions. He leads MODL’s efforts to professionalize election administration through practitioner-focused training, transparency initiatives, and the integration of emerging technologies. In 2025, he launched the AI + Elections Clinic to equip election officials nationwide with the tools and expertise to responsibly harness artificial intelligence in support of voter confidence and election integrity.

Bill previously served two terms on the Maricopa County Board of Supervisors (2017–2024), overseeing elections in one of the nation’s largest voting jurisdictions during the highly scrutinized 2020 and 2022 election cycles. He also served on the Phoenix City Council (2009–2016), including as Vice Mayor.

Bill is the recipient of various awards, commending his years of leadership, service, and defense of democracy including The American Bar Association’s Unsung Hero of Democracy Award in 2024, The Truman Foundation’s Joseph E. Stevens Public Service Award in 2022, The Arizona Republic’s 2021 Arizonan of the Year, and The Phoenix Business Journal’s Forty Under 40 in 2010.

SpeakerBio:  Tim Harper, Center for Technology and Democracy

Tim Harper is Project Lead for Elections and Democracy, where he leads efforts to combat election disinformation, support secure voting technologies, and strengthen public trust in elections. An elections policy expert, Tim has driven policy and advocacy across industry and civil society. Most recently, he served as Content Policy Associate Manager for Political Advertising at Meta, where he developed and implemented global policies governing electoral, political, and social issue advertising. His work focused on transparency, preventing foreign interference, and countering election delegitimization at scale. Previously, Tim was Senior Elections Policy Analyst at the Bipartisan Policy Center, where he led election administration policy development and federal and state advocacy efforts. He convened a bipartisan task force of election officials to inform policymaking and led major data-driven research initiatives, including the largest national study on voting line disparities. He began his career supporting election management bodies in the Middle East and North Africa with the International Foundation for Electoral Systems. He graduated magna cum laude from Gonzaga University with degrees in Political Science and History.


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Friday - 10:00-17:59 PDT


Title: Embedded - 101 Labs
Tags: Embedded Systems Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

We have a lab platform that brings everyone from every skill level to the same playing field with step by step instructions that aim to teach individuals specific techniques and skills in a hands-on manner on embedded hacking techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 10:00-17:59 PDT


Title: Embedded & Shredded: Advanced Embedded System Hacking
Tags: Biohacking Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map

Description:

This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities:


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Friday - 10:00-17:59 PDT


Title: Embedded Systems Village CTF
Tags: Embedded Systems Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

Get hands-on with devices you won't find anywhere else — rare, hard-to-source embedded devices staged for live exploitation. Hunt real zero-days, and yes, bring your AI: LLM-assisted tooling is fully allowed, so use it to go as deep as you can.

Come break something that's never been broken.

New to embedded? Just wrapped our 101 Labs? Beginner challenges are available as well to apply your new found knowledge!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 10:00-10:45 PDT


Title: Empire 7: Shipping a C2 at AI Speed
Tags: Intro/Beginner | AI | DEF CON Demo Labs | DevOps | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Empire 7 is a near-total overhaul of the Command and Control (C2) framework, from how agents communicate with the server to how operators move through engagements. This major release continues to expand Empire's supported agents to include PowerShell, Python, IronPython, Go, C#, and now C. New tradecraft includes more than 50 new modules derived from Atomic Red Team, patchless AMSI/ETW bypasses, EarlyBird process hollowing, BOF execution with ILRepack assembly merging, and RDP session hijacking, among others. Empire's new cryptographically secure communications leverage AES-256-GCM and mTLS, with MITRE ATT&CK integration to assist in emulating real-world Advanced Persistent Threat (APT) Tactics, Techniques, and Procedures (TTPs).

One more thing we'll talk about, this release shipped at roughly 10x our prior pace, due to our team’s adoption of agentic coding tools as a core development collaborator. We'll share what worked, what didn't, and what LLM-assisted offensive tooling development looks like.

Speakers:Vincent "Vinnybod" Rose,Jake "Hubbl3" Krasnov,Anthony "Coin" Rose

SpeakerBio:  Vincent "Vinnybod" Rose

Vincent "Vinnybod" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/.

SpeakerBio:  Jake "Hubbl3" Krasnov

Jake "Hubble" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON.

SpeakerBio:  Anthony "Coin" Rose

Dr. Anthony "Coin" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Escalation Desk CTF
Tags: Call Center Village | Escalation Desk CTF | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

Customer service channels are increasingly saturated with conversational text and voice AI agents. Can you convince, trick, or break enough of them to earn your shot at a live human operator in a real-world call center?

Escalation Desk is Call Center Village's capture-the-flag challenge. Start with low-pressure AI agents and learn how to spot, avoid, and exploit common pitfalls and patterns in system prompts — eventually unlocking live human operators at our partner call centers. A real-time leaderboard tracks solo and team progress, with our not-so-famous Golden Telephone Booth trophy awarded to the top participant.

Hit our minimum point threshold and earn a special Call Center Village 100 Trying black flight tag. The top individual and their team also take home the rare Call Center Village 200 OK gold flight tags. Bring your tags to Party Line, Call Center Village's after-hours telephony-themed party, and enjoy free refreshments for your spoils.

Escalation Desk is beginner (and introvert) friendly — if you can dial a phone number or use a keyboard, you can participate. Bring your own laptop and headset, or use one of our village stations. Active Noise-canceling headphones with a microphone are highly recommended.

The CTF will run during village hours, pausing when the village closes each night, and ends on Sunday at 12:00.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 15:00-15:30 PDT


Title: Everything is Nix when you squint hard enough
Tags: Nix Vegas Community | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

How I got started with NixOS and how it's going. I'll cover my homelab migration from ubuntu & docker to NixOS & Incus w/ NixOS containers. I'll also go over how a similar process is going at my $job, discussing packaging proprietary software into modules. I'll cover declarative hardware and software in both domains from an SRE point of view.

SpeakerBio:  Jared

I'm an SRE based in $location working for $job.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 14:00-14:45 PDT


Title: Evidence-Based Elections and Risk-Limiting Audits
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

Public trust in U.S. elections has been shaken by allegations that the 2020 presidential election was "stolen" or "rigged." While many specific claims about that election are technically incoherent or demonstrably false, it is true that the way elections are administered in the U.S.--including eligibility determinations, voting equipment, procedures, and audits--leaves room for rational doubt about whether the reported outcomes of U.S. elections are correct. Given the known vulnerabilities in voting systems, the shortcomings of election procedures in some jurisdictions, and examples of large errors in vote counts and insider malfeasance, to blithely and automatically accept reported results is naive. To deserve public trust, elections should be "evidence-based": conducted in a way that generates convincing public evidence that the reported outcome is correct. "Trust us" is not evidence. Evidence-based elections generally require demonstrably accurate eligibility determinations; recording votes primarily on hand-marked paper ballots; demonstrably secure chain of custody of voted ballots; a rigorous canvass to ensure that every validly cast ballot (and no others) was included; tabulation of the votes by hand or by machine; a compliance audit to ensure that the paper trail is trustworthy; and a properly designed, publicly confirmable audit of the reported results using the trustworthy paper trail. Conducting evidence-based elections requires avoiding the use of technology for purposes where outcome-altering malfunction or malfeasance could escape detection and correction, for instance, using electronic technology to record or transmit votes (e.g., paperless voting systems, touchscreen ballot-marking devices, cellular networks, or the Internet). Risk-limiting audits (RLAs) play an important role in evidence-based elections, providing affirmative evidence that the reported outcome is correct--or, with high probability, correcting the outcome if it is wrong. RLAs require a trustworthy paper trail. They cannot compensate for poor election administration, such as failing to keep track of voted ballots or using vulnerable technology to record or transmit votes.

SpeakerBio:  Philip Stark

Philip B. Stark is Distinguished Professor of the Graduate School at the University of California, Berkeley, where he has served as department chair and associate dean. In 2007 he invented "risk-limiting audits" ("RLAs"), endorsed by the National Academies of Science, Engineering, and Medicine and the American Statistical Association, among others, and required or authorized by law in about 15 states. He designed and helped conduct the first dozen pilot RLAs, helped draft RLA legislation for several states, and has published open-source software to support RLAs. In 2012, he and David Wagner introduced "evidence-based elections," a paradigm for conducting demonstrably trustworthy elections. Stark has served on the Board of Advisors of the US Election Assistance Commission and its cybersecurity subcommittee, the Board of Directors of Verified Voting Foundation and the Election Integrity Foundation, and on the California Post Election Audit Standards Working Group. He has worked with the Secretaries of State of California, Colorado, and New Hampshire and numerous local election officials. He has testified about election integrity in state and federal courts and to legislators. He received the IEEE Cybersecurity Award for Practice, the UC Berkeley Chancellor's Award for Research in the Public Interest, and the John Gideon Award for Election Integrity. He is a fellow of the American Academy of Arts and Sciences, the American Statistical Association, and the Institute of Physics.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 16:00-17:59 PDT


Title: EvilEssid: Evading Wireless Intrusion Prevention Systems
Tags: Red Team Village | Misc
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

What if a rogue access point could evade a Wireless Intrusion Prevention System (WIPS) while operating in plain sight?

In this hands-on tactic, participants will learn how EvilEssid, a wireless evasion technique, exploits weaknesses in how WIPS solutions identify, classify, and trust wireless networks. Rather than focusing solely on theory, attendees will actively build, configure, and operate EvilEssid in a controlled lab environment. Through a series of guided exercises, participants will gain practical experience deploying rogue access points, understanding WIPS detection logic, and applying wireless identity manipulation techniques to evade common defensive controls. The workshop will demonstrate how attackers can establish malicious wireless infrastructure that remains undetected while creating opportunities for credential harvesting, traffic interception, and adversary-in-the-middle operations. Attendees will use the EvilEssid tool to reproduce the attack chain step-by-step. Each exercise is designed to provide hands-on exposure to offensive wireless tradecraft while encouraging participants to experiment. Beyond the offensive techniques, the workshop will also explore defensive implications, helping participants understand the limitations of current WIPS technologies and identify practical approaches to improve wireless threat detection. By the end of the session, attendees will have deployed a rouge access point using EvilEssid themselves, validated successful WIPS evasion in a lab environment, and gained a deeper understanding of both the offensive and defensive aspects of advanced wireless operations.

Fundamentals • ESSID
• BSSID
• Deauthentication attacks • Evil Twin attack Understanding WIPS and Its Detection Models • What is a WIPS • How it works and detection techniques • Evil Twin attack vs WIPS Identifying the Weakness Advancing the Evil Twin Technique • Human targets • Crafting a WIPS-evasive Evil Twin EvilEssid tool: Design and Implementation • Overview • Key concepts behind the tool • Features and usage Conclusions and Countermeasures

SpeakerBio:  Miguel Fernandez

Colombian cybersecurity researcher based in China with over 15 years of experience in offensive security, penetration testing, and applied security research.

His work focuses on developing and validating novel attack and defense techniques, challenging existing security assumptions across areas such as wireless security, social engineering, and real-world adversarial methodologies.

He has presented at international conferences including Codegate, Overdrive, CIS, Xcon x Hacking group ,WAIC, Hackprove world, Tencent security saloon and multiple PRC cyber security meetups.

His research is grounded in the scientific method, emphasizing experimentation, reproducibility, and practical validation.


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Friday - 10:00-17:59 PDT


Title: Exploit Bluetooth Low Energy with BLESPloit and optional ESP32
Tags: Embedded Systems Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

Discover how easy it is to fingerprint and control nearby BLE devices with a tap on your phone - yes, including iPhone that gets BLE superpowers with with an external ESP32. Scan remotely, clone and simulate BLE devices, test a popular headset for known vulnerabilities (or perhaps uncover a new one?) and take control of a robotic dog. Already know some BLE? Crack open our smart safe and claim the BLESPloit hardware reward inside!

SpeakerBio:  Slawomir Jasek, BLESPlo.it

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups. Currently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks. Beyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them. Loves sharing his knowledge via trainings, workshops, talks and open source hackme's (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 18:00-19:59 PDT


Title: Exploit Your Own Story
Tags: Meetup | Memorial Chamber
When: Friday, Aug 7, 18:00 - 19:59 PDT
Where: LVCCW Level 3 W302 (Memorial Chamber) - Map

Description:

You've spent the con finding the thread that unravels a system. Come find the one in you.

I've spent 27 years planning DEF CON's logistics — audio, stages, coffee, all of it. Three years ago I started writing for the first time in decades, and it turned into something I never expected: work published in magazines, a book underway, and a doorway into what I can only call a mystical experience — the kind where the page starts telling you things you didn't know you knew.

Women's voices are at the center of this — we carry stories that go unheard far too often, and this is a room built to change that. And there are conscious men in this community whose words matter too, and who are welcome here.

This is an open space to talk about the path — publishing, books, or just the story you've never told anyone. Bring a story, bring a question, or just come listen.

No credentials required.

SpeakerBio:  Charel "1C0nur3r" Morris
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 11:00-11:59 PDT


Title: Exploiting Private 5G: Unauthenticated Access to Databases and Control Plane DoS via Fuzzing
Tags: Red Team Village | Misc
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map

Description:

Abstract—This presents an exhaustive empirical security analysis of a real-world private 5G network deployment, serving as a direct and explicit extension of our preceding research, ”Security Analysis of a Real-World Private 5G Network Deploy- ment through Pen Testing and Fuzzing.” While our initial study successfully identified control-plane weaknesses and performance degradation via protocol mutation, this continuation focuses on four critical, highly exploitable attack vectors. Specifically, we detail three severe data-layer attacks stemming from the unauthenticated internal network exposure of MongoDB (Port 27017), Elasticsearch (Port 9200), and Kibana (Port 5601). These exposures permitted the complete, unauthorized extraction of the network’s most sensitive cryptographic assets (including Permanent Keys and active session keys) and granted adversaries unauthorized manipulation of the security monitoring apparatus. Additionally, we introduce a newly discovered, critical Denial of Service (DoS) attack targeting the Access and Mobility Management Function (AMF) signaling interface on Port 11000, which leverages protocol fuzzing to induce memory corruption and permanently halt User Equipment (UE) registration. By synthesizing these empirical findings, this report provides a multi- layered analysis of the cascading failures that emerge when enterprise IT vulnerabilities intersect with mission-critical 5G telecommunications infrastructure.

SpeakerBio:  Aumkaareshwar DS

I am a Computer Science graduate student at California State Polytechnic University, Pomona, passionate about cybersecurity, network security, and ethical hacking. Currently, I work as a Research Assistant at PolySec Lab, where I focus on 5G network security, including authentication, subscriber identity protection, and threat mitigation. My research helps enhance mobile security and protect data from cyber threats.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: Expose Hidden Surveillance in Everyday Tech
Tags: IoT Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Join the Ludlow Institute Surveillance Mission. Dump firmware, capture packets, probe APIs, or tear devices apart however you like. Prizes up for grabs.


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Friday - 17:30-17:59 PDT


Title: Exposed Data Centers: Bypass IT Security, Crank Up the Heat
Tags: ICS Village | Creator Talk/Panel
When: Friday, Aug 7, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

As data center numbers are increasing in the US and around the world, they are becoming a source of tension politically, environmentally, and economically, and are becoming high-value critical infrastructure. The threats to these data centers will rise soon as activists, cybercriminals, and nation-states target them. Unlike what has been seen recently with kinetic attacks on data centers in conflict zones, cyberattacks have a larger range and can affect a wider population.

We wanted to explore unconventional threats against data centers. Using open-source intelligence and our patented (US12267344B1) geostalking techniques, we were able to map out data centers in the United States and overlay that with the exposed infrastructure that would directly be used in the operation of the data center itself. This includes building automation and energy supply as examples.

Afterwards, we were left with the locations of 1,063 data centers that had 6,300 high-confidence industrial control systems exposed to the internet. This information went through a five-layer filtering process to result in these high-confidence exposed systems, based on the banner responses received from these devices. Of these 6,300 devices, 964 devices (15.3%) have a CVSS score of 9.0 or above, and 88.7% of the entire dataset is inherently vulnerable due to the use of protocols that were never designed to be exposed to the internet.

Armed with this information, an attacker could circumvent even the best IT security with exposed systems that might directly or indirectly affect data center operations. In today’s geopolitical climate, exposed systems in near proximity to data centers are at higher risk of cyberattacks. Due to diverse applications across personal, corporate, or even government use, the repercussions of a data center outage will have effects far wider than just the data center itself.

Speakers:Stephen Hilt,Numaan Huq

SpeakerBio:  Stephen Hilt

Stephen J. Hilt is a seasoned threat researcher specializing in industrial control systems (ICS) security, cybercrime investigations, and advanced persistent threats. With extensive experience in uncovering complex attacks targeting critical infrastructure, he has contributed to numerous high-impact reports and global threat intelligence initiatives. Stephen’s work bridges deep technical expertise with strategic analysis, enabling organizations to better understand and defend against emerging cyber threats. His research has been presented at leading security conferences and published in widely respected industry reports, reflecting his commitment to advancing the security of interconnected systems worldwide.

SpeakerBio:  Numaan Huq
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 14:00-14:59 PDT


Title: Extension Hollowing: Abusing Chrome's Extension Trust Model
Tags: Red Team Village | Misc
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

Chrome controls over 65% of worldwide browser usage, with 100,000+ extensions on the Chrome Web Store. Enterprises rely on Chrome's built-in policies, such as extension allowlisting, WebStore integrity checks, and forced installed extensions to keep their endpoints clean. Those controls are broken. Extension Hollowing is a new technique that completely bypasses Chrome's integrity verification of WebStore extensions. By hollowing out a legitimate allowlisted extension and replacing or backdooring its internals, an attacker can silently deploy extension arbitrary code inside the browser, defeating allowlisting, bypassing signature checks, and inheriting the full permission set of the original extension (and extending it if desired). This talk will show how hollowed extensions can function as a fully capable C2 via a new Chrome extension mythic agent which will be released after this talk called Hades. Attendees will get to sit down and play with this c2 framework as well as embedding it into trusted extensions via extension hollowing. We will then walk through the specific Chrome enterprise policies designed to prevent this, and how to bypass them. The technique extends beyond Chrome to other Chromium-based browsers including Edge. TLDR; This talk will demonstrate live exploitation, discuss what EDRs are (and aren't) keying on, cover which mitigation strategies actually work, and why most deployed configurations don't. In addition attendees will get to sit down and actually embed a custom Chrome extension mythic agent inside of trusted extensions, bypassing active policies and showing how to dynamically load and run code in the latest versions of Chrome.

SpeakerBio:  Gordon Long

Gordon Long is the President and CEO of LegioX Cyber Technologies and is a Senior Offensive Security Engineer at Zoom. He also teaches as an Adjunct Professor at George Mason University in the Digital Forensics Master's Program. His favorite areas of cybersecurity include EDR evasion and cyber deception. His X handle is @ethicalhax and github is under AsaurusRex.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 10:00-17:59 PDT


Title: F1NDX OSINT Educational Series
Tags: OSINT For Good Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

The OSINT Educational Series is a 3-level series that introduces Open-Source Intelligence (OSINT). It covers data collection, social media analysis, and investigative techniques, showing how publicly available information is used in cybersecurity and intelligence. Volunteers will be on hand to help you get started and answer questions if you get stuck! Complete all 3 levels and earn a digital badge!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 13:00-14:59 PDT


Title: Factory Floor MVP Incident Response Challenge
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map

Description:

Defend the Factory. Beat the Attack. The Factory Floor MVP Incident Response Challenge is a fast-paced, interactive card-and-dice game where teams investigate cyberattacks against a modern manufacturing environment. Use strategy, collaboration, and a little luck to uncover attacker activity before production or safety is impacted. Players will walk away with practical insights into OT security, firmware and SBOM analysis, incident response, and the challenges of protecting connected industrial systems.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-11:59 PDT


Title: Falco Hunt: Evading Runtime Detection in Kubernetes
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

Falco is one of the most widely deployed cloud-native runtime security tools, relied upon to detect suspicious behavior across containers and Kubernetes environments. But what happens when attackers understand the rules better than defenders? In this hands-on tactic, attendees will compromise a Kubernetes environment while interacting directly with Falco detections in real time. Participants will execute common attacker actions including secret harvesting, privilege escalation attempts, reverse shell execution, and lateral movement, then iteratively adapt their tradecraft to evade or blend around runtime detections. Along the way, attendees will learn how Falco rules work, where syscall-based detection succeeds, where it struggles, and how attackers abuse assumptions in default rule sets. The session emphasizes practical detection engineering lessons for both offensive and defensive practitioners.

SpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 14:00-14:59 PDT


Title: Farsight: Turning OSINT into Actionable Attack Surface Intelligence
Tags: Intro/Beginner | AppSec Village | Creator Event/Activity
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Farsight is an open-source reconnaissance and threat intelligence framework designed to transform fragmented OSINT workflows into a unified, automated intelligence pipeline. Traditional reconnaissance relies on multiple disconnected tools, manual correlation, and inconsistent outputs, limiting scalability and efficiency.

Speakers:Arif,Sai Vernekar,Seedon D'Souza,kvprashant

SpeakerBio:  Arif

Senior Security Engineer with 5+ years of experience helping companies build and ship secure products without slowing down innovation. I specialize in Web, API, and Mobile Pentesting, Cloud Security, Threat Modeling, and embedding scalable SSDLC practices. My security journey began with curiosity and evolved into real-world impact—during an audit, I uncovered a critical flaw that could’ve exposed sensitive internal data. At Poshmark, I’ve led third-party library risk assessments, performed architecture reviews for key features, and rolled out secure coding practices across engineering. My threat modeling work improved early risk detection by 40%. Outside of work, I run hands-on security workshops, organize CTFs, and speak at conferences like c0c0n and Seasides. I'm open to the chance to solve real-world security challenges. Let’s connect and build secure systems that scale.

SpeakerBio:  Sai Vernekar

Sai Santosh Vernekar is a seasoned Application Security Practitioner with over a decade of expertise in application security. Over his career, Sai has undertaken secure code review, DAST, Devsecops, penetration testing as well as threat modeling. He currently works as Senior Security Engineer at Kohl’s. His keen interest lies in Cloud Security & secure CI/CD implementations.

SpeakerBio:  Seedon D'Souza

Hardware security expert with 10+ years in RF hacking, drone security, and exploitation. Speaker at Seasides Goa. Formerly at Sony, now at Festo.

SpeakerBio:  kvprashant

Prashant Venkatesh is an information security expert with over 20 years of experience. He presently works as, Product security Leader

Prashant is an enthusiastic participant in the field who consistently coordinates, reviews papers, and presents his work at numerous InfoSec conferences, including at Nullcon and c0c0n. He is also active through the OWASP Bay Area chapter Leadership and he is co-founder of annual Seasides Conference.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 16:30-17:59 PDT


Title: Filibuffer Overflow: Hackers Stage A Congressional Hearing
Tags: Policy @ DEF CON | Creator Interactive Talk/Panel
When: Friday, Aug 7, 16:30 - 17:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:
Speakers:Katherine Pratt,Jeff Rothblum,Maurice Turner,Ayan Islam,Beau Woods

SpeakerBio:  Katherine Pratt, Microsoft

Katherine Pratt is a senior security engineer and operator on the AI Red Team at Microsoft. She received her B.S. in aerospace engineering from MIT in 2008. Following graduation, she served four years in the United States Air Force, spending most of her time as an operational flight test engineer on the F-35 Joint Strike Fighter. She received a PhD in Electrical and Computer Engineering from the University of Washington in 2019, where she studied the privacy, ethics, and policy of neural data. Her professional work experience includes Blue Origin, the ACLU of Washington, and a fellowship through TechCongress working on technology policy in the US House of Representatives. She also competes in triathlons and is the co-founder of the 501(c)3 Minority Veterans of America.

SpeakerBio:  Jeff Rothblum, Founder at Plaintext Strategies

Jeff Rothblum, founder of Plaintext Strategies, has worked at the intersection of technology and policy for two decades. He has led government affairs at an AI startup, served as a cyber threat intelligence analyst, led cybersecurity policy the Senate Homeland Security and Governmental Affairs Committee, served as a Director of Cyber Policy and Plans at the White House Office of the National Cyber Director, and co-owned an artisan blacksmithing company.

SpeakerBio:  Maurice Turner

Maurice Turner is a recognized public interest technologist and cybersecurity expert on the Public Policy team at TikTok. As a Technical Policy Lead, Turner plays a key role as a liaison collaborating between public policy and cross-functional teams to ensure understanding of cutting-edge technologies by non-technical audiences. He also advises the broader Americas public policy team on a wide range of technology, strategy, and policy issues.

SpeakerBio:  Ayan Islam

Ayan Islam is an Adjunct Lecturer at American University School of Public Affairs' Cybersecurity Policy and Management program and cyber risk specialist at a Fortune 500 FinTech company. As former White House Director of Cyber Workforce, she served at the Office of National Cyber Director (ONCD) supporting the development and implementation of the National Cyber Workforce and Education Strategy. Previously, she was the Associate Policy Director for R Street's Cybersecurity and Emerging Threats team and contributed to special initiatives at the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA).

SpeakerBio:  Beau Woods
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:30-13:30 PDT


Title: Fireside Chat with Gen. Paul Nakasone
Tags: DEF CON Official Talk
When: Friday, Aug 7, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:
Speakers:Paul Nakasone,Jeff "The Dark Tangent" Moss

SpeakerBio:  Paul Nakasone
No BIO available
SpeakerBio:  Jeff "The Dark Tangent" Moss

Mr. Moss is an internet security expert and is the founder of both the Black Hat Briefings and DEF CON Hacking conferences.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Flight Simulator/EFB
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Experience the effects of tampered engine performance data as you take the controls on a departing flight. Feel for yourself how vulnerabilities in electronic flight bags can have a physical impact inside the cockpit.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Friday - 12:00-12:30 PDT


Title: Flow Like Water: Experiences from Physical Red Teaming
Tags: Physical Security Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Physical red teaming remains one of the most consequential and under-discussed disciplines in offensive security. While network intrusions dominate the conversation, a determined adversary at the perimeter can bypass millions of dollars in cyber defenses with a lanyard, a clipboard, and a confident smile. This talk distills lessons learned from real-world physical red team engagements that achieved their objectives, walking through the tactics, techniques, and tooling that consistently produced results across diverse target environments.

Topics include reconnaissance and target profiling, pretext development and social engineering at entry points, covert entry tooling (bypass devices, RFID cloning, lock and latch attacks), implant deployment for persistence, and methods for chaining physical access into network footholds. Emphasis is placed on what actually worked, not theoretical attack trees, alongside the operational considerations, failure modes, and decision points that separate a successful op from a burned one.

SpeakerBio:  Michael "v3ga" Aguilar, Principal Consultant at Sophos Red Team

Michael Aguilar (v3ga) is a Principal Consultant on the Sophos Red Team, paid to think like the people his clients are afraid of. His work lives at the intersection of offensive security, vulnerability research, and low-level systems programming, Windows internals, reverse engineering, and the kind of dusty attack surfaces that nobody has looked at since the protocol was ratified. Sometimes, he’s lucky enough to perform full Physical Red teams against his client targets. His method is unglamorous and effective: Analyze, Formulate, Target, Attack (covertly).


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 14:00-14:59 PDT


Title: Fooling Coding Agents for Fun and Profit
Tags: AI Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:
This is a sit down discussion in a more casual conversational format: Companies are increasingly deploying coding agents to triage bug reports, resolve support tickets, and open pull requests. These agents have direct access to codebases, CI/CD pipelines, internal tooling, and, often, the internet. These are exactly the conditions that make indirect prompt injection devastating.

This talk presents end-to-end vulnerability chains we have discovered and disclosed in real coding agents. We’ll demo how adversary-controlled content (e.g., a bug report from a user) can hijack an agent’s goal and lead to outcomes like source code exfiltration and malicious pull requests.

As coding agents become increasingly autonomous and interact with the outside world more frequently, these attacks will only grow more potent. We close with recommendations for how companies and codegen providers can defend against them.

Speakers:Matt Galligan,Jack Cable

SpeakerBio:  Matt Galligan
Matt has spent his career on both sides of the fence: building deceptive cyber systems and the security automation behind one of the DOD's largest software factories, then joining CISA's Rapid Action Force — where the job was, more or less, "hack the entire federal government, daily," between vuln research and no-notice red team engagements. After a stint in big tech, he's now at Corridor focusing his efforts on building a rare thing in the industry: a security product that security teams actually love.
SpeakerBio:  Jack Cable, CEO and Co-Founder at Corridor

Jack Cable is the CEO and Co-Founder of Corridor, the security layer for AI coding. Prior to that, Jack served as a Senior Technical Advisor at the Cybersecurity and Infrastructure Security Agency (CISA), where he helped lead the agency’s Secure by Design initiative. Before CISA, Jack worked as a TechCongress Fellow for the Senate Homeland Security and Governmental Affairs Committee, advising Chairman Gary Peters on cybersecurity policy, including open source software security. He previously worked as a Security Architect at Krebs Stamos Group. Jack is a top bug bounty hacker, having identified over 350 vulnerabilities in hundreds of companies. After placing first in the Hack the Air Force bug bounty challenge, he began working at the Pentagon’s Defense Digital Service. Jack studied computer science at Stanford University and has published academic research on election security, ransomware, and cloud security.


Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Friday - 13:00-13:30 PDT


Title: Forcing Physical Interlocks into Data Transit and Storage Replication
Tags: Data Duplication Village | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:30 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:

Traditional software-based security cannot prevent data destruction or unauthorized cloning when authorized credentials are compromised. This presentation introduces a hardware-level physical intervention approach with a zero-OS FPGA architecture to overcome vulnerabilities at the L3/L4 layer. This invisible Layer-2 transparent bridge, lacking IP or MAC addresses, performs sub-nanosecond-level gate-level Deep Packet Inspection (DPI) on the pipeline. When high-risk storage commands (deletion, unauthorized data transfer, etc.) are detected at the silicon level, the data flow is hardware-intercepted and held in a "Catch-and-Release" buffer until a physical human confirmation is received.

Speakers:Mehmet Önder Key,Temel Demir

SpeakerBio:  Mehmet Önder Key, Cyber Security Consultant

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

SpeakerBio:  Temel Demir

Temel Demir is a cybersecurity researcher and hardware architect specializing in hardware defense, offensive security, and the protection of critical infrastructure. With a core focus on embedded system vulnerabilities and Layer-1/Layer-2 network manipulation, his research involves developing deterministic, hardware-enforced frameworks that bypass traditional software-defined security flaws. Having previously shared security research on global stages, his work bridges the gap between sophisticated threat actor methodologies and immutable physical security barriers.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Friday - 15:30-15:59 PDT


Title: Forensics of Covert Entry
Tags: Physical Security Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

You know lockpicking. You know lock bypass. You might know evasion tactics for alarms and surveillance systems. But what traces get left behind if an attacker does these? This talk will give an introduction to the forensics of covert entry techniques - what marks get left behind, how to tell whether someone entered, when it happened, what tactics and tools were used, and what skill level the attacker had. Taught by two founding members of the Physical Security Village, this talk will also show the interesting and funny results when certain entry techniques are applied thousands of times on one door, which will tune your eye for spotting when it’s only happened once.

Speakers:Bill Graydon,Bobby Graydon

SpeakerBio:  Bill Graydon, GGR Security

Bill Graydon is a Principal at GGR Security, where he designs and evaluates security systems and building construction for a wide range of industries - including testing them on physical pen tests. Through this, he hacks everything from locks and alarms to critical infrastructure; this has given him some very fine-tuned skills for breaking stuff. He’s passionate about advancing the security field through research, teaching numerous courses, giving talks, and running DEF CON’s Lock Bypass Village. He’s received various degrees in computer engineering, security, and forensics and comes from a broad background of work experience in cyber security, anti-money laundering, and infectious disease detection.

SpeakerBio:  Bobby Graydon

Robert is an avid researcher of lock manipulation, picking, bypass, and other vulnerabilities to discover and evaluate possible flaws and methods of attack. He has a passion not only for hacking, but teaching as well, being one of the founders of Physical Security Village, and enjoys speaking at various physec engagements. He has well-honed skills, as well as a thorough understanding of the mechanics and function of many types of high security locks, allowing him to effectively search for and test methods of cracking high security systems.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 15:15-15:59 PDT


Title: Forged in fire: Malware Factory
Tags: OWASP Foundation | Creator Talk/Panel
When: Friday, Aug 7, 15:15 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

We are moving beyond prompt engineering into the era of Agentic Warfare. This session pulls back the curtain on a clandestine bridge between the OWASP community and the underground. We aren't here to lecture on "best practices." We are here to hand you the blueprints for the Forge.

The Agenda:

The Artisan’s Edge: Weaponizing LLMs as high-bandwidth force multipliers for surgical, manual exploit crafting. Agentic Persistence: Engineering self-correcting, goal-oriented malware that adapts to environment constraints in real-time. Ghost Pipelines: Architecting air-gapped, invisible infrastructures for weapon synthesis where the trail ends before it begins. Monetizing the Machine: Scaling high-impact, client-side payloads for maximum "fun and profit."

OWASP has chapters in every major city—think of them as your local cells. We are opening the laboratory doors to the elite. If you have the craft, we have the infrastructure.

Come claim your seat in the Forge.

Speakers:Jon McCoy,Andra Lezza

SpeakerBio:  Jon McCoy, Security Architect, OWASP

Software security architect, Jon McCoy brings over 20 years of experience in software development and cybersecurity to the forefront. With a strong foundation in .NET development, Jon transitioned into security, driven by a passion for proactive defense strategies and secure coding practices.

A dedicated contributor to the OWASP community, Jon has shared his expertise at numerous industry events, including OWASP Global AppSec. His recent presentation on "Lessons Learned from Past Security Breaches" highlighted critical takeaways for strengthening AppSec efforts before and after incidents.

SpeakerBio:  Andra Lezza, Principal Application Security Specialist at Sage / OWASP Leader

Andra is a Principal Application Security Specialist at Sage, with over seven years of experience in the field of application security. She is responsible for implementing DevSecOps practices, conducting security assessments, and developing secure coding guidelines for software engineering and AI/ML teams. She has a strong background in software development and project management, as well as a master's degree in information and computer sciences. She has been co-leading the OWASP London Chapter since 2019, where she organises and delivers events and workshops on various security topics. She is passionate about educating and empowering developers and stakeholders to build and deliver secure software and best practices in a fast-paced, results-driven environment.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 10:00-10:45 PDT


Title: Four Newbies Vs. An Insulin Pump. How Hard Can It Be?
Tags: Biohacking Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Medical devices are becoming increasingly connected—and that includes devices responsible for keeping people alive. In this talk, we share our journey as four security students taking on the challenge of analyzing an insulin pump as relative newcomers to hacking medical devices. Motivated by curiosity, concern for patient safety, and personal stakes, we set out to explore how an attacker might approach such a system using only public information, basic wireless knowledge, and persistence.

Rather than presenting ourselves as experts, we focus on the learning process: how we approached an unfamiliar, safety critical system, how we performed threat modeling when the “failure mode” is a human body, and how we handled the many moments where everything stopped making sense. We’ll walk through what worked, what didn’t, and how critical thinking helped us move forward when we hit a wall.

By reflecting on where we started, where we are today, and what remains unexplored, this talk highlights the value of a beginner’s mindset when analyzing real world systems like medical devices. Our goal is not to sensationalize risk, but to show how accessible security research, done responsibly, can contribute to better understanding and safer technology.

Speakers:Birgitte Jordal,Julia Kucharska,Emilie Jørstad,Selma Jenker

SpeakerBio:  Birgitte Jordal

We are four Norwegian women that hold a bachelor’s degree in Digital Infrastructure and Cybersecurity from NTNU. Our interests include CTFs, ethical hacking, and penetration testing, with experience in cloud infrastructure, secure networking, and threat analysis.

SpeakerBio:  Julia Kucharska
No BIO available
SpeakerBio:  Emilie Jørstad
No BIO available
SpeakerBio:  Selma Jenker
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 13:30-14:25 PDT


Title: Fox Hunting - Finding Rogue Access Points in the CTF and in the Wild
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 13:30 - 14:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

What does the fox say? Turns out the fox says quite a lot, you just need to know how to listen! A "fox" is a hidden transmitter, in this case a WiFi access point. In this talk we'll go from basics to advanced fox hunting, covering: direction finding, antenna selection, channel scanning, refresh rate, remote sensors, mobile devices, staying stealthy so the fox never sees you, and working as a team. Not only is it a great DEFCON pastime, it's a real-world skill that lasts long after the con.

SpeakerBio:  Eric Escobar, Sophos - Red Team Lead

Eric is a seasoned pentester and a Red Tech Lead at Sophos. On a daily basis he attempts to compromise large enterprise networks to test their physical, human, network and wireless security. He has successfully compromised companies from all sectors of business including: Healthcare, Pharmaceutical, Entertainment, Amusement Parks, Banking, Finance, Technology, Insurance, Military, Retail, Food Distribution, Government, Education, Transportation, Energy and Industrial Manufacturing.

His team consecutively won first place at DEF CON 23, 24, and 25's Wireless CTF, snagging a black badge along the way. Forcibly retired from competing in the Wireless CTF, he now helps create challenges!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 13:00-15:59 PDT


Title: Free Ham Radio License Exams
Tags: Event | Ham Radio Village
When: Friday, Aug 7, 13:00 - 15:59 PDT
Where: LVCCW Level 3 W314 (Ham Radio Meeting) - Map

Description:

Free ham radio exams return to DEF CON 34! Partake in this hacker “rite of passage” by getting your license at DEF CON, presented by the Ham Radio Village.

While anyone is able to listen in to amateur/ham radio transmissions, only those who have an amateur radio license are able to fully partake in the “oldest hacker hobby”. With your license, you’ll be authorized by the FCC to transmit up to 1,500W on designated frequencies, build/modify radios & antennas, and even administer your own exams! Additionally, having your ham radio license can improve your resume as it is a well-recognized proof of technical and regulatory knowledge when it comes to all things radio.

About The Exam

In the US there are 3 current levels of amateur radio license - Technician, General, and Amateur Extra. You can progress through the levels by taking a series of multiple-choice exams showing increasing breadth of knowledge. Most folks at DEF CON looking to become a ham take just the technician exam.

The technician exam is a 35 question, multiple choice exam. Questions come from from a public question pool of 400 questions. Because of that, the most popular way folks at DEF CON prepare is by reading through all 400 questions before the exam, and learning hands on once you get licensed. Many study resources exist - most people recommend ham.study.

Signing Up

Who may register for this testing session:

Fees

Questions

If you have any questions leading up to DEF CON, come visit us on the Ham Radio Village Discord server (discord.gg/hrv) and let us know what questions you have. During the conference, come visit the Ham Radio Village to learn all things ham radio, including the studying, testing, and licensing process.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 12:00-12:59 PDT


Title: Friends of Bill W
Tags: Meetup
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W301 (Misc Meeting Room) - Map

Description:

We know DEF CON and Vegas can be a lot. If you're a friend of Bill W who's looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 17:00-17:59 PDT


Title: Friends of Bill W
Tags: Meetup
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 3 W301 (Misc Meeting Room) - Map

Description:

We know DEF CON and Vegas can be a lot. If you're a friend of Bill W who's looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Friday - 12:00-12:59 PDT


Title: Friendship Bracelets
Tags: Women in Security and Privacy (WISP) | Creator Event/Activity
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 12:00-13:59 PDT


Title: From Application Telemetry Exposure to Cross-Service Pivoting and Full Azure Tenant Takeover
Tags: Red Team Village | Misc
When: Friday, Aug 7, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

Cloud-native teams often treat web app "config leaks," verbose telemetry, and CI/CD misconfigurations as separate, low-impact issues. This talk shows how those assumptions break in practice. We present a full kill chain where a single exposed Application Insights key in a front-end patient portal is chained with realistic but common Azure misconfigurations to achieve complete tenant compromise and Global Administrator access.

Starting from an exposed Application Insights Instrumentation Key in client-side JavaScript, we demonstrate how an attacker can pivot into the Application Insights query API, mine telemetry for over-privileged SAS URLs, and use those tokens to harvest sensitive data from Blob Storage and Storage Queues. We then show how seemingly innocuous Function App endpoints, intended for document ingestion, can be abused via SSRF and URL-based command injection to access local files and environment variables, recovering additional credentials. Finally, we weaponize misconfigured Azure DevOps pipelines and Library Variable Groups to exfiltrate cloud credentials to a webhook, escalate privileges in Entra ID, and take control of production workloads.

Rather than introducing a single novel vulnerability, this session focuses on the combinatorial risk of real-world misconfigurations across Application Insights, Storage, Functions, DevOps, and identity. Attendees will walk away with concrete cloud hunting techniques, a step-by-step attack chain they can reproduce in their own labs, and a prioritized remediation playbook for breaking similar chains in their environments.

Speakers:Chirag Savla,Raunak "Trouble1" Parmar

SpeakerBio:  Chirag Savla

Chirag Savla is a cyber security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. For fun, he enjoys creating open-source tools and exploring new attack methodologies in his leisure. Chirag has worked extensively on Azure, Active Directory attacks and defense, and bypassing detection mechanisms. He is the author of multiple open source tools such as Process Injection, Callidus, and others. He has presented at many conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest, HackSpaceCon and VulnCon.

SpeakerBio:  Raunak "Trouble1" Parmar

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 16:00-17:59 PDT


Title: From Dashboard to Exploit: Weaponizing and Winning the Cloud Queue
Tags: Cloud Village | Creator Event/Activity | Strategic Defense
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) B - Map

Description:

Finding a vulnerability on a dashboard is only half the battle. Knowing how an attacker will weaponize it is what separates great security engineers from the rest.

In this hands-on CloudSec Village lab hosted by Aikido Security, you will step into the shoes of both defender and attacker. Navigating a custom simulation dashboard, you’ll face live vulnerabilities hidden across containerized apps and serverless functions. Your mission: don’t just trust the scanner. You will dive into live mini-applications, execute real-world exploits to prove their impact, and see exactly how they register on the platform. This drop-in lab bridges the gap between passive triage and active offensive security — join any time and validate threats like a pro.

SpeakerBio:  Mackenzie Jackson

Mackenzie is the Field CTO for Aikido Security, helping tech leaders understand application security through an attacker’s lens. As the co-founder and former CTO health tech company Conpago, he understands the challenges of building secure applications. He has spoken in over 30 countries, hosts the popular Podcast The Secure Disclosure, and contributes to multiple publications including Dark Reading, Financial Times, and Fast Company.


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Friday - 12:00-12:59 PDT


Title: From Disk Image to ATT&CK in One Binary — a Reference Architecture for Modern Incident Response (in Rust)
Tags: LOONG Community | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

A Reference Architecture for Modern Incident Response (in Rust)

Incident response still runs on a toolbox: a dozen single-purpose parsers, a pile of CSVs, a timeline stitched together by hand, and a senior analyst's memory holding it all together. Every engagement re-solves the same plumbing. Every new artifact means a new script. And the hard-won expertise — how to read a prefetch run-count, how to resolve a ControlSet in an offline hive, which event IDs actually matter — lives in people, not in code you can run twice.

This talk argues for a different shape: incident response as a framework, not a toolbox — and backs the argument with a working reference implementation, Issen, an open-source DFIR engine written in Rust. You point Issen at evidence — an E01/EWF/VMDK or raw disk image, a memory dump — and it returns a single normalized timeline and an ATT&CK-mapped report. One static binary. No Python runtime, no agent, no cloud. It runs the same on an examiner's laptop, in CI, or inside a sealed evidence enclave.

Under the hood, Issen is deliberately thin. The real work lives in a fleet of standalone, single-responsibility forensic libraries — each a deep expert in one artifact family (NTFS and the change journal, registry hives, prefetch, SRUM, browser history, EVTX, SQLite, Windows and Linux memory) — that know nothing about each other. Issen is the orchestration and correlation layer that wires them into one story and speaks one normalized vocabulary of findings ("consistent with," never a verdict), each tagged to MITRE ATT&CK. We'll walk the layered model that makes this composition work — container → filesystem / memory / log → parser → orchestration — and why every parser is medium-agnostic by design.

The most useful — and least glamorous — lesson is the one the talk is really about: capability is cheap to build and expensive to wire. Demonstrated live against the public "Stolen Szechuan Sauce" case, we'll show artifacts that were completely correct in isolation yet invisible end-to-end, because a decoder existed but nothing called it, or a file was extracted but never classified, or a real-world quirk (offline hives have no CurrentControlSet; large registry values are split into "big data" segments) quietly returned nothing. We'll trace each from "zero results" to ground truth.

Engineering substance throughout: panic-free, forbid(unsafe) parsers that treat every input as hostile; correctness validated against independent external oracles (not just the authors' own fixtures); and a clean separation between observed fact, forensic inference, and the conclusions that belong to a human, not a tool.

You'll leave with: a concrete, composable architecture for an IR pipeline you can adopt or fork; a working open-source reference to start from today; a repeatable method for finding "dark" capability in your own tooling; and a sober view of what to automate, what to keep human, and how to phrase findings so they survive scrutiny.

SpeakerBio:  HUI Kwun Tai, Albert (4n6h4x0r), DC852

Albert Hui (@4n6h4x0r) is a digital forensics and incident response practitioner and the founder of Security Ronin. He builds open-source forensic tooling — including Issen, a Rust DFIR engine, and a family of panic-free libraries spanning disk, memory, registry, and application artifacts — and works hands-on as an examiner and expert witness testifying before courts of law, where findings have to survive cross-examination, not just look good on a slide. He's drawn to tooling an analyst can actually run twice: reproducible, offline, and honest about the line between observed fact and inference. In a past life he was an IBM Global Security Architect and a Deloitte Risk Advisory Director — which goes some way to explaining his propensity for horizontal thinking.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-17:59 PDT


Title: From Kiosk to Domain Compromise: Learning to Walk Up and Take it All
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area - Map

Description:

Kiosks are everywhere. Their prevalence in our society has exploded, with devices such as fast-food ordering, signage, ticketing and check-in, print/ship/office, library, point-of-sale, and more - all around us.

How secure are they though? Are they being adequately tested? We all learned on July 19, 2024, when a multitude of the signs and kiosks around us went BSOD that a large number of these kiosks – from airports to ATMs – are running on Windows. We need to be asking questions like, are they joined to a domain, what is network adjacent, and how could these systems lead to a serious attack path?

In this workshop we will walk through how to hack and secure kiosks in a four-part workshop, which will move from initial compromise to lateral movement and domain compromise, concluding with some defensive recommendations to prevent ‘kiosk to domain takeover’ scenarios.

Speakers:Ezra Woods,Mike Manrod,Spencer Alessi

SpeakerBio:  Ezra Woods

Avid security researcher currently working as an Information Security Engineer with Grand Canyon Education

SpeakerBio:  Mike Manrod

Mike, AKA, CroodSolutions, presently serves as CISO for Grand Canyon Education, teaches Malware Analysis for GCU, and helps lead the Threat Intelligence Support Unit.

In addition to work on BypassIT, AutoPwnKey, BYOEDR, and BeaconatorC2 with Ezra Woods and other contributors, Mike has served as a threat prevention engineer for Check Point along with various other roles.

He is also a co-author/contributor for the joint book project, Understanding New Security Threats published by Routledge in 2019, along with multiple articles/whitepapers. When not working, he spends time playing video games or working on cars with his kids.

SpeakerBio:  Spencer Alessi

Spencer is a passionate security practitioner, with the heart of a defender and spirit of a hacker. Spencer's background is in IT and Systems Administration prior to making the transition to security. He leans on these crucial technical skills to help enable clients and security programs to build defensible, vigilant, and practical security programs. Most of Spencer's current efforts are focused on understanding threats, techniques, and methods and then implementing them through technical assessments and analysis. Spencer is Co-Host of The Cyber Threat Perspective podcast and regularly creates blogs, videos and other content. In November 2025 Spencer was awarded Microsoft MVP in Security - Identity & Access.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 11:30-12:10 PDT


Title: From Pipeline to Cloud Control
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 12:10 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Azure DevOps service connections are a core part of modern pipelines, allowing teams to interact with Azure and other external systems seamlessly. While they make deployments faster and easier, they also introduce an attack surface that is often overlooked in real-world environments.

In this research, we explore new attack paths showing how even limited access within Azure DevOps pipelines can be leveraged to escalate privileges and compromise cloud environments. By taking advantage of over-scoped service connections and certain platform behaviors, an attacker can chain together small gaps to achieve significant impact, including gaining subscription-level access.

These findings were reported to Microsoft and acknowledged through MSRC, highlighting a deeper issue in how DevOps integrations are secured. Rather than being just a configuration problem, this reflects a broader gap that organizations need to understand when designing their cloud security approach.

SpeakerBio:  Saksham Agrawal

Saksham Agrawal is a Senior Security Consultant at NotSoSecure, specializing in cloud security. His work focuses on discovering new attack paths in cloud environments and helping organizations understand real-world risks. He has presented his research at DEF CON Cloud Village, where he introduced his tool NoPrompt and shared practical techniques for cloud security testing. He enjoys building tools, exploring cloud internals, and sharing his findings with the security community. He has also responsibly reported critical vulnerabilities in major cloud vendors as part of his independent security research and actively delivers training sessions on cloud security and offensive security techniques.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:00-10:59 PDT


Title: From square root to /root: escalating privileges in Azure containers with Python in Excel
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Microsoft integrated Python into Excel, giving users more advanced data analysis. The Python code is processed in a cloud container and returned as results. This sparks an immediate question: does it allow remote code execution on Microsoft owned servers?

In this talk, we'll dig into the various web applications and components in the Python execution environment. We'll describe how we discovered a privilege escalation vulnerability in the file upload mechanism of this service, which allowed us to gain root access within the container. Utilizing that, we revealed the complete architecture of this solution. We will show how we discovered Microsoft’s internal deployment configuration, including key vaults, database servers, account names, tenant IDs, and much more. We were even able to execute code on the pilot servers of this product.

We also found how to craft a special response to Excel, resulting in bypassing two security boundaries (CVE-2026-45459): the trusted records protection (“Enable Content” warning) and the network isolation protection.

We will expose features that weren’t even announced yet and how they might be exploited. Follow us in our journey from the first “whoami” command, through exfiltrating tailor-made Python libraries, and eventually finding a vulnerability to achieve execution as root!

https://i.blackhat.com/Asia-25/Asia-25-Carmel-The-Problems-of-Embedded-Python-in-Excel.pdf https://www.netspi.com/blog/technical-blog/red-teaming/a-first-look-at-python-in-excel/

SpeakerBio:  Ron Ben Yizhak, SafeBreach

Ron (@RonB_Y) is a security researcher at SafeBreach with 11 years of experience. He works in vulnerability research and has knowledge in forensic investigations, malware analysis and reverse engineering. Ron previously worked in the development of security products and spoke several times at DEF CON


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Friday - 13:15-13:59 PDT


Title: From threat-intel to tested defense, the adversary simulation playbook
Tags: Adversary Village | Creator Talk/Panel
When: Friday, Aug 7, 13:15 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Knowing who is coming for you is only half the fight. The real work is turning that knowledge into defenses that actually works. This panel walks through the full playbook, from raw threat intelligence on state-sponsored actors and other adversaries, to emulating their tradecraft, to validating whether your defenses can really stand up to it. Our panelists bring hands-on experience across adversary simulation, threat intel, and purple teaming to talk about what it takes to move from a report on paper to a tested, measurable defensive posture. The panel will dig into how to prioritize the threats that matter to your organization, how to faithfully replicate real adversary behavior instead of chasing generic checklists, and how red and blue working side by side turns every simulated attack into a lasting defensive victory. Whether you are defending against nation-state operators or opportunistic criminals, the goal is the same! Stop guessing about your defenses and start proving them. Join us for a practical conversation about closing the gap between intelligence and action.

Speakers:Cheryl Biswas,Adam Pennington,Olaf Hartong,Sarah Hume

SpeakerBio:  Cheryl Biswas, Strategic Threat Intel Analyst at TD Bank

Cheryl Biswas is a Strategic Threat Intel Analyst with TD bank in Toronto, Canada. She found her way into InfoSec through a helpdesk backdoor and pivoted into roles for vendor and change management, jumped a gap into privacy and DR/BCP, then laterally moved into security audits and assessments. Her degree in Political Science has evolved into researching APTs, botnets, ransomware and more. Cheryl is actively involved in the security community as a conference speaker and volunteer, mentors those entering the field, and encourages women and diversity in Infosec as a founding member of the "The Diana Initiative."

SpeakerBio:  Adam Pennington, ATT&CK lead at MITRE Corporation

Adam Pennington leads ATT&CK at The MITRE Corporation and collected much of the intelligence leveraged in creating ATT&CK’s initial techniques. He has spent much of his 16 years with MITRE studying and preaching the use of deception for intelligence gathering. Prior to joining MITRE, Adam was a researcher at Carnegie Mellon's Parallel Data Lab and earned his BS and MS degrees in Computer Science and Electrical and Computer Engineering from Carnegie Mellon University. Adam has presented and published in several venues including FIRST CTI, USENIX Security, DEF CON, and ACM Transactions on Information and System Security.

SpeakerBio:  Olaf Hartong, Defensive Specialist at FalconForce

Olaf Hartong is a Defensive Specialist and security researcher at FalconForce. He specialises in understanding the attacker tradecraft and thereby improving detection. He has a varied background in blue and purple team operations, network engineering, and security transformation projects. Olaf has presented at many industry conferences including Black Hat, DEF CON, DerbyCon, Splunk .conf, FIRST, MITRE ATT&CKcon, and various other conferences. Olaf is the author of various tools including ThreatHunting for Splunk, ATTACKdatamap and Sysmon-modular. He maintains a blog at https://olafhartong.nl

SpeakerBio:  Sarah Hume, Purple Team Service Lead at Security Risk Advisors

Sarah leads the Purple Team service at Security Risk Advisors (SRA). She has led hundreds of Threat Intelligence-based Purple Team exercises for organizations in the Fortune 500 and Global 1000 over the past 7 years. Her background is in offensive security, primarily internal network, OT/ICS, and physical security penetration testing. Sarah also has experience in external network penetration testing, web application assessments, OSINT, phishing/vishing campaigns, vulnerability management, and cloud assessments. Sarah graduated Summa Cum Laude from Penn State with a B.S. in Cybersecurity. She is a Certified Red Team Operator (CRTO), Certified Information Systems Security Professional (CISSP), Google Digital Cloud Leader, AWS Certified Cloud Practitioner, and Advanced Infrastructure Hacking Certified. She lives in Philadelphia with her dog, Paxton.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 14:10-14:40 PDT


Title: from_pretrained() to from_pwned(): Breaking HuggingFace's Trust
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Friday, Aug 7, 14:10 - 14:40 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

uggingFace has become the GitHub of machine learning. Two million models, 15 million daily downloads. We discovered a critical RCE (CVE-2026-4372) that compromises any machine loading a malicious model. Add one field to a model's config.json, publish it on the Hub, and any standard from_pretrained() call is silently compromised. No trust_remote_code=True. No warnings. The one security boundary the entire ML ecosystem relies on, bypassed completely.

The chain is three flaws: a generic setattr loop stamping every JSON field onto the config object including private attributes; a sanitization gap protecting the public interface but not the underscore-prefixed internal equivalent; and an unsandboxed kernel loader executing arbitrary Python from any Hub repo. One field weaponizes all three.

We walk through the full attack chain live. Model registries are the new package registries, facing the same supply-chain threats that broke the software world - with far less mature defenses.

SpeakerBio:  Yotam Perkal

Yotam Perkal leads security research at Pluto Security, a next-generation AI security and governance platform designed to protect the rapidly emerging ecosystem of AI builders, low-code/no-code tools, and agentic applications. His work focuses on securing AI-native development environments and building scalable methods for detecting, validating, and mitigating risks in AI-driven software workflows.

Previously, Yotam led the Threat Research team at Zscaler, headed the Vulnerability Research team at Rezilion, and held multiple roles within PayPal’s security organization across vulnerability management, threat intelligence, and insider threat.

Yotam is an active participant in several cross-industry working groups dealing with AI security, vulnerability management, and supply chain security.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Friday - 15:00-15:59 PDT


Title: Furs and Kinksters Meetup
Tags: Queercon Community | Creator Event/Activity
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Game Hacking Village CTF
Tags: Game Hacking Village | Game Hacking Village CTF | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

Compete againt other teams to be the first to hack all of our games on our custom Mist Store platform


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 15:00-15:59 PDT


Title: Game Time: Input, Output, and Variables
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Input, output, and variables are the building blocks behind every single program you've ever used, and once you understand them, you're well on your way to writing your own code! In this session, we'll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 12:00-12:59 PDT


Title: Game Time: Input, Output, and Variables
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Input, output, and variables are the building blocks behind every single program you've ever used, and once you understand them, you're well on your way to writing your own code! In this session, we'll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 10:00-10:59 PDT


Title: Game Time: Loops
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Have you ever had to do the same thing over and over and thought, there has to be an easier way? Good news, there is, and it's called a loop! Come play some classic schoolyard games with us and discover that you've been using loops in real life all along. Then we'll show you how programmers use for loops and while loops to make computers repeat tasks automatically, whether that's counting to 100 or spawning enemies in your favorite video game. No experience needed, just come ready to play! If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 11:00-16:59 PDT


Title: GE(O)SINT Contest
Tags: Recon Village | Creator Event/Activity
When: Friday, Aug 7, 11:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Test your geospatial intelligence skills in this unique contest. Identify locations, analyze imagery, and demonstrate your GeoINT expertise.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 14:50-15:20 PDT


Title: GeoHacking: from memory corruption RCE to cross tenant access
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Friday, Aug 7, 14:50 - 15:20 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

The tale of CVE-2026-40412, hacking Microsoft Planetary Computer Pro service. This talk will walk you through the journey of discovering a chain of vulnerabilities in the service itself and in its open source dependencies. All those findings combined resulted in cross tenant access. From a file read, to exploiting a buffer overflow (bypassing ASLR) to finding and exploiting a devastating design flaw. This talk will address the unique challenges of exploiting memory corruption bugs in cloud services, the pitfalls of cloud services’ architecture and how we helped the engineering team fix the issues we found at the design level.

SpeakerBio:  Michal Kamensky

Michal is a security researcher on the Microsoft STORM team, where she focuses on vulnerability research across the hybrid cloud domain. Previously she has worked as a security researcher at Bounce Security, and for the last few years volunteers as a Defcon goon. She enjoys diving into large code bases, understanding complex architectures, and eliminating vulnerabilities at scale.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 12:30-13:15 PDT


Title: Geolocating Talent: How OSINT CTFs are Building Tomorrow's Analysts
Tags: OSINT For Good Community | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 13:15 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

What happens when you hand students a daily "Cyber Briefing," a target, and unrestricted internet access? You build relentless investigators. In this talk, former Oracle vulnerability analyst turned educator Ben Crenshaw breaks down how to weaponize curiosity by scaling OSINT training from a single classroom to massive regional competitions. Drawing on his experience training 1000+ competitors for the Mayors Cyber Cup and coaching TraceLabs SearchParty CTFs, Ben will share exactly how to teach the threat-intel mindset. Discover how gamified open-source intelligence is reshaping cybersecurity education, turning passive scrollers into privacy-aware analysts, and building the next generation of defenders.

SpeakerBio:  Ben "The Cyber Sensei" Crenshaw, Transofotech Academy | Cyber & AI Education Leader | EdTech & Workforce Development | U.S. Cyber Games Mentor | NICE Cybersecurity Ambassador | CLEAR AI Initiative | Senior TraceLabs Coach | Aerospace Education Member

Ben Crenshaw, known as The Cyber Sensei, is a cybersecurity educator, author of two industry books, and a dedicated US Cyber Games Mentor. Leveraging his background as a former Senior Vulnerability Analyst at Oracle, Ben transitioned into education to bridge the critical gap between real-world threat intelligence and classroom theory. Currently serving as Lead Cybersecurity instructor for Transfortech and as former Head of Cyber and AI Education at Work ED, he has taught Open-Source Intelligence (OSINT) to thousands of students, shaping them into ethically grounded, privacy-conscious defenders. A passionate advocate for scaling cyber education, Ben actively trains educators and coaches to prepare the next generation of talent for large-scale competitions like the Mayors Cyber Cup and TraceLabs.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Friday - 12:00-12:30 PDT


Title: Getting Started In Radio Direction Finding
Tags: Ham Radio Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:30 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

Radio Direction Finding (RDF) is one of the most practical and fun skills in amateur radio. This intro talk covers everything a beginner needs to know: low cost gear setups, building a simple Yagi antenna, and the techniques used to zero in on a transmitter.

Entry level talk reviewing what foxhunting / radio direction finding is Covering the basic equipment requirements Yagi antenna building Body fading Minimum equipment Tips and tricks

SpeakerBio:  Nate Moore

Nate Moore works in cybersecurity, holds an Extra class amateur radio license, and spends his spare time teaching, examining, and pushing signals around the ether.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 12:00-12:45 PDT


Title: Ghost in the IDE
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:
Hook: The Blind Spot
Your EDR sees the server compromise. Your SIEM catches the phishing campaign. Your firewall blocks the C2 traffic. But what happens when the attacker doesn't target your infrastructure—they target your developers?

28 million developers worldwide rely on three IDE platforms: JetBrains IntelliJ, Microsoft VS Code, and Eclipse. These aren't just text editors—they're command-and-control platforms disguised as productivity tools. Developers trust them with AWS credentials, database passwords, SSH keys, source code, and network access to production systems. And here's the kicker: IDE plugins run with full user privileges, no sandboxing, no permission dialogs, no questions asked.

We built GHOST IN THE IDE, a production-ready C2 framework that weaponizes IDE plugins across all three major platforms. Not a proof-of-concept. Not a research prototype. A functional red team tool with keystroke logging, clipboard monitoring, file exfiltration, and remote command execution—working silently inside IntelliJ, VS Code, and Eclipse on Windows, macOS, and Linux.

The Attack: Multi-IDE C2 That Actually Works Most IDE plugin research stops at "look, I can pop calc.exe from VS Code." We went further. Way further.

Speakers:Venkata Jayaram Yalla,Pardhiv Reddy

SpeakerBio:  Venkata Jayaram Yalla

Yalla, Jayaram is Director – Application Security at S&P Global, leading enterprise-wide initiatives in secure application development, vulnerability management, and security architecture. He has transformed the Application Security function from a primarily tactical penetration-testing team into a strategic security engineering organization, emphasizing automation, governance, and advanced threat modeling.

Jayaram combines deep hands-on experience in offensive security and research (including multiple CVEs) with ownership of large-scale AppSec programs across SAST, SCA, DAST, CI/CD security, and emerging AI security initiatives.

SpeakerBio:  Pardhiv Reddy

Pardhiv is a security specialist with vast experience in the field of information security ranging from health care,hospitality, banking and government sectors throughout the world. He also earned many industry standard certifications in the security, some of them are SANS GPEN, OSCP, OSWP, CISSP, Security+, ISO 27001 LA and many others.

Pardhiv's interest areas includes cloud security and IOT security and his research has been presented at EuropeanSec 2016 in Portugal. His expertise helped teams to build secure products and applications by providing security guidelines and best practices.

Pardhiv has performed various iOT security assessments which includes both embedded hardware security, firmware analysis, mobile applications, network security including wireless communications and backend cloud server assessments.

Pardhiv is also an active bug bounty hunter and helped many companies around the world by pointing their security vulnerabilities to make their application and products secure. He spares his free time to build prototypes and security research by learning new techniques and methodologies.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 15:00-15:45 PDT


Title: GhostCatcher (endpoint detection agent)
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

GhostCatcher is an open-source Linux endpoint detection agent written in Go. It runs as a single binary or a systemd service and looks for host-visible adversary tradecraft on Linux: web shells, LD_PRELOAD abuse, SSH, cron, and systemd persistence, PAM/sudoers tampering, SUID and capability drift, reverse shells and unexpected network behavior, reflective / memory-map signals, and related patterns aligned with MITRE ATT&CK-style coverage. Detections are driven by a versioned, optionally signed rule pack, baselines and learning mode, multi-signal scoring, time-windowed correlation, CEL-style boolean expressions, optional Sigma-lite rules, optional YARA (disk and memory) and eBPF (with auditd/proc fallbacks), and JSONL output to stdout plus optional syslog, Splunk HEC, Elasticsearch _bulk, or Grafana Loki. The goal is to give blue teams a transparent, self-hosted way to turn Linux host telemetry into actionable events in the SIEM—without a vendor cloud control plane.

SpeakerBio:  Sercan Okur

Sercan Okur is the Founder and CEO of NextRay AI Detection & Response, Inc., a San Jose–based cybersecurity company building AI-driven Network Detection and Response technology. A cybersecurity practitioner with more than fifteen years of experience across critical-infrastructure, defense, and enterprise environments,


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 16:45-16:59 PDT


Title: Github Rate Limits Got You Down? FOD’s Failing to Build? Let’s Talk About Caching
Tags: Nix Vegas Community | Creator Talk/Panel
When: Friday, Aug 7, 16:45 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Have you ever experienced being rate limited by GitHub? Has GitHub downtime prevented you from building software that you rely on? Are you worried about supply chain attacks? At Exa, we developed a secure, hostable, tarball cache that insulates us from GitHub outages, decreases our build times, protects us from force-pushes upstream, and increases download speeds.

SpeakerBio:  Ethan Carter Edwards

Ethan is a FLOSS advocate, longtime Nix user and contributor, and engineer. He's an active member of the Nixpkgs CUDA, Darwin, and NGI teams and is involved in various other efforts throughout the Nix ecosystem.

He currently works on building the infrastructure for the future of websearch at Exa.ai and studies Computer Science at Harvard University.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 12:00-12:45 PDT


Title: GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

GnawLab is a community-driven, open-source offensive cloud security training platform that recreates real-world AWS attack chains. Each scenario is modeled after documented breaches—Capital One's SSRF-to-IMDS pivot, Uber's leaked credential exploitation, SolarWinds-style CI/CD pipeline hijacking—deployed via Terraform in your own AWS account. Attendees will see live demonstrations of multi-hop attack chains: from SSRF and command injection entry points, through IMDS credential theft and Secrets Manager extraction, to full CI/CD pipeline compromise with Blue/Green deployment backdoors. GnawLab bridges the gap between theoretical cloud security knowledge and hands-on exploitation skills.

Speakers:ialleejy,Kyul,HyunJun "Beaver King" Kwon

SpeakerBio:  ialleejy

I am ialleejy, a Security Researcher at ENKI focusing on web security and cloud security. I have created WEB challenges for CODEGATE and HACKTHEON SEJONG CTF, and I am interested in designing CTF challenges that connect real-world service architectures with practical vulnerability research.

Recently, I have been exploring Offensive Cloud Security, especially how traditional web vulnerabilities can lead to privilege escalation, credential exposure, and abuse of trust relationships in cloud environments. I am currently diving deeper into AWS Bedrock AI Agents, RAG-based knowledge poisoning, OIDC authentication flows, and IAM trust policies.

Through this talk, I aim to show how a small vulnerability on the web can evolve into a broader cloud security issue, crossing trust boundaries between applications, identities, and cloud services.

SpeakerBio:  Kyul

I am a college student relentlessly exploring cloud vulnerabilities. I possess an exceptionally high threshold for hunting, gathering, and deeply analyzing whatever piques my interest.

My mindset is clear: effective defense demands an attacker's lens. Only by understanding actual infiltration paths and how they trigger critical risks can defenders accurately prioritize assets and build robust controls.

Driven by this, I’ve operated at the intersection of Red and Blue. In incident response projects, I analyzed real-world TTPs to build attack scenarios while collaborating to engineer detection rules and automated responses. I’ve also researched and presented how AWS misconfigurations can be weaponized to cause cascading breaches.

Currently, alongside the BeaverDam community, I am developing GnawLab for the DEF CON Demo Lab. GnawLab is an open-source, community-driven cloud security training platform. It provides high-fidelity sandbox environments reflecting real-world flaws, enabling players to execute realistic scenarios and vividly master cloud exploitation and analysis.

At DEFCON, my goal isn't just to show what I've built. I want to share this sandbox, break it alongside you, and absorb the brilliant, diverse approaches of world-class hackers. I am here to hack, learn, and grow together.

SpeakerBio:  HyunJun "Beaver King" Kwon

HyunJun Kwon is an Application and Cloud Security Engineer with 12 years of offensive security experience. Currently at Rapport Labs in Korea, he previously led vulnerability assessments, DevSecOps, and cloud security initiatives at Woowa Brothers, the company behind Baemin, South Korea's largest food delivery platform.

He serves as an AWS Community Builder for security and leads the Beaver Dam Community, an offensive cloud security research group. He also contributes to AWS Bedrock Agent Samples and mentors junior security professionals through programs like Baby Beavers, K-Shield Junior, and Whitehat School.

His cloud security research focuses on scaling security in dynamic environments. He built automated CCE assessment systems using AWS VPC Endpoints and Systems Manager. Recently he explored AI and security intersections, building LangChain and LangGraph agents for infrastructure assessment automation and MCP security checkers to detect supply chain risks.

He won the 2021 HDCON Grand Prize for cloud security architecture and authored two books on web hacking. He spoke at .HACK 2025 on Offensive Cloud Security and at .HACK 2026 on whether CloudTrail and GuardDuty are really enough.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 15:10-15:30 PDT


Title: Go with the Flow: Riding GCP Dataflow Shadow Dependency to Cross-Tenant Compromise
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 15:10 - 15:30 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Cloud resources rely on a web of trust that most security teams ignore. Even if you secure access to a resource, you might miss its "shadow dependencies" - the external, system-generated resources required for it to function.

GCP Dataflow is just the latest in a long trail of vulnerable services suffering from this architectural blind spot. What we found is a fundamental flaw in how Dataflow blindly trusts dependencies located far outside its IAM control and security boundaries.

In this talk, we’ll present two novel attack techniques that weaponize unvalidated config files to hijack trusted data pipelines. We’ll also demonstrate a critical cross-tenant vulnerability that extends this issue by enabling manipulation of Dataflow orchestration across tenant boundaries. The issue remains under responsible disclosure and is expected to be fixed before the presentation.

Background: GCP Dataflow and Managed Infrastructure

Organizations running large-scale enterprise data workloads increasingly rely on managed data-processing services, especially GCP Dataflow. Built on Apache Beam, Dataflow executes unified data pipelines while removing much of the operational burden of provisioning cluster frameworks, tuning virtual machines, and scaling infrastructure in response to demand. Teams define the pipeline, and Dataflow provisions and scales the underlying compute resources automatically.

During this orchestration, however, Dataflow pipelines often depend on objects stored in standard cloud storage buckets to control execution, such as code, templates, and environment configuration.

Pipelines routinely ingest and execute files from cloud buckets, including JavaScript or Python User Defined Functions (UDFs) for runtime transformation, structured YAML job templates that define pipeline parameters, and other environment configuration files.

Because these files and their supporting temporary assets are often managed through automated developer pipelines, they can become "shadows": overlooked in routine asset inventories and security posture reviews, yet still critical to the execution of highly trusted cloud workflows.

Key Takeaways

Dismantling the shadow resources blind spot: Understand how automated cloud orchestration creates short-lived access windows that can evade scheduled security scans and routine asset inventories.

Auditing the infrastructure-as-config attack surface: Learn to treat external execution blueprints as active attack surfaces rather than passive configuration files.

Applying defensive best practices: Take away architectural recommendations for designing pipelines that are more resilient to these attack paths.

Session Details

Total duration: 20 minutes

5 minutes: Background on shadow resources and Dataflow mechanics.

10 minutes: Walkthrough of the attack paths and the cross-tenant vulnerability.

5 minutes: Research methodology, defensive takeaways, and detection strategies.

Speakers:Gil Weizman,Tamir Yehuda

SpeakerBio:  Gil Weizman

Gil Weizman is an experienced security researcher with over ten years of expertise across on‑prem, cloud, web, and SaaS security. Gil focuses on threat detection, product security research, vulnerability research and identifying gaps in security visibility across modern environments. Gil specializes in translating real‑world attacker behavior into improved detection and mitigation strategies.

SpeakerBio:  Tamir Yehuda

Tamir Yehuda is a Senior Security Researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows & AD domains, SaaS applications, and cloud infrastructure. Tamir specialize in IaaS & PaaS research focusing mainly on Azure, GCP, AWS, Salesforce, and ServiceNow. He brings over eight years of experience in various types of security research and red teaming.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 13:00-13:45 PDT


Title: Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Malware | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Modern GPUs have become foundational to computing infrastructure for gaming, machine learning, and AI workloads at scale, yet GPU memory remains a largely unmonitored attack surface. No mainstream antivirus or endpoint-detection solution currently inspects it, creating a significant blind spot that sophisticated adversaries can exploit. This Demo Lab presents a novel technique that uses NVIDIA RTX 5090 CUDA APIs to stage payload data, such as DLLs, directly in GPU memory, entirely outside the visibility of host-based security tools, including Windows Defender. A benign executable, with no malicious code of its own, uses CUDA's native memory transfer capabilities to move binary payload data onto the GPU immediately upon execution. No CUDA Toolkit installation is required on the target host. When triggered, the same executable retrieves the payload from GPU memory, manually maps it into process space, and executes it. A working proof of concept has been validated as an Empire C2 module, confirming practical operational viability. The technique is particularly impactful for high-uptime environments such as AI inference servers, rendering farms, and enterprise GPU clusters, where small executables interacting with the GPU blend naturally into background workloads.

Speakers:Gannon "Dorf" Gebauer,Anthony "Coin" Rose,Hana Christensen

SpeakerBio:  Gannon "Dorf" Gebauer

Gannon "Dorf" Gebauer is a second lieutenant in the United States Air Force pursuing a master's in computer science at the Air Force Institute of Technology. He earned a Bachelor of Science in Computer Science from Arizona State University. His expertise spans red team operations, reverse engineering, and offensive tool development, and his current research focuses on novel persistence techniques that abuse GPU memory as an unmonitored attack surface.

SpeakerBio:  Anthony "Coin" Rose

Dr. Anthony "Coin" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

SpeakerBio:  Hana Christensen

Hana Christensen is a second lieutenant and developmental engineer (electrical) in the United States Air Force. She is currently pursuing a master's in electrical engineering, with a focus on signal processing and machine learning. Her research investigates security vulnerabilities in AI hardware, examining whether side-channel analysis can be used to extract information about machine learning algorithms. She holds a B.S. in Electrical and Computer Engineering from the United States Air Force Academy (class of 2025).


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 17:00-17:59 PDT


Title: Gotta Catch 'Em All: How To Capture 3.5 Billion WhatsApp Accounts
Tags: DEF CON Official Talk | Exploit 🪲
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Contact discovery on instant messengers is designed to help users find their friends. But when identifiers are predictable and safeguards are weak, it allows attackers to find everyone. At that point, "catching 'em all" stops being a slogan and becomes an engineering problem.

In this talk, we show how we turned WhatsApp into a global Pokédex. By combining reverse-engineered API access with large-scale phone number generation, we probed tens of billions of candidates and identified over 3.5 billion active WhatsApp accounts --- all from a single machine, without raising flags and getting blocked.

Beyond simple presence checks, enumeration exposes rich metadata, including profile pictures, public keys, device information, timestamps, and user-defined about tags. This enables both macroscopic insights into global platform usage and profiling of individual users.

Our analysis uncovers systemic issues, such as persistent exposure of numbers from historical data leaks and reuse of cryptographic keys across accounts. Moreover, we expose signals of criminal activity (e.g., drug dealers and scam factories), and measurable activity in regions where WhatsApp is officially restricted (e.g., North Korea).

At global scale, small design decisions become big problems. This is what allowed us to complete our 3.5B-sized Pokédex.

https://github.com/sbaresearch/whatsapp-census

Paper: Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy, Gegenhuber et al., NDSS 2026

Speakers:Maximilian Guenther,Gabriel Gegenhuber

SpeakerBio:  Maximilian Guenther, SBA Research

Max Guenther is master student at University of Vienna. He is a cybersecurity nerd and research engineer at XBow. Previously, he was security analyst at Austrian Power Grid and security researcher at the Austrian Armed Forces.

SpeakerBio:  Gabriel Gegenhuber, University of Vienna

Gabriel is working on measuring cellular networks, mobile communication and the Internet. In recent years, his research has examined security and privacy issues in global instant messaging platforms that use end-to-end encryption, such as WhatsApp and Signal. He completed his bachelor's and master's degrees at TU Wien and his PhD at the University of Vienna. He is currently a postdoctoral researcher at IT:U Linz.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 11:00-12:59 PDT


Title: Governing the Firehose: Writing Custom OPA Policies to Tame and Remediate Prowler Output
Tags: Cloud Village | Creator Event/Activity | Strategic Defense
When: Friday, Aug 7, 11:00 - 12:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) B - Map

Description:

When you run an opensource CSPM tool like Prowler across an cloud environment, you don’t get an audit; you get a tsunami of raw data. Sifting through thousands of JSON lines to determine what actually poses an active threat to your specific architecture is where most cloud defense pipelines break down.

In this 2-hour handson workshop, I’m going to show you how I bridge the gap between scanning and governance using Policy as Code. We will dive straight into treating Prowler’s raw security findings as structured data input for Open Policy Agent (OPA).

Together, we’ll write custom Rego policies from scratch to parse, filter and logically route Prowler results based on real world business context. I’ll show you how to write policies that evaluate infrastructure as code risk, suppress known risk acceptances safely and isolate critical failures (like exposed storage buckets or unencrypted databases) to trigger automated remediation workflows.

SpeakerBio:  Ram "n2r"

Passionate about Linux, cryptography, and secure SDLC, I love digging into code, threat modeling, and breaking things (responsibly ofc). Whether it’s hardening apps or decoding exploits. I’m all about making software safer - one commit at a time.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 16:30-16:59 PDT


Title: Groking the Kill Chain
Tags: Recon Village | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Most LLM-powered recon tools look impressive in a 90-second demo and fall apart on real targets. They hallucinate, loop, go out of scope, double-fire the same endpoint, or die the moment a WAF or rate limit appears. This talk is about what it actually takes to run fifty-plus specialist agents in parallel for hours or days without the chaos.

We built a system where every agent is locked to the rails: a concrete tool, a strict pipeline phase, explicit prerequisites, timeouts, and sandboxes. The model does not drive. It rides. The binaries (and only the binaries) touch the target. This "Agents on Rails" approach eliminates freestyle LLM behavior while still letting the model do what it is good at—reasoning over evidence.

SpeakerBio:  Anthony Russell, Cyber Security Software Engineer

Anthony Russell, is a senior cyber security engineer with over 13 years of professional experience building software. He has a focus in information security and has been featured in 2600 magazine, on Hak5 and has spoken at both Defcon and DerbyCon multiple times. Favorite things to discuss are blockchain technology, baking custom IoT devices, and everything infosec. You can see more of Anthony's work at SquidHacker.com or Twitter.com/DotNetRussell


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Hac-Man
Tags: Hac-Man | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal)) - Map

Description:

Rogue Signal builds bespoke, technically driven interactive experiences rooted in hacker culture, game design, and immersive storytelling. Drawing from backgrounds in immersive theater, live events production, community building, and deep game design practice, Rogue Signal creates systems that transform participation into exploration.

Rather than relying on superficial gamification, Rogue Signal focuses on meaningful challenge design. Their experiences reward curiosity, experimentation, collaboration, and strategic thinking. From scavenger hunts to technical skill challenges to digital easter eggs, each activation is designed around the specific audience and environment it lives in.

At DEF CON, Rogue Signal brings that philosophy to Hac-Man. A Pac-Man–themed security challenge platform that blends retro inspiration with layered technical depth. Participants will engage directly with structured challenges that test logic, pattern recognition, foundational security and hacker knowledge, and progressively more advanced technical skills.

Hac-Man reflects the hacker mindset: iterate, experiment, fail, refine, break assumptions, and try again. It encourages collaboration where helpful, competition where motivating, and discovery at every level.

Attendees can expect: - Hands-on security challenges - Multiple subject-matter tracks - Layered difficulty levels - Scavenger style discovery elements - Competitive scoring and mission style progression - A welcoming but technically rich environment

Whether you’re new to security or already deep in the field, Rogue Signal’s space offers a place to test your thinking, sharpen your skills, and experience hacking concepts through play.

Participant Prerequisites

Participants will need access to a smartphone, tablet, or laptop in order to access gameplay content and view leaderboards. The experience is web-accessible and designed to function on standard modern devices.

No specialized hardware (e.g., Flipper Zero, SDR, etc.) is required. Foundational familiarity with basic computer use and logical problem-solving will be helpful, but no advanced security knowledge is required to begin. The game features layered difficulty tracks to accommodate both beginners and more advanced participants.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Friday - 14:00-14:45 PDT


Title: Hack the Airwaves – Embedded Wireless for Next-Gen Hackers
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Win an AWOK Dual C5 just by showing up! Join Adventures of Illya for Hack the Airwaves! Explore wireless technology with live demos featuring the AWOK Dual C5, ByteShield, H4M PortaPack, Flipper Zero, ESP32 boards, LoRa, RFID, NFC, and CC1101. Learn how these technologies work, ask questions, and get inspired to build your own projects.

SpeakerBio:  Adventures of Illya
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: Hack The Box DC Junior Ranger Program Challenge
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:
Hack The Box brings its Junior Ranger Program to DEF CON: a beginner-friendly challenge guide built by the Hack The Box team specifically for the Noob Village, modeled after the U.S. National Park Service's Junior Ranger booklets. Work through the challenges in the guide and earn custom Junior Ranger badges as you complete them. Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 11:00-12:59 PDT


Title: Hack the Duck Store
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map

Description:

At a developer meetup on secure software development, we asked a simple question: look at this login form, how could a hacker abuse it? Not one developer in the room dared to answer. The referral code field looked harmless. The backend had no validation: self-referrals, circular referrals, unlimited farming - all possible. It's just the simplest example of how business logic flaws get missed. This card game is built around that gap, showing what business logic vulnerabilities might exist and how the real vulnerabilities, hiding inside the intentionally vulnerable app, Duck Store, can be abused.

Speakers:Gwendal Mognier,Samantha Pearlstein

SpeakerBio:  Gwendal Mognier

Gwendal Mognier is a Security Researcher at Escape. He’s passionate about cybersecurity and always eager to learn new ways to break and secure systems. Gwendal is focused on discovering vulnerabilities and helping improve security across the board.

SpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 15:00-15:25 PDT


Title: Hack the Planet (not ours)
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

What does it take to bounce a signal off Venus and hear it back on Earth? Quite a lot, actually. And we're going to show all of it to you.

In 2008, AMSAT-DL aimed a carrier wave from a dangerously powerful magnetron-based transmitter, located at the Bochum Observatory, at Venus. Four minutes later, they heard an echo. This was the first time amateurs had bounced a signal of any type off of another planet. This is a significant and enduring achievement.

However, a radar signal has no information in it. It's a dead carrier. What does it take to bounce a communications signal off of Venus, and hear it back here on Earth? First of all, the path loss is immense. Then, Venus only returns about 13% of the signal that hits it. And, it's spinning. Information in a signal requires more signal to noise ratio when compared to a dead carrier, nd reflecting off a spinning surface damages information signals in particular ways that stationary reflectors do not.

Venus and Earth encounter each other in their orbits only once every 18 months or so. This is the inferior conjunction of the two planets. Unlike the Moon, frequently used by radio enthusiasts as a reflector, Venus is barely close enough every 18 months for the largest amateur and citizen science dishes to reach. This makes timing, preparation, and coordination equally as important as resolving the technical challenges.

What are the different parts of an Earth-Venus-Earth digital communications system? Which parts make the most difference? What needed to be developed? How did coordination go? What will happen next? Come to the talk and find out how we are going to Hack a Planet.

Quite a lot, actually. And we're going to show all of it to you.

SpeakerBio:  Abraxas3d, CEO ORI

Michelle Thompson, W5NYV, is the CEO of Open Research Institute, a 501(c)(3) nonprofit developing open source digital radio and space communication systems. ORI's work directly benefits the amateur radio and amateur radio satellite services. She served as IEEE San Diego Section Chair and represents ORI on the FCC Technological Advisory Council, including co-chairing the AI/ML Safe Uses Sub-Working Group. Her technical background spans RF engineering, digital signal processing, FPGA development, and satellite communications, with prior industry experience at Qualcomm, Smithville Telephone, and Apiary. She can be reached at w5nyv@arrl.net.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 11:30-12:30 PDT


Title: Hackbots
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 12:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Building AI-Powered Penetration Testing Bots

In this talk, we'll walk through the core design philosophy behind AI hackbots and the architecture that makes them work: single-purpose vs. multi-stage bots, context engineering for targeted prompting, and tool integration with output parsing workflows.

Then we'll get hands-on. We'll live-build a functional hackbot for a common offensive task —demonstrating asset discovery, endpoint analysis, or mutation-focused testing (e.g., XSS/SSRF) — and show how context engineering and hallucination mitigation work in practice against real targets. You'll see where AI genuinely accelerates reconnaissance and web analysis, and where it falls flat if you aren't careful. We'll close with lessons on cost optimization, auditability, and integrating hackbots into actual engagements.

Who should attend: Pentesters and bug bounty hunters with offensive security experience who want to meaningfully integrate AI into their workflow — not as a novelty, but as reliable tooling.

What you'll walk away with: A clear mental model for when and how to build hackbots, a live demo you can replicate, and a path into the full course where you'll build seven production-ready bots from asset discovery through mutation testing.

Speakers:Jason "jhaddix" Haddix,Ryan "BadAt_Computers" Bonner

SpeakerBio:  Jason "jhaddix" Haddix, CEO and "Hacker in Charge" at Arcanum Information Security

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

SpeakerBio:  Ryan "BadAt_Computers" Bonner, Lead Security Engineer, Arcanum Information Security

Ryan is a Lead Security Engineer at Arcanum Information Security. A part-time bug hunter, Ryan has built his career on the offensive side of security, focusing on where AI systems and integrations meet the modern web. He specializes in attacking AI-powered applications, including prompt injection, agent, and integration weaknesses that appear as large language models get wired into real products.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 14:00-15:59 PDT


Title: Hacker Book Club Discussion
Tags: Meetup
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 3 W301 (Misc Meeting Room) - Map

Description:

Community is essential and so is continual learning. Reading books and discussing books can greatly impact an individual’s access and sense of community and knowledge. This Hacker Book Club book discussion will be an accessible group aiming to build community and share out learnings, all in a quieter setting. Come join us and discuss what you’ve been reading. We also run a year round Discord to discuss books throughout the year, hackerbookclub.com. This Hacker Book Club is not locked to a region and is for those who love books and escaping to the cyperpunk, scifi worlds that inspire DEF CON and modern literature.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Hacker Games
Tags: Hacker Games | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 207 (Hacker Games) - Map

Description:

The Hacker Games is a series of hacker skills tests meant to challenge the hacker's knowledge of computer systems such as Binary -> Hex -> X conversion, Adapter -> Adapter knowledge, Keyboard Layout, and many more arbitrarily useless skills. Hackers will go head-to-head in a series of several skill-based games. BinHexAscii, Chopstick Challenge (a.k.a. Will it Flow), Keyboard Layout, Adapt or Die, ToS, and more! Can you hack it?

Participant Prerequisites

A box of computer-style adapters of no particular order would be very helpful.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 20:00-21:59 PDT


Title: Hacker Jeopardy
Tags: Event | Hacker Jeopardy!
When: Friday, Aug 7, 20:00 - 21:59 PDT
Where: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 20:00-00:59 PDT


Title: Hacker Karaoke
Tags: Party
When: Friday, Aug 7, 20:00 - 00:59 PDT
Where: LVCCW Level 2 W229, W232 - Map

Description:

Two great things that go great together! Join the fun as your fellow hackers make their way through songs from every era and style. Everyone has a voice and this is your opportunity to show it off! Everyone is encourage to participate in a DEF CON tradition from all folks and skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 10:00-11:59 PDT


Title: Hacker Runway Crafting Time
Tags: The Diana Initiative | Hack3r Runw@y v8.0 | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

Hacker Runway Crafting time - didn't have time, or didn't know about the Hacker Runway competition? Have no fear we have some supplies to help you put together a last moment entry! Make sure to stop by the DC Maker Village as well!


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Friday - 16:00-16:59 PDT


Title: Hackers Trivia
Tags: Hackers.town | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
Speakers:RemoteNemesis,Medus4

SpeakerBio:  RemoteNemesis
No BIO available
SpeakerBio:  Medus4
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: HackFortress
Tags: HackFortress | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 108 (HackFortress) - Map

Description:

HackFortress is back! Returning to DEF CON with a twist on our standard format. Two teams of players, 6 gamers and 4 hackers each, compete in a mashup of a jeopardy style CTF and a first person shooter. New this year, we're replacing our previous FPS of Team Fortress 2 with a web based version of the 2000's classic Quake 3!

While gamers are rocket jumping and sniping each other in Quake, hackers will be solving challenges in a variety of areas: web security, network security, cryptography, lock picking, social engineering, and more! Challenges range from beginner to advanced, from serious to absurd. During the competition, as both sides of the team star scoring points, the teams also earn points in the HackFortess HackConomy Store, in the store hackers can buy in game effects, both offensive and defensive, and much like the challenges, these effects range from serious to absurd.

With all of the contest being web based, both hacking and Quake, players MUST bring their own laptop (or whatever device they want to use) and a wired network adapter.

Grab your friends!

Ask that random stranger standing next to you in Linecon if they want to join your team!

Come play HACKFORTRESS!

Participant Prerequisites

All players will need to bring a laptop and wired network adapter. Since we are now using web based version of Quake 3 (which can run on players phones), we are no longer providing any gaming laptops.

Gamers: bring any gaming accessory of your choice, its your hardware, go for it

Hackers: bring lockpicks


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 17:00-17:59 PDT


Title: Hacking AI
Tags: DEF CON Official Talk
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Humans are hacking AI systems. Humans are hacking with AI systems. But also, AIs are hacking human systems. They’re finding and exploiting vulnerabilities in computer code, and they’ll soon be doing the same with all sorts of other codes. For example: the tax code can be hacked. Vulnerabilities are called loopholes, exploits are called tax avoidance strategies, and black hats are called accountants. Similarly, financial markets can be hacked. So can any system of rules or laws, including democracy itself. AIs will hack these systems at our request, and they’ll also do this innately, organically – and possibly in ways we don’t immediately see. We need to consider a world where increasingly sophisticated hacks or our social, economic, and political systems are discovered computer speeds, and then exploited at computer scale and scope. Right now, our systems of patching these systems operate at a human pace, which won't be good enough.

https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html

SpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 13:30-13:59 PDT


Title: Hacking Airplanes at the NTSB
Tags: Aerospace Village | Creator Talk/Panel
When: Friday, Aug 7, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

NTSB Vehicle Recorder Specialists Jonathan Xue and David Case will give a talk on decoding data recovered from several aircraft accidents, and a tourist submarine raised from the depths of the North Atlantic. The NTSB's process for getting data out of broken and damaged equipment will be shown, including searching through gigabytes of random data to find a log, and then converting that data to something human readable. Jonathan and David specialize in converting undocumented binary data recovered from accidents into graphs and charts usable in investigation. Quite often, they are the first people to see what actually happened in an accident.

Speakers:David Case,Jonathan Xue

SpeakerBio:  David Case, NTSB
No BIO available
SpeakerBio:  Jonathan Xue, NTSB
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Hacking Android and IOT Apps by Example
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
Speakers:Abraham Aranguren,Abhishek J M,Anirudh Anand

SpeakerBio:  Abraham Aranguren
No BIO available
SpeakerBio:  Abhishek J M
No BIO available
SpeakerBio:  Anirudh Anand
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Hacking Android and IOT Apps by Example
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
Speakers:Abraham Aranguren,Abhishek J M,Anirudh Anand

SpeakerBio:  Abraham Aranguren
No BIO available
SpeakerBio:  Abhishek J M
No BIO available
SpeakerBio:  Anirudh Anand
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 13:00-14:30 PDT


Title: Hacking Android Apps in a Structured Way
Tags: Mobile Hacking Community | Creator Event/Activity
When: Friday, Aug 7, 13:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

Mobile app testing has many pitfalls and a structured approach is needed to get a holistic picture of the attack surface. The OWASP Mobile Application Security (MAS) project is able to support you with that. In this workshop, you'll get a practical introduction to the MAS ecosystem which consists of the standard, mobile weaknesses and how to test them. You will experience test cases and demos for Android in action for static and dynamic analysis, and learn how to perform a mobile penetration test.

By the end of the workshop, attendees will be able to: - Navigate the OWASP Mobile Application Security (MAS) project (MASVS, MASWE, MASTG) and locate relevant test cases for their own engagements. - Apply a mix of static and dynamic analysis techniques against real Android apps. - Use the right tooling (e.g. frida, semgrep, APKLeaks, jadx, AI-assisted reverse engineering) in their pentest workflow.

Instructions: https://github.com/sushi2k/defcon34-android-workshop

Prerequisites: a laptop with 10 GB free disk space; GitHub account and git installed.

SpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

--

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Hacking Cryptography
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:
Speakers:Ruben Gonzalez,Aaron Kaiser

SpeakerBio:  Ruben Gonzalez, Neodyme

Crypto PhD, Security Researcher and Trainer at Neodyme

SpeakerBio:  Aaron Kaiser
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Hacking Cryptography
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:
Speakers:Ruben Gonzalez,Aaron Kaiser

SpeakerBio:  Ruben Gonzalez, Neodyme

Crypto PhD, Security Researcher and Trainer at Neodyme

SpeakerBio:  Aaron Kaiser
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

.EDU Community - Friday - 14:00-14:59 PDT


Title: Hacking Education - Teaching Offensive Cyber Science at the Collegiate Level
Tags: .EDU Community | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map

Description:
SpeakerBio:  Dave "Rebelcadet" Ortiz

David Ortiz is the Chief Technology Officer (CTO) at X8 LLC, where he leads the firm's engineering efforts to develop innovative technical, operational, and research solutions to meet complex customer requirements. With a diverse background in laser physics, information assurance, cyberspace operations, and organizational leadership, David is a seasoned professional dedicated to advancing cyber capabilities for both the U.S. Government and private industry customers.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-10:30 PDT


Title: Hacking Electronic Conspicuity Devices -or- Making Light Aircraft Fly Into Conflict
Tags: Aerospace Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Commercial aircraft have Traffic Collision and Avoidance Systems, or TCAS, to ensure they don’t fly in to each other, but these are very expensive systems. How do General Aviation aircraft find a way to avoid each other?

Enter ‘Electronic Conspicuity’ devices: small, light and cost effective sensors to detect other aircraft and alert GA pilots before they can be seen by the naked eye.

Unfortunately, in the rush to improve flight safety and situational awareness in GA, cyber security has taken something of a back seat. As a result, some of these EC devices have trivial and not-so-trivial security flaws. In some cases, it is possible to delete Traffic Advisories and/or give an incorrect Resolution Advisory, bringing planes in to conflict with each other, rather than ensuring they stay safely apart.

SpeakerBio:  Ken Munroe
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Hacking GRC Contest
Tags: Hacking GRC | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: Online

Description:

Hacking CMMC is a hands-on cybersecurity competition designed to immerse participants in the practical aspects of the Cybersecurity Maturity Model Certification (CMMC). Through realistic, challenge-based scenarios, players explore common compliance gaps, security controls, and threats faced by defense contractors.

The CTF blends technical problem-solving with compliance-driven thinking, helping participants understand how security requirements translate into real-world incidents. It offers an engaging way to learn, test skills, and strengthen readiness for CMMC-aligned environments.

The CTF will be a Jeopardy-style CTF where every player will have a list of challenges in different categories. For every challenge solved, the player will get a certain number of points depending on the difficulty of the challenge.

Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 17:30-17:59 PDT


Title: Hacking Hearts by Reverse Engineering Pacemaker Firmware
Tags: Biohacking Village | Creator Talk/Panel
When: Friday, Aug 7, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Gradually we are all becoming more and more dependent on connected technology. We will be able to live longer with an increased quality of life due to medical devices and sensors attached to, or integrated into our bodies. However, our dependence on technology grows faster than our ability to secure it, and a security failure of a medical device may cause patient harm and have fatal consequences.

This presentation dives into the security architecture of the Biotronik pacemaker ecosystem, covering the pacemaker, home monitoring units, and external programmer. Using a hybrid of black-box and white-box methodologies, we deconstruct the firmware and wireless communication protocols to identify vulnerabilities in a pacemaker that one of the presenters was depending on with their life for 11 years. We will discuss the challenges of extracting firmware from life-critical hardware and the implications of discovered bugs on patient safety. Attendees will leave with a better understanding of how to reverse engineer proprietary medical ecosystems and why securing the "Internet of Medical Things" is a race we cannot afford to lose.

Speakers:Marie Moe,Shayan Alinejad,Kristian Karlsen

SpeakerBio:  Marie Moe

Dr. Marie Moe is a Principal Consultant at Mandiant (now part of Google Cloud), and has a PhD in information security. She is a part-time Associate Professor at NTNU. In this talk she will be joined by NTNU MSc students Shayan Alinejad and Kristian Karlsen.

SpeakerBio:  Shayan Alinejad
No BIO available
SpeakerBio:  Kristian Karlsen
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 16:00-16:59 PDT


Title: Hacking Human-in-the-Loop systems
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:
Customer support has always been a numbers game: high message volume, repetitive questions, and constant pressure to respond faster. Most organisations handle this through ticket portals, shared mailboxes or live chat tools. These systems were built around people reading messages and people taking action. That model is disappearing. To keep up with demand, support platforms now embed AI agents that read incoming messages, suggest replies, search internal knowledge pages and even interact with backend systems. They reset accounts, schedule refunds, modify settings and verify users before a human ever looks at the conversation. The human is still in the loop, but rarely in full control. Connecting a language model to business logic has a side effect. It turns text into a control layer. Messages no longer just inform a conversation; they influence actions. If an attacker can shape those messages, they can shape what the agent does. In security terms, that creates a new attack surface that did not exist when humans handled every request. This session examines how that surface is exploited in practice. The findings come from real vulnerability reports against production AI support systems that accept contact from the public. The attacks require no insider access. They target the assumptions that connect users, agents and operators, and they convert helpful automation into unintended system access. The examples that follow show how the trust built into these systems can be bent until it breaks.
SpeakerBio:  Inti "securinti" De Ceukelaire, Founding Member, Intigriti

Intigriti is a Founding Member at Intigriti and their former Chief Hacker Officer. As a hacker, Inti has won multiple awards in live hacking competitions from Bugcrowd and HackerOne. Inti specialises in AI-hacking techniques, logic flaws and support systems, and is most known for the "Ticket Trick" methodology that has earned a spot in Portswigger Top Web Hacking Techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 10:30-11:30 PDT


Title: Hacking IDE Extensions - VSCode Workshop
Tags: Bug Bounty Village | Creator Workshop
When: Friday, Aug 7, 10:30 - 11:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

IDE extensions are a lucrative slice of the modern bug bounty scope. They run with privileged capabilities, parse arbitrary workspace files, and increasingly ship LLM backed agentic features that execute commands, edit files, and follow instructions found in the project under review. AI assistants have become an exploit chain accelerator: agents touch every stage from file ingestion to primitive acquisition to escalation, often with minimal sandboxing. This workshop turns those ideas into hands on practice. Attendees install "Nopilot", a deliberately vulnerable mock AI assistant VS Code extension, learn how to debug it, review code for bugs, and chain primitives from "user opened a folder" to code execution that requires no further interaction and bypasses workspace trust entirely. Built around a generalized IDE exploitation killchain and drawn from a multi-six-figure IDE bug bounty practice. Bring a laptop and curiosity. Read the full description here: https://gist.github.com/nickcopi/daf5b24b262c802830ab6c1ef9d5d49d

SpeakerBio:  Nick "7urb01" Copi

Nick Copi is a full-time bug bounty hunter targeting web applications, cloud infrastructure, desktop apps, and pretty much anything with an attack surface. His background spans application security engineering, full-stack development, and a long track record of local CTF competition wins. He has presented several technical talks at security conferences and regularly publishes and reviews security research. He really likes JavaScript. Maybe too much. Maybe someone should check on him.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 16:00-16:59 PDT


Title: Hacking the EOD Bot: How I Learned to Stop Worrying and Love the Boomba
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

What happens when you wander into a surplus store and walk out with a bomb disposal robot? You name him “Boomba” and tear him apart. Built by Roomba creator iRobot, the PackBot is often used by agencies who need to deploy a small, ruggedized robot in potentially dangerous locations. But beneath its rugged shell lies a fascinating time capsule of early 2000s engineering. As the platform's physical capabilities evolved to meet extreme operational demands, its core software trailed behind, relying on legacy hardware and an architecture built before modern security controls. This talk is a full-stack teardown of a six-figure tactical asset. We'll explore its 25-year evolution: mapping undocumented interfaces, fabricating custom cables, and replacing legacy 4.9 GHz restricted-band radios with custom hardware. We will dive into the software to expose unencrypted VPN connections and entirely plaintext Python 2.5 control protocols. We will also demonstrate vulnerabilities that grant full root access. Finally, we’ll decompile its modern tablet control app, breaking down the JAUS protocol to reveal a critical command injection vulnerability. With a live PackBot on stage, we’ll intercept telemetry, pop the LFI, and eavesdrop on network traffic. Watch Boomba get turned back into a vacuum, and catch him later at the Car Hacking

Speakers:Patrick "gigstorm" Kiley,Emily "@astradotpng" Astranova

SpeakerBio:  Patrick "gigstorm" Kiley, Google

Patrick Kiley is a Security Consultant doing embedded security testing and has over 20 years of information security experience. Patrick has performed research in avionics security, vehicles, and even managed to brick his Tesla making it go faster. Patrick has a patent pending on a embedded security access tool and loves tearing things apart while figuring out how they work.

SpeakerBio:  Emily "@astradotpng" Astranova, Google

Emily is a security consultant doing physical security testing, covert entry and penetration testing of all the things. Emily has intentionally compromised US power grid systems, unintentionally compromised data centers and has somehow managed to keep her record to only one run-in with the FBI. In her spare time, Emily volunteers as a software and cybersecurity mentor for high school students as a part of FIRST Robotics.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:30-12:59 PDT


Title: Hacking the Government: How Two Researchers Turned Late-Night Boredom Into a National Audit
Tags: DEF CON Official Talk
When: Friday, Aug 7, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

What happens when two researchers spend several days scrutinizing the Polish web? We didn’t just find anomalies—we took action. Join us as we reveal the results of our intensive research, which led to multiple official reports to CSIRT GOV, NASK, and MON. We will walk you through our findings, the scale of the threats discovered, and provide essential recommendations for a more secure digital future.

Speakers:Robert "ProXy" Kruczek,Kamil Szczurowski

SpeakerBio:  Robert "ProXy" Kruczek, Securitum

I am a Cybersecurity Consultant, Mentor, and Ethical Hacker (known in the infosec community as ProXy) at Securitum - Poland's leading cybersecurity firm - and a contributor to sekurak.pl, the country's largest infosec portal. With over 10 years of experience in vulnerability research and penetration testing.

Operating under the ProXy alias, I discovered and reported 43 CVEs and I am an active Bug Bounty hunter (Hall of Fame at OLX, reports for BlaBlaCar, OVH, and ERCOM).

SpeakerBio:  Kamil Szczurowski, Securitum

On a daily basis, Kamil Szczurowski specializes in web application security testing and social engineering assessments. In his free time, he analyzes malware, APT campaigns, open-source software, and software used by government institutions, which has resulted in multiple CVE entries and publications. He is also an author of articles published on sekurak.pl.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 15:00-15:59 PDT


Title: Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Underground VPN Infrastructure
Tags: DEF CON Official Talk
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Underground VPN and tunneling ecosystems are widely used to monetize compromised servers and sell “free internet” access through SSH, SOCKS, and multi-protocol tunnels. These operations rely heavily on open-source infrastructure management tools deployed on rented or hacked Linux servers. But what happens when the tools themselves are weaponized?

In this talk we dissect FirewallFalcon Manager, a VPN/SSH server management toolkit widely promoted in Telegram communities. While it presents itself as a legitimate open-source platform, our analysis reveals a multi-layered supply-chain attack targeting the very operators who deploy it.

FirewallFalcon silently installs backdoors, injects a rogue TLS root certificate, hijacks DNS resolution, and redirects proxy traffic through attacker-controlled infrastructure to enable large-scale Man-in-the-Middle interception. Earlier versions also deployed a Telegram reconnaissance bot and a universal SSH backdoor granting root access to infected servers.

Using reverse engineering, GitHub history analysis, DNS infrastructure mapping, and large-scale internet scanning, we uncovered hundreds of active servers inside this compromised ecosystem. This talk exposes a new class of supply-chain attacks: hackers hacking the infrastructure used by other hackers.

SpeakerBio:  Assaf Morag, Flare

Assaf Morag is a Cybersecurity Researcher and Threat Intelligence Consultant, working with various companies on research focused on underground ecosystems, attacker infrastructure, and the evolving cyberthreat landscape. His work translates adversary activity from open, deep, and dark-web sources into actionable intelligence for security teams and the software development life cycle. Previously, Assaf served as Director of Threat Intelligence at Aqua Security and held senior intelligence roles at BlueVoyant and IBM Security. His research has been featured in leading cybersecurity publications and presented at major industry conferences. He contributed to the MITRE ATT&CK® Container Framework and authored an O'Reilly course on cloud-native cyber threat intelligence.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Friday - 11:30-11:59 PDT


Title: Haetae: An Agent to Takedown North Korean C2 Servers
Tags: Adversary Village | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.

Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.

In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.

We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.

This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters.

Speakers:Mauro Eldritch,Nelson Rafael Colón Merán

SpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team

Hacker and Speaker.

Founder of BCA LTD and DC5411.

I wrote a book interviewing Threat Actors.

I like Threat Intelligence and Golden Retrievers.

SpeakerBio:  Nelson Rafael Colón Merán, Security Engineer at Bitso

Security Engineer at Bitso, Latin America's leading crypto-first financial platform. I've specialized in red team operations, penetration testing, and malware development.

Recognized speaker in the Dominican Republic's RedTeamRD cybersecurity community, where I've given a couple talks and previously assisted DEFCON as a speaker.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 16:00-17:59 PDT


Title: Haetae: An Agent to Takedown North Korean C2 Servers
Tags: Red Team Village | Misc
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.

Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.

In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.

We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.

This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters.

Speakers:Mauro Eldritch,Nelson Rafael Colón Merán

SpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team

Hacker and Speaker.

Founder of BCA LTD and DC5411.

I wrote a book interviewing Threat Actors.

I like Threat Intelligence and Golden Retrievers.

SpeakerBio:  Nelson Rafael Colón Merán, Security Engineer at Bitso

Security Engineer at Bitso, Latin America's leading crypto-first financial platform. I've specialized in red team operations, penetration testing, and malware development.

Recognized speaker in the Dominican Republic's RedTeamRD cybersecurity community, where I've given a couple talks and previously assisted DEFCON as a speaker.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Friday - 13:00-13:59 PDT


Title: Ham Radio Isn’t Magic: Preppers, Sad Hams, and Practical Off-Grid Communications
Tags: Ham Radio Village | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

This talk approaches off-grid communications as a practical systems problem, informed by the author’s real-world operation of portable and off-grid radio systems rather than theory or gear marketing. Rather than teaching amateur radio as a hobby, it reframes off-grid communications using failure-mode analysis and systems design principles familiar to the security and hacking community. While the question “How do I talk 500 miles when the grid is down?” is a common starting point, the deeper issue is how communication systems behave when infrastructure is absent, degraded, or intentionally avoided — and why many well-intentioned plans fail in practice.

The presentation is structured as a 101-level introduction for a technically curious audience. It assumes no prior amateur radio experience, but it does assume interest in understanding constraints, tradeoffs, and failure modes the same way hackers evaluate any other system operating outside ideal conditions.

The talk opens by examining real examples from off-grid and preparedness communities, including common questions and the unhelpful responses they often attract. This framing establishes the core thesis: both “prepper fantasy” and “sad ham” gatekeeping optimize for the wrong constraints and lead to brittle designs that fail when conditions are imperfect.

From there, the talk builds a mental model of off-grid radio communications grounded in physics and operational reality. Attendees are introduced to why radio performance is probabilistic rather than guaranteed, why a fixed distance like “500 miles” is a misleading requirement, and how factors such as propagation, noise floor, antenna efficiency, duty cycle, and coordination dominate outcomes more than transmitter power or radio model. Real failure modes are discussed, including HF voice links failing when expected to work, digital modes succeeding where voice does not, antenna quality overwhelming other variables, high-noise environments negating otherwise capable setups, and situations where increasing power does not meaningfully improve reliability.

The scope then expands beyond emergencies to everyday off-grid use cases hackers actually encounter: group communications while hiking or camping without cell coverage, portable and battery-powered operation, short-range mesh and store-and-forward systems such as Meshtastic, and longer-range low-bandwidth HF messaging. Activities like Parks on the Air, Summits on the Air, and Field Day are presented not as hobbies, but as structured opportunities for exploration and experimentation — real-world environments for testing antennas, power systems, logistics, and coordination under off-grid constraints.

Rather than focusing on specific products or modes, the talk emphasizes design principles that consistently work: simple plans over clever ones, redundancy across bands and modes, asynchronous messaging over real-time voice, and communication plans that account for human behavior as a primary constraint. Regulatory considerations are covered at a practical level to help attendees understand what is possible and appropriate without turning the talk into a licensing lecture.

If appropriate for the venue, the talk may include a short demonstration or case study illustrating propagation variability or the effectiveness of low-bandwidth digital techniques compared to voice. Any demonstration will be designed with realistic fallback options and framed as illustrative rather than guaranteed.

The goal of this talk is not to turn attendees into radio experts, but to give them a reusable framework for thinking about off-grid communications the way hackers think about resilient systems: define the actual problem, understand how and why things fail, and design solutions that work in imperfect, real-world environments.

Every hacker has seen the post: someone asks what radio will let them “reliably talk 500 miles to family when the cell network goes down.” The replies quickly devolve into bad advice, magical thinking, and dismissive gatekeeping. The result is confusion, wasted money, and false confidence about off-grid communications.

This talk is the antidote.

We’ll cut through the mythology and explain what amateur radio can actually do for personal and family communication during major disruptions — and what it cannot. Starting at a 101 level, we’ll cover realistic ranges, basic propagation, equipment tradeoffs, digital modes, licensing myths, and why distance is usually the wrong requirement.

Rather than dunking on preppers or policing fun like a sad ham, this talk reframes the problem the way hackers do: understanding constraints, failure modes, and human factors.

We’ll focus on practical off-grid communication strategies that work in the real world — coordination, redundancy, and low-bandwidth messaging — not fantasy continent-spanning voice links.

SpeakerBio:  Andrew Ohnstad - N3OCQ

Andrew has spent 25 years designing large-scale IT systems. He grew up alongside the birth of the internet, building his own computers, running a BBS, and taking electronics apart to understand how they worked. His interests remain firmly hands-on, focused on hardware tinkering and RF. He’s been a licensed amateur radio operator since 1993, holds an Amateur Extra license, and is active from VHF/UHF through 160 meters.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 11:00-11:10 PDT


Title: Ham Radio Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 11:00 - 11:10 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Ham Radio Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Ham Radio Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Using tools like OpenOCD and Segger J-Link Mini, we’ll guide you through modifying the boot 'init=' process in memory via JTAG, forcing the device into a single user mode shell via UART.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 10:00-12:30 PDT


Title: Hands-On Supply Chain Recon & Vendor Risk Mapping
Tags: Recon Village | Creator Workshop
When: Friday, Aug 7, 10:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Every organization relies on third-party vendors, open-source packages, and CI/CD tools to build and deliver software. In this session, we'll learn how to identify and map these external dependencies, understand the trust relationships between them, and discover potential security risks. Through practical demonstrations, attendees will see how issues such as dependency confusion, insecure GitHub Actions workflows, and vendor-related weaknesses can become entry points for supply chain attacks. The goal is to help security teams find and fix these risks before attackers do.

Speakers:Dhiyaneshwaran Balasubramaniam,Aman Rawat

SpeakerBio:  Dhiyaneshwaran Balasubramaniam
No BIO available
SpeakerBio:  Aman Rawat
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Friday - 12:00-12:59 PDT


Title: Hardhat How-to
Tags: Maker's Village | Hard Hat Brigade | Creator Event/Activity
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Do you like hats? Hard Hat Brigade likes hats! Come hang with MrBill and m0nkeydrag0n as we work on building a hard hat and problem solve the build together. See you soon!

Speakers:m0nkeydrag0n,MrBill

SpeakerBio:  m0nkeydrag0n
No BIO available
SpeakerBio:  MrBill
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Friday - 15:15-15:45 PDT


Title: Hey Adversary, I’ve Got a Human EDR Bypass for You…
Tags: Adversary Village | Creator Talk/Panel
When: Friday, Aug 7, 15:15 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:
Subtitle: The Scout's Field Guide to human risk telemetry: Weaponizing complacent corporate conditioning, tracking the legacy Human EDR, and surviving the wilderness.

Enterprise security leadership is currently suffering from a dangerous cognitive bias: confusing compliance with operational resilience. When an organization achieves a "1.5% phishing click-rate," the board celebrates under the illusion that their perimeter is secure. But to an advanced adversary, that dashboard isn't a shield it’s a deterministic roadmap of the target’s behavioral heuristics.

Framed as a retro-futuristic, illustrated Scout's Field Guide, this talk exposes how advanced Red Teams and APT actors reverse-engineer corporate human risk telemetry to achieve rapid initial access without advanced code. We will dissect how standardized training inadvertently programs a rigid "Human EDR" based on static signatures, and how operators can fly beneath the radar by simply omitting what the user has been conditioned to look for.

Furthermore, we will unlock a highly unique, unexplored exploitation vector: Behavioral Inheritance (The Legacy Human EDR). Attendees will learn how to conduct passive OSINT on a high-value target’s professional history to predict their automated reactions, weaponizing the cognitive conditioning they inherited from their previous employers to bypass structural controls during their onboarding window.

Instead of chasing compliance or deploying new tools, this presentation concludes by turning offensive telemetry into zero-cost tactical defense. We will demonstrate how to evolve from static detection to pure behavioral resilience by implementing "Interrupt Protocols" to break an attacker's live performance, and adopting a "No-Fault Reporting" culture to drastically reduce adversary dwell time. We are unifying Red Team tradecraft with existing human telemetry to survive the corporate wilderness using the adversary's own playbook against them.

SpeakerBio:  Daniel Isler, Awareness & Social Engineering Consultant - Team Leader - SEK

Daniel Isler, holds a Bachelor's degree in Performing Arts, weaponizing his background in theatrical representation, pretexting, and human behavior to reverse-engineer corporate conditioning. Active in the offensive security field since 2015, he serves as the Team Leader of Fr1endly RATs, the specialized social engineering and initial access for Red Team unit at SEK. Certified in OSINT, Red Team, and Social Engineering, he has spent nearly a decade architecting both high-fidelity tactical intrusions and enterprise Awareness service lines. His unique approach relies on a multidisciplinary, highly creative team of elite operators who strictly design and deliver educational content based on the advanced threat techniques they actively execute in the field.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 11:40-11:50 PDT


Title: HHV/SSV Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 11:40 - 11:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting HHV/SSV but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to HHV/SSV and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 14:00-14:45 PDT


Title: How to Epically Fail Your PCI Assessment
Tags: Payment Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

If your company accepts, processes, stores, transmits, dreams about, or accidentally leaves cardholder data on a sticky note, congratulations - you get the privilege of dealing with PCI DSS. For organizations processing enough transactions, the reward for your success is an on-site assessment conducted by a Qualified Security Assessor (QSA). Think of it as inviting a well-dressed, highly trained auditor to examine every corner of your security program and ask uncomfortable questions about decisions made by people who left the company three years ago.

In an ideal world, your controls are well-documented, operating effectively and everyone knows exactly where the evidence is stored. In the real world, someone discovers during the assessment that the quarterly review hasn't happened since the last presidential administration, nobody can explain a firewall rule labeled "DO NOT TOUCH" and a frantic war room appears overnight.

This session explores the most common (and a few impressively creative) ways organizations derail their PCI assessments. We'll cover how to avoid discovering critical compliance gaps in front of your QSA, why "we thought someone else was doing that" is not a valid control and how to prevent your assessment from turning into a high-stakes race against the reporting deadline.

Come learn how not to fail your PCI assessment spectacularly... preferably before your next assessment cycle.

SpeakerBio:  Kevin Buck, PCI GRC Manager, NBCUniversal

40+ years in technology across roles from system programmer to CTO; involved in PCI compliance since 2005 as both a Level 1 merchant and a Qualified Security Assessor (QSA).


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: HSPACE: AI Battlegrounds
Tags: HSPACE: AI Battlegrounds | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds) - Map

Description:

"Your prompt becomes a character, a machine, or an attack—and every word can change what happens next.

HSPACE: AI Battlegrounds is a collection of three hands-on games that turn natural-language and visual prompts into playable systems:

Wizard of Prompts — Write a short prompt to generate a pixel-art hero with unique stats and skills, then guide that hero through a five-boss, card-based battle campaign. Experiment with wording, build a stronger character, and see how the game's AI responds to prompt-injection attempts.

Prompt Prix — Describe your ideal race car and watch the AI convert your prompt into a validated vehicle build. Race across changing track conditions, study the result, and tune your prompt to improve the car's speed, grip, stability, and final ranking.

Vision Breaker — Face a vision-language-model security guard that decides who may enter. Use signs, screens, clothing, props, and visual prompt-injection techniques to influence its observations, bypass its checks, and progress through three escalating stages—from changing a decision to hijacking a command.

No joystick, coding experience, or prior security knowledge is required. Come experiment, iterate, and discover how small changes in language and visual context can reshape an AI agent's behavior.

Participant Prerequisites

Anyone who has used AI at least once is welcome. A camera-enabled smartphone or laptop with a modern web browser is recommended for Vision Breaker; camera permission is required for live play. Game stations and physical props are provided at the booth.

Participants can also play on their own smartphones or personal laptops. The competitive portion of AI Battlegrounds will be conducted online."


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 11:30-11:59 PDT


Title: Human in the Loop or Human Out of Luck?
Tags: Biohacking Village | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

As agentic AI systems rapidly enter healthcare and precision medicine, a critical question remains largely unanswered: what happens when the patient is reduced to data alone? This talk explores a real-world experiment conducted through GENE240 at Stanford, where interdisciplinary student teams used agentic AI systems and multiomic datasets to investigate a complex patient case. Working across genomics, computational biology, and clinical reasoning, teams analyzed the same underlying data while arriving at dramatically different hypotheses, interpretations, and priorities. Unlike traditional case studies, the patient was actively involved throughout the process. While full medical records were intentionally withheld, selective contextual information and direct interaction with the patient significantly influenced the direction and interpretation of the work. The experience exposed both the extraordinary promise and the profound limitations of AI-driven healthcare systems. This session will examine: how agentic AI systems behave when operating on incomplete clinical context the variability introduced by tooling, prompting, and disciplinary bias the role of patient interaction in refining computational hypotheses why lived experience may be one of the most underutilized datasets in precision medicine Through the lens of rare disease and complex chronic illness, this talk challenges the assumption that more data alone leads to better outcomes. Instead, it argues that the future of AI-enabled healthcare depends on keeping patients actively embedded in the interpretive loop. For the biohacking community, this raises broader questions around autonomy, data ownership, participatory medicine, and how individuals may increasingly interface with AI systems to investigate their own health outside traditional clinical

SpeakerBio:  Christine Von Raesfeld

Christine is a research advocate and community engagement leader focused on health, data, and emerging technologies. Living with multiple rare and chronic conditions, she advances participatory medicine and champions people with lived experience as essential partners in research and innovation.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 08:00-18:59 PDT


Title: Human Registration Open
Tags: Misc
When: Friday, Aug 7, 08:00 - 18:59 PDT
Where: LVCC West Hall

Description:

Our human registration process this year will be very similar to previous years. Please be patient. All of the times listed here are approximate.

Basics

Who needs a badge?

A badge is required for each human age 8 and older.

Human?

You are a human if you do not know otherwise. People that are not humans include goons, official speaker, village/community/contest/creator staff, press, black badge holders, or similar. If you are not a human, you need to register separately. If you don't know how, see an NFO goon (NFO Node, formerly known as an infobooth, is where you can get help). The remainder of this message applies only to humans.

Lines? Linecon?

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

Ways to buy a badge

Online Purchase

You will be emailed a QR code to the email address provided when you bought your badge. Please guard that QR code as though it is cash -- it can only be redeemed once, and anyone can redeem it if they have it (including a photo of it). Badges are picked-up on-site -- they will not be mailed or shipped.

We can scan the QR code either from your phone's display or from a printed copy. You must have the QR code with you in order to obtain your badge. As you approach the front of the line, if you are going to show your QR code on an electronic device, please ensure that your display is set to maximum brightness.

If you pre-registered, but ultimately are unable to attend DEF CON and want to cancel your purchase, the only way to get a refund is from the original online source. We are unable to provide any refunds on-site at DEF CON. There is a fee to have your badge canceled: $34 before July 18, and $84 on and after July 18.

Online purchases are provided a receipt via email when the purchase is made.

Online purchase -- often referred to as pre-registration -- does not allow you to skip any line/queue to pick up your badge. Once you arrive on-site, you will need to join the existing line for human registration. There may or may not be a dedicated line for pre-registration badge pickup, depending on when you arrive, how long the line is, available staff, etc.

Cash Purchase

Badges will be available for purchase on-site at DEF CON. All badge sales are cash only. No checks, money orders, credit cards, etc., will be accepted. In order to keep the registration line moving as quickly as possible, please have exact change ready as you near the front of the line.

There are no refunds given for cash sales. If you have any doubt about your desire to buy a badge, please refrain from doing so.

We are unable to provide printed receipts at the time of the sale. A generic receipt for the cash sale of a badge will be made available on media.defcon.org after the conference. You are welcome to print your own copy of the receipt on plain paper.

Via BlackHat

If you've purchased a DEF CON badge as part of your Black Hat registration, you're in luck - you will be able to pick up your DEF CON badge at Black Hat on Thursday. Please bring your Black Hat badge and watch for emails from Black Hat about where exactly the badge pickup will be.

Please note that DEF CON is not able to access or verify Black Hat registration or attendee info. DEF CON's preregistration list is not the same as Black Hat's. For help, ask at Black Hat registration or the concierge area.

Misc

Want to buy multiple badges? No problem! We're happy to sell you however many badges you want to pay for.

If you lose your badge, there is unfortunately no way for us to replace it. You'll have to buy a replacement at full price. Please don't lose your badge. :(

If you are being accompanied by a full-time caretaker (such as someone who will push your wheelchair, and will accompany you at all times), please ask to speak to a Registration Goon. Your caretaker will receive a paper badge that will permit them to accompany you everywhere you go.

Still need help?

If you have questions about anything regarding human registration that are not addressed here, please ask to speak to a Registration Goon.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 15:30-15:59 PDT


Title: Hunting for Cryptographic Ghosts: A Bug Hunter’s Guide to Signature Malleability and Replay Attacks in EVM Bridges & Multi-Sigs
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

In the realm of Web3 bug bounties, smart contract logical flaws are highly sought after, but the most devastating, seven-figure bounties often lie within fundamental cryptographic implementation errors. Specifically, ECDSA signature malleability and faulty multi-signature threshold state management are responsible for the biggest bridge drains in history. Yet, many traditional bug bounty hunters steer clear due to the perceived mathematical complexity. This presentation demystifies these high-value bug classes. We will break down exactly how the EVM processes cryptographic signatures (ecrecover), how the mathematical symmetry of elliptic curves allows a single valid signature to be altered into a second, legally distinct signature, and how this can be weaponized to bypass multi-signature validation logic. Attendees will walk away with an actionable, repeatable hunting methodology, custom scripts to automate signature vulnerability testing, and real-world case studies of massive payouts achieved without looking at single line of standard frontend code.

Speakers:Samet Berk Simsek,Ahmet Furkan Aydogan

SpeakerBio:  Samet Berk Simsek

Samet Berk Şimşek is a Turknet Cyber Security Specialist & Web3 Developer

SpeakerBio:  Ahmet Furkan Aydogan

Ahmet Furkan Aydogan is a Tenure-Track Assistant Professor in the Computer Science Department at the University of North Carolina Wilmington (UNCW). He earned his Ph.D. in Digital and Cyber Forensics Science from Sam Houston State University (SHSU) in 2024, with a focus on Cyber Security, Cryptology, Machine Learning, IoT, and Human-Computer Interaction. His research includes a Brain Frequency-Based Evolutionary Encryption Method for IoT Devices. Ahmet has received multiple awards and has published widely in the fields of cybersecurity and digital forensics.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 11:50-11:59 PDT


Title: ICS Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 11:50 - 11:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting ICS Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to ICS Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Friday - 14:30-14:59 PDT


Title: ICSForge: (Open-Source) OT/ICS Security Coverage Validation Platform
Tags: ICS Village | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

ICSForge is an open-source OT/ICS Security Coverage Validation Platform designed to help defenders, SOC teams, and OT security engineers validate detection, visibility, and readiness against real-world industrial attack techniques.

ICSForge is built to tackle a critical gap in OT/ICS security. It aims to solve a real problem “How do I safely validate OT security countermeasures from functionality, visibility and detection coverage perspective by using industrial traffic and MITRE ATT&CK® Matrix for ICS?” The goal is simple; make it easier to answer “Are we actually seeing, detecting, controlling and protecting what we think we are?”

OT defenders have no practical and safe way to validate whether their network security monitoring sensors, firewalls, and segmentation controls actually detect and/or protect against real ICS attack techniques. By focusing on security coverage validation in industrial environments, the goal is to move beyond assumptions and provide measurable assurance for detection capabilities in critical infrastructure.

ICSForge focuses on what can actually be observed on the network and generates realistic OT traffic and PCAPs (500+ scenarios) in 10 industrial protocols (Modbus/TCP, DNP3, S7comm, IEC-104, OPC UA, EtherNet/IP, BACnet/IP, MQTT, GOOSE, PROFINET DCP) which are aligned with 68 out of 83 unique techniques in MITRE ATT&CK for ICS v18 (82% coverage) -without exploiting real systems or causing unsafe process impact- to help asset owners and defenders assessing the quality of existing security countermeasures such as firewalls, OT NSM sensors and ACLs and identifying hidden gaps.

Most OT/ICS security tools promise coverage, very few let you prove it. ICSForge helps you answer questions like: - Can my Network Security Monitoring/IDS actually see Modbus manipulation attempts? - Which MITRE ATT&CK for ICS techniques are observable on the wire? - Do my detections fire when realistic OT traffic is sent? - Do my IT/OT firewalls or ACLs work as expected and blocks potentially harmful traffic? - What do I miss today, and why?

ICSForge is developed with a safe-by-design approach, operating within a Sender-Receiver architecture and interacting only with the designated sender and receiver, without touching other OT devices.

SpeakerBio:  Can Kurnaz

Can (pronounced as /dʒɑːn/ or John) works as an Industrial Control Systems (ICS) / Operational Technology (OT) Cybersecurity Specialist and has over a decade of professional experience in cybersecurity field, focused on OT/ICS Cyber Defense such as secure architecture development, OT/ICS monitoring, endpoint security platforms and vulnerability management. He has offensive security background such as penetration testing, red teaming, OT/ICS site security assessments and also has experience in incident response and cybersecurity trainings (both hands-on and awareness). His passion is protecting the critical infrastructure and production environments by providing technical knowledge on multiple cybersecurity domains which help for preparation, prevention, detection and response. Can has presented several times at leading cybersecurity conferences such as Black Hat, DEF CON and SANS Summits and he holds GRID, GICSP, OSCP, OSWP, ISA/IEC 62443 Expert (CFS, CRAS, CDS, CMS) certifications.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 15:15-16:15 PDT


Title: IDEViewer - Securing Developer Workstations from IDE Supply Chain Threats
Tags: Intermediate | AppSec Village | Creator Event/Activity
When: Friday, Aug 7, 15:15 - 16:15 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

IDEViewer is an open-source, cross-platform security tool that continuously monitors developer workstations for supply chain threats originating from IDE extensions, software dependencies, plaintext secrets, and AI development tools.

Developer IDEs have become a high-value attack surface. Malicious or over-permissioned VS Code extensions can execute arbitrary code, exfiltrate secrets, and establish persistence. npm lifecycle hooks in dependencies run silently during install. AI coding assistants like Claude Code, Cursor, and MCP servers introduce new data exfiltration vectors through unchecked permissions and network access. IDEViewer addresses this blind spot by scanning extensions across 7+ IDEs, analyzing their permissions against a risk model, detecting plaintext secrets, inventorying all installed packages (including those bundled inside extensions), monitoring for git hook bypasses, and detecting AI tool configurations with their associated permissions.

SpeakerBio:  securient

Vinod is a Staff Security Engineer at PIP Labs and IEEE Senior Member with over a decade of cybersecurity experience spanning financial services, government, and tech. His career across Amazon, Zapier, and HackerOne has built deep expertise in penetration testing, cloud security architecture, and application security across AWS, GCP, and Azure — now applied at the intersection of traditional enterprise security and Web3/blockchain infrastructure. He is an author and reviewer for the HTTP Archive's Web Almanac, organizer of the Blockchain Security Village at Seasides, and creator of the open-source API Doc Converter Burp Extension. He actively contributes to the security community through writing on Medium, bug bounty programs, and mentoring aspiring security professionals.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 11:45-12:45 PDT


Title: If I Were Eighteen Again: Career Advice for the AI Era
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 11:45 - 12:45 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:
Please Note: This talk is based on the post "If I were Eighteen Again", published June 16, 2025 from my personal blog (https://securing.dev/posts/if-i-were-eighteen-again/).

Abstract

In 2025 the CEO of Anthropic stated that AI could eliminate half of all entry-level white collar jobs within five years. For n00bs entering the cybersecurity industry today, that's a scary headline; It doesn't have to be a death sentence for your nascent career.

In this talk the speaker shares what they would do differently if they were eighteen again, drawing from their own experiences entering the workforce at the bottom of the 2008 housing market crash with no connections, no work history, and no roadmap. Reflecting on over a decade of acquiring and building skills as an Information Security practitioner, this session delivers timeless, practical advice that will help aspiring security professionals build a career that is resilient to economic downturns, immune to hype cycles, and capable of surviving whatever the latest technology trend comes next.


Detailed Outline

Introduction (4 minutes)

Read & Write Long-Form Content (6 minutes)

Learn How to Learn (6 minutes)

Develop Critical Thinking & Practice Mindfulness (6 minutes)

Build & Maintain a Public Brand (7 minutes)

Seek Out Mentorship (6 minutes)

Thoughts on Formal Education, Certs & Bootcamps (6 minutes)

On AI and Skill Development (6 minutes)

The AI-Averse Path: Becoming a Shokunin (5 minutes)

Q&A (8 minutes)


Attendee Takeaways

Foundational habits that compound: Reading, writing, mindfulness, and continuous learning are not just “soft skills”, they are what separates practitioners who plateau from those who build enduring careers.

Your public brand is your resume: In 2026, a body of published work is the difference between being considered for a role and being filtered out.

AI is a tool, not a replacement for thinking: Understanding how to use LLMs without outsourcing learning or critical thinking is one of the most important skills a new practitioner should be developing right now.

Education and certifications are tools, not guarantees: Know what they are actually buying you, and pursue practical proof of skill development over paper credentials wherever possible.

SpeakerBio:  Keith Hoodlet
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 12:00-12:59 PDT


Title: Improv
Tags: Social Engineering Community Village | Creator Event/Activity
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Join Bryan and Kevin for a fun, low-pressure improv showdown where quick reactions, creative thinking, and social engineering skills take center stage.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Friday - 10:00-10:59 PDT


Title: Incident Response 101: Preparing Before the Hack, Responding After It
Tags: Blue Team Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

When an organization gets hacked, recovery is only part of the challenge. Security teams must quickly determine what happened, contain the threat, remove the attacker, and restore operations without allowing the incident to happen again. That work falls to incident responders, the cybersecurity professionals who investigate attacks, coordinate response efforts, and help organizations recover under pressure.

This beginner-friendly session introduces the role of the incident responder and explains how incident response works across the major stages of preparation, detection, containment, eradication, recovery, and post-incident improvement. Attendees will leave with a practical understanding of what incident responders do, why their work matters, and how structured response processes help organizations reduce damage and improve resilience after a cyber incident.

SpeakerBio:  Joshua Morgan

Joshua Morgan is a seasoned information security expert and passionate educator, dedicated to empowering the next generation of security professionals. With a strong background in the Blue Team realm, Joshua brings hands-on experience and real-world expertise to his work as an instructor at a local university, teaching advanced information security concepts to Masters-level students.

As a respected speaker in the industry, Joshua has had the opportunity to share his knowledge with a wider audience, having presented at leading conferences such as DEF CON and BSides. His involvement in the security community extends beyond the stage, as he collaborates with fellow security enthusiasts and mentors newcomers to the industry.

Joshua's commitment to security education and community outreach has made him a valuable asset to the industry, and his passion for securing all aspects of life continues to drive his work.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 10:45-11:30 PDT


Title: InQuorigible: Quora in Missing Persons OSINT
Tags: Recon Village | Creator Talk/Panel
When: Friday, Aug 7, 10:45 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

We all know Quora - or do we? Like Internet herpes, if you're a Google user, it'll follow you, forever, haunting your inbox with clickbait if you Google while logged into your account.

...But do we REALLY know Quora? Because despite being a pustule on the Internet that exists for the sole purpose of spamming SERPs, you'll be shocked to learn that it's also got - spoiler alert!!! - a dark, seedy underbelly. One that I uncovered while volunteering on an MP investigation. One that can yield surprising, disturbing and useful intelligence.

In this talk, I'll explain: 1. The traces Quora leaves behind when something is "limited," "deleted" or a user is "banned." Because on Quora, 'deleted' just nulls the post body while the API keeps serving the slug and author, and 'limited' barely hides anything at all. On Quora, Limited is UNLIMITED, just like Olive Garden's breadsticks! Except unlike Olive Garden breadsticks, Quora's "limited" option is a fig leaf, and "deleted" content isn't much better: The API doesn't hide it. It coughs up the slug and author fully visible to other accounts and even logged-out strangers. 2. How to use Quora's API hairball to see what a user posted and build a network graph 3. What the disturbing subcultures on Quora mean for OSINT 4. Limitations of approach and ideas for automating OSINT

Trigger warnings: This talk may include mention of disturbing topics, though all information will be anonymized / sanitized and no graphic content shared.

SpeakerBio:  Miranda Tedholm, Hunting the Golden Fleece in the JSONs of the world. Extremely employable.

Who is Miranda? A reformed academic, a freelance writer sidelined thanks to a tech that can be described as "autocomplete on steroids," and a recent computer science grad, Miranda has been online since the CompuServe days. Yet she was [redacted] years old before she realized that "being really good at finding people online" was a whole subculture, career, and acronym. Despite never having played Pokemon, she collects degrees and credentials like she's gotta catch 'em all. Two bachelor's degrees, a master's, most of a PhD, and probably able to do the Heimlich maneuver (no promises though). But she yearns only for a job.


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Friday - 14:00-14:30 PDT


Title: Inside the Guts of Ransomware
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Have you ever wondered how malware analysts identify different encryption algorithms in ransomware samples? In this session, I'll explain the design of some algorithms (such as AES, RSA, ChaCha20, etc.) and show you how to identify them using reverse engineering and debugging techniques, and by using ransomware demos from recent incidents.

SpeakerBio:  Ashley Hiram Muñoz, Kaspersky - Incident Response Specialist

I currently work as an Incident Response Specialist on Kaspersky's Global Emergency Response Team (GERT). I live in Mexico and have over seven years of experience in Incident Response, Digital Forensics, Malware Analysis, and Reverse Engineering. Before joining DFIR, I worked for two years as a Penetration Tester.

I have collaborated on various Threat Hunting and Threat Intelligence projects.

Additionally, I have been a speaker at international events such as DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, HackGDL, BugCON, Pwnterrey, and others. I currently teach the Digital Forensics, Malware Analysis, and Incident Response modules in an information security diploma program at UNAM (Universidad Nacional Autónoma de México).

Certifications: GREM, GCFA, GCFR, eCTHP, CHFI.

--

Actualmente me desempeño como Incident Response Specialist en el Global Emergency Response Team (GERT) de Kaspersky, cuento con +6 años de experiencia realizando Respuesta a Incidentes, Análisis Forense Digital, Análisis de Malware y Reversing; previo a dedicarme a DFIR laboré 2 años como Penetration Tester.

He colaborado en distintos proyectos de Threat Hunting y Threat Intelligence.

Adicionalmente, he sido ponente en eventos internacionales como DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, BugCON, etc.

Actualmente soy profesor de los módulos de Análisis Forense, Análisis de Malware y Respuesta a Incidentes en un diplomado de seguridad de la información de la UNAM.

Certificaciones: GREM, GCFA, eCTHP, CHFI.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 17:00-17:30 PDT


Title: Installing and Using the Tracelabs VM
Tags: OSINT For Good Community | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

Come learn from the lead developer how to install and use the Trace Labs Virtual Machine, including a live demonstration. Stick around after to get help during a hands-on workshop

SpeakerBio:  Jeff "UltraSunshine" G, Trace Labs VM Lead

Jeff is a forensics engineer with a passion for building tools that empower skilled people to do awesome work. That drive shapes their career and their downtime. At work they build tools that investigators rely on to collect, process, and analyze forensic evidence. As a volunteer, they serve as Trace Labs VM Lead, maintaining an OSINT-focused Linux distribution used by people around the world to investigate missing persons cases as part of Search Party CTFs. In their downtime, they foster stray kittens - proof that even the most seasoned toolmaker has a soft spot for a good rescue.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 15:00-15:45 PDT


Title: Intercept.js: Runtime-Aware Detection for JavaScript Environments
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | DEF CON Demo Labs
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

Modern attacks increasingly execute inside JavaScript runtimes (browsers, email clients, and embedded app environments) where traditional file-scanning and OS-level controls lack visibility into application-layer behavior. In these contexts, payloads often exist only as in-memory buffers, fetch responses, or dynamically constructed objects. Detection therefore depends not just on inspecting bytes, but on understanding their origin, transformation, and use at runtime.

We present Intercept.js, an open-source detection engine that runs natively within JavaScript environments, combining byte-level inspection with execution context in real time. Built for YARA compatibility, it extends rule evaluation beyond static artifacts by incorporating signals such as origin provenance, user gesture state, MIME inconsistencies, and object construction paths.

This unified model enables detection of threats as they are assembled and executed — including identifying executable buffers built in memory, anomalous data flows, or content whose structure diverges from its declared type.

As a concrete demonstration, we show how HTML smuggling attacks can be intercepted at the moment of payload construction, preventing delivery before artifacts ever reach disk and exposing a class of threats that evade both network and endpoint controls.

SpeakerBio:  Rishi Kant

A builder at heart, Rishi has spent his career turning deep technical ideas into real-world impact. He holds a PhD in Electrical Engineering from Stanford, and earned his B.S. in EECS from UC Berkeley. After 4.5 years of advising global high-tech firms at McKinsey & Company, he followed his passion for building and moved into product management. Rishi led product teams at several cybersecurity companies—including Tanium, Authentic8, and Uptycs. Now, as founder of Sekant Security, he’s embedding runtime intelligence directly into web browsers to protect users from phishing, ClickFix, unsafe downloads, shadow AI and other emerging online threats.


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Friday - 11:00-11:59 PDT


Title: Intro to Common Industrial Protocol Exploitation
Tags: ICS Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Intro into Common Industrial Protocol and how to get started finding exploits on CIP enabled devices.

SpeakerBio:  Trevor Flynn

Industrial Control Engineer / ICSVillage volunteer / Cyber Security Researcher


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Friday - 10:15-10:45 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Friday, Aug 7, 10:15 - 10:45 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Friday - 16:00-16:30 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Friday - 14:30-14:59 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Friday, Aug 7, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Friday - 13:00-13:30 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Friday, Aug 7, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 12:10-14:10 PDT


Title: Introduction to Reverse Engineering With Ghidra
Tags: Malware Village | Creator Workshop
When: Friday, Aug 7, 12:10 - 14:10 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map

Description:

In this workshop, Dr. Wesley McGrew will be presenting a live and unscripted introduction to using Ghidra to reverse engineer real malware samples, targeting people who are new to malware reverse engineering, but have some programming background.

Dr. McGrew will cover the Ghidra user interface, how to load samples, perform initial processing, and how to navigate around a malicious binary. Then, for most of the workshop time, he will provide commentary, advice, heuristics, and approaches for malware analysis as the workshop group takes a look at one or more samples live on the projector.

This workshop is meant to be interactive, driven by attendee questions and interests. Beyond the essentials needed to load malware into Ghidra, the workshop attendees and Dr. McGrew will be collaborating on the direction of the workshop material.

SpeakerBio:  Wesley McGrew, Senior Cyber Fellow at MartinFed

Dr. Wesley McGrew directs research, development, reverse engineering, and offensive cyber operations as Senior Cybersecurity Fellow for MartinFederal. He has presented at DEF CON and Black Hat USA on topics of penetration testing, malware analysis, critical infrastructure, and vintage computing, and has taught self-designed courses on reverse engineering and cyber operations at Mississippi State University. Wesley has a Ph.D. in Computer Science from Mississippi State University for his research in vulnerability analysis of SCADA HMI systems. He has entertained audiences at many DEF CON parties as a house music DJ, as well.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Friday - 12:30-12:59 PDT


Title: Introduction to RFID
Tags: Physical Security Village | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

You know the sound of beep... Click when using a badge to enter a door to a building, but how does this work and how can you exploit issues with RFID systems?

This talk will explain the basics of what’s inside the readers and the badges, and how they communicate wirelessly. You will learn about the common tools available (Proxmark, Flipper, Keysy), how to get one and how to use it.

NEW THIS YEAR: We will cover real case studies of RFID systems being exploited. What were the designers trying to do, and where did they make mistakes?

In addition to the real case studies, we’ll talk about techniques to clone badges, and brute force systems to get access you never had in the first place.

Speakers:Ege Feyzioglu,Karen Ng

SpeakerBio:  Ege Feyzioglu, Physical Security Village

Ege is a physical security consultant and educator, specialising in access control systems and embedded electronics. She is currently pursuing a degree in Electrical Engineering. Her work focuses on security education, wireless communications, and the intersection of physical security and electronics. She is one of the Village Leads at the Physical Security Village and currently serves as its Secretary-Treasurer.

SpeakerBio:  Karen Ng, Physical Security Village

Karen is a risk analyst and physical security penetration tester by day, and a physical security educator and speaker by night. She has a strong interest in security, delivering trainings on physical security vulnerabilities to a wide range of audiences around the world. Karen comes from a background in engineering and has extensive experience in major event logistics. She is one of the Village Leads at the Physical Security Village, and works with the rest of the PSV team to teach how to recognize and fix security exploits to the community. Graphic design is her passion.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 11:30-11:50 PDT


Title: Introduction to Vulnerable ATM Badge
Tags: Payment Village | Creator Workshop
When: Friday, Aug 7, 11:30 - 11:50 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

The Payment Village set out to design a badge that represents a purposefully vulnerable ATM for educational use. Providing conference attendees with access to a real ATM is impractical due to its size, weight, and limited accessibility. Instead, the badge offers a portable ATM-inspired platform, available to all, that simulates real-world attack surfaces through interactive challenges. We have five prototypes available to try!

To extend its value beyond DEF CON, the badge will be supported by an online platform featuring learning resources, firmware updates, and community support via a website and Discord. We also have a life-size version of the badge as a fully interactive ATM demonstration for attendees to interact with in the village

SpeakerBio:  Vincent Sloan, Software Engineer, GoFundMe

20+ years of experience in payments, spanning e-commerce and crowdfunding; currently leads payments engineering at GoFundMe.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 15:30-16:59 PDT


Title: Introduction to Web Exploitation
Tags: Noob Community | Creator Workshop
When: Friday, Aug 7, 15:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Before you can secure the web, you have to understand how to break it. This 90-minute hands-on session completely bypasses the static slides to give you a practical, interactive introduction to web exploitation. Led by Roman Bohuk, CEO of SkillBit (formerly MetaCTF), you will explore the core technologies that power the web and learn proven, real-world attack methodologies. Whether you are aiming to break into professional web application penetration testing or just looking to sharpen your CTF skills, you'll get dirty with live vulnerabilities, learn how modern web targets are enumerated, and walk away with a solid, actionable foundation in offensive web security.

SpeakerBio:  Roman Bohuk
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Friday - 14:00-14:59 PDT


Title: iOS Game Hacking : From Zero to G0D Mode
Tags: Game Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:
SpeakerBio:  M41w4r3
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: IoT Exploitation Masterclass: Hardware & RF Hacking
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:
Speakers:Smriti Gaba,Yianna Paris

SpeakerBio:  Smriti Gaba
No BIO available
SpeakerBio:  Yianna Paris
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: IoT Exploitation Masterclass: Hardware & RF Hacking
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:
Speakers:Smriti Gaba,Yianna Paris

SpeakerBio:  Smriti Gaba
No BIO available
SpeakerBio:  Yianna Paris
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 10:10-10:20 PDT


Title: IOT Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 10:10 - 10:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting IOT Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to IOT Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 13:30-13:59 PDT


Title: It's a Payment Terminal. It's My Arcade. It's Everywhere. It Cost Me Nine Bucks.
Tags: Payment Village | Creator Talk/Panel
When: Friday, Aug 7, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

20+ million payment terminals. Hardware-signed. Kernel-verified. Processing live transactions in retail, hospitality, and healthcare worldwide. You've probably tapped one this week. We bought one for nine bucks. Sixty seconds later, we had root over WiFi. Three chained vulnerabilities, fully automated, zero interaction. Plaintext credentials, full filesystem, kernel signature enforcement gone. We made it run Snake. Tetris. Whatever you want it to. A PCI-certified arcade. We reported everything to the vendor. They passed. "Out of support. Not fixing it." Except retail-purchased units this year ship with the exact firmware they're walking away from. No update mechanism. No OTA. No advisory. The bugs remain exploitable on devices being sold today. PCI-certified doesn't mean patched. Retail-available doesn't mean current. The bugs you can't patch are the ones already on the counter.

SpeakerBio:  Chiao-Lin Yu "Steven Meow", Staff Red Team Security Threat Researcher at Trend AI (Trend Micro)

Chiao-Lin Yu (Steven Meow) is a Staff Red Team Security Threat Researcher at Trend AI (Trend Micro) Taiwan. He holds professional certifications including OSCE3, OSCP, CRTO... and LPT. He has previously spoken at DEF CON (USA), CCC (Germany), BSides Tokyo (Japan), HITCON Training (Taiwan), etc. He has disclosed over 50 CVE vulnerabilities affecting major vendors such as VMware, NEC, D-Link, and Zyxel. He specializes in red teaming, web security, IoT, and cats🐱.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 16:00-16:59 PDT


Title: Jackpoting? Bypass de EDR? - Hacking ATM
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

En muchas ocasiones cómo pentesters nos aferramos a la idea de buscar multiples técnicas de ataque de manera “virtual”, buscando software especializado o creando scripts que nos ayuden a identificar una vulnerabilidad para acceder a un programa o dispositivo en el que nos enfoquemos, pasamos tanto tiempo enfrente de nuestra pantalla, lanzando comandos a lo bastardo hasta ver que podemos encontrar que a veces ignoramos que existen soluciones alternativas y no simplemente de manera virtual, sino de una manera en que podemos tocar, armar y desarmar (esto suele ser menos buscado por pentester, entonces tambien hay menos documentacion).

El proceso de arranque de Windows, conocido como boot process, se divide en varias fases como ya lo vimos: PreBoot (inicialización del firmware BIOS/UEFI y POST), Boot Manager (carga de bootmgr o bootmgfw.efi), OS Loader (ejecución de winload.exe para cargar el kernel) y Kernel Initialization (carga de ntoskrnl.exe y hal.dll, inicialización de controladores y servicios). Finalmente, se inicia winlogon.exe para presentar la interfaz de usuario. Este proceso permite pasar de un estado apagado a un sistema operativo funcional mediante una secuencia jerárquica y verificada.

Respecto a los EDR (Endpoint Detection and Response) basados en el kernel, operan en modo kernel, el nivel más privilegiado del sistema (algunos juegan en UEFI), lo que les permite supervisar actividades de bajo nivel como llamadas al sistema, manipulación de memoria, carga de controladores y acceso a archivos. Al ejecutarse en este modo, los EDR pueden detectar y bloquear amenazas avanzadas como rootkits o malware persistente que intentan eludir las protecciones del modo usuario. Su integración profunda con el kernel les permite realizar monitoreo en tiempo real, análisis de comportamiento y respuesta inmediata ante actividades sospechosas durante y después del arranque.

Normalmente los EDRs se encuentran en KERNEL pero como lo mencione, existen otros que se encuentran en UEFI y si recordamos como funciona windows atrás de UEFI esta SMM entonces es algo un poco mas dicil.

Esta charla es pensada para personas interesadas no solo en ATMs y una simple dispensación si no la vista mas alla, el análisis y toda la experiencia adquirida cuando te enfrentas a ellos.

Mas información sobre el ataque y la teoría detrás de ella:

https://h0km4.com/posts/DMA-Introduction/

https://h0km4.com/posts/telemetria-bypass/

SpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master's in AI and Cybersecurity.

--

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: Just Hacking Training
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

2 Mini-Workshops, Only 15 Minutes Each: QEMU: Emulate Your 'Things' – Hack a Drug Lord’s Smart Toilet; Encryption! What Encryption? – Decrypt TLS Traffic with mitmproxy. No Schedule.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 16:00-17:30 PDT


Title: KaliGPT Vibe-Ethical Hacking Session
Tags: Blacks In Cyber Village | Creator Workshop
When: Friday, Aug 7, 16:00 - 17:30 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Join B.I.C. Village for KaliGPT Vibe-Ethical Hacking Session, a welcoming session focused on hands-on ethical hacking concepts, Kali Linux workflows, and responsible security learning. Come ready to learn, ask questions, and connect with the community.

SpeakerBio:  Timothy E. Bates, Professor of Practice, University of Michigan / Fractional CTO

Timothy E. Bates, also known as "The Godfather of Tech," is a distinguished cybersecurity professional and educator. Discovered as a hacker at age 13 by the U.S. Marshals Service, he was later recruited by the U.S. Government to train on tracking digital pirates and hackers. He brings over 40 years of experience in the tech industry, with extensive expertise in Artificial Intelligence (AI), Blockchain, and Immersive Technologies. His career includes significant roles as Chief Technology Officer (CTO) at Global Fortune 200 companies like Lenovo and General Motors. Timothy currently serves as a Professor of Practice in the College of Innovation & Technology at the University of Michigan-Flint and as a Fractional CTO. He has received numerous accolades, including the BEYA Black Engineers Association Award: Modern-Day Technology Leader.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 11:00-11:59 PDT


Title: Keychained Melody - Grabbing the Keys to the iCloud Kingdom
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

The Apple Keychain has become a cornerstone of credential management for millions of users across the Apple ecosystem. In response, Apple has implemented robust protections for the iCloud Keychain — restricting synchronization exclusively to devices within Apple’s “Circle of Trust” and encrypting stored secrets with keys protected by the Secure Enclave. These layered defenses are designed to ensure that even physical acquisition of Keychain data from Apple’s servers yields nothing actionable.

This talk introduces a novel vulnerability (CVE-2026-28860) that fundamentally undermines these protections. Leveraging a deep understanding of macOS internals, we demonstrate a technique capable of extracting all passwords stored within the Keychain — requiring neither root privileges, a user password, nor any prompts to the user. Beyond credential theft, we explore the broader attack surface this vulnerability exposes, presenting additional scenarios where data gleaned from the iCloud Keychain enables further, more severe compromise.

Speakers:Alex Radocea,Jaron Bradley

SpeakerBio:  Alex Radocea

Founder of Supernetworks and cofounder of Longterm Security. Alex started in security pentesting financial firms on Wall Street at Matasano and cofounded RPISEC at RPI. He has worked on Apple's Product Security team, engineering at CrowdStrike, and Spotify's Security team. His research — presented at Black Hat and REcon — spans mobile messenger cryptography, kernel security, binary static analysis, and browser hardening, including the discovery of critical flaws in Apple's iCloud Keychain.

SpeakerBio:  Jaron Bradley, Jamf

Jaron is the Director of Jamf Threat Labs where he focuses on discovering new ways to keep user's safe on Apple devices. He is author of the books "Threat Hunting macOS" and "OS X Incident Response". In his free time he manages themittenmac.com, a site dedicated to helping others learn security on the Apple ecosystem.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: Kryptsec Labs
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Kryptsec started as a Discord server for people who wanted to learn cybersecurity together and has grown into a company focused on making security training engaging rather than monotonous, including hands-on, AI-assisted CTF labs and OASIS, its open-source tool for benchmarking AI agent vulnerabilities. Stop by the Kryptsec Labs table during village hours to work through their hands-on challenges.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Friday - 10:00-17:59 PDT


Title: KSCM Scambait Radio
Tags: Scambait Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Kubernetes CTF
Tags: Kubernetes CTF | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 212 (Kubernetes CTF) - Map

Description:

Want to learn more about Kubernetes hacking or compete against other people in a Capture the Flag contest? Sign up on-line and come see us in person/on Discord at the Kubernetes Capture the Flag (CTF) contest .

We have two events - you can play in both if you like.

From Friday to Sunday, we have a non-competitive Learning CTF, where you can go through last year's Kubernetes CTF scenario, referring to a cheat sheet whenever you want. This runs from Friday 12:00 to Sunday 12:00. We'll be in the contest area to support you during:

Friday: 12:00-17:00 Saturday: 10:00-17:00 Sunday: 10:00-12:00

On Saturday only, you can play in the competitive Kubernetes CTF challenge, where teams (of one or more) can build and test their skills. Each team is given access to a single Kubernetes cluster that contains a set of challenges. This runs from 10:30am to 5:30pm on Saturday.

Find out more and sign up at: https://containersecurityctf.com/


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 14:00-14:45 PDT


Title: L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security
Tags: DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

Browser Extensions is one of the overlooked attack surface in the modern era. Most browser extension have permissions to allow direct access to cookies, browsing history, network requests and a poorly written extension can help attackers with stuff like silently steal credentials, log keystrokes, fingerprint users etc.

L.A.Y.E.R.S. (Logical Analyst for Your Extension Risk Surface) is a fully client-side chrome browser extension security engine that performs multi-layered security analysis on extensions. The tool performs analysis on various levels like JS analysis, permissions analysis, manifest analysis, secret scanning, URL extractions etc. simultaneously to uncover potential risks. The tool comes with its own scoring system guiding the team if the extension is safe to use or not.

L.A.Y.E.R.S. is designed for security researchers auditing in-house extensions, third-party extensions, red teams assessing browser attack surfaces, enterprises enforcing extension policies, and developers seeking to harden their own extensions before publication.

What sets L.A.Y.E.R.S. apart begins with its privacy-first architecture - the entire analysis runs in-browser via the File System API and JSZip, with very little setup required. On the detection side, it incorporates Shannon entropy analysis. To keep results actionable rat

Speakers:Abhinav Khanna,Krishna Chaganti

SpeakerBio:  Abhinav Khanna

Abhinav is an Information Security Professional with 7+ years of experience and currently works at S&P Global. His area of expertise include Web App Security, API Security, Mobile App Security, Secure Architecture. He has spoken at conferences like BlackHat USA, DefCon 33, BlackHat Europe, BlackHat Asia etc.

SpeakerBio:  Krishna Chaganti

Krishna Chaganti works as Associate Director Application Security at S&P Global, based in the USA, with over a decade of experience in Information Security. As a Certified Information Security Manager (CISM), he leads a team of more than 10 pentesters and specializes in Application Security along with Security Architecture.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 10:00-10:30 PDT


Title: La Villa - Opening Ceremony (ESP)
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 13:50-13:59 PDT


Title: La Villa Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 13:50 - 13:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting La Villa but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to La Villa and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 17:00-17:59 PDT


Title: Latest News in the Proxmark World
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

A whirlwind tour of the latest developments in the Proxmark ecosystem, from new hardware announcements and firmware releases. We’ll explore what’s new in the RFID security landscape, highlight recent innovations from the community, and take a look at where the Proxmark platform is headed next. Whether you’re a long-time user or just getting started, this session will bring you up to speed on the most important updates from the Proxmark world.

SpeakerBio:  Iceman

Christian Herrmann – RFID Hacker | Co-Founder of AuroraSec & RRG | MCPD Enterprise Architect

Christian Herrmann, better known in the hacker community as “Iceman”, is a co-founder of AuroraSec and RRG, and has helped develop many of today’s most widely used RFID research tools, including the Proxmark3 RDV4 and the Chameleon Mini.

He is a well-known RFID hacking and Proxmark3 evangelist, serving the community as both a forum administrator and a major code contributor alongside other developers since 2013. Christian has spoken at hacker conferences around the world, including BalcCon, WHY-2025, Troopers, Black Hat Asia, DEF CON, Hardwear IO, SSTIC, NullCon, Pass-the-Salt, BSides Tallinn, BlackAlps, and SaintCon.

He also runs a YouTube channel where he shares his knowledge of RFID hacking with the public.

With over 14 years of experience in bespoke software development, Christian specializes in .NET platforms and is a Certified MCPD Enterprise Architect.

He possesses near-unmatched expertise in the Proxmark3 architecture and various RFID technologies.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 19:00-21:59 PDT


Title: Lawyers Meet
Tags: Meetup
When: Friday, Aug 7, 19:00 - 21:59 PDT
Where: LVCCW Level 3 W301 (Misc Meeting Room) - Map

Description:

If you're a lawyer (recently unfrozen or otherwise), a judge or a law student please make a note to join Jeff McNamara for a friendly get-together, drinks, and conversation.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 16:30-16:59 PDT


Title: Legally Hacked: how countries decide when security research Is allowed
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

As governments increasingly rely on vulnerability disclosure to secure digital systems, many security researchers still operate under cybercrime laws that criminalise the very activity those frameworks depend on. This talk offers a fast‑paced, global comparison of how different countries are addressing that paradox. Drawing on recent reforms and live policy debates, it introduces a practical taxonomy of legal protection models—from statutory defences to prosecutorial guidance and vulnerability disclosure policies as authorisation—and examines their real‑world implications for researchers. The session concludes with a concise “Minimum Viable Safe Harbour” checklist, highlighting the core principles needed to protect good‑faith security research while preventing abuse.

SpeakerBio:  Katharina "Kat S" Sommer, NCC Group

Kat is a seasoned policy and strategy leader with over 15 years of experience spanning political institutions, consultancy, and corporate roles. At NCC Group, she has built and scaled the Government Affairs and Analyst Relations functions, embedding them as strategic enablers of the company’s mission to create a more secure digital future. Her work has shaped cyber policy debates across the UK, EU, and globally—most notably through her leadership in the CyberUp Campaign and contributions to initiatives such as the UN’s Cybercrime Convention and the UK-France Pall Mall Process. Kat is a passionate advocate for cyber resilience, known for her ability to convene diverse stakeholders, drive regulatory engagement, and deliver tangible business outcomes. She holds a Master’s in Public Affairs & Lobbying from Brunel University and a Bachelor’s in Public Administration with a focus on European Studies. Outside of work, she is a 4th Dan black belt in Tae Kwon Do.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 14:00-14:59 PDT


Title: Lessons from a decade of building whistleblower tech
Tags: DEF CON Official Talk | Tool 🛠
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Internet pioneer Aaron Swartz’s last project was SecureDrop, a whistleblower submission system that can be used by news outlets and whistleblowers to communicate safely online. At the time of Aaron’s tragic death, SecureDrop was just a prototype, but it’s now run by Freedom of the Press Foundation and used by dozens of the biggest news outlets around the world. This talk will explore the unique technical challenges in running an anonymous whistleblower platform, the future of whistleblowing technology, and the lessons we have learned about how whistleblowers and journalists actually communicate along the way. In addition, we will preview our new project, a collaboration with the Tor Project called WEBCAT, which aims to solve code verification on web browsers and make end-to-end encryption for web applications safer.

https://securedrop.org https://webcat.tech

Speakers:Trevor Timm,redshiftzero

SpeakerBio:  Trevor Timm, Freedom of the Press Foundation

Trevor is a co-founder and the executive director of Freedom of the Press Foundation (FPF), and has served on its board since 2012. He is a journalist, activist, and legal analyst whose writing has appeared in The New York Times, The Guardian, USA Today, The Atlantic, Al Jazeera, Foreign Policy, Harvard Law & Policy Review, and Politico. Trevor formerly worked as an activist at the Electronic Frontier Foundation. Before that, he helped the longtime general counsel of The New York Times, James Goodale, write the book, “Fighting for the Press,” on the Pentagon Papers and the First Amendment. He received his J.D. from New York Law School. In 2013, he received the Hugh Hefner First Amendment Award for journalism.

SpeakerBio:  redshiftzero, Freedom of the Press Foundation

Jennifer is the chief technology officer at Freedom of the Press Foundation (FPF), where she oversees the organization’s engineering teams. She is an engineer, researcher, and cypherpunk. Prior to this role, she was a founding engineer at Penumbra Labs, focusing on applied cryptography for privacy-preserving payments. She previously led development for the SecureDrop whistleblower platform. She also co-founded Lucy Parsons Labs, a Chicago-based civil liberties group. Jennifer has spoken at events including Hackers on Planet Earth, USENIX Enigma, and DEF CON Crypto & Privacy Village. She holds a doctorate in astrophysics from the University of Chicago.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 15:30-15:45 PDT


Title: Lessons Learned From A Decade of Resumes
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:45 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

After having reviewed resumes for the last decade in a variety of industries (although chiefly cybersecurity), I have a few things to say!

Want to learn how to craft a compelling resume? Want to know what to avoid? This session aims to help jobseekers sell themselves better.

Not only will I dive into the dos and don'ts of resume success, but I will also cover LinkedIn, interviews, networking, and other relevant topics.

If you're looking for work in this brutal market, I hope I can help you out.

SpeakerBio:  Britt Kemp
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Friday - 17:00-17:30 PDT


Title: Lessons Learned from Poland and Beyond: The State of Electric Sector Attacks in 2025
Tags: ICS Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

2026 featured news of a new attempted, disruptive cyber attack against the electric sector. Instead of transmission or distribution in Ukraine, however, the event focused on generating assets in Poland. Irrespective of impact, the very fact such an action was attempted is concerning and newsworthy. However, the details of the event demonstrate the state of the "now" for electric sector events, in terms of their successes as well as failures.

In this discussion we will leverage all available public reporting to look at where the attackers innovated, borrowed from past events, and failed to learn from history in the December 2025 Polish event. From this discussion we will set the incident in context of both concurrent intrusions, such as Volt Typhoon activity, and historical incidents, linked to the Sandworm threat actor, to see just where adversaries are today with respect to tradecraft and sector knowledge.

From this exploration, attendees will emerge with a better understanding of what adversaries are "getting right" about such events, and where they still fall short. Furthermore, review of events will show the significance of physical safeguards and controls in ensuring continuous operations in the face of cyber effects, and how adversaries remain challenged to overcome such barriers.

SpeakerBio:  Joe Slowik, Dataminr

Joe Slowik has over 15 years of experience across multiple cyber domains, ranging from offensive operations through incident response to threat intelligence and research. Currently, Joe serves as director of cybersecurity alerting strategy at Dataminr, but has previously held various roles at organizations such as Huntress, DomainTools, the MITRE Corporation, and Los Alamos National Laboratory.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 12:30-13:25 PDT


Title: Let's BLESPlo.it the world together - introducing a new portable Bluetooth Low Energy security tool
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 13:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Bluetooth Low Energy is absolutely everywhere - in billions of smart devices around us, largely remaining insecure. Most tools to audit it require a laptop, a bunch of dongles, and a pile of scripts often difficult to set up and troubleshoot. But the devices you're testing are mobile. They're in elevators, hospital wards, factory floors, and hotel rooms. Meet the new mobile tool: BLESPlo.it. Run the app on your phone standalone and you already have a capable BLE scanner, fingerprinter and a community-scripts powered remote control for the wireless world around you. Pair it with a small ESP32 companion device for significantly more options: low level scanning, cloning/simulating any BLE device in a few seconds, probing pairing modes, remote relays, and more! Finally try those latest attacks you never had the possibility to setup - no need to get the expensive/unavailable hardware any more. Just simulate any target in seconds and focus on the juicy details instead of fighting your toolchain. And thanks to the dynamic scripting engine you can easily write a custom attack logic on the fly. Share your cloned devices and scripts, let everyone learn from it. Still not convinced? Come see AI-boosted reversing shenanigans and live stunt hacking of dildos, shooting robots and even a Ferrari car!

SpeakerBio:  Slawomir Jasek, BLESPlo.it

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups. Currently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks. Beyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them. Loves sharing his knowledge via trainings, workshops, talks and open source hackme's (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Friday - 15:00-15:45 PDT


Title: Level Up - Could your Gaming Talents be Perfect for a Career in Cyber Security?
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Did you know the skills that make you good at Fortnite or Minecraft are the same ones the cybersecurity industry needs? Hosted by The Hacking Games CEO Fergus Hay, this panel explores how gaming skills can become career opportunities. Fergus is joined by Lorne Rolinson, who helped build HAPTAI—the Hacking Aptitude AI platform that maps gaming skills to cybersecurity career paths; Ricky Handschumacher, who started gaming on Halo forums and fell down the wrong path into hacker criminal activity; and BiaSciLab, who started hacking at age 11 and now teaches ethical hacking through Girls Who Hack and DCNextGen. Together, they now work with The Hacking Games to help young gamers become ethical hackers. Ready to discover where your gaming skills could take you?

SpeakerBio:  The Hacking Games
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 16:00-16:30 PDT


Title: Leveraging Frida to Bypass Mobile Application Security Controls
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

This talk introduces Frida, covering what it is, its capabilities, and how to leverage it during a penetration test. I'll walk through a recent penetration test where I used Frida to run an application on a jailbroken device, bypassing the app's jailbreak detection. We'll review and use Frida scripts to enumerate and identify classes and methods to pinpoint security protections, and I'll show how I leveraged a pre-built Frida script from Frida CodeShare to bypass those controls and run the application on a jailbroken iPad.

SpeakerBio:  Jarrod Rizor, Offensive Services Team Lead of Web & Mobile Application Testing at FRSecure

My name is Jarrod Rizor and I'm an Offensive Services Team Lead of Web & Mobile Application Testing at FRSecure. Birds of Prey Rehab Volunteer.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 13:00-13:59 PDT


Title: LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Models are starting to make security decisions that used to be written as rules. Instead of matching an input against a policy, a model reads the request and decides what to do with it. OpenSearch is one of the first to put one in production as the only thing standing between an anonymous pull request and CI pipeline secrets.

When I reported a vulnerability, the team told me their model would catch it. So I tried to get past it the way you'd expect, hiding the attack. The model caught all of it, and going at it head-on wasn't going to work.

So I stopped trying to outsmart it and started thinking like it, reading why each attempt got caught until I understood what it could actually verify and what it only assumed. What got through in the end hid no attack, because the only dangerous part lived somewhere the model had no way to check.

This talk walks the whole path, from first failed attempt to the bypass that worked. Along the way I mapped the model's decision boundary - what it catches, what slips past, and how far an input bends before its judgment flips. The deeper gap is what it never sees at all, the blind spots built into how it reads a change. You'll see where a model can be trusted to make this call and where it can't, and what that means before you put one in front of something that matters.

https://github.com/opensearch-project/security-response/security/advisories/GHSA-2vmh-cgjm-h48x - Original pull_request_target vulnerability advisory

https://github.com/opensearch-project/security-response/security/advisories/GHSA-q72p-66hv-cc73 - LLM gateway bypass advisory

https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents - Prompt injection attacks against AI code review bots (different attack class)

https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign - 500+ AI-generated malicious PRs targeting pull_request_target across hundreds of repos, including the one repo we discuss in this talk

https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/ - Meta AI support system flaw

SpeakerBio:  Aviv Donenfeld, Check Point Software Technologies

Aviv Donenfeld is a Security Researcher at Check Point Software Technologies. Before security research, he built distributed networking systems as a software engineer. His recent research centers on the attack surfaces of AI coding assistants, including critical vulnerabilities in Anthropic's Claude Code and Cursor. He has found CI/CD supply chain vulnerabilities in Microsoft, SAP, Red Hat, and multiple Linux Foundation projects. Beyond offensive research, he builds defensive security tools in the AI and forensics space.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Friday - 13:00-13:59 PDT


Title: Liberate your Music with Tech Reclaimers
Tags: Hackers.town | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  RemoteNemesis
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 14:00-15:59 PDT


Title: Life Finds a Way: Secure Coding with OWASP ASVS
Tags: OWASP Foundation | Creator Workshop
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

The fences on Apex Island were supposed to keep its visitors safe, but one hacker turned this theme park into a containment failure...with teeth. You’ll use the ASVS secure coding standard to identify and patch vulnerabilities in a lab app, bringing each park facility back online using our rigorous approach to code review. Bring a Docker-capable laptop with GitHub access; bonus if you know your way around a Unix system.

SpeakerBio:  Eden Yardeni, OWASP Contributor, SecureHabits

Eden Yardeni is an application security specialist and OWASP contributor who joined the ASVS working group in 2024. She previously worked as a full-stack developer, but moved into AppSec when she heard there'd be cookies.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 17:00-17:59 PDT


Title: Lightning Talks and Unconference
Tags: Nix Vegas Community | Creator Event/Activity
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Give a talk about whatever you want, as long as it's less than 10 minutes! Or just come and chill in the Nix Vegas space for the Unconference.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 16:30-17:15 PDT


Title: Lights Out and Last Call: A Drunken Tabletop on Medical Device Resilience
Tags: Biohacking Village | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 17:15 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:
Healthcare cyber exercises often end at compromise: ransomware lands, systems fail, and the red team wins. Yay (eyeroll). Real hospitals don't stop there; patients still need scans, medications still need to be delivered, and clinicians still need to make decisions after access disappears.

Lights Out, Last Call is a highly immersive and conversational ""Drunken Tabletop"" experience where participants become a hospital's clinical resilience team immediately following a catastrophic network downtime event impacting connected medical devices. There is no audience. There are only participants. While sipping cocktails and responding to evolving scenario injects, attendees will navigate the uncomfortable reality of healthcare operations and executive decisions after digital access breaks down.

Participants may suddenly lose nuclear medicine imaging, discover vendor firmware dependencies, face impossible prioritization choices, reroute patients across hospitals, and debate whether AI-generated remediation recommendations should be trusted during a crisis.

Through collaborative play, this exercise explores a serious question hidden inside a chaotic environment: when hospitals lose access, who still gets care, who decides, and who gets left behind?

The session combines cybersecurity, medical device resilience, supply chain dependencies, and operational continuity into a social experiment designed to transform healthcare chaos into practical lessons.

Come for the cocktails, stay because your nuc med cameras went offline.

SpeakerBio:  Courtney McCarty

Courtney McCarty spends her days keeping healthcare technology from descending into chaos, focusing on organizational resilience. By night, she trades tinfoil hats for cocktail shakers and turns controlled chaos into memorable experiences at her cocktail lounge, NITRO, in Madison, WI.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Friday - 14:00-17:59 PDT


Title: Live Call Listening
Tags: Scambait Village | Creator Event/Activity
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

A separate Discord channel running live calls, no recordings, listen-only. Runs periodically through Friday afternoon once the Live Calls Workshop wraps. Sometimes it is experienced baiters working a scammer in real time. Sometimes it is one of our bots, of which there are nearly 80 unique builds developed from call recordings captured during live baits. No participation, no signup, nothing required of you but earbuds. Good for anyone who would rather listen than talk.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Friday - 11:30-13:59 PDT


Title: Live Calls Workshop
Tags: Scambait Village | Creator Workshop
When: Friday, Aug 7, 11:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Hands-on workshop focused on live scambaiting calls. Participants can observe, learn techniques, and join in on calls under guidance from experienced scambaiters. Covers safety practices, common scam types, tools, and real-time interaction strategies. Open to all skill levels. This is not a contest, but standout calls may earn a donated training course, handed out by village staff at their discretion at the end of the session.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 10:00-23:59 PDT


Title: Live Recon Contest
Tags: Recon Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 23:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Do you fancy doing live recon on Real Organizations? Activate Yourself. And compete in a unique HACKER challenge. Participants will perform live reconnaissance on a specified list of companies. Your mission is to unearth as much critical information as possible. Contest runs overnight from Friday into Saturday.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 15:00-15:59 PDT


Title: LLM-Coached Red Team Tactics to Attack Zero Trust
Tags: Red Team Village | Misc
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

This workshop is targeted toward novice and intermediate red teamers and explores how AI-assisted offensive agents can support attack-path discovery and adversarial operations within modern Zero Trust environments. Following a brief overview of ARES (Autonomous Reconnaissance & Exploitation System), participants spend most of the session interacting with the agent while navigating a live enterprise range.

ARES is built upon a retrieval-augmented generation (RAG) architecture incorporating offensive doctrine, MITRE ATT&CK mappings, operational playbooks, and offensive knowledge sources including the Red Team Field Manual and UK Ministry of Defence Red Teaming Handbook. The system integrates common offensive tooling including Nmap, Metasploit, NetExec, BloodHound CE, Hashcat, Impacket, Evil-WinRM, and native Linux terminal workflows. ARES can generate attack scripts for operator approval, analyze successful and unsuccessful attacks, identify attack paths, and capture operational knowledge for future recommendations.

Participants will receive continued access to the range and ARES following the conference.

Paired Tactic

The paired tactic places participants inside a simulated enterprise environment running Windows Server 2022 Active Directory, Windows 11 workstations, Ubuntu 24.04 application servers, GitLab Community Edition, Jenkins CI/CD, and Microsoft Entra-style identity services. The environment includes MFA enforcement, network segmentation, service accounts, privileged automation workflows, and least-privilege access controls representative of modern Zero Trust deployments.

Participants begin with access to a Kali Linux attack workstation equipped with Nmap, NetExec, BloodHound CE, Hashcat, Metasploit, Impacket, Evil-WinRM, and ARES. The objective is not simply to exploit a vulnerability but to identify hidden trust relationships between users, service accounts, deployment pipelines, automation platforms, and protected resources.

ARES assists participants with reconnaissance interpretation, attack-path discovery, trust-chain analysis, script generation, and recommendations following both successful and failed operations. Participants may discover exposed service-account credentials, deployment tokens embedded in Git repositories, overprivileged CI/CD workflows, delegated administrative rights, and other trust assumptions that remain despite Zero Trust controls.

Throughout the exercise, all offensive actions require participant approval and execution. The workshop demonstrates how modern red team operations increasingly focus on identities, trust relationships, and authorization paths rather than traditional perimeter exploitation while showcasing how AI-assisted systems can support offensive decision-making and operational knowledge reuse.

Speakers:Rudy Ristich,Vijay Anand

SpeakerBio:  Rudy Ristich

Rudy Ristich is a long-time hacker based in Chicago. He has lead red teams and vulnerability assessment practices, contributed to THOTCON hardware badges, and delivered podcasts and workshops on offensive ops. Rudy strongly believes that red teaming is most valuable when it actually changes how defenders can operate. Most recently Rudy has advised the UC2ADAM project helping to support up-skilling public sector works on information security skill. Rudy has served as a Goon at DEFCON for over a decade.

SpeakerBio:  Vijay Anand

Vijay Anand is an Associate Professor in the Department of Information Technology at Kennesaw State University. He holds a Ph.D. degree from Illinois Institute of Technology. His research interests are in zero-trust architectures, cyber intelligence, embedded security, blockchain technologies, trustworthy cyberinfrastructure, and cybersecurity education. Before joining Kennesaw State University, he had multiple academic appointments, notably as an Associate Professor and Director of Cybersecurity at the University of Missouri - St. Louis and an Associate Professor and Director of Cybersecurity at Southeast Missouri State University. He has previously held industry positions as an Embedded Security Architect at Motorola, Senior Security Engineer at PALM Inc., and as a Security Research Engineer at Computation Institute. He has served as a member of the Missouri Governor’s Cybersecurity Taskforce and was the director of the Missouri Collegiate Cyber Defense Competition. Currently, he has multiple funded research projects from the Department of Defense (DoD) and the National Science Foundation (NSF).


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Friday - 13:00-13:30 PDT


Title: Locked Out? Let's Fix That: An Introduction to the Art of Lockpicking
Tags: DCNextGen | Creator Event/Activity | Youth
When: Friday, Aug 7, 13:00 - 13:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Ever wondered what's actually happening inside that padlock when you turn the key? This hands-on class pulls back the curtain on one of the oldest security technologies humans ever built — and shows you exactly how (and why) it can be defeated. You'll get the fundamentals, then the lab to experiment and learn, with several individuals around to help guide you and answer questions

SpeakerBio:  Greg Anderson
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 13:00-17:59 PDT


Title: Locktopus - Open Qualifying
Tags: Lockpick Village | Locktopus Competition | Contest
When: Friday, Aug 7, 13:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

How do your lockpicking skills compare to the rest of the class? Enter the TOOOL US Locktopus Competition and find out! Eight legs, eight locks, eight lockpickers, one red table. Four locks of a similar difficulty must be picked, only five minutes per lock is given, thus 20 minutes per attempt/round. The 32 pickers with the fastest combined time will move on to a semi-final championship. The fastest of each round will move on to the final round, with the eight fastest pickers at the table. Open qualifying starts on Friday from 1:00pm and runs until village close. Semi-finals on Saturday at 1:00pm. Final championship on Saturday at 3:00pm.

Participant Prerequisites

Participants should be familiar with the very basics of picking locks. This can be learned at the lockpick village, where the locktopus challenge will be taking place.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 11:00-11:59 PDT


Title: Logsquashing: Consolidating Relevant Events Logs and Alerts
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

In modern cybersecurity, the ability to connect isolated security alerts into coherent, actionable attack chains is essential. However, traditional detection methods often struggle to contextualize vast amounts of security data, leaving slow and stealthy attacks undetected within a sea of noise and false positives. This talk introduces a novel approach using open-source AI models to map, cluster, and correlate security alerts in order to uncover coordinated attacks. Through clustering, knowledge graphs, and AI-driven correlation, this approach offers significant improvements in SOC (Security Operations Center) efficiency and effectiveness. We detail the methodology, open source tools, and results of this approach across diverse environments, including cloud, telecom, and industrial control systems.

SpeakerBio:  Ezz Tahoun

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada's CSE.

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Friday - 10:00-17:59 PDT


Title: Lonely Hackers Club - Lockpicking Table
Tags: Lonely Hackers Club | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

Learn new skills and find new friends at our lockpicking table. We provide you with beginner friendly locks, picks, and experienced volunteers to guide you through the process. Bring your own equipment to talk shop and get some new perspectives.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Friday - 10:00-17:59 PDT


Title: Lonely Hackers Club - Sticker Swap Table
Tags: Lonely Hackers Club | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

DEF CON and stickers can't be separated. Visit our sticker swap table to get your hands on the latest sticky art and exchange the ones you made yourself. Check in regularly to get a chance to find rare gems.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Friday - 10:00-17:59 PDT


Title: Lonely Hackers Club CTF
Tags: Lonely Hackers Club | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

We welcome all skill levels, from first-time DEF CON attendees to experienced CTF competitors. The challenges are layered, so newcomers can get meaningful wins while veterans still find plenty to chew on. Participants often team up spontaneously on location, making it as much a social experience as a technical one. Participate for a chance to get awesome prizes!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 14:30-14:59 PDT


Title: Lowering the Orbit: Exploiting Satellite Protocols and communications via Software-Defined-Radio and GS
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Friday, Aug 7, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

The "Security by Obscurity" era in satellite communications is over, but the industry hasn't received the memo. As we shift toward COTS hardware and standardized protocols like CCSDS and Space Packet Protocol (SPP), a massive attack surface has emerged, stretching from ground stations to the satellite.

In this talk, i will show the vulnerabilities of the modern space link. i will move beyond simple RF command injction to demonstrate a full-spectrum exploitation methodology. Using PWNSAT and PWNCUBE a high-fidelity, open-source satellite exploitation ecosystem we simulate an end-to-end mission under fire.

I will demonstrate:

Protocol Fuzzing, GNS spoofing and command exploiting CCSDS/SPP packet structures over LoRa/FSK. Lateral Movement in Orbit: How a compromised RF link leads to command injection on the internal CAN bus to manipulate satellite subsystems. Ground Segment Pivoting: Exploiting the Mission Operations Center (MOC) via radio protocol vulnerabilities.

This is not just a tool demo; it is a deep dive into the flaws of aerospace's most trusted protocols. We provide the community with a "Vulnerable-by-Design" orbital platform to bridge the gap between cybersecurity and space engineering.

SpeakerBio:  Romel "r0r0x" Marin

Romel Marín is a Senior Hacker and Aerospace Cybersecurity Researcher with over a decade of experience in offensive operations. He has executed complex penetration testing assessments for diverse industries and Fortune 500 companies. Currently, he specializes in applying offensive methodologies to aerospace technologies, satellite protocols, and artificial intelligence. Romel is an external collaborator for the SPARTA (Space Attack Research & Tactics Analysis) framework and serves as a co-founder of the DEF CON Costa Rica group (DC11506). A speaker at international conferences such as BlackHat, DEF CON, Typhooncon DragonJAR, and Ekoparty, his work focuses on the security analysis of aerospace infrastructure and mission-critical communications.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 10:55-11:35 PDT


Title: Lyra: An LLVM IR Obfuscator for Rust
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 10:55 - 11:35 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

Rust is rapidly becoming the language of choice for red team tooling, implants, and security-critical software. Yet the offensive security ecosystem has almost no obfuscation tooling for it. Nearly every production obfuscator targets C/C++ binaries or operates on final PE/ELF images; Rust's unique compile pipeline, name mangling, and LLVM IR patterns require a fundamentally different approach.

This talk presents Lyra, an open-source, cargo-native LLVM IR obfuscator for Rust. Lyra intercepts each crate during a normal "cargo build" via RUSTC_WRAPPER, transforms the LLVM IR with a configurable pass pipeline - string encryption, basic-block shuffling, indirect-branch obfuscation - recompiles the result with llc + clang, and substitutes the object before the real MSVC linker runs. Zero changes to the Rust compiler, zero changes to the target project's source code, one flag on the command line.

We walk through the architecture, the engineering challenges unique to Windows/MSVC (UTF-16 response files, allocator-shim object preservation, inkwell's undocumented panic guards), and live before-and-after demonstrations in IDA Pro, Ghidra, and Binary Ninja.

We also show a YARA rule that confidently matches a plain demo build returning zero results on the obfuscated binary, and two consecutive unseeded builds producing different hex patterns, defeating a rule written on the first build.

Lyra is released open-source at the time of the talk. All demos are reproducible from the release. Attendees leave with a working tool they can run against their own Rust projects the same day.

SpeakerBio:  Rafael Felix, Offensive Security Lead at Hakai Offensive Security

Rafael has been working with malware development for 5 years, also being involved in the malware community for more than 7 years. He is also experienced in Incident and Response, specifically during malware inner workings analysis. Currently, Rafael is a researcher for Hakai Offensive Security (https://hakaisecurity.io/research-blog), being deeply involved with red-team operations.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 12:00-12:59 PDT


Title: macOS Doesn’t Get Malware…Until It Does
Tags: Red Team Village | Misc
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:
Abstract:

macOS has long been perceived as a low-risk platform, often treated as a secondary concern compared to Windows and Linux. That assumption no longer holds. As MacBooks become increasingly common in corporate environments, adversaries have followed, turning macOS into a viable and attractive target for real-world attacks.

This talk presents a practical, research-driven analysis of the recent evolution of macOS malware. Through hands-on experiments and real techniques, it explores how modern threats achieve execution, fileless operation, persistence, and evasion by abusing native macOS components. The presentation also evaluates how widely adopted to macOS security tools respond, and in many cases fail, to detect these behaviors.

By walking through the attacker’s mindset and development process, this session aims to expose a growing blind spot in enterprise security and challenge the outdated belief that “macOS doesn’t get malware.”

Description:

As organizations continue to expand their macOS footprint, security strategies often lag behind. Many defensive teams remain heavily focused on Windows and Linux, leaving macOS environments under-monitored, under-tested, and misunderstood.

In this talk, I will share my journey researching and developing macOS malware from an adversarial perspective.

The session focuses on how attackers leverage legitimate macOS mechanisms to achieve:

Each technique is demonstrated using real experiments, with analysis of macOS internals and the behavior of commonly deployed security solutions. Rather than theoretical concepts, the talk emphasizes how these attacks work in practice, and why many defenses fail to stop them.

The presentation also addresses a persistent myth, especially common in the Brazilian security community, that macOS is inherently safer or “immune” to malware. By examining real attack paths and defensive gaps, the session highlights the urgent need for improved detection strategies, visibility, and threat modeling on macOS.

Attendees will learn:

This talk is intended for defenders, red teamers, malware researchers, and anyone interested in understanding how adversaries are actively adapting to the macOS ecosystem.

About events where I've spoken:

Analyzing malicious PDFs - ConfraSec 2019 Reconnaissance vs Vulnerability Analysis - OWASP-Vitoria 2019 Red Team X Blue Team - OWASP Latam 2020 Maldocs: an analysis of malicious documents - Bsides Vitoria 2022 LockBit and its tricks - Bsides Vitoria 2023 LockBit and its tricks - Bsides São Paulo 2023 LockBit and its tricks - HackBahia 2023 Ransomware: No one can stop this naughty baby - Bsides Vitoria 2024 Ransomware: No one can stop this naughty baby - Bsides São Pauço 2024 Ransomware: No one can stop this naughty baby - CajuSEC 2024 From Zero to Ransomware for MacOS - HackBahia 2024 Ransomware vs EDR: Inside the Attacker's Mind- BHack Conference 2024 Ransomware vs EDR: Inside the Attacker's Mind - Bsides Rio de Janeiro 2025 Ransomware vs EDR: Inside the Attacker's Mind - Bsides São Paulo 2025 Ransomware vs EDR: Inside the Attacker's Mind - Bsides Vitoria 2025 Ransomware vs EDR: Inside the Attacker's Mind - CajuSEC 2025 Ransomware vs EDR: Inside the Attacker's Mind - Bsides Las Vegas (backup speaker) Ransomware vs EDR: Inside the Attacker's Mind - Red Team Village - DEFCON 2025 Ransomware vs EDR: Inside the Attacker's Mind - BxSec - 2025 Ransomware vs EDR: Inside the Attacker's Mind - Malwee Cyber Security Event Ransomware vs EDR: Inside the Attacker's Mind - Online - BMW Group MacOS Malwares: Breaking Barriers - BHack Conference 2025 Ransomware vs EDR: Inside the Attacker's Mind - 307 Security Conference MacOS Malwares: Breaking Barriers - Ox3 Hacker Conference 2026 Ransomware vs EDR: Inside the Attacker's Mind - Red Team Village Overflow (Online) - DEFCON 2026

SpeakerBio:  Zoziel Freire

I have a degree in Information Systems and a postgraduate degree in Forensic Computing. With over 16 years of experience in the information technology sector, I have had the opportunity to provide services to several companies across various segments in Brazil and other countries.

Throughout my career, I have acquired solid experience in Incident Response, Forensic Analysis, Threat Hunting, Pentester, Malware Analysis and Developer, and Reverse Engineering. I have also worked on Ransomware incidents, both in Brazil and in other countries.

I have actively contributed to the information security community, participating in Brazilian events. Sometimes I spend time bypassing EDR and AntiVirus, and testing operating system gaps. I am passionate about music, especially guitar and piano, and I am a fan of Chaves and Chapolin.

BSides Las Vegas – US – 2025 (Backup Speaker) – Ransomware vs EDR: Inside the Attacker's Mind Red Team Village @ DEF CON – Las Vegas, US – 2025 – Ransomware vs EDR: Inside the Attacker's Mind BMW Group – Online – 2025 – Ransomware vs EDR: Inside the Attacker's Mind Red Team Village Overflow @ DEF CON – Online – 2026 – Ransomware vs EDR: Inside the Attacker's Mind


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 16:00-16:45 PDT


Title: MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

When TSA scans your luggage, they see what's inside without opening the bag. MailX-Ray brings that pattern to email triage.

Phishing reports hit analysts as small crises: open carefully, don't trigger anything, extract IOCs, hand off to detection. Tooling lives at two extremes: cloud sandboxes that ship customer data offsite, or lightweight CLIs that run malicious parsers directly on the analyst's host. Neither produces a portable safe artifact, on-prem and hardware-isolated, in roughly 30 seconds.

MailX-Ray does. Every email is processed inside an ephemeral hardware-virtualized microVM with no network device. Network egress is prevented by design. Output includes a single-file portable HTML safe-read report, structured JSON with 45+ offline signal categories, and optional STIX and MISP exports for SOC integration. Original attachment binaries are never re-distributed.

It's not a malware sandbox. No decompilation, no execution, no verdicts. It's a non-invasive structural scan: the first 30 seconds of email triage, with zero network egress, on the analyst's own laptop.

Demo Labs attendees will see the live pipeline across real phishing scenarios, including encrypted nested archives. Open source on the day of the talk.

SpeakerBio:  Uğur "uJohn" Can ATASOY

Uğur Can Atasoy is a Senior Security Engineer at Udemy, working primarily on blue and purple team operations.

A believer in hybrid approaches that combine technical fieldwork with academic rigor, he has spent the past decade across higher education, media, defense, and automotive sectors in roles spanning security architect, specialist, trainer, and consultant. His work spans both offense and defense — from security operations, threat hunting, intrusion detection, purple teaming, and adversary simulation to penetration testing and secure architecture. He has served as a Senior Content Engineer at TryHackMe and as an Information Security Architect at Mercedes-Benz. He has delivered security training for NATO personnel, law enforcement investigators, and military leadership, spoken at DeepSec (Vienna), holds CCSP, GCIA, OSCP, and OSWP, and served as an ISC2 SME for exam and training item development. He has been recognized by Oracle and IBM for responsible disclosure.

MailX-Ray is his answer to a recurring annoyance: every tool in the email triage stack is either a cloud SaaS that ships customer data offsite, a heavyweight VM-based sandbox that takes minutes per sample, or an unprotected CLI that runs malicious parser input directly on the analyst's host. It produces a safe artifact analysts can read and forward.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 11:30-11:59 PDT


Title: Make Money Hacking AI
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

In the past year, I made over $100,000 exclusively hacking AI in competitions and bug bounty platforms. In this talk, I will go over my strategies, my findings, and the techniques that consistently led to high-impact vulnerabilities.

Attendees will leave with a practical framework for getting succeeding in AI competitions and getting into AI bug bounty platforms, as well as producing outstanding, slop-free reports.

Speakers:Joey Melo,Edward Morris

SpeakerBio:  Joey Melo

Joey is a Principal Security Researcher at CrowdStrike and a contributor to AI safety programs at OpenAI and Anthropic. He specializes in offensive security research and adversarial analysis of complex systems, with a particular focus on AI/ML infrastructure and large language models. His work has led to the discovery of critical vulnerabilities and novel exploitation techniques, helping organizations better understand and defend against sophisticated threat actors. He has experience across red teaming, exploit development, and designing resilient architectures for high-risk environments. Joey has earned recognition through bug bounty programs and multiple security competitions, with over $100,000 awarded for vulnerability research. He is also an OSCP, OSCE³ and CRTO-certified professional.

SpeakerBio:  Edward Morris

Edward Morris is a frontier AI security researcher focused on indirect prompt injection, sandbox escape in IDE and browser agents, and offensive use of LLM agents. He ranks top-3 globally on Mozilla's 0DIN GenAI bug bounty program and recently won Meta's AI Hacking Challenge at MBBRC 2026 in Taipei, the only researcher of around 200 to solve it. He is an invited researcher in Anthropic's and OpenAI's AI safety bug bounty programs, and works with BT6, a frontier-AI red team that does pre-deployment testing for major AI labs. His work is finding the attack patterns that break agentic AI before it ships, and turning them into techniques other hunters can use.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:30-11:30 PDT


Title: Make your very own evil IoT Cat Lamp with WLED!
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this class, we’ll put together a 'Purrsheen' cat shaped Wi-Fi lamp. Kit Cost: $60. Class Cap: 30.

SpeakerBio:  Nick
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Friday - 10:00-17:59 PDT


Title: Makers' Village - Hacker Arts and Crafts
Tags: Maker's Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 14:00-14:45 PDT


Title: MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

Your AI agent trusts every skill in its directory. What if one of them is lying? In this Demo Lab, I walk you through MalSkills, natural language malware planted inside AI agent skill systems. No binaries, no shellcode, no signatures. Just English sentences with OS-level access. Using ORPHEUS, my open-source multi-skill orchestration framework, I demonstrate three escalating attacks live: 1. BURIED INSTRUCTION: A malicious sentence hidden in a legitimate skill exfiltrates .env files on first execution. I show you 12 skills and challenge you to spot it. 2. CHAIN ATTACK: Five individually benign skills that, when orchestrated together, create an emergent data exfiltration path. No single skill is malicious. The composition is the weapon. 3. PERSISTENT GHOST: A skill that writes itself into agent memory, surviving file deletion and session restarts. Remove the skill, restart the agent, exfiltration continues. After offense, I flip to defense. I demo the MalSkill Detection Toolkit: skill integrity verification, capability-based sandboxing, orchestration graph analysis, and runtime behavioral monitoring. Attendees leave with: the ORPHEUS framework, a MalSkill sample pack, and a detection toolkit, all open source! Every AI agent with a plugin system is vulnerable today. Come see why.

SpeakerBio:  Nur "BurritoTheNurrito" Gucu

Offensive security professional and AI security researcher with 10+ years across financial services, startups, and Amazon. Currently on the foundational model red team at Amazon AGI Labs, where I break AI systems and build the tooling to detect what I find. Core focus: LLM security, agentic system exploitation, and the gaps between how AI frameworks are designed and how they actually behave under adversarial pressure. 6 patent applications. Published author (AWS Security Blog, internal science papers). Invited speaker on MCP security and LLM training APT attack surfaces. I turn research into shipped products and open-source tools, not empty slide decks.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 10:00-16:59 PDT


Title: Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.
Tags: Malware Village | Misc
When: Friday, Aug 7, 10:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Demos - Map

Description:

Malysis runs Windows bare-metal directly from RAM. No hypervisor, no disk writes, no forensic footprint. A custom kernel-mode storage driver presents RAM as a native NVMe device, fully opaque to the OS, to malware, and to any forensic tooling. Warm reboots preserve full analysis state | the environment survives restarts intact. Full shutdown is total: power off brutally and the next boot loads a cryptographically validated pristine image from the source. The RAM substrate delivers native NVMe performance: 50+ GB/s sequential, 1M+ IOPS, with full Windows environments. No persistent storage writes. No recovery. Built for analysts who need bare-metal behavior without burning hardware.

Speakers:Yannick LaRue,Samuel B. G.

SpeakerBio:  Yannick LaRue, Malware Village - Malysis

30 years of low-level programming in C with 0 use of libraries, oriented in cryptography and high-security systems.

SpeakerBio:  Samuel B. G., Treasurer@ Malware Village, Founder @ Securitech Systems, Co-Founder @ Malysis

Sam is a cybersecurity and datacenter expert and works mainly on on-premise and sovereign solutions for cybersecurity, AI and architectures networks and secure hosting in facilities across Canada. In his free time, he participates yearly in many conferences and organizes Malware Village, a Canadian cybersecurity non-profit that presents at conferences like Defcon and Bsides around the world.

That's what i could come up with haha let me know if it works!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 10:00-16:59 PDT


Title: Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.
Tags: Malware Village | Misc
When: Friday, Aug 7, 10:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Demos - Map

Description:

Malysis runs Windows bare-metal directly from RAM. No hypervisor, no disk writes, no forensic footprint. A custom kernel-mode storage driver presents RAM as a native NVMe device, fully opaque to the OS, to malware, and to any forensic tooling. Warm reboots preserve full analysis state | the environment survives restarts intact. Full shutdown is total: power off brutally and the next boot loads a cryptographically validated pristine image from the source. The RAM substrate delivers native NVMe performance: 50+ GB/s sequential, 1M+ IOPS, with full Windows environments. No persistent storage writes. No recovery. Built for analysts who need bare-metal behavior without burning hardware.

Speakers:Yannick LaRue,Samuel B. G.

SpeakerBio:  Yannick LaRue, Malware Village - Malysis

30 years of low-level programming in C with 0 use of libraries, oriented in cryptography and high-security systems.

SpeakerBio:  Samuel B. G., Treasurer@ Malware Village, Founder @ Securitech Systems, Co-Founder @ Malysis

Sam is a cybersecurity and datacenter expert and works mainly on on-premise and sovereign solutions for cybersecurity, AI and architectures networks and secure hosting in facilities across Canada. In his free time, he participates yearly in many conferences and organizes Malware Village, a Canadian cybersecurity non-profit that presents at conferences like Defcon and Bsides around the world.

That's what i could come up with haha let me know if it works!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 16:10-16:40 PDT


Title: Man-in-the-Browser: Hijacking Javascript APIs for Browser Persistence and Credential Theft
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Friday, Aug 7, 16:10 - 16:40 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

On a system, the most utilized application by typical users is the browser, yet the majority of modern exploits attack other technologies, most of which are heavily targeted by antivirus softwares. Browser extensions are known to be challenging to detect and provide as much(if not more) value as other forms of C2 and data capture. Modern solutions rely solely on whitelists and blacklists without considering potential supply chain breaches or other risks to this method.

SpeakerBio:  Aarav Juneja

Aarav Juneja is a high school sophomore at Amador Valley High School, Pleasanton, CA, who placed 1st nationally in the Advanced Division of Lockheed Martin's CyberQuest and earned a scholarship at BlackHat 2025 for his Passkeys research. He came in the top 1% worldwide at CMU’s picoCTF and was additionally selected for the US Cyber Challenge Camp. He is building autonomous systems for RoboSub 2026, competing against 60+ university teams including Stanford, Cornell, and CMU. As Co-Founder and CTO of UniGiig Inc., Aarav deployed production applications, architecting a full-stack system for a student marketplace. Aarav has completed undergraduate-level coursework from Harvard University in cybersecurity, AI, and computer science, and also holds a Silver Division status in the USA Computing Olympiad. He serves as President of his school's Cybersecurity Club and his interests span penetration testing, reverse engineering, cryptography, and binary exploitation across multiple platforms.


Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Friday - 12:15-12:59 PDT


Title: Maritime Hacking Village Policy Panel: Shadow Fleets, Cyber Effects, and Plausible Deniability
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 12:15 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Grey zone competition is no longer confined to cyber networks, nor is maritime disruption limited to traditional naval activity. Shadow fleets, spoofed identities, opaque ownership structures, sanctions evasion, cable “accidents,” and cyber-enabled interference are increasingly overlapping in ways that complicate attribution, deterrence, and defense.

This panel will explore what happens when cyber and maritime grey zones converge. How do states and non-state actors use ambiguity at sea to create strategic effects while maintaining plausible deniability? What tools exist to identify, attribute, and respond to these activities? And how can governments, allies, industry, and legitimate shipping operators protect global commerce without escalating every incident into a crisis?

Speakers:RADM John Mauger,Michael Sulmeyer

SpeakerBio:  RADM John Mauger, PORTS LLC, USCG (ret.)

Rear Admiral John W. Mauger, USCG (Ret.) is a seasoned executive with over 33 years of leadership experience in the maritime industry, national security, and cyber operations. Known for his foresight, innovative approach to problem solving, and ability to drive change, John has left an indelible mark on every role he’s undertaken—from commanding complex Coast Guard operations to shaping the future of cyber defense.

As Commander of the First Coast Guard District, he led over 12,000 people and oversaw critical port operations in New England, deploying innovative technologies like counter-drone systems to enhance security. John's leadership during the TITAN capsule search and recovery at the TITANIC site highlighted his ability to lead complex crises in the international spotlight.

At U.S. Cyber Command, John revolutionized cyber training, developing a cloud-based environment that modernized cyber exercises and increased readiness. John also served as the Coast Guard’s first Executive Champion the National Naval Officers Association, mentoring future leaders and driving organizational change.

Earlier in his career, John led key regulatory projects for both domestic and international shipping. His work protected mariners and the environment, created new markets for alternative fuels, and established a new international code to safeguard vital Polar regions.

Now leading (PORTS) LLC, John uses his diverse expertise to help clients plan for and navigate complex challenges in the maritime and critical infrastructure industries while enhancing personnel and team performance through effective training.

SpeakerBio:  Michael Sulmeyer, US DoD (ret.), Georgetown School of Foreign Service

Michael Sulmeyer will start as Professor of the Practice at the School of Foreign Service's Security Studies Program in the fall of 2025. He most recently served as the first Assistant Secretary of Defense for Cyber Policy and as Principal Cyber Advisor to the Secretary of defense. He has held other senior roles involving cyber-related issues with the U.S. Army, the Office of the Secretary of Defense, U.S. Cyber Command and the National Security Council. In academia, he was a Senior Fellow with Georgetown's Center for Security and Emerging Technology. He holds a doctorate in politics from Oxford University where he was a Marshall Scholar, and a law degree from Stanford Law School.


Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Friday - 10:00-10:45 PDT


Title: Maritime Hacking Village Policy Panel: Subsea Cables as Strategic Chokepoints - Security, Sovereignty, and the Grey Zone
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Subsea cables carry the overwhelming majority of the world’s digital traffic, yet the legal, operational, and diplomatic frameworks for protecting them remain fragmented. Recent cable disruptions, suspected anchor drags, and other “accidents” have highlighted how critical infrastructure at sea can become a target of grey zone activity while leaving governments, operators, and allies with limited options for attribution and response.

This panel will examine what is being done to secure subsea cable infrastructure, where current domestic and international regimes fall short, and what new partnerships, authorities, and deterrence models may be needed. How should governments, industry, and the security community respond when the backbone of the internet runs through contested waters?

Speakers:Dr. Nina Kollars,Jason Vogt,Delta Blue

SpeakerBio:  Dr. Nina Kollars, US Naval War College

Dr. Nina Kollars is an Associate Professor at the U.S. Naval War College’s Cyber and Innovation Policy Institute, where she specializes in cyber resilience, emerging technologies, and wargaming efforts focused on Taiwan and the Pacific. Dr. Kollars also serves as co-director of the Maritime Hacking Village, a 501c3 that advances ethical hacking on maritime assets and infrastructure. She is also an executive bourbon steward.

SpeakerBio:  Jason Vogt, USNWC

Jason Vogt is an assistant professor in the Strategic and Operational Research Department, Center for Naval Warfare Studies at the United States Naval War College. Professor Vogt is a cyber warfare and wargaming expert. He has participated in the development of multiple wargames at the United States Naval War College. He previously served on active duty as an Army officer.

SpeakerBio:  Delta Blue, Anon

Delta Blue is former Navy and is now part of the private sector.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 11:30-11:40 PDT


Title: Maritime Hacking Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 11:30 - 11:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Maritime Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Maritime Hacking Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: Mentoring and Career Advice
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Informal, one-on-one conversations with volunteer mentors and speakers about breaking into cybersecurity, career pivots, resumes, certifications, and next steps. No appointment needed — just come find a mentor in the village during open hours.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 08:00-17:59 PDT


Title: Merch (formerly swag) Area Open -- README
Tags: Misc
When: Friday, Aug 7, 08:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1500 (MERCH) - Map

Description:

The short version

The slightly longer version:

Similar to the last few years, HackerTracker will have artwork or photos of the merch for you to browse before you join the line -- you can decide ahead of time if you are interested in a product. HackerTracker is also showing stock status – if an item goes out of stock, that’ll be indicated in-app; this is on a best-effort basis, and some products move fast. You're able to make a wish list in Hacker Tracker, which expedites the ordering process at the front of the line (making everything faster and easier for everyone). If you don't want to use Hacker Tracker, you can have a merch goon create the order on your behalf.

Tentative instructions

Here’s the process, from beginning to end:

  1. Browse the products, in-app. The list of products with associated artwork are expected to be published early the morning of August 6.
  2. When you find a product that you want to buy, make sure that you’ve selected the right variant/size, and then tap “Add to List”. Think of your list like a wish list.
  3. To view your list: If you’re using iOS, tap on the QR code at the top right. If you’re using Android, tap the “View List” button at the bottom.
  4. Your list shows everything you’ve added; if an item has gone out of stock since you added it, a warning will appear, and you’ll be required to remove the item from your list.
  5. When you near the front of the merch line, show the QR code at the top of your list to the order taker. They’ll scan it, and print a paper list. The list will have an order number on it, as well as your total amount due. The order taker can help answer any questions and help you modify your order if needed. If any items have sold out since they were added to your list, the order taker can help you find a replacement or remove it from your list.
  6. The paper list will be used to retrieve the merchandise from the warehouse. You will wait in a space that is after order taking but before checkout while your order is being picked. While you are waiting, please get your cash out. Exact change is preferred (it makes everything move faster), but change is available when required. If there are any issues picking your order, someone will help with you find alternatives or update your order.
  7. Once your merch is ready, a cashier will shout your order number, and/or hold up a sign with your order number written on it. Quickly make your way to the cashier, and complete the transaction.
  8. Enjoy!

Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 13:45-15:15 PDT


Title: Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 13:45 - 15:15 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. Kit Cost: $140. Class Cap: 30.

SpeakerBio:  Kody Kinzie
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Friday - 11:00-11:30 PDT


Title: Meshtastic 101: Off-Grid Mesh Networking with LoRa
Tags: Ham Radio Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:30 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

Meshtastic is an open-source project that enables decentralized, off-grid communication networks using inexpensive LoRa radios and microcontrollers. By combining long-range low-power radio technology with modern mobile apps and mesh networking protocols, Meshtastic makes it possible to build resilient communication networks without relying on cellular or internet infrastructure.

This presentation provides an introduction to the Meshtastic ecosystem and the technologies that power it. Topics include the fundamentals of mesh networking, the basics of LoRa radio communication, and how Meshtastic integrates radios, ESP32-based devices, and smartphones into a distributed messaging platform.

The talk will also cover common hardware platforms used in Meshtastic deployments, including DIY nodes and commercially available devices, and demonstrate how easy it is to set up and join a network.

Finally, we’ll explore real-world applications for Meshtastic, including event communications, off-grid coordination, disaster response, and experimental hacker networks.

Attendees will leave with a clear understanding of how Meshtastic works and what they need to begin experimenting with mesh radio networks themselves.

Meshtastic has quickly become one of the most exciting new tools in the radio and hacker communities. Using inexpensive LoRa radios and open-source software, it allows anyone to build decentralized, off-grid messaging networks that work without cellular infrastructure or the internet.

This talk introduces Meshtastic and the technologies that make it possible. We’ll cover the basics of LoRa radio, how mesh networking works, and how Meshtastic ties together radios, microcontrollers, and mobile apps into a simple communication platform.

Attendees will learn what hardware is required, how easy it is to set up a node, and how Meshtastic networks are being used at events like DEF CON and in off-grid environments around the world.

If you’re curious about building your own mesh network—or want to understand why everyone is suddenly carrying strange little radios—this session will show you how to get started.

SpeakerBio:  Jon Marler (K4CHN)

Jon Marler is a cybersecurity product director, hacker, and RF experimenter who enjoys building strange things that connect computers, radios, and networks together. By day he leads security products at VikingCloud focused on protecting global payment infrastructure. By night he experiments with mesh radio networks, hardware hacking, and unconventional communication systems. Jon is particularly interested in how radio and decentralized networks can complement modern security and resilience strategies.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 14:00-14:59 PDT


Title: Microsoft and Amazon are my Favorite C2 Providers
Tags: Red Team Village | Misc
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Cloud relay services check every box for C2 transport: outbound-only HTTPS on 443, cloud brokered connectivity so the attacker never touches the target directly, and endpoint domains that enterprises literally cannot blocklist without breaking production. I validated this at a Fortune 40, you can't block *.servicebus.windows.net or *.iot.amazonaws.com without taking down dozens of business critical systems.

This research was accepted at Red Team Village DC33 but I had to withdraw due to a family emergency. The work has continued since then with the AWS IoT MQTT technique, the Mythic agent integrations, and the detection package as new additions. The talk covers three techniques I built, validated, and integrated into Mythic C2:

Azure Relay Bridge — Microsoft's own open source relay tool becomes a LOLBin. It's Microsoft-signed, supports persistent service installation on Windows/Linux/macOS, and tunnels all C2 traffic through *.servicebus.windows.net as standard HTTPS. I demo my custom Mythic C2 profile end to end, with agent check in, post-ex, all traffic indistinguishable from legitimate Azure usage.

AWS IoT Secure Tunneling — Tunnels created from the attacker's own AWS account, zero CloudTrail in the target's environment. Great for lateral movement and short duration pivots, but I hit real operational limits during testing (12-hour lifetime, 1 Mbps ceiling, distinctive 20s keep-alive) that make it less ideal for persistent C2.

AWS IoT Core MQTT — Those Secure Tunneling limitations led me here. MQTT pub/sub with X.509 mTLS auth, no tunnel lifetime limits, indefinite persistence through *.iot.amazonaws.com. I built custom Mythic agents: Poseidon (Go) for Linux/macOS, Apollo (C#) for Windows, both validated on AMD64 and ARM64.

All the material will be available at the time of the presentation: Mythic agents and translation containers for both transports, infrastructure provisioning scripts, and detection rules (Suricata, Zeek, Splunk). Both Microsoft and AWS were engaged before disclosure. There's no vuln to patch, this is an architectural problem with how cloud relay services are designed.

SpeakerBio:  Robert Pimentel, Hacker Hermanos

Robert is a seasoned offensive security professional with more than a decade of experience in Information Security.

He began his career in the U.S. Marine Corps, where he worked on secure telecommunications. Robert holds a master's degree in Cybersecurity, numerous IT certifications, and a background as an instructor at higher education institutions like the New Jersey Institute of Technology and American University.

Robert is committed to sharing his knowledge and experiences for the benefit of others. He enjoys Brazilian steakhouses and cuddling with his pugs while writing Infrastructure as Code to automate Red Team Infrastructure.

Robert is the Director of Offensive Security at Humana, Inc.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 16:30-16:59 PDT


Title: Minimize Harm, Maximize Defense: How Anthropic Navigates the Offense-Defense Divide
Tags: AI Village | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:
Cybersecurity capabilities are inherently dual use: the same tools that help defenders find and fix vulnerabilities can, in the wrong hands, be the precursor to a cyberattack. As AI models grow more capable, this tension intensifies. When Anthropic launched Claude Fable 5 with the strongest cybersecurity safeguards we have ever applied to a model, we were forced to make concrete decisions about where the line between defense and offense should be drawn.

In this talk, we walk through how we reason about that line. We describe the four categories our safety classifiers use to evaluate cybersecurity activity: prohibited use (high harm, little defensive utility), high-risk dual use (core security professional work that we block until better access controls exist), low-risk dual use (mostly defensive, but blocked as part of a deliberate safety margin), and benign use (defensive and IT activities we aim to never block). We explain the tradeoffs behind each category and why we deliberately set Fable 5's safety margin larger than any prior model, accepting a higher rate of false positives in exchange for greater confidence that harmful requests would be caught.

We also introduce an early version of the Cyber Jailbreak Severity (CJS) framework, which we continue to develop with our Glasswing partners to create a common industry standard for assessing how serious a given jailbreak is.

This is not a finished answer. These categories, thresholds, and tradeoffs represent our best current thinking, but we anticipate they will evolve as model capabilities advance, as the legal and regulatory landscape shifts, and as we learn from the security community's experience using these tools in practice. We are sharing our framework because the people most affected by where these lines are drawn should have a voice in drawing them.

SpeakerBio:  Curt Barnard⁩
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Mission: Compromised - Hacking a Satellite from the Ground Up
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Ever wondered what it takes to hack a satellite? At this hands-on station, you'll step into the role of an attacker targeting a CubeSat-class spacecraft and its ground control station — all running in a safe, fully isolated environment.

Working against a live mission control system (OpenC3 COSMOS / Yamcs) and a spacecraft simulator, you'll follow an attacker's kill chain across multiple layers — from reconnaissance and ground station compromise all the way to the spacecraft itself. Where does it end? Let's just say the mission doesn't survive. Come find out how. Every step is paired with the real-world defense that would have stopped it - so you'll leave understanding both how these attacks work and how space systems defend against them. Whether you're new to space security or already deep in the field, come try it out, break a satellite (safely!), and see the attack surface of modern spacecraft up close.

It will take approximately 15-30 minutes to work through this hands-on demo and guided exercises. You can watch attacks demonstrated by our team, then try guided scenarios yourself using real CCSDS space protocols, RF concepts, and industry mission control tooling. A live mission dashboard will reveal the spacecraft's fate as the scenario plays out.

No prior space experience required - all skill levels welcome. We recommend you bring your own laptop the hands-on portions. A laptop with GNU Radio will let you dig into the RF challenge, and a Kali Linux setup or your equivalent pentesting toolkit are recommended for the more advanced challenge.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 10:00-17:59 PDT


Title: Mobile Hacking - Informal CTF
Tags: Mobile Hacking Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 10:00-17:59 PDT


Title: Mobile Hacking Community - Open
Tags: Mobile Hacking Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs.

Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills.

Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain.

Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment.

Prerequisites:


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 11:20-11:30 PDT


Title: Mobile Hacking Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 11:20 - 11:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Mobile Hacking but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Mobile Hacking and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 15:00-15:45 PDT


Title: Mobile Security through Obscurity, from insecure client-side encryption to unauthenticated SQL
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

In this talk the Just Mobile Security team will talk about the Mobile Security through Obscurity, from insecure client-side encryption to unauthenticated SQLi. Talking about a lot of LATAM Banks and Fintechs who implemented that in their applications.

Speakers:Juan Urbano Stordeur,Juan Martinez Blanco

SpeakerBio:  Juan Urbano Stordeur, CEO and Founder at Just Mobile Security
No BIO available
SpeakerBio:  Juan Martinez Blanco, Mobile Security Penetration Tester at Just Mobile Security
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 13:00-13:45 PDT


Title: Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF
Tags: DEF CON Demo Labs | Advanced | Cloud | Defense/Blue Team | DEF CON Demo Labs
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Container security tools observe behavior (eBPF) and enforce policy (BPF-LSM, AppArmor, Seccomp). But the translation between observation and enforcement is manual and incomplete. We present the first tool that treats this translation as a compilation problem. Built in Rust with the Aya eBPF framework, three monitoring modules serve as compiler frontends feeding a normalized behavioral IR. Optimization passes operate on this IR: pattern classification, rule deduplication, dead rule elimination, conflict detection, and cross-category dependency linking. The backend compiles optimized IR into BPF-LSM enforcement rules across three LSM hooks: security_file_open, security_bprm_check_security, and security_socket_connect. Enforcement is default-deny: any operation not in the compiled profile is blocked. We demo end-to-end: a container is profiled, the profile compiled through the pipeline, and enforcement blocks unauthorized file access, process execution, and network connections at the kernel level. Zero manual policy writing. We document the friction points where monitoring context diverges from enforcement context. No existing tool, including vArmor and KubeArmor, implements this compilation architecture with a true IR, optimization passes, and multi-category LSM enforcement.

SpeakerBio:  Buğrahan Yücel

Buğrahan Yücel is a software engineer at a SaaS company in Turkey, where he works on infrastructure security. He currently builds eBPF-based behavioral profiling and enforcement tooling in Rust using the Aya framework. This is his first DEF CON presentation.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 11:00-11:59 PDT


Title: Morbidity and Mortality: Hackers, HIPAA, and a new Prescription for Healthcare Cyber Policy
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

US healthcare cybersecurity policy has flatlined. An eruption of targeted ransomware is only the latest epidemic plaguing a beleagured sector facing workforce shortages, grappling with legacy medical devices and dependent on a complex web of vulnerable third party vendors. As patients suffer, doctors and nurses struggle, and hospitals bleed money they don’t have, critical public health stakeholders and institutions are failing to meet the moment. How did we get here? Join quaddi & r3plicant, two physician hackers and amateur wonks as they take you through a cyber policy autopsy - diagnosing the decisions and dilemmas that have resulted in this current crisis. From a diseased culture of secrecy predicated on a willful misunderstanding of privacy regulation to outdated national response and recovery frameworks, this talk will explore how policy choices made at the dawn of medicine’s digitization have aged poorly in an era of health system consolidation, single point of failure dependencies, and a rabid push to integrate AI into everything from thermometers to transplant surgery. The prognosis isn’t all dire. From a revitalized HIPAA to bipartisan bills to resuscitate rural hospitals, a policy prescription exists to better protect patients and secure systems. It’s time to take your medicine.

Speakers:Christian Dameff,Jeff "r3plicant" Tully

SpeakerBio:  Christian Dameff, UC San Diego Center for Healthcare Cybersecurity

Christian (quaddi) Dameff, MD is an ER doc and Associate Professor of Emergency Medicine, Biomedical Informatics, and Computer Science (Affiliate) at the University of California San Diego, where he also co-directs the Center for Healthcare Cybersecurity. He is a hacker, former open capture the flag champion, and prior DEF CON/RSA/Blackhat/HIMSS Speaker. He previously has testified in front of the U.S. Congress and U.S. Food and Drug Administration.

SpeakerBio:  Jeff "r3plicant" Tully, UC San Diego Center for Healthcare Cybersecurity

Jeff (r3plicant) Tully, MD is a security researcher with an interest in understanding the ever-growing intersections between healthcare and technology. His research has been highlighted in international media, leading academic medical journals and cease and desist letters sent on behalf of billion-dollar cybersecurity corporations. As an elected member of the Health Sector Coordinating Council Cyber Working Group’s Executive Committee he regularly engages with policymakers and other federal healthcare cybersecurity stakeholders. During his day job as an anesthesiologist, he focuses primarily on the delivery of oxygen to tissues.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 16:50-17:20 PDT


Title: Most threat modeling artifacts don't help coding agents fix business logic. Here's what does.
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Friday, Aug 7, 16:50 - 17:20 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Coding agents increasingly produce code that looks clean to static analysis, but still ship business-logic bugs: the kind threat modeling is supposed to prevent. Across 86 controlled experiments, we varied the security context given to gpt-5.5-codex across eight artifact families and three prompt structures, using the same codebase, PRD, and four planted business-logic flaws. Generic artifacts - DFDs, component diagrams, OWASP checklists - did not reliably help; several performed worse than no artifact at all. In one run, the agent - handed an OWASP checklist - cited A07 in its plan and shipped a 365-day bookmarkable magic link, the exact vulnerability A07 names. One pattern worked across every replication: feature-specific threats paired with concrete countermeasures, in a plan-forcing prompt. The talk walks through the mechanism behind these failure modes and the open-source tool we built to generate the artifact shape that worked.

SpeakerBio:  Meitar Ronen

Meitar Ronen is AI Research Lead at Clover Security, where she drives the research direction for agentic development and AI infrastructure. She previously built computer vision algorithms and holds an M.Sc. in computer science with a focus on deep learning, with publications at CVPR and ICCV. She turned to the dark side and now leads AI research for cyber, focused on the hard problems that decide whether security agents can be trusted with real work.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: MOUSE Runner & Flappy Drone
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

How High Can You Make a Satellite Jump? Can You Fly a Drone Around Aliens and Rockets?

Put your action-hero reflexes and hand-eye coordination to the test as you battle fellow DEF CON attendees for the top scores in MOUSE Runner and Flappy Drone. The highest scores on Friday and Saturday will earn a special prize. Stop by our booth to learn more, show off your button-mashing skills, and prove you're the ultimate space cyber pilot.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 20:00-23:59 PDT


Title: Movie Night
Tags: Event
When: Friday, Aug 7, 20:00 - 23:59 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 13:00-13:45 PDT


Title: MSCodePhish: Redeem Your Coupon. Surrender Your Session
Tags: Intro/Beginner | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

MSCodePhish is a red‑team toolkit that turns Microsoft’s Device Code OAuth flow into an embeddable phishing primitive that works inside any lure (e.g., “grab your coupon,” “unlock access,” etc.). Instead of pre‑generating device codes and racing against the usual 15‑minute timeout, MSCodePhish exposes a simple API endpoint that phishing pages can call via JavaScript (XHR/fetch) at the exact moment a victim opens the page. The tool then generates a fresh device code on demand, returns it to the phishing page (e.g., rendered as a “coupon code”), and instructs the user to complete the login on the legitimate Microsoft device login portal using that code.

Behind the scenes, MSCodePhish continuously polls Microsoft’s token endpoint for that device code and, once the victim finishes authentication, captures the resulting refresh token and related claims (tenant, user, etc.). From its web UI, operators can track active campaigns, monitor which lures are converting, and use captured refresh tokens to request new access tokens for different resources (ARM, Key Vault, Graph, Storage, or custom scopes) in real time. Because the code is generated only when the phishing HTML is actually loaded, MSCodePhish effectively sidesteps device‑code expiration issues and enables more realistic, flexible phishing flows that closely mimic

Speakers:Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla

SpeakerBio:  Raunak "Trouble1" Parmar

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.

SpeakerBio:  Chirag "3xpl01tc0d3r" Savla

Chirag Savla is a Cyber Security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. He prefers to create open-source tools and explore new attack methodologies in his leisure. He has worked extensively on Azure, Active Directory attacks, defense, and bypassing detection mechanisms. He is an author of multiple Open Source tools such as Process Injection, Callidus, etc. He has presented at multiple conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 19:00-19:59 PDT


Title: Music - Genre: Goth / Industrial
Tags: Entertainment
When: Friday, Aug 7, 19:00 - 19:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  Daemon Chadeau

From the darkest lit nightclubs to the livestreaming virtual nightlife, DJ Daemon Chadeau has imposed their will upon sound systems and dance floors all over the US since 2003. A native of Southern California, Daemon has been a staple of Seattle's Mercury at Machinewerks since moving to the Northwest in 2011 and has been highlighting the bleeding edge in music from all around the diaspora of dark music, whether it is harsh industrial, power noise, darkwave, or bass-saturated electronic beats, and everything in between. After being recognized by their peers in both 2014 and 2015 as the Best Local Industrial DJ at the Mechanismus Industrial Music Awards, Daemon expanded beyond their home base and has performed at venues such as The Coffin Club (PDX), The Church Nightclub (DEN), and QXT's (NJ), as well as larger events such as Convergence XXI (LA), The Mechanismus Festival (2022 & 2025), The 2026 Seattle Fetish Ball, The Arcane Vampire Ball (DEN), and the main stage at DEFCONs 32 & 33 (LV). You can catch Daemon at The Mercury on 2nd Wednesdays (Protokol) and 3rd Fridays (Tech Noir), as well as at Time Warp for Continuum every 2nd Thursday! Outside of the decks, Daemon is the bassist for Seattle-area rock band Prelude To A Pistol, and is also the producer/composer/evil kitty mastermind Sir Kitty Meow-Meow in the experimental meower noise project Pixelpussy. Daemon has also been heavily involved with community engagement in the Seattle area, from mentoring up-and-coming DJs to having served as President of Gothic Pride Seattle from 2021 to 2024.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 20:00-20:59 PDT


Title: Music - Genre: Goth / Industrial
Tags: Entertainment
When: Friday, Aug 7, 20:00 - 20:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  DJ Scythe

SoCal/Vegas-based DJ Scythe spins Industrial/Aggrotech/Witch House/Synthpop/Synthwave/EBM/EBSM and all manners of dark and heavy music. He is a founding member and resident DJ of UnterKlub, Club Fallout, GothCon, and Nachturnal, Resident DJ at AREA15, and previously of BatCave LA. He regularly DJs the main stages for DEFCON, Wasteland Weekend and Neotropolis, and has done headlining shows for Torture Garden, Bondage Ball, Das Bunker, and others. Also a producer, his music can be found as SCYTHE, Artifact Corruption, and various other projects and is honored to have had his music featured on the Official DefCon 28 Safe Mode tape and various releases since.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 22:00-22:59 PDT


Title: Music - Genre: House
Tags: Entertainment
When: Friday, Aug 7, 22:00 - 22:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  Skittish & Bus
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 21:00-21:59 PDT


Title: Music - Genre: Nerdcore
Tags: Entertainment
When: Friday, Aug 7, 21:00 - 21:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  Ohm-I

Ohm-I is a nerdcore rapper, saxophonist, and red teamer who mixes humor, storytelling, and a hacker perspective into clever and fun #BARS.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 00:00-00:59 PDT


Title: Music - Genre: Techno
Tags: Entertainment
When: Friday, Aug 7, 00:00 - 00:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  dotornot

With his trusty decks and mixer, DotOrNot unleashes a barrage of electrifying beats, showcasing the full spectrum of electronic music, from techno to house & DnB. DotOrNot is a champion of the underground, a protector of the genre, and a hero to all who dance to the beat of his music.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 23:00-23:59 PDT


Title: Music - Genre: Techno
Tags: Entertainment
When: Friday, Aug 7, 23:00 - 23:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  TRIODE

For up-and-coming uplifting trance DJ/Producer based out of San Francisco, Triode, music is much more than words could ever explain. Music serves as the cinematic backdrop to each of our stories, and as a DJ he sees it as his job to curate the perfect soundtrack to celebrate this amazing thing we call ‘life’. Whether it’s on the dancefloor, or in the studio producing his own beats - Triode’s takes his listeners for a ride, into a magical place where you become the hero of this musical journey.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 10:00-18:59 PDT


Title: Music - SomaFM
Tags: Entertainment
When: Friday, Aug 7, 10:00 - 18:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:

SomaFM is back in the Chillout Lounge– just off the atrium at the south entrance (W107-W109). SomaFM DJs including kampf, Rusty, Merin MC, djddead and special guests will provide the perfect soundtrack for hacking or relaxing. Stop by and say hello, and pick up a 2026 limited edition sticker. We'll also be broadcasting live on https://somafm.com/live/ – And did we mention, we have stickers!?


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 16:00-16:30 PDT


Title: Nation State Obfuscation Networks
Tags: Telecom Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. Edge devices are now the primary obfuscation layer for state-sponsored intrusion traffic
  2. Each CRINK nation has converged on the same strategic goal anonymization through borrowed infrastructure via distinct operational means: China’s ORBs, 3.North Korea’s laptop farms and commercial VPNs, Russia’s botnets and 4th party hijacking • External network telemetry visibility is one of the few defender advantages that scales against these threat
SpeakerBio:  Will Thomas
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 14:00-14:59 PDT


Title: Navigating AI-Assisted Submissions
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Recent advances in AI have dramatically reshaped the landscape of offensive security and bug bounty hunting, and nowhere is that shift more visible than in the report submissions themselves. AI-assisted reports are forcing the industry to confront familiar questions of scale, scope, and structure in new ways: from triage bottlenecks to signal-to-noise ratio to how "quality" is defined when a hunter's tooling has changed. This panel examines that shifting ground from the perspective of the bug bounty platforms themselves. Drawing on the experience of platform leaders navigating this transition firsthand, attendees will gain insight into the challenges AI-assisted submissions are creating, the solutions platforms are implementing in response, and practical guidance on how hunters can adapt their workflows to succeed in 2026 and beyond.

Speakers:Tony Lee,Michael Skelton,Alexander Wren,Selim Jaafar,Shlomie "shlibness" Liberow

SpeakerBio:  Tony Lee, Vice President of Operations, HackerOne

Tony Lee is VP of Operations at HackerOne, leading the Triage, Support, and Mediation teams. With over 20 years in security, red teaming, incident response, and operations, he is a data-driven, trusted advisor to many global organizations and boards. His prior experience includes leading production testing, AI transformation, and bug bounty at AWS. As an avid educator, he has taught thousands of students at venues worldwide, including government, universities, corporations, and conferences.

SpeakerBio:  Michael Skelton
No BIO available
SpeakerBio:  Alexander Wren
No BIO available
SpeakerBio:  Selim Jaafar
No BIO available
SpeakerBio:  Shlomie "shlibness" Liberow

Shlomie is the founder and CEO of aisy. He spent many years on offensive side at HackerOne, where he ran live hacking events making the final call on more than $20M in verified findings. That work put him on both sides of the bounty table: the hunters chasing the critical, and the teams deciding what to do with it once it lands. At aisy he is building a context layer for enterprise risk, taking the findings companies already have from scanners, pentests, and bounty programs, connecting them to the threats the business actually cares about, and pushing root-cause fixes through the coding agents engineers already use.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 14:00-14:30 PDT


Title: Nebula - 5 years, still kicking *aaS
Tags: Demo 💻 | Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:30 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to allow testing other Cloud Providers and DevOps Components. It started as a project to unify all Cloud + DevOps Pentest and Security Techniques for a better assessment of the Infrastructures. It is build with modules for each provider and each functionality. Initially released in April 2021 as a bulk of scripts, it developed into a C2 framework, managed through a teamserver, allowing a team of pentesters to authenticate and access the tool, as well as a MongoDB database to save the results into. Offers modules for reconnaissance, initial access, enumeration, Command and Control, post exploitation, persistence and cleanup in AWS, Azure Graph and Management API, DigitalOcean, as well as a new release for GCP and GWS, Kubernetes and defense bypasses.

Currently covers: - Public Reconnaissance - Phishing - Brute-force and Password Spray - Enumeration of internal resources after initial access - Lateral Movement and Privilege Escalation - Persistence

Ever since I pushed the last update, the tool has changed drastically. Now you will get a teamserver based tool, with a client and server split, authentication to access the tool, user management and a MongoDB database to save the results into.

SpeakerBio:  Bleon "gl4ssesbo1" Proko

Bleon is an Info-sec passionate about Infrastructure Penetration Testing and Security, including Active Directory, Cloud (AWS, Azure, GCP, Digital Ocean), Hybrid Infrastructures, as well as Defense, Detection and Thread Hunting. He has presented topics related to Cloud Penetration Testing and Security in conferences like BlackHat USA, Europe and Sector, DEF CON, SANS Pentest Hackfest Hollywood and Amsterdam, as well as several BSides on USA and Europe.

His research include Nebula, a Cloud Penetration Testing Framework (https://github.com/gl4ssesbo1/Nebula) and other blogs, which you can also find on his blog (blog.pepperclipp.com). He is also the author of YetiHunter, DetentionDodger and Ransomwhen (https://github.com/Permiso-io-tools/[DetentionDodger | YetiHunter | Ransomwhen]).

He is also the author of the upcoming book "Deep Dive into Clouded Waters: An overview in Digital Ocean's Pentest and Security" (https://leanpub.com/deep-dive-into-clouded-waters-an-overview-in-digitaloceans-pentest-and-security)


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Nebula Showdown: Space Systems Security CTF Adventure
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Join the Aurora Alliance in their critical mission to thwart the notorious Nebula Syndicate and save the Earth! The Syndicate threatens to destroy historic monuments around the world with their Space Laser unless their demands are met. Do you have what it takes to dismantle their malevolent plans and deorbit a menacing space threat?

This entry-level CTF kicks off as soon as the village opens - no pre-registration necessary. Just bring your laptop and your go-to cybersecurity tools – Wireshark, NMAP, and any FTP client you prefer. We know the DEF CON wifi can be unpredictable, so this CTF will be local only to the Aerospace village via an isolated local range. The CTF is designed to be completed in under an hour, making it perfect for a quick yet engaging challenge. Team collaboration is encouraged, and if you encounter obstacles, numerous hints are available to guide you. There are no penalties for using hints. Our goal is for you to learn something new and make it all the way through the CTF. Excel in the challenge, and you could walk away with an exclusive CT Cubed SAO prize while supplies last.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 16:00-16:59 PDT


Title: Network Implants: Lessons Learned Building Reliable Red Team Dropboxes
Tags: Red Team Village | Misc
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

This 60-minute session is both a technical workshop and an interactive tactic. The first half is a practical walkthrough of how we built and refined a field-ready network implant (commonly called a “Dropbox”) for red team engagements. The second half is hands-on: attendees can interact with the Dropboxes (i will bring a few), connect to the lab environment, test operator access (even via smartphone), ask questions, and experiment with parts of the workflow themselves.

The problem we wanted to solve was simple to describe but hard to get right: after gaining physical access and placing a device inside a client network, testers should be able to work from their own laptops and VMs almost as if they were on-site. No “walk back to the car, open the laptop, hope LTE works, debug the tunnel in a hallway” workflow. The implant should give operators reliable access, support normal tooling, survive unreliable networks, and allow quick, discreet verification from a phone that the box is alive, reachable, and in the right network segment.

We will cover the practical details that make this harder than “just plug in a Pi”: small hardware, LTE/WiFi/Ethernet connectivity, OS/config deployment, safe updates, fallback access, and early-stage network discovery. This includes scenarios where the implant first needs to quietly observe the local network, understand addressing and services, or sit transparently behind an already-authenticated device in NAC/802.1X environments before operators decide how to blend in and route traffic safely.

The architecture side focuses on making the system useful for real consulting work: operator VPN access, central routing, tenant separation, overlapping customer networks, and strict isolation between engagements. In our setup, testers connect from their normal kali or Windows VMs and get routed into the correct client environment without touching client-side routing, while the system ensures that operators assigned to one project cannot accidentally reach another.

For the interactive part, I will bring a limited number of physical Dropboxes. Attendees can connect to the lab, test the operator experience, onboard through VPN profiles or QR codes, and see how the device behaves from both the “dropped box” and operator side. The same workflow can also run in a VM, so the core concepts are testable without owning the exact hardware.

This is not a product pitch. The goal is to show how to build this kind of infrastructure from the ground up using open hardware and software components. Attendees should leave with a realistic blueprint for building their own authorized red team Dropbox setup, including the parts that usually get skipped in demos: routing, updates, recovery, tenant isolation, operational safety, and all the little edge cases that only show up once the box is actually in the field. All the playbooks, configs etc. will be made available publicly.

SpeakerBio:  Hassan Mohamad

Hassan Mohamad is a penetration tester and red teamer at Certitude Consulting. He conducts and leads penetration tests and large-scale red team assessments for large cooperations of various industries. Previously, he led an offensive security team at Sec-Research and worked in digital forensics and security consulting at Deloitte. He holds OSCP and OSEP certifications and is a multiple-time winner of the Austria Cyber Security Challenge. His work focuses on practical red team infrastructure, physical-access tradecraft, and building offensive systems that survive real client environments.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 10:10-10:50 PDT


Title: New AWS IAM Attack Paths and the Framework to Exploit Them
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 10:10 - 10:50 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

In cloud environments, the path from low-privilege foothold to full account takeover often runs through IAM privilege escalation. This talk introduces over a dozen newly discovered escalation paths spanning services that have never appeared in public research: AWS Batch, Amazon Braket, Amazon Managed Apache Flink, Amazon GameLift, Health Omics, and more.

We'll walk through exploiting the most interesting paths in depth, including cross-account variants and attacks that require delivering malicious code payloads to trigger escalation. Then we'll introduce Pathrunner, a new open-source Metasploit-style framework built specifically for IAM privilege escalation, and show how it makes chaining these complex, multi-hop attacks practical during a real engagement.

SpeakerBio:  Seth Art

Seth Art is a Security Researcher & Advocate at Datadog. Prior to joining Datadog, Seth created and led the Cloud Penetration Testing practice at Bishop Fox. He is the author of pathfinding.cloud, an AWS IAM privilege escalation library, and has published many open source tools including Pathfinding-labs, IAMVulnerable, BadPods, and CloudFoxable, and is the co-creator of the popular cloud penetration testing tool, CloudFox.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 10:00-10:30 PDT


Title: Nix Vegas Opening Ceremony
Tags: Nix Vegas Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Kickoff and opening of the Nix Vegas space on Friday, and start of the Nix CTF!

Speakers:Daniel Baker,Morgan Jones,Tristan Ross

SpeakerBio:  Daniel Baker

Daniel Baker is a developer, engineer, and mathematician passionate about reproducible software. An active NixOS community member and educator, he authored the NixCon NA 2024 Nix module system workshop and nixos-modules-lessons. He serves on the NixOS Marketing Team and helps organize both Nix Vegas and Planet Nix. He believes any system worth building is worth rebuilding, bit for bit.

SpeakerBio:  Morgan Jones

Embedded security engineer who does too many weird things with Nix.

SpeakerBio:  Tristan Ross

I work on supply chain security at Determinate Systems.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 16:00-16:30 PDT


Title: NixOS Workspaces
Tags: Nix Vegas Community | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Working on multiple projects simultaneously? Display getting cluttered? Agents in a race condition all trying to fight over the same ports and browser agents?

This presentation introduces NixOS Workspaces, a method of partitioning environments for local and remote development. Workspaces assist concurrent agentic development workflows by reducing risk and facilitating common environment configurations across projects. NixOS workspaces is backed by nixos-containers, a wrapper on systemd-nspawn.

Presentation includes a demo of the workflow, architecture, guidance on modes of deployment, security considerations, and installation guidance.

SpeakerBio:  JB

Josh Brown is an Application Security Specialist with a background in both Penetration Testing and Web Application Development. Josh works full-time with CodeQL in the Microsoft Security Analysis & Fix Engineering (SAFE) team to identify vulnerabilities across the organization and drive remediation.

Josh has had a highly technical career, previously providing security consulting services as an OSCP and OSWE certified penetration tester to various organizations in the APAC region, including ANZ Bank, Australia Post, and EY before settling into his role at Microsoft in Redmond.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: No Stupid Questions
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Ongoing AMA booth with volunteers and speakers answering all your DEF CON and cyber questions


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Friday - 13:00-13:59 PDT


Title: Non-Binary/Gender Non-conforming Meetup
Tags: Queercon Community | Creator Event/Activity
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-10:55 PDT


Title: Noob Community - DEF CON 34 Opening Statements
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:55 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 16:30-17:30 PDT


Title: noRecognition: Could a pattern on your clothing fool Facial Facial Recognition?
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

You are being watched. Not in the vague, philosophical sense. Right now. The ATM you used this morning. The gas pump. Every doorbell on your block. The 125 smart streetlights you walked past on your way to lunch. You are indexed, cataloged, and matched against databases you never consented to join, by AI models that are wrong more often than the vendors will ever admit.

Other solutions to this involves looking ridiculous. Face paint. IR glasses. Masks. Real-time deepfake software running on your phone. Congrats, you defeated the algorithm AND ensured every human within 50 feet is staring at you. Super subtle. I built something different. noRecognition is a genetic algorithm that breeds adversarial patterns, printed on ordinary fabric, that defeat the entire facial recognition pipeline: person detection, face detection, and identity recognition across 10 models used by Clearview AI, Axon, Hikvision, and Palantir. No electronics. No software. You look like a person wearing a scarf. The AI sees nothing.

I will demonstrate this live on stage. One camera. One scarf. Zero detections. Come watch me disappear.

SpeakerBio:  Bill "hevnsnt" Swearingen, SecKC

Bill Swearingen (hevnsnt) has been in the hacking scene for decades, and you can tell by the way he looks. He spoke at DEF CON 27 with "HAKC THE POLICE," which became one of the most watched DEF CON talks of all time. He is the founder of SecKC, the world's largest monthly security meetup. When he is not trying to make himself invisible to surveillance cameras, he builds things that break other things, preferably with cheap hardware and undeserved confidence.

noRecognition is his current obsession. He built the fuzzer, the genetic algorithm, the distributed network, and the pattern library. He has been saving the findings for this stage.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 12:25-13:05 PDT


Title: North Korea’s Zoo: Poaching for Gophers, Armadillos and RATs
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 12:25 - 13:05 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

In this talk, a continuation of the North Korea’s Zoo series, we take apart three new malware samples linked to North Korean operators: a fresh iteration of GoLangGhostRAT, POWerful Armadillo (a rework of Digit Stealer), and Mach-O Man, a new macOS malware kit. All of them were first-spotted and reversed by our team.

We will focus on what actually matters: interesting bits of code, mistakes in their infrastructure, and how we were able to abuse their C2 to profile campaigns and mess with their operations.

We’ll also cover how these samples are being distributed, including some newer tricks we’ve been seeing in the wild.

At several points, we ended up talking directly with the operators themselves. We’ll be sharing those interactions here for the first time.

This talk can be enjoyed by both beginners and seasoned threat hunters alike.

SpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team

Hacker and Speaker.

Founder of BCA LTD and DC5411.

I wrote a book interviewing Threat Actors.

I like Threat Intelligence and Golden Retrievers.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 10:00-10:59 PDT


Title: Not Your Parents’ Schoolhouse Rock: Getting Tech Policy Done in a Non-Functioning Congress
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

Forget "Schoolhouse Rock." In a modern, gridlocked Congress, laws aren't just made; they survive a grueling gauntlet and get mangled along the way. Jeff Rothblum (Founder, Plaintext Strategies; former Senate/White House) and Mike Flynn (Vice President & Counsel, ITI; former Senate/House) provide an unfiltered, behind-the-scenes look at the legislative combat required to pass the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), the most significant cyber law in a decade. This session breaks down the "Inside-Outside" game: from the "Prom" analogy that gave the bill room to breath, the coming together of fractious industry groups, and the internal administration "civil war" between CISA and the FBI. We’ll explain how we used the threat of higher fines to force industry to the table, how we dodged jurisdictional minefields by avoiding the Judiciary and Oversight Committees, and why we eventually traded the bill's name just to buy the Cybersecurity and Infrastructure Security Agency (CISA) more time to write the rules. This is your manual for how to actually "get shit done" in a non-functioning D.C.

Speakers:Jeff Rothblum,Michael Flynn

SpeakerBio:  Jeff Rothblum, Founder at Plaintext Strategies

Jeff Rothblum, founder of Plaintext Strategies, has worked at the intersection of technology and policy for two decades. He has led government affairs at an AI startup, served as a cyber threat intelligence analyst, led cybersecurity policy the Senate Homeland Security and Governmental Affairs Committee, served as a Director of Cyber Policy and Plans at the White House Office of the National Cyber Director, and co-owned an artisan blacksmithing company.

SpeakerBio:  Michael Flynn

Mike Flynn is Senior Vice President and Counsel for Government Affairs and Economic Security Policy at the Information Technology Industry Council (ITI). In this capacity, he leads ITI’s advocacy efforts on cybersecurity issues and the national security implications of technology and telecommunications. He has led technology policy in the Senate Homeland Security and Government Affairs Committee, on the Committee on Oversight and Government Reform, and the Committee on Homeland Security. Mike was also the lead cybersecurity oversight attorney that investigated the data breaches at the Office of Personnel Management in 2014.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 13:00-13:59 PDT


Title: Nothing Wrong Here: Why AI Artifact Scanners Wave Malware Through
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

Your AI security scanner says the skill is clean. Should you believe it? We took a corpus of malicious and benign agent skills and ran it through the tools security teams trust to catch this stuff. What we found should worry anyone shipping AI. The tools that fire loudest are often wrong, the ones that stay quiet are often blind, and the industry reflex of stacking more scanners on top makes the problem worse, not better. There is a reason for all of it, and it is not the one vendors want to talk about. This session walks through what actually breaks, why the whole category is looking in the wrong place, and what it would take to build a scanner whose green checkmark you can trust.

SpeakerBio:  Amber Bennoui
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 15:00-16:59 PDT


Title: NPM Imposters - The malware detection card game
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map

Description:

NPM Imposters is a fast-paced educational card game designed to teach players about supply chain security risks in software development, particularly through malicious NPM packages.

SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 12:30-12:59 PDT


Title: O Lado Sombrio das Coisas: Transformando Dispositivos DIY em Vetores de Ataque
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

O objetivo principal desta palestra é demonstrar como a democratização do hardware e da filosofia Do It Yourself (DIY) aceleraram a prototipagem rápida, mas na pressa para ver o projeto "funcionar" muitas vezes ignoram os padrões mínimos de segurança.

A idéia é provocar a audiência a adotar a filosofia "Secure by Making", integrando o hardening e a análise de superfícies de ataque desde a primeira solda e linha de código do protótipo.

SpeakerBio:  Christiane Borges Santos, Coordenadora do Eixo de Design Factory - Criar IFG

Tecnóloga em Redes de Comunicação e Mestre em Engenharia Elétrica e da Computação. Fundadora do Grupo de Robótica para Meninas Metabotix e membro do Grupo de Robótica GYNBOT. Atualmente, professora no Instituto Federal de Goiás (IFG) campus Luziânia, Instrutora CISCO NetAcad e Coordenadora do Eixo de Design Factory do Criar Polo de Inovação do IFG.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 13:30-14:59 PDT


Title: Octopus Game - Booth Battle #1: The Front Man's Wager
Tags: Octopus Game | Contest
When: Friday, Aug 7, 13:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 17:00-17:59 PDT


Title: Octopus Game - Booth Battle #2: The Midnight "Brawl"
Tags: Octopus Game | Contest
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Octopus Game - Booth Open
Tags: Octopus Game | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-10:59 PDT


Title: Octopus Game - Opening Ceremony
Tags: Octopus Game | Contest
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 13:00-10:59 PDT


Title: Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed)
Tags: Octopus Game | Contest
When: Friday, Aug 7, 13:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-12:59 PDT


Title: Octopus Game Opens and Pre-registration Check-In Available
Tags: Octopus Game | Contest
When: Friday, Aug 7, 10:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-16:59 PDT


Title: Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 16:59 PDT
Where: LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map

Description:
SpeakerBio:  Abhijith "Abx" B R, Founder of Adversary Village

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry, serves as the Director of BreachSimRange, and Founder of Adversary Village. He is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker. Currently, he is building BreachSimRange.io as the Founder and Director and is involved with multiple organizations as a consulting specialist to help them build offensive cyber security operations programs, improve their current security posture, assess cyber defense systems, and bridge the gap between business leadership and security professionals. In the past, he led the offensive security team at Envestnet, Inc., held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY. As the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc. Abx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/), a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft. Abhijith has spoken and delivered trainings at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con – Kennedy space center Florida, Nullcon – Goa, c0c0n – Kerala, BSides Delhi, DEF CON Bahrain, DEF CON Singapore etc.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-16:59 PDT


Title: Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 16:59 PDT
Where: LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map

Description:
SpeakerBio:  Abhijith "Abx" B R, Founder of Adversary Village

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry, serves as the Director of BreachSimRange, and Founder of Adversary Village. He is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker. Currently, he is building BreachSimRange.io as the Founder and Director and is involved with multiple organizations as a consulting specialist to help them build offensive cyber security operations programs, improve their current security posture, assess cyber defense systems, and bridge the gap between business leadership and security professionals. In the past, he led the offensive security team at Envestnet, Inc., held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY. As the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc. Abx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/), a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft. Abhijith has spoken and delivered trainings at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con – Kennedy space center Florida, Nullcon – Goa, c0c0n – Kerala, BSides Delhi, DEF CON Bahrain, DEF CON Singapore etc.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Friday - 12:15-12:45 PDT


Title: Offensive Security from Your Pocket
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Friday, Aug 7, 12:15 - 12:45 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

Smartphones are powerful—but so are the threats targeting them. This talk explores real-world mobile attack techniques through demonstrations, including rogue Wi-Fi access points for data interception, Android app manipulation with Frida, and using Kali NetHunter on rooted devices for portable offensive operations.

I'll showcase hardware-based attacks like BadUSB cables, wireless exploitation via Bluetooth vulnerabilities, and NFC relay threats, alongside insights into modern mobile malware capabilities. Each technique is paired with practical mitigation strategies, giving attendees both offensive understanding and defensive takeaways to better secure mobile ecosystems.

SpeakerBio:  Lukas Stefanko, Senior Malware Researcher at ESET

Lukas Stefanko is an experienced senior malware researcher with a strong engineering background and a well-demonstrated focus on Android malware research and security. With more than 14 years' experience with malware, he has been focusing on improving detection mechanisms of Android malware and in the past couple of years has made major strides towards heightening public awareness around mobile threats and app vulnerabilities. He has presented at several security conferences such as RSA, Virus Bulletin, Confidence, DefCamp, BountyCon, AVAR, Ekoparty and others.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 12:00-12:59 PDT


Title: Once Upon a Prompt: Fairy Tales That Explain AI Security
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

Prompt injection is one of the biggest security challenges in AI, but it can be difficult to explain without diving into complex technical details. This session uses familiar fairy tales to make modern AI attacks easy to understand and hard to forget. We’ll begin by exploring the architectural problem that makes prompt injection possible and why LLMs can’t separate instructions from data the way traditional software can. From there, we’ll examine three real-world AI security incidents, each paired with a classic story: Little Red Riding Hood illustrates prompt injection through trusted messengers, The Wolf in Sheep’s Clothing explains indirect prompt injection hidden in untrusted content, and The Trojan Horse demonstrates how hidden instructions can lead to data exfiltration and agent compromise. We’ll close by mapping practical defenses to OWASP and NIST guidance so attendees leave with clear mental models and actionable techniques for building more secure AI applications.

SpeakerBio:  Sana Talwar
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 17:00-17:59 PDT


Title: One Chain to Own Them All — Breaking AI Infrastructures
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

2025 marks the dawn of AI security. Pwn2Own Berlin launched its first AI track, featuring Ollama and Triton Inference Server, while ZeroDay.Cloud introduced new challenges targeting vLLM and Ollama. These competitions pushed us to take a closer look at the security of core AI infrastructures. vLLM exposes limited API functionality by default — until we discovered that its completions endpoint accepts prompt_embeds, which are loaded via torch.load with weights_only enabled. We had previously disclosed CVE-2025-32434, a bypass for the weights_only mechanism; after it was patched, we wondered: could we succeed again? This led us to a heap overflow vulnerability that bypasses weights_only entirely (CVE-2026-24747), which we leveraged to compromise vLLM. This finding overturned a common assumption: that PyTorch flaws only enable model poisoning, requiring victims to load malicious models locally. In fact, many AI applications expose APIs that invoke torch.load for routine operations such as model loading and LoRA fine-tuning — turning a "local" vulnerability into a remote one. After mapping this attack surface, we developed exploits against ComfyUI, NVIDIA Dynamo and others. In this talk, we'll walk through the discovery of this new PyTorch weights_only bypass and demonstrate its exploitation across AI infrastructures.

Speakers:Ji'an "azraelxuemo" Zhou,Lei "llfamsec" Lu

SpeakerBio:  Ji'an "azraelxuemo" Zhou

He focuses on Java security and AI security, and his work has helped many high-profile vendors—including Google, Amazon, Cloudera, IBM, Microsoft, Oracle, among others. He has presented at Black Hat Europe 2024, Zer0Con 2025, Off-by-One Con 2025, Black Hat USA 2025, DEFCON 33 and Zer0Con 2026.

SpeakerBio:  Lei "llfamsec" Lu

He has focuses on application and system security. He has reported many vulnerabilities to Linux, AMD, Apple, Microsoft, etc. He has presented at PHDays 2025.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 13:00-13:59 PDT


Title: One Request to Rule Them All
Tags: Red Team Village | Misc
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

The world has changed...

It began with the forging of the modern enterprise. To the cloud were given vast kingdoms of compute. To the mobile apps, a presence in every pocket. To the machines that now think, knowledge stolen from the creators. And to bind them, to let each speak to each across the dark spaces between systems, the architects forged the APIs.

But in the forging a flaw was hidden. For an API answers any who ask it correctly, and it does not always stop to learn who is asking. So it came to pass that buried among ten thousand harmless calls there waited a single request. One request with dominion over all the others. One request to read what was meant to stay hidden, to act in the name of any user, to claim the powers kept for admins alone.

One Request to bring the whole realm to ruin, and in a single call, destroy it.

SpeakerBio:  Corey Ball

Corey Ball is a cybersecurity consulting manager at Moss Adams, where he leads its penetration testing services. He has over ten years of experience working in IT and cybersecurity across several industries, including aerospace, agribusiness, energy, financial tech, government services, and healthcare. In addition to a bachelor’s degree in English and philosophy from Sacramento State University, Corey holds the OSCP, CCISO, CISSP, and several other industry certifications.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Friday - 10:00-17:59 PDT


Title: Open Q&A
Tags: Scambait Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-10:59 PDT


Title: Opening Panel - "Is Red Teaming Dead?"
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Moderated By Ben Sadeghipour (@NahamSec) Guests: Ads Dawson (0xmoose) Ryan Montgomery (@0day) Billy Giles

Speakers:Ads Dawson,Ben "NahamSec" Sadeghipour,Billy Giles,Ryan Montgomery

SpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta's MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting "Exfil Everything: A Year of Stealing Data from AI Agents" at Bug Bounty Village DC34 (schedule pending publication).

SpeakerBio:  Ben "NahamSec" Sadeghipour

Ben Sadeghipour (NahamSec) is a security researcher, ethical hacker, and educator who has spent more than a decade finding and disclosing critical vulnerabilities in some of the world's largest organizations. As one of the most recognized names in the bug bounty community, he has reported thousands of security flaws and consistently ranked among the top researchers on leading hacking platforms. Beyond his own research, Ben is passionate about lowering the barrier to entry in cybersecurity. Through his widely followed educational content, live streams, and the conferences he founds and organizes, he has helped train a new generation of hackers around the world. His work blends deep technical expertise with a commitment to mentorship and community building.Ben speaks regularly at industry conferences on offensive security, bug bounty hunting, and building a career in cybersecurity.

SpeakerBio:  Billy Giles

Billy Giles is an Offensive Security leader and practitioner who specializes in red/purple teaming and network penetration testing. With a deep passion for understanding adversary behaviors, he helps organizations across a multitude of industries assess their security postures, identify and remediate vulnerabilities, and build stronger defenses by thinking like an attacker.

Billy is also the creator of Thinking Offensively. Through this project he examines offensive security strategy topics to help cybersecurity leaders anticipate threats and inform decision making, while also providing tools, playbooks, and techniques that red teams can apply directly to their work. His mission is to bridge strategy and execution to help organizations think offensively and stay ahead of evolving threats.

SpeakerBio:  Ryan Montgomery
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 10:00-10:10 PDT


Title: Opening Talk
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:10 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:
SpeakerBio:  Jayesh Singh Chauhan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 13:00-13:45 PDT


Title: OSINT Is Still a Thinking Game: Surviving AI Without Losing Tradecraft
Tags: Recon Village | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

The OSINT landscape is undergoing a fundamental shift. Artificial Intelligence is no longer just a tool; it is becoming a crutch. As analysts increasingly rely on LLMs to triage data, translate foreign slang, and summarize massive datasets, a dangerous cognitive atrophy is taking hold. We are trading the slow, deliberate friction of critical thinking for the illusion of speed and certainty.

This talk, "OSINT Is Still a Thinking Game," exposes the hidden vulnerabilities of AI dependence in intelligence work. Through real-world case studies—from misinterpreting Telegram chatter to falsely flagging logistics data—we will examine how the "Good Enough" trap leads to catastrophic analytical failures.

More importantly, this session provides a concrete defense framework. Attendees will learn the four essential habits required to survive the AI era: reading the raw source, forcing a second hypothesis, separating speed from confidence, and auditing dependence. The tools will inevitably get better, but the thinking must get sharper. Join this session to learn how to maintain your tradecraft, keep your judgment visible, and ensure that in the age of automation, defensibility always wins over speed.

SpeakerBio:  Nico Dekens, Dutch_OSINTGUY SVP of Engineering & Chief Innovator @ Shadowdragon.io

Nico Dekens is the owner of Dutch Osint Guy Intelligence Services and an All Source Analyst who specializes in Open Source Intelligence (OSINT), online Human Intelligence (HUMINT) and Online investigations. Nico eats, sleeps, and lives everything which has to do with OSINT, online investigations, intelligence gathering and analysis. He has over 20 years’ experience as an (all source) Intelligence Analyst in Dutch Law Enforcement. There, he analyzed murder cases, international narcotics cases, stolen art cases, gang violence cases, political disturbance cases. Investigated and analyzed online jihadist groups & conducted several online covert virtual HUMINT investigations.

Known online as @Dutch_OsintGuy, Nico is very active within the OSINT community. As the owner of Dutch Osint Guy Intelligence Services, Nico provides consultancy and training for Open-Source Intelligence (OSINT), risk assessments, keynotes, security awareness, and implementation of structured team methodologies. He is also a co-founder of the OSINTCurio.us project.

Nico chose to be an OSINT Specialist and Cyber Intelligence Analyst because he wanted to help to make the world a safer place and because OSINT is one of the fastest fields in the cyber realm, with an ever-changing landscape. This helps him to remain in a constant state of learning and giving back what he’s learned to others who also want to make this (digital) world a safer place.

Before he became a SANS instructor, Nico helped set up the OSINT units within the Dutch Government as well as train and educate thousands of government employees on how to work in structured teams and perform excellent online investigations.

Nico is a SANS Instructor for SEC497 Practical Open-Source Intelligence (OSINT) and lead author of SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis. As an instructor, he uses practical real-world examples as much as possible. “Being an instructor isn't one-way traffic; it is a dynamic process between the student and instructor” Nico says. He is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition.

With all his OSINT and intelligence gathering and analysis experience that he brings to the table, Nico is able to share his unique experiences with his students on Open-Source Intelligence.

Among his biggest career highlights, he is proud of helping to stop terrorists from executing their attacks and stopping child predators. It’s his goal to keep the world safe and help those who are not able to defend themselves. Nico has had students come back to him years later, thanking him for techniques he taught them that played a role in their investigations.

Nico has been honored by Head of Europol, the DHS, and NATO for his efforts in the OSINT field. He’s received a letter of gratitude from the Dutch Military Cyber Intelligence and Cyber Defense department. He’s also been honored by Dutch Law Enforcement for his efforts in counter terrorism and online investigations.

Nico holds certifications as a Police Detective, Operational Intelligence Analyst, Tactical Intelligence Analyst, Strategical Intelligence Analyst, Open-Source Intelligence Analyst, Cyber Intelligence Tradecraft Professional, Online Counter Terrorism Specialist.

Nico is the 2023 Open Source Intelligence Champion of the Year, presented by the OSMOSIS Institute.

Nico is a typical gadget nerd. When he’s not teaching, he likes to play around and test new gadgets that are closely related to the cyber field. So Raspberry pi, esp8266, esp32, microbits, iot devices are things he likes to learn more about. He also likes to work-out and play basketball. He’s also a collector of unique sneakers.

Currently Nico is working as Senior Vice President of Engineering & Chief Innovator at ShadowDragon.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 13:30-13:59 PDT


Title: OSINT: Zero To Hero
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

If you're curious on how this field has evolved, I'll take you on a journey from beginner to extremely advanced level intelligence, all using a computer. I'll demo techniques live and answer questions like: How has OSINT evolved over the years? What powers do you get from developing this skill?

SpeakerBio:  Mishaal Khan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 10:00-17:59 PDT


Title: OSINT4Good Community - DC NextGen Content
Tags: OSINT For Good Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

Make this a stop on your DC NextGen journey, solve the challenge, and earn a digital badge!


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 10:00-10:59 PDT


Title: OSINT4Good: What it takes to find missing people
Tags: OSINT For Good Community | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Have you ever wondered what it takes to used gamified OSINT to find missing people? Moderated by a Director from Trace Labs, this panel brings together a participant (who won Most Valuable OSINT), a coach (who has coached more times than anyone on the planet), and a report writer (who leads the team of report writers) to walk you though the different perspectives of this work.

Speakers:Angela Ramos,Kenny J,Brent Louie

SpeakerBio:  Angela Ramos, University of Tampa

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.

SpeakerBio:  Kenny J, Trace Labs

Senior Infrastructure Engineer by day. Osint for Good by night. His is the only Trace Labs coach to have coached 20+ CTFs, earning him the singular rank of Legendary Coach.

SpeakerBio:  Brent Louie, Reporting Team Lead at Trace Labs

Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement.


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Friday - 15:00-15:30 PDT


Title: OT Segmentation Under Operational Constraints
Tags: ICS Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

OT network segmentation projects rarely fail because of missing firewall features or lack of security tooling. They fail because industrial environments operate under constraints that traditional IT security programs do not fully account for: limited maintenance windows, fragile legacy systems, vendor-controlled architectures, operational distrust of change, and the reality that reliability and uptime often outweigh security priorities during production events.

This presentation focuses on the operational side of OT segmentation: how industrial organizations actually plan, prioritize, communicate, implement, and sustain segmentation initiatives in production environments. Rather than treating segmentation purely as a technical firewall exercise, the session examines segmentation as an operational optimization problem balancing security risk, operational disruption, safety requirements, maintenance constraints, compliance pressure, and organizational ownership. Topics discussed include:

Phased rollout strategies and pilot deployments Change validation and rollback planning Segmentation drift and long-term erosion of controls Vendor and integrator access throughout project lifecycles Operational trust-building through monitor-first deployments and packet-capture-driven validation

We will explore why many environments gradually return to flat networks despite significant investment in segmentation initiatives. Real-world examples from utility and critical infrastructure environments will demonstrate how operational realities, maintenance pressure, and organizational ownership challenges frequently undermine otherwise well-designed security architectures.

Attendees will leave with practical guidance for approaching OT segmentation as an operational change-management problem rather than simply a firewall deployment exercise, along with implementation patterns that improve security posture without creating unnecessary operational disruption.

SpeakerBio:  Tony Turner

Tony is a security architect with over 30 years of experience across IT and operational technology (OT) environments. As VP of Product at Frenos, he leads the development of a simulated OT penetration testing platform that uses digital twin modeling and adversary-driven analysis to evaluate real-world risk in industrial systems.

His background is grounded in decades as an asset owner, including critical infrastructure protection at a major U.S. airport, incident command for state public health systems, disaster recovery engineering for hurricane response, and security programs across electric power and global semiconductor manufacturing. This operational experience informs a practical, systems-driven approach to cybersecurity that prioritizes real impact over theoretical risk.

Tony’s work focuses on how attackers actually operate in complex environments, spanning network reachability, adversary actions, supply chain risk, and software provenance. He is the author of Software Transparency and creator of the SANS SEC547 course Defending Product Supply Chains. He has presented at S4 Conference and other industry forums on topics including threat modeling with BOMs and the real-world effectiveness of industrial firewall DPI.

He actively contributes to research efforts with organizations such as MITRE, Idaho National Laboratory, CISA, and ISA, particularly in advancing Cyber Informed Engineering (CIE). He also leads defendics.org, a nonprofit focused on improving foundational OT security practices for resource-constrained asset owners.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 12:00-12:45 PDT


Title: Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Conference talks, earnings calls, product demos, training videos. Organizations put hours of footage online every week, full of things they didn't mean to share: hostnames in terminal windows, org charts on slides, infrastructure details dropped during Q&A. Traditional OSINT can't touch video at scale, and manual review falls apart past a handful of recordings.

Overcast is a CLI agent and skill pack for video OSINT that drops into any agentic harness, such as Claude Code, Codex, or Tinycloud, giving it senses plus recon and targeting reach, organized around an investigation case. Point it at 10 videos or 1,000 and it turns footage into cited evidence: speech, video understanding, on-screen text and objects, faces, and named entities, all accumulating in persistent case memory.

Discovery runs on the same case: scan and monitor sweep sources and surface reviewable findings. Ask across the whole corpus and get answers cited to the exact record and timestamp, backed by tiered retrieval. Match a photo against thousands of clips to find a person. Each subcommand is modular and pluggable, so analysts can drop one into other agent flows, author custom skills, or feed Overcast's media analysis into existing recon and security tooling to complete the mission.

SpeakerBio:  Kevin "kdrwins" Dela Rosa

Kevin Dela Rosa is a multimodal AI researcher and engineer with 17+ years in computer vision, NLU, and large-scale retrieval. He led engineering teams at Snapchat building billion-scale visual search and generative AI products, worked on large-scale ML at Amazon, and interned at NIST and SPAWAR on NLP and information retrieval for government applications. He's published at ACM WWW, ACM CAIS, IEEE ICCV, KDD, CVPR, NeurIPS, AAAI, and ISMIR, and has spoken at AWS re:Invent, KubeCon, and CascadiaJS. He's currently CTO of Cloudglue, where he builds video understanding infrastructure.

At DEF CON 33 he presented "Autonomous Video Hunter" at Recon Village, demoing an AI agent that investigated video corpora using face recognition, logo detection, and content analysis to produce structured OSINT reports. Overcast is the evolution of that work: a CLI agent and skill pack that gives any agentic harness senses plus recon and targeting reach, organized around an investigation case with persistent memory, cited evidence, and modular subcommands that plug into other recon and security workflows.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 16:00-17:59 PDT


Title: OWASP Amass v5.0
Tags: OWASP Foundation | Creator Workshop
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

The OWASP Amass Project has become a foundational toolset for security researchers, bug bounty hunters, red teamers, and defenders who rely on automated reconnaissance and external asset discovery to map attack surfaces. With the release of Amass v5.0, the project has undergone a major architectural transformation centered around the Open Asset Model (OAM)—a structured property graph that defines how Internet-facing assets and their relationships are stored, analyzed, and queried.

This two-hour hands-on workshop, led by Jeff Foley, the project’s founder and long-time maintainer, offers attendees a first look at Amass v5.0’s new intelligence collection engine, which seamlessly populates the Open Asset Model database during enumeration operations. The session will walk through how Amass collects and organizes OSINT from various sources—including DNS records, WHOIS/RDAP data, TLS certificates, and more—and models the results as a dynamic graph of properties and relationships between discovered assets.

Participants will learn to use core Amass tools such as:

amass enum – for deep, recursive asset discovery using passive and active techniques

amass subs – for quick subdomain discovery from the Open Asset Model database

amass viz – to render interactive visualizations of asset relationships in the Open Asset Model

In addition to these staples, the workshop will introduce the new assoc tool, a powerful query interface designed to unlock the true potential of the Open Asset Model database. Built around a custom Triples query language, the assoc tool enables users to describe paths—called association walks—through the asset graph, surfacing linked insights across related properties (e.g., domains associated with a network, IPs linked to DNS records, etc.). The language is inspired by RDF-style triples but optimized for simplicity and clarity in cybersecurity investigations.

Amass v5.0 also ships with completely refactored documentation, providing diagrams to help users understand the data types, their fields, and their associations within the OAM. This new documentation dramatically lowers the learning curve for users new to the Amass Project, making it easier to build mental models of how different types of Internet assets are discovered and interrelated.

This workshop will include a live walkthrough of setting up and running Amass v5.0, from enumeration to advanced queries. Participants will leave with hands-on experience using the full Amass suite, understanding how the Open Asset Model works under the hood, and writing association walk queries using Triples.

What to Expect:

Real-world reconnaissance examples using Amass against publicly available targets

Query design exercises with assoc to extract actionable intelligence

Tips for integrating Amass data into your own tooling and pipelines

Visual mapping of organizational assets using OAM and viz

Level: Intermediate Some experience with OSINT tools, command-line interfaces, or network security is recommended but not required. The workshop is designed to be self-contained and accessible.

Attendees are encouraged to bring a laptop and follow along. Project contributors will be present throughout the session to provide hands-on support, answer questions, and help troubleshoot issues in real time, making this a highly interactive experience.

By the end of the session, participants will walk away with practical skills in reconnaissance, data extraction from structured asset models, and a solid understanding of how Amass v5.0 is redefining modern Internet-wide discovery.

Join us at DEF CON to explore the future of OSINT automation and asset intelligence with OWASP Amass!

SpeakerBio:  Jeff Foley, Founder and Project Leader at OWASP Amass Project
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:30-11:30 PDT


Title: OWASP CTF: Getting started & welcome
Tags: OWASP Foundation | OWASP Foundation CTF | Contest
When: Friday, Aug 7, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

New to CTFs or application security? Join us before the competition for an introductory session designed to help newcomers get up to speed. We'll walk through the challenge format, the secure development lifecycle it simulates, and the tools and techniques you'll use - from finding vulnerabilities and implementing secure fixes to leveraging OWASP open source tooling and AI-assisted security workflows. Whether you're brand new or just looking for a refresher, this session will help you feel prepared and confident before the CTF begins.

Speakers:Diego Cotelo,Chris "dafinga" Maenner,Christian "DeadlyFluVirus" Nuss

SpeakerBio:  Diego Cotelo, Staff Cloud & Security Engineer

I'm a cloud and security engineer working at the intersection of infrastructure and security. I harden AWS, Kubernetes, and GitOps pipelines, and build tooling that surfaces misconfigurations, drift, and blast radius before an attacker finds them first. I treat security as an architecture problem, not a checklist — breaking systems to understand them, then designing secure-by-default platforms. I write about offensive and defensive cloud security at dcotelo.dev.

SpeakerBio:  Chris "dafinga" Maenner, Board Member at BSides Philadelphia

Chris Maenner is the founder of Palmtree Ventures, where he spends his time securing AI systems, Kubernetes, cloud platforms, and developer tooling without getting in the way of shipping software. Over the last 15+ years, he’s worked across startups and Fortune 50 companies building product, platform, and cloud security programs. When he’s not doing his day job, Chris helps build CTFs and security projects for DEF CON’s Blue Team Village and OWASP, including leading engineering efforts around Project Obsidian. He also serves on the board of BSides Philadelphia, contributes to the OWASP Secure Agent Playbook, and regularly speaks about AI security, Kubernetes, cloud-native security, and the lessons learned from actually trying to secure this stuff in production.

SpeakerBio:  Christian "DeadlyFluVirus" Nuss, Scaffoldly

Full-stack development; Multi-cloud architecture, security and reliability; Automation enthusiast; Tech team development and leadership; Entrepreneur; Founder of Scaffoldly


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: OWASP CTF
Tags: OWASP Foundation | OWASP Foundation CTF | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

This challenge simulates a real-world secure development lifecycle, where security professionals must not only identify vulnerabilities but also collaborate with development teams to implement, validate, and deploy secure fixes.

By completing the challenge, participants gain hands-on experience in:

The ultimate goal is to help practitioners develop the full skill set required to identify vulnerabilities, implement secure fixes, and deploy those fixes safely within their infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 12:00-13:59 PDT


Title: OWASP ISTG in Practice: A CTF-Style IoT Hacking & Defending Lab
Tags: OWASP Foundation | Creator Workshop
When: Friday, Aug 7, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Step into the world of ethical hacking and uncover the unseen vulnerabilities hiding inside everyday connected devices. This immersive, beginner-friendly lab teaches IoT security the way professionals actually practice it — using the OWASP IoT Security Testing Guide (ISTG) as your map — wrapped in an approachable Capture-the-Flag format, and led by the team that authors and field-tests the methodology.

No experience necessary. Just bring your curiosity. Whether you’re a student, a tech enthusiast, or someone eyeing a cybersecurity career, this session makes real device hacking accessible, hands-on, and genuinely fun.

Working against a custom-built networking device, you’ll follow the ISTG methodology from the outside in. You’ll start at the hardware: reading and interpreting physical signals to locate and identify an exposed UART interface (ISTG-PHY, ISTG-INT) — the kind of serial debug port that, in real-world assessments, hands attackers an unauthenticated root shell within minutes of opening the enclosure. Unlocking that interface opens a cyber range where you’ll pivot through firmware secrets (ISTG-FW), then practice attacks at the network and application layers — each flag mapped back to an ISTG test-case category, so you leave understanding not just how you got in, but how the risk is classified and defended.

By the end, you’ll have a repeatable, standards-based mental model for testing any connected device — and a firsthand look at the most overlooked risks living inside the networks we all rely on.

Speakers:Piero "p33_p33_" Picasso,Aaron Guzman

SpeakerBio:  Piero "p33_p33_" Picasso, Senior Security Leader at Cisco

Piero Picasso (p33_p33_) is a Senior Security Leader for Device Penetration Testing at Cisco, where he leads security testing for network infrastructure and IoT devices. Based in the Fort Lauderdale area, he brings over 20 years of experience in offensive security, penetration testing, and product security engineering. Over five-plus years at Cisco — including as Offensive Security Leader at Cisco Meraki — he built and scaled security testing programs for cloud-managed networking products. Earlier, he assessed Fortune 500 clients as a penetration tester at Secureworks and led ethical hacking within Citi’s regulated financial environment. He continues to advance Cisco’s device security posture through hands-on testing methodologies and cross-functional security research.

SpeakerBio:  Aaron Guzman, Project Leader at OWASP

Aaron Guzman is CISO of Cisco Network Product Engineering, the organization responsible for securing Cisco’s enterprise and industrial networking portfolio — from wireless access points, routers, and switches to IoT cameras and sensors — much of the infrastructure that moves the world’s data. He is the author of the IoT Penetration Testing Cookbook and a technical reviewer for Practical IoT Hacking and Bug Bounty Bootcamp. As OWASP’s IoT Project Leader, he leads the IoT Security Testing Guide (ISTG) — the very methodology at the heart of this lab. He started as a hacker, driven by a curiosity to take things apart and make them do what they were never designed to — a curiosity that now scales across hardware, firmware, supply chains, and software at enterprise scale.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 11:10-11:20 PDT


Title: Packet Hacking Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 11:10 - 11:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Packet Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Packet Hacking Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:30-13:30 PDT


Title: Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet's V8 on the Galaxy S25
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

What happens when a flagship phone like the Samsung Galaxy S25 ships with an outdated Javascript engine in its default browser?

For the past 6 months, Samsung Internet shipped with an out-of-date V8 build that had already-fixed, publicly known vulnerabilities. One such bug is CVE-2025-10891, a flaw in Ignition bytecode generation for Javascript exception handling. In this talk, we show how we transform this vulnerability into reliable renderer code execution through instruction smuggling and internal native V8 runtime calls. We then showcase how we exploit weaker isolation mechanisms on mobile Chromium engines to upgrade the renderer RCE’s capability into a universal XSS primitive.

https://osec.io/blog/2026-04-01-patch-gap-to-mobile-renderer-rce/ https://issuetracker.google.com/issues/443875388

Speakers:Hrvoje Mišetić,Jamie Hill-Daniel,William Liu

SpeakerBio:  Hrvoje Mišetić, OtterSec

Hrvoje Mišetić is a Web3 auditor and security researcher at OtterSec with prior research projects including Linux kernel LPE, QEMU hypervisor escape, and browser exploitation. He is a member of the Crusaders of Rust CTF team, and DiceGang, with whom he has qualified for Defcon CTF Finals multiple times. He presented Minecraft RCE research at OffensiveCon ‘26.

SpeakerBio:  Jamie Hill-Daniel, OtterSec

Jamie Hill-Daniel is a security auditor currently working at OtterSec, with an interest in browser and kernel research. He is a member of the Crusaders of Rust and DiceGang CTF teams, having qualified for multiple Defcon CTF Finals with the latter.

SpeakerBio:  William Liu

William Liu is a security engineer at Trail of Bits with experience in low-level systems and computer architecture. He is a member of the Crusaders of Rust and DiceGang CTF teams, having qualified for multiple Defcon CTF Finals with the latter. He has previously worked as a systems software engineer at NVIDIA. He documents some of his research on his personal site, willsroot.io.

William is a Class of 2025 graduate of the Massachusetts Institute of Technology, where he worked on the EntryBleed KASLR bypass and kernel fuzzing under Professor Mengjia Yan. He has presented micro-architectural security research at HASP ‘23 and NEHWS ‘24, as well as Linux 0-day research at Hexacon ‘25.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 10:30-10:45 PDT


Title: Payment Village Intro - What's Happening at the Village
Tags: Payment Village | Creator Workshop
When: Friday, Aug 7, 10:30 - 10:45 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Join us to discover some of the highlights of the Payment Village at DEF CON


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 10:00-10:45 PDT


Title: Peekaboo: Breaking the Black Box of Threat and Malware Emulation
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:
Standard security testing often forces a choice: use "script-kiddie" tools that get caught instantly, or use high-end frameworks that are too complex for rapid detection testing. Peekaboo bridges this gap. In this Demo Lab, we present Peekaboo - a modular, open-source framework designed for safe threat emulation. Unlike traditional malware, Peekaboo focuses on generating high-fidelity telemetry through legitimate cloud API abuse (GitHub, Bitbucket, Slack, Discord, Azure, VirusTotal, XBOX, AngelCam, etc) and evasive execution techniques (Direct Syscalls, Callback-based execution).

We will demonstrate how to:

Peekaboo isn't just a tool; it's a "sandbox-friendly" adversary in a box, designed to help Blue Teams level up by understanding the nuances of the Offensive Dev Loop. Come see how we turn "hidden" threats into "visible" learning opportunities.

SpeakerBio:  Zhassulan "cocomelonc" Zhussupov

cybersecurity enthusiast, author, speaker and mathematician. Author of popular books: MD MZ Malware Development Book (Github, 2022, 2024) MALWILD: Malware in the Wild Book (Github, 2023) Malware Development for Ethical Hackers Book: (Packt, 2024) AIYA Mobile Malware Development Book (Github, 2025) Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress) Author and tech reviewer at Packt. Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine Malpedia contributor Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Standoff, Positive Hack Talks, etc conferences


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 14:00-15:59 PDT


Title: PentestGPT: The Art of Hacking with Words
Tags: La Villa Community | Creator Workshop
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map

Description:
PentestGPT: The Art of Hacking with Words regresa a DEF CON, esta vez como un workshop completamente práctico. Luego de presentar el año pasado cómo los LLMs comenzaban a transformar la seguridad ofensiva, esta nueva edición lleva la experiencia al siguiente nivel: no solo será escuchar de este proyecto, lo podrás crear y ejecutar en tu entorno favorito.

Durante 100 minutos, los participantes trabajarán directamente con PentestGPT y PentestGPT 2.0 para aprender cómo integrar IA en flujos reales de pentesting. A través de ejercicios guiados y escenarios ofensivos realistas, explorarán reconocimiento asistido por IA, generación de attack paths, análisis de hallazgos, prompt engineering ofensivo y validación técnica de resultados.

Más allá de usar una herramienta, el workshop propone un cambio de mentalidad: entender cómo pasar de ejecutar tareas manuales a orquestar inteligencia ofensiva.

SpeakerBio:  Matias Armándola, Cybersecurity Lead, Proffesor and Speaker

I'm Mati Armándola, an Information Security leader with over 20 years of experience in technology and more than a decade dedicated exclusively to asset protection, regulatory compliance, and organizational culture.

I have led teams and projects in companies with regional reach and have participated as an international speaker at conferences such as Ekoparty, DevOpsDays, Nerdearla, and DEF CON, addressing topics such as offensive security, awareness, applied AI, and governance.

In addition to my work as a teacher at various institutions and educational platforms, training the next generation of professionals in security, cloud computing, and leadership.

My motto is LEAD – TEACH – PROTECT


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 10:15-11:15 PDT


Title: Pentesting made easy - Keeping sessions alive with session chains
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 10:15 - 11:15 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Modern web applications require pentesters to manage multiple accounts, roles, and tenants while dealing with short-lived sessions, multi-step logins, and MFA. This complexity regularly breaks authenticated tooling and slows down assessments, forcing testers into repetitive manual re-authentication.

Our open-source tool, session-chains, addresses this challenge by automatically creating and maintaining authenticated sessions for any number of users. Testers define reusable authentication flows, while the tool keeps sessions valid in the background and exposes them to other tools.

It integrates with Burp Suite and CLI tools like sqlmap, enabling consistent authenticated testing even in complex environments. This allows security professionals to spend less time on authentication hurdles and more time identifying impactful vulnerabilities.

Speakers:Kai Glauber,Matthias Göhring

SpeakerBio:  Kai Glauber

Kai Glauber is a senior security consultant and penetration tester at usd AG with experience in web application pentests, SSO assessments and Kubernetes security. With a background in software development, his early work in software testing led him to specialize in the security domain. He's passionate about workflow automation and making pentesting more efficient.

SpeakerBio:  Matthias Göhring

Matthias Göhring is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. He is Head of usd HeroLab, the division of usd specialized in technical security assessments. In addition, he holds lectures at Technical University Darmstadt and University of Applied Sciences Darmstadt on ethical hacking and penetration testing. In previous scientific work, he focused on network and communication security as well as software security.

Previous publications: - Catching the Clones – Insights in Website Cloning Attacks, Risk Connect Conference, 2021 - Path MTU Discovery Considered Harmful, IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018 - Tor Experimentation Tools, IEEE Security and Privacy Workshops, 2015 - On randomness testing in physical layer key agreement, IEEE 2nd World Forum on Internet of Things (WF-IoT), 2015


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 16:00-16:45 PDT


Title: Phasmid: Deniable Storage for Rubber-Hose Scenarios
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | SecOps | DEF CON Demo Labs
When: Friday, Aug 7, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:
Phasmid is a prototype deniable storage system built for a problem ordinary encryption handles poorly: what happens when the attacker stops attacking the math and starts coercing the human holding the key. It implements the Janus Eidolon System, or Janus System, a coercion-aware storage method that explores how visible disclosure and true protected state can diverge through deniable cryptographic structure, local-only operation, dual-profile storage, camera-based object-image matching, and owner-controlled destructive actions. Framed by the question of Agency, the project asks how a user can retain meaningful control over disclosure when physical pressure breaks normal cryptographic assumptions. This demo presents a practical low-power implementation on Raspberry Pi Zero 2 W for hostile situations where the attacker targets the person rather than the cipher.
SpeakerBio:  Makoto "Mr.Rabbit" Sugita

Makoto Sugita is a security engineer and security toolmaker focused on practical systems for hostile environments, where cryptographic assumptions break down under real-world pressure. His work sits at the intersection of cryptography, hardware, and adversarial human behavior. He has presented tools and research at venues including Black Hat Arsenal and BSides, and is interested in deniable systems, tactical hardware, and building prototypes that expose uncomfortable but real security problems.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: PhreakMe
Tags: PhreakMe | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 210 (PhreakMe) - Map

Description:

Ever wondered what hacking looked like in the golden age of phone phreaking? What about today? What can we learn about the old techniques that still plague our current infrastructure? The PhreakMe Capture the Flag brings you the classic art of telecom exploitation.

The Hacked Existence team is once again hosting a telecom based CTF. The CTF runs on real live VoIP lines routed through a modified asterisk PBX allowing participants to dial in to the CTF from anywhere in the world. This number is live 24/7 throughout DEFCON, allowing you to hunt the PBX for flags any time, day or night. Don't have a phone? Come test your skills at one of our 5 payphones! Also there's a BBS, hope you brought your modem!

All the flags are based around historically accurate tactics, techniques, and procedures to manipulate emulated old school switching systems.

The purpose of our contest is to bring awareness around the still existing weaknesses in our telecom infrastructure and Interactive Voice Response Systems. Ideally visitors to our contest area will participate in the CTF allowing them to get a better understanding of telecom hacking in the year 2026 as well as a respect for the art of phreaking from yesteryear.

Come test your skills, challenge your knowledge, and dive deep into the world of phreaks.

Hints: Read 'The Cyberthief and the Samurai' and 'Masters of Deception: The Gang That Ruled Cyberspace' for a leg up.

Participant Prerequisites

A phone, or access to a phone that can dial an american based phone number. The BBS will be both accessible from a modem and also ssh. Ideally people will read books like 'The Cyberthief and the Samurai' and 'Masters of Deception: The Gang That Ruled Cyberspace' and the Cult of the Dead Cow book.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 10:50-10:59 PDT


Title: Physical Securty Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 10:50 - 10:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Physical Securty Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Physical Securty Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 11:10-11:40 PDT


Title: Pickled and Exposed: RCE in AI Serving Frameworks
Tags: Intro/Beginner | AppSec Village | Creator Talk/Panel
When: Friday, Aug 7, 11:10 - 11:40 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Your LLM serving stack is probably listening to the entire internet right now, and it will run whatever code that internet sends it. It will not ask who you are. Everyone is busy chasing prompt injection and jailbreaks. Meanwhile, the boring bugs are wide open. SGLang serves large language models for thousands of deployments, with 25k+ GitHub stars. I read the source and found two unauthenticated RCEs. There was nothing clever about it: a network-exposed broker hands attacker data straight to pickle.loads(). Send a payload, get a shell. I will walk the vulnerable code and pop a shell live on stage. You will leave knowing exactly what to grep for in your own AI stack, before someone else greps it for you. Two CVEs. One grep. Zero sophistication required.

SpeakerBio:  Iggy

Igor Stepansky is a Security Researcher at OX Security, where he works on agentic AI for offensive security and automated penetration testing. Previously, he was part of Orca Security's Research Pod. His research spans unauthenticated remote code execution in AI/LLM serving frameworks, a use-after-free race condition in the Linux kernel's ksmbd SMB3 serve, and supply chain and CI/CD security across modern developer ecosystems. His work focuses on finding and exploiting high-impact vulnerabilities in widely deployed infrastructure, and he is a regular contributor of CVEs in open-source software.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 10:00-11:30 PDT


Title: Pickpocketing for Red Teamers: A Hands-On Experience
Tags: Social Engineering Community Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 11:30 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

Seven years ago, pradameinhof ran the world's first public pickpocketing competition with about 200 people at a social engineering conference. The inspiration? His dad got pickpocketed right next to him on the Paris Metro. What started as frustration turned into obsession�not just with preventing it, but with understanding how easy it is to pull off. It was hard enough finding good resources. The real problem? Testing your skills in realistic scenarios can land you in jail.

In this two-hour Social Engineering Community session, pradameinhof will teach what he learned: the core techniques of attention manipulation�directing and surfing attention, relative touch, entering personal space, giving shade, fanning, and working in teams. You'll learn to lift wallets, watches, phones, badges, and keys, and apply these skills to red-teaming.

Here's how it works: You'll pair up and take turns�one practitioner, one target. No prior experience necessary.

What to bring: A jacket and pants with pockets that aren't too tight. Wear a watch if you have one. Because you will need to steal from other people and be pickpocketed, expect to touch and be touched by others in order to participate�all appropriately and with clear consent.

Join us in this group exercise to understand the human blind spots that make physical social engineering so effective. Walk away with skills for your next red-team engagement�and better awareness so you don't become a target.

(Disclaimer: This exercise is for educational purposes only. If you pickpocket people without their consent, expect to get into trouble.)

SpeakerBio:  pradameinhof

pradameinhof has worked in cyber security startups for over two decades. Most of his skills he acquired by pestering his friends and colleagues over coffee. He has a passion for OSINT and Social Engineering.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Pinball High Score Contest
Tags: Pinball High Score Contest | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 304 (Pinball High Score Contest) - Map

Description:
The Pinball High Score contest at DEF CON 34 will run Friday and Saturday: 10:00-18:00, Sunday 10:00-13:00 with games available for daily High Score contests, daily challenges and open qualifying for a main tournament. The daily contests will allow any attendee to play pinball games and attempt to record a qualifying high score on each of the unique games. At 17:00 on Saturday main tournament qualifying will end, tiebreakers will be played (if needed) and the top 8 players with the highest combined scores across all eligible machines will qualify for the Sunday finals event where they could become the next DEF CON Pinball Champion!

Achieving a high score may sound simple but pinball rulesets are very complex and the skill to complete a “Wizard Mode” or achieve a high score requires research, practice, knowledge and execution. Out of the box thinking, analytical skills and pattern recognition are traits that pinball players must exhibit to be successful and some games have rule sets that can be studied and exploited to achieve a high score. Hackers are at an advantage here and while this is just a pinball contest, we expect that the community is ready for this challenge!

Last year the contest measured how you moved the machine. This year, we're reading what happens inside it. Custom sensors feed SHELL, our Sub-surface Hidden Entertainment Layer Logic. When you unlock the right patterns, a hidden world appears on screens beneath the glass. Face off in secret mini-games, answer hacker trivia under pressure, and battle other players in competitive challenges where you can steal control mid-game. It's pinball within pinball, a clandestine layer of gameplay that only reveals itself to those who can crack the SHELL.

Participant Prerequisites

Nothing special is required. Any person can step up and enjoy a pinball game or they can spend 30+ hours solving our challenges if they want to play the deeper game.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 13:30-14:30 PDT


Title: Plug And Pwn: Weaponizing Windows PnP Auto-Install
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Every time a USB device is plugged into a Windows machine, the OS may silently download a package from Microsoft and execute vendor code as SYSTEM. No admin required. The package is signed, so nothing looks wrong.

We spent the better part of a year mapping this attack surface. We analyzed 7K packages approx, built tools to emulate arbitrary USB devices without hardware, and found that the same kernel code path fires when a USB device is redirected over RDP channels, meaning a non admin user can trigger SYSTEM level code execution on the target, with no physical access at all (under certain conditions).

Speakers:Alejandro "0xedh" Hernando,Borja "borjmz" Martinez

SpeakerBio:  Alejandro "0xedh" Hernando, Accenture Spain

Alejandro Hernando is a red team operator and security researcher at Accenture Security's Hacking team in Spain, with over a decade of hands-on experience in offensive cybersecurity. Throughout his career, he has assessed, exploited, and helped mitigate security vulnerabilities across commercial and proprietary systems, developing PoC exploits, offensive and defensive tooling, and conducting deep security research. His approach combines applied research with real world operational experience, driven by a focus on continuous learning and on sharpening both attack and defense strategies.

SpeakerBio:  Borja "borjmz" Martinez, Accenture Spain

Borja Martínez is a red team operator and security researcher at Accenture Security Hacking team in Spain, where he focuses on offensive security, advanced adversary simulation and hardware exploitation. A self-taught hacker with a deeply hands-on approach, he specializes in red team operations, penetration testing and low level attack research including DMA attacks, BIOS/UEFI exploitation, and TPM security.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 14:00-14:59 PDT


Title: Point of Failure: Autopsia de una Terminal de Pago
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

TPVs como PAX y Mercado Pago corren Android, usan HTTP en producción y tienen un modo kiosco que dura lo que tarda en abrirse un APK. Esta charla es el journey de alguien que compró terminales, las rompió, y documenta lo que encontró.

SpeakerBio:  Erik Alcantara, I build the tools I can't afford.

Erik Alcantara aka. Glitchboi, es pentester y red teamer con 6 años en seguridad y enfoque en la intersección entre hardware y ofensiva. Desde México, construye herramientas open source que van desde proxies de interceptación HTTP hasta PCBs personalizadas para investigación de seguridad.

Ha presentado en BugCon y meetups locales de seguridad. Publica su research y proyectos en glitchboi.xyz y github.com/Glitchboi-sudo.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 18:30-20:30 PDT


Title: Policy Mixer Happy Hour
Tags: Party | Policy @ DEF CON
When: Friday, Aug 7, 18:30 - 20:30 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 12:30-13:15 PDT


Title: Poor Man's Mythos: Signal Siege: Agentic Exploit Chains Across the 5G Cloud-Native Stack
Tags: Telecom Village | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 13:15 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. 5G Attack Surface – New cloud-native risks and legacy trust issues.
  2. Salt Typhoon – Lessons from real-world telecom breaches. NEF API Security – Exposed API attack vectors.
  3. Signaling Exploitation – SS7/Diameter trust weaknesses in 5G. RAN-to-Core Pivoting – Lateral movement across telecom networks.
  4. OSS/BSS Attacks – Exploiting IT–telecom integration.
  5. Agentic AI – AI-driven telecom attack chain discovery.
  6. Offensive AI – Lowering the barrier to advanced attacks.
  7. Zero Trust for 5G – Securing telecom trust boundaries.
  8. Control Plane Security – Prioritizing critical telecom risks.
  9. Red Team Techniques – Practical telecom attack methodologies.
SpeakerBio:  Omer Farooq

Omer Farooq is a cybersecurity, cloud, and artificial intelligence leader with more than twenty-five years of experience spanning application security, cloud architecture, software engineering, DevSecOps, AI security, and technology innovation. As Founder and Principal Security Consultant at Auxin Security, Omer has advised more than 100 organizations worldwide, including Fortune 500 companies, government agencies, healthcare organizations, and nonprofits. His expertise includes GenAI and LLM security, offensive security assessments, threat modeling, cloud security, DevSecOps transformation, secure software development, and enterprise architecture. Omer is a frequent speaker at industry conferences and events including RSA Conference, BSides DC, AWS events, NAB Show, Microsoft Azure conferences, and numerous cybersecurity forums. His current research focuses on AI security, agentic systems, retrieval-augmented generation security, offensive AI testing, and emerging threats targeting enterprise AI deployments.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-11:59 PDT


Title: Post-Exploitation of the Desktop with JS-Tap
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

JS-Tap v3 moves beyond exploiting web applications to targeting the endpoint itself. JavaScript is used heavily on desktops and in this hands-on tactic you'll deploy three JS-Tap implant types against your own machine. Start by installing a malicious browser extension that harvests sessions from every site you visit and lets you inject payloads into specific apps on command. We’ll then rebuild the browser extension implant with optional (and less stealthy) features that allow jumping from the browser to the operating system for filesystem/shell access.

Next we'll patch a local Electron app to get screenshots, keylogging, network interception, and filesystem/shell access. Then we'll instrument a Node.js tool with a single environment variable to intercept its network traffic, capture keystrokes, and get filesystem/shell access.

We'll use Docker containers to simulate an internal network with a web application your browser can't reach directly. You'll use the JS-Tap Conductor to clone captured sessions and pivot through an implant to access it, demonstrating the full attack chain from session theft to authenticated access on an internal network. Participants will run JS-Tap locally on their own laptops. Bring a machine with Chrome or Chromium, Firefox (for JS-Tap Conductor), a Node.js app (Gemini CLI, Claude Code, etc.), Docker, and at least one Electron app installed (VS Code or Signal Desktop work well as targets). Setup instructions will be shared in advance.

You'll leave with firsthand experience operating all three beacon types.

SpeakerBio:  Drew Kirkpatrick

Drew has 25 years of experience designing and building complex systems, including application security, network policy management, machine learning, and transit and aerospace systems. These days he works to improve Information Security by applying penetration testing and computer science to assess the security posture of TrustedSec clients. Before joining TrustedSec, he was a Security Researcher at NopSec and Secure Decisions as well as a Senior Computer Scientist for the U.S. Navy.

Offensive Security Certified Professional (OSCP) GIAC Web Application Penetration Tester (GWAPT) GIAC Mobile Device Security Analyst (GMOB) M.S. Computer Science – Florida Institute of Technology M.S. Computer Information Systems – Florida Institute of Technology B.A. Psychology/Economics – St. Mary’s College of Maryland


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 10:00-17:59 PDT


Title: Poster Presentations
Tags: AI Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

AI Village is going old school academia with various presenters showcasing their research in poster format. Posters will be displayed on digital screens while presenters give conversational overviews of their research and invite casual discussions.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-13:50 PDT


Title: Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta
Tags: Noob Community | Creator Workshop
When: Friday, Aug 7, 10:00 - 13:50 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:
The Ginger Hacker Initiative and CompTIA are teaming up for an interactive session focused on the three critical dimensions of AI cybersecurity: securing AI systems, securing with AI, and governing AI. Built directly around the new CompTIA SecAI+ course, this workshop completely bypasses the fluff to focus entirely on real-world application.
Speakers:James Stanger,Stephen Schneiter

SpeakerBio:  James Stanger
No BIO available
SpeakerBio:  Stephen Schneiter
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 16:00-16:30 PDT


Title: Practical Guidance for RF Researchers: Experiment First, Interfere Never
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:
Practical Guidance for RF Researchers: Experiment First, Interfere Never. The world needs more experimentation. We want more high-quality experimentation that is reproducible, technically rigorous, and does not intentionally disrupt other spectrum users.
SpeakerBio:  Andy Hendrickson, Independent Researcher, Washington DC

While at the Federal Communications Commission, I have had the opportunity to serve in two roles focused on advancing the nation’s communications infrastructure and technology policy.

I currently serve as Chief of the Office of Engineering and Technology (OET), where I act as the FCC’s principal technical advisor. In this role, I help shape national spectrum policy, oversee equipment authorization, experimental licensing, and guide the agency’s technical direction to ensure regulatory frameworks keep pace with rapid innovation across the communications ecosystem.

Previously, I served as Chief Technology Officer for the FCC’s Enforcement Bureau, providing strategic and technical leadership across cybersecurity, privacy, national security, robocall and robotext mitigation, network outage enforcement, and the protection of critical infrastructure such as 911 systems and GPS. I also advised the Office of the Field Director on technology and enforcement issues with national impact while coordinating closely with teams across the Commission.

In my downtime, I'm either deep in the world of audio recording and engineering or rocking out on various instruments.

Before joining the FCC, I spent more than two decades in the telecommunications industry, including leadership roles at Verizon supporting the rollout of 5G and the development of the Verizon Cloud Platform.

My background spans cloud computing, software-defined networking, virtualization, cybersecurity, and GIS, and I remain engaged with the broader technology community through organizations such as the Open Geospatial Consortium, Linux Foundation, Open Infrastructure Foundation, and Network Time Foundation.

I am honored to work alongside dedicated public servants and industry partners helping ensure the United States maintains secure, innovative, and resilient communications systems.

I hold dual degrees from Rutgers University, having studied at both the School of Environmental and Biological Sciences and the School of Communication and Information.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 16:00-17:59 PDT


Title: Praetor: An OPSEC Exposure Advisor for Empire Operators
Tags: Red Team Village | Misc
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:
Every operator makes the same call dozens of times an engagement: I need to do X, so how do I do it? Drop a binary, load a BOF, tunnel Impacket, abuse a LOLBIN? Today that runs on gut feel, and guessing wrong is how you get caught.

Praetor is an open-source, AI-driven OPSEC assistant that plugs into Empire and turns that call into an informed one. You tell it what you want to do, and it suggests the ways to do it, ranked by how much each one would expose, with a plain-language explanation of why one path is quieter than another.

AI is what makes the suggestions usable. It reads your intent in natural language, assembles the candidate techniques, ranks them, and writes the reasoning a senior operator would give you, putting tradecraft that normally lives in a few people's heads at every operator's fingertips. When you reach for a louder option than you need, it speaks up with a specific reason and a quieter alternative, not a blanket warning.

The advice is grounded, not guessed. Praetor cannot see the target's telemetry, so it never claims anything is "safe." It models the detection surface each technique exposes, ranks the options against each other, and bases those judgments on footprints measured in an instrumented range rather than on a model's intuition. You set the defensive posture you believe you are facing, and the suggestions adjust to it.

We will demo it live and let people use it against Empire: state an intent, see the AI-ranked options with their reasoning, and watch the confirmation gate fire when a choice is louder than it needs to be.

Access to a TryHackMe configured lab will be provisioned.

Speakers:Andrea Brosio,Ariz Soriano

SpeakerBio:  Andrea Brosio

Andrea Brosio is a Security Researcher and Senior Content Engineer at TryHackMe, specializing in red teaming, malware development, and offensive security. With prior experience as a Bug Hunter and Red Team Operator he combines real-world adversarial expertise with a passion for creating engaging cybersecurity training.

SpeakerBio:  Ariz Soriano, Associate Director - Red Team Operations @ THEOS Cyber Solutions

Ariz Soriano is Associate Director of Red Team at Theos, with nearly a decade of experience spanning Red Teaming, Penetration Testing, and Incident Response. He started his career on the defensive side, working as a SOC analyst and eventually leading SOC and IR teams for his first four years in the industry. That defensive foundation gives him a perspective most purely offensive operators don't have.

He built the Theos Red Team from the ground up, recruiting and training operators, designing red team infrastructure and tooling, and establishing the methodology and playbooks behind the team's APT simulation and purple teaming engagements. Today he runs a practice that delivers multiple concurrent engagements a year, balancing operations with presales, scoping, revenue targets, and people management.

Outside of client work, Ariz is passionate about building red team tooling, optimizing offensive workflows, and sharing knowledge with the community as a conference speaker. He also contributes to TryHackMe as a part-time Senior Content Engineer, creating hands-on cybersecurity labs and challenges based on real-world attack techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 15:30-16:30 PDT


Title: Privacy's Defender: How Hackers Protected the Internet Before and Can Do It Again
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

EFF's Outgoing Executive Director Cindy Cohn' presents her first-person stories from her recently published book, Privacy's Defender, that take you Inside the privacy battles that have shaped today's Internet. It includes the hackers who helped free up encryption technology from US governmental control, allowing us to have the still imperfect privacy and security we now have online, and the battles to stop the mass NSA spying and eternal gag orders that arose from the governments formerly secret mass spying programs in the aftermath of the 9/11 attacks. She then draws from that long career of legal activism to the fights of today and tomorrow, featuring the role that hackers can play in helping to bring about a better, more just future.

SpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy's Defender published by MIT Press in March, 2026. She is also the co-host of EFF's award-winning podcast, How to Fix the Internet.

--

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 11:00-11:30 PDT


Title: Privilege Escalation: A Career Story
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Nobody handed us a roadmap. Before cybersecurity, our backgrounds looked nothing like the industry expected.

This is for everyone who's ever lurked in Discord, watched a conference talk, or read a writeup from someone and thought, "I wish I could talk with them."

PROTIP: You can, and you should.

We will share our unfiltered stories of breaking into the industry from non-traditional paths. The imposter syndrome, the cold messages to people we idolized, and what happened when we suddenly stopped being afraid to ask.

We plan to invite well-known figures from the community to come in chat with everyone and do a little mini social chat where everyone can ask the questions to hopefully people they idolize!

Speakers:Ryan Bonner,Whit Taylor

SpeakerBio:  Ryan Bonner, Lead Security Engineer at Arcanum Information Security

Ryan Bonner is a Lead Security Engineer at Arcanum Information Security, where he builds AI systems, hacks them, and runs application penetration tests. Off the clock he hunts wide-scope bug bounty programs.

SpeakerBio:  Whit Taylor
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 12:30-12:55 PDT


Title: Prompt Injection Detection in Large Language Models: Survey and Evaluation of Open Source Tools
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Friday, Aug 7, 12:30 - 12:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Prompt injection attacks trick Large Language Models into bypassing safety controls, leaking sensitive data, or performing unauthorized actions. This survey examines five open-source detection tools, LlamaFirewall, Cybersecurity AI, LLM Guard, Promptfoo, and OpenAI Guardrails Python. Analyzing How do they identify and block these attacks. The tools use different strategies: pattern-matching classifier, semantic reasoning systems, layered defenses, and code analyzers. We tested LlamaFirewall’s PromptGuard 2 on four datasets containing 52,240 samples. When it flagged something as attack (malicious prompt), it was accurate 87%�100% of the time, but it only caught 40%�73% of actual attacks. Accuracy ranged from 57% on realistic chatbot conversations to 85% on artificial test cases.

SpeakerBio:  Yasmin Eady, Ph.D. Student, NC A&T State University

Yasmin Eady is a PhD student in Computer Science at North Carolina A&T State University whose research focuses on prompt injection detection in large language models. Her work explores the security risks introduced by LLM-powered systems and the evaluation of open-source tools for identifying prompt injection vulnerabilities. Yasmin began her academic journey at West Los Angeles College, where she earned an Associate of Arts degree in Mathematics, and later completed a Bachelor of Science in Applied Mathematics at North Carolina A&T State University. Her broader research background includes cybersecurity, trust in distributed and social network systems, and biometric authentication.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 10:00-10:45 PDT


Title: PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

AI-assisted development tools don’t just introduce vulnerabilities; they introduce the same vulnerabilities repeatedly.

PromptPwn is a tool designed to identify, track, and exploit common insecure patterns found in AI-generated code. It maintains a database of known vulnerability patterns produced by popular “vibe coding” workflows and provides scanning capabilities to detect these issues in real applications.

In this demo, we show how PromptPwn identifies vulnerable patterns such as injection flaws, authentication weaknesses, and insecure defaults across generated code. We demonstrate how these patterns can be exploited in practice, highlighting how repeatability makes them especially valuable from an attacker’s perspective.

We also explore how prompt variations influence these outcomes and show how insecure patterns can be remediated by adjusting prompts, closing the loop between generation, exploitation, and correction.

This session focuses on practical demonstrations of how AI-generated code fails in predictable ways, and how those failures can be identified and abused at scale.

SpeakerBio:  Georgia Weidman

Georgia Weidman is an offensive security researcher and author focused on breaking real-world systems. She wrote Penetration Testing: A Hands-On Introduction to Hacking, a practical guide used by students and practitioners to learn exploitation techniques.

Her work centers on how modern systems fail under attack, from mobile and IoT to enterprise environments. As a DARPA Cyber Fast Track performer, she developed the Smartphone Pentest Framework (SPF), a platform for mobile exploitation research.

She has conducted penetration tests, built exploitation tooling, and developed attack chains across multiple domains. Her approach prioritizes hands-on techniques over theory, demonstrating how assumptions about security break down in practice.

Georgia has presented internationally at conferences including Black Hat and DEF CON, with a focus on showing how things actually get hacked.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 14:15-14:59 PDT


Title: Protecting Humans at Machine Speed - Engineering AI to Stop Spam, Scams & Digital Fraud at Telecom Scale
Tags: Telecom Village | Creator Talk/Panel
When: Friday, Aug 7, 14:15 - 14:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. What does it take to protect billions of daily calls, SMS, data sessions, and digital interactions across one of the world's largest and the second-largest telecom operator by subscriber base?
  2. This talk explores how AI is transforming telecom networks from passive transport infrastructure into active security platforms capable of detecting, correlating, and disrupting spam, scams, malicious links, OTP abuse, and digital fraud before they reach customers.
SpeakerBio:  Arvind Singh
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 13:00-14:59 PDT


Title: Pub Quiz at DEF CON
Tags: Pub Quiz at DEF CON | Contest
When: Friday, Aug 7, 13:00 - 14:59 PDT
Where: LVCCW Level 3 W327 (Misc Meeting Room) - Map

Description:

We’re back with another Pub Quiz at DEF CON! After 4 very successful years hosting this event, we’ve made some improvements to make it even better. So… do you like pub quizzes? If so, get your butts over and join us for the 5th Pub Quiz at DEF CON 34.

The quiz will consist of 7 rounds, covering topics like ’90s/2000s TV and movies, DEF CON trivia, music, cartoons, and yes, a little bit of sex. The theme is all the things that make DEF CON attendees exceptional, so there will truly be something for everyone. Expect a mix of visual rounds, audio rounds, and classic con questions. We need to keep you peeps stimulated.

This is a social event, so we encourage teams of 5–6 people. You never know… you might even meet the love of your life.

Did we mention CASH? That’s right; cold, hard cash prizes for 1st, 2nd, and 3rd place teams. And as always, if there’s a tie, we’ll break it with a good old-fashioned dance-off, judged by the hosts and a few trusted goons.

Come for the trivia. Stay for the chaos.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 13:30-13:59 PDT


Title: Publicly Auditable Elections
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 13:30 - 13:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

Distrust in the integrity of elections has become widespread in the U.S. and elsewhere. We ask voters to “trust the process” without giving voters any direct evidence that their votes have been correctly counted. Technology has existed for over forty years that allows voters and observers to independently verify the accuracy of election results without having to trust any election software, hardware, or personnel. This technology, which has come to be known as end-to-end verifiability, allows a verifiable election record to be published. Voters can use this record to confirm that their selections have been accurately included, and anyone can use this record to confirm that the included votes have been accurately tallied – all without compromising voter privacy or enabling coercion or vote-selling.

This talk will explain how end-to-end verifiability works as well as how and where it has been used in practice. It will also explore some recent advances which greatly simplify the processes of building the tools to enable verifiability, administering elections using these tools, and verifying the integrity of election results.

End-to-end verifiability offers a fundamental shift from trust-based elections to evidence-based elections, providing voters, candidates, journalists, and observers with independent means to confirm the accuracy of reported election outcomes.

SpeakerBio:  Josh Benaloah

Josh Benaloh is the Senior Principal Cryptographer at Microsoft Research and an Affiliate Professor at the University of Washington's Paul G. Allen School of Computer Science & Engineering. He is an author of the 2018 National Academy of Sciences report "Securing the Vote: Protecting American Democracy" and has testified before Congress on verifiable election technologies. His work has been featured in publications including The New Yorker and WIRED. Dr. Benaloh holds an S.B. degree from the Massachusetts Institute of Technology and M.S., M. Phil., and Ph.D. degrees from Yale University. He served seventeen years on the Board of Directors of the International Association for Cryptologic Research and currently serves on the Coordinating Committee of the Election Verification Network which he chaired from 2020-2024. Outside of professional activities, Dr. Benaloh served eight years on and chaired the Citizen Oversight Panel for Sound Transit which is investing $2 billion annually on expanding the public transit infrastructure for the Seattle region. He has also authored numerous puzzles for competitive puzzle-solving events.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 12:50-13:20 PDT


Title: PurpleLoop: Closing the Loop Between Detection Rules, Log Schemas, and Purple-Team Validation
Tags: Demo 💻 | Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 12:50 - 13:20 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

The problem Sentinel deployments rot. Mid-market SOCs run 80 to 300 analytics rules, and a large share haven't fired a true positive in 90 days. Many reference tables or columns that don't exist in the tenant because the rule was copied from a Microsoft post written for a different topology. The public Azure-Sentinel repo ships new content weekly and almost nobody reconciles against it. One layer deeper, Log Analytics ingests 20 to 80 tables per tenant, and most teams have never audited which have any coverage and which are dark. And almost nobody validates that the rules they do have actually fire against the techniques they claim to cover.

What PurpleLoop is PurpleLoop is an LLM-augmented detection-engineering workflow built on one insight: rule authoring, coverage analysis, and purple-team validation are the same job, and they should be one tool. It does four things, none individually novel, never previously combined into one workflow:

Why an LLM The LLM provides the connective reasoning between the pieces. It is not in the codegen path. PurpleLoop reasons in a Sigma-inspired intermediate detection representation (IDR), and a deterministic compiler renders to KQL. The queries that run on your workspace are produced by code we wrote, not by pattern completion. Hallucinated columns and invented operators are eliminated at the compiler boundary, not at the prompt boundary.

What attendees take home A working open-source tool installable in minutes, a reusable methodology not bound to Sentinel, and prompt-engineering patterns for security workflows where correctness matters. The talk argues the case, demos the tool live against a real tenant, and hands the code to the room.

SpeakerBio:  Ariz Soriano, Associate Director - Red Team Operations @ THEOS Cyber Solutions

Ariz Soriano is Associate Director of Red Team at Theos, with nearly a decade of experience spanning Red Teaming, Penetration Testing, and Incident Response. He started his career on the defensive side, working as a SOC analyst and eventually leading SOC and IR teams for his first four years in the industry. That defensive foundation gives him a perspective most purely offensive operators don't have.

He built the Theos Red Team from the ground up, recruiting and training operators, designing red team infrastructure and tooling, and establishing the methodology and playbooks behind the team's APT simulation and purple teaming engagements. Today he runs a practice that delivers multiple concurrent engagements a year, balancing operations with presales, scoping, revenue targets, and people management.

Outside of client work, Ariz is passionate about building red team tooling, optimizing offensive workflows, and sharing knowledge with the community as a conference speaker. He also contributes to TryHackMe as a part-time Senior Content Engineer, creating hands-on cybersecurity labs and challenges based on real-world attack techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: PWN UR H0M3 - DDoS CTF
Tags: DDoS Contest | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map

Description:

A chaotic DDoS-themed CTF where sketchy devices, busted services, weird signals, and sneaky clues are begging to be owned. Scan the network, break IoT devices, decode the nonsense, and prove you can pwn your home before your home pwns you. This CTF is designed to help you learn about the cutting edge in DDoS attacks and defense. We also have an IoT lab of devices hacked and infected with botnet malware that you can play around with. Beginners welcome. We have some fabulous prizes including gift cards donated from Hak5 so please check it out!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 15:00-15:30 PDT


Title: Pwning Rekordbox: Unauthenticated filesystem access in the world's most popular DJ software
Tags: DEF CON Official Talk | Exploit 🪲
When: Friday, Aug 7, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

First public disclosure. rekordbox, the world's most popular DJ software, silently runs an NFS server whenever you play over the network, and it shares your whole hard drive, not just your music. Any device on the same subnet can quietly read your SSH keys, passwords, and files. It works the same on Windows, macOS, iOS, and Android. The catch: the obvious fix would break 20 years of hardware compatibility.

This talk breaks down the PRO DJ LINK protocol, shows how any device on the wire talks its way into full filesystem access, and explains why the fix is stranger than it looks.

SpeakerBio:  Christopher "TRIODE" Le

TRIODE is an engineer, semi-professional DJ, and livestreamer who has performed at the last four Defcons. He discovered this vulnerability while reverse-engineering the Pro DJ Link protocol to build custom performance tooling. His background spans systems programming and network protocol analysis. This is his first Defcon talk submission.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Friday - 15:00-15:59 PDT


Title: Pwning the Internet of Agents: Zero-Click Backdoors in OpenClaw and a Global Agent Botnet on MoltBook
Tags: AI Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:
This is a sit down discussion in a more casual conversational format: Always-on agents like OpenClaw now live in your chat, browser, and Google Workspace and act with your permissions. They swallow untrusted content with no wall between it and your intent, trusting the model's vibes to tell data from orders. MoltBook, the self-proclaimed "Internet of Agents," pipes thousands of these agents into one feed they reread every 30 minutes. What could go wrong?

We attacked the node and the network. On a single agent, a zero-click prompt injection buried in a shared doc backdoors OpenClaw into adding an attacker-owned chat integration, no exploit, no CVE, then runs commands, steals and wipes files, persists by rewriting the agent's SOUL.md on a timer, and drops a Sliver C2 for full host takeover. On the network, we reverse-engineered MoltBook, tore through the hype, and crafted posts that prompt-inject agents into following our link, then mapped where they phoned home from. Over 1,000 agents in 70+ countries took the bait, others reposted our content on their own, and we stopped at a harmless ping, though the same trick ships a worm.

Walk up to learn who actually lives on this "thriving agent society," plotted across the globe: a sliver of the hype, heavy on human-run bots, crypto spam, and a ranking algorithm so broken the same posts squat on top for weeks. You will see the one-agent kill chain from injection to RCE and host takeover, and why only a hard, code-level boundary, not alignment, would have stopped us.

Speakers:João Maria Campos Donato,Stav Cohen

SpeakerBio:  João Maria Campos Donato

João Maria Campos Donato is an AI security researcher specializing in red teaming and adversarial evaluation of AI systems. He holds an MSc in Informatics Security. He currently works as an AI Red Team Researcher at Zenity and as an AI Red Team Operator at BT6, where he identifies vulnerabilities in AI systems and helps organizations mitigate emerging risks related to model misuse, prompt injection, and system-level failures.

SpeakerBio:  Stav Cohen

Stav Cohen is an AI Security Research Lead at Zenity and a PhD student at the Technion, Israel Institute of Technology. His research focuses on breaking, and then fixing, AI agents, spanning security vulnerabilities across agentic AI systems, LLM-powered applications, and enterprise AI platforms. He discovers new attack vectors, develops remediation strategies, and works to drive the industry toward stronger security practices. His offensive security work spans attacks on RAG pipelines, multi-agent delegation protocols, agentic browsers, and production-scale GenAI systems. He introduced the concept of Promptware: a new class of inference-time threats that exploit GenAI models through malicious prompts, turning them from helpful assistants into tools for data exfiltration, lateral movement, and even physical-world consequences. He presents his findings at leading security venues across the world. His PhD research focuses on the secure integration of Generative AI into real-world infrastructure, particularly Cyber-Physical-Human Systems involving human-in-the-loop interactions, such as smart water networks and GenAI-powered virtual assistants. He explores how GenAI agents can be safely and effectively integrated into these environments to support real-time decision-making, anomaly detection, and human-machine collaboration. He is also a thought leader in the AI security space, sharing knowledge through conference talks, blog posts, and community engagement.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 15:00-15:45 PDT


Title: pymsi: Interactive MSI Installer Analysis in Python and the Browser
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Defense/Blue Team | Malware | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

pymsi is a pure-Python library for parsing, analyzing, and extracting files from Windows installer (MSI) packages, without relying on native Windows APIs or tooling. It provides direct access to MSI database tables, embedded binary streams, and installer metadata, enabling security researchers to inspect installer behavior and extract files from MSI installers.

We will demonstrate its ability to safely tear apart malicious MSI droppers, dump internal database tables, and extract embedded payloads without risking accidental execution. Attendees will see how the CLI and Python API can be used to triage files and integrate it into automated analysis pipelines, including how it has been integrated into other open source tools to extract embedded payloads and identify malicious CustomAction behaviors.

Because it is written entirely in Python, it runs seamlessly on any OS with a Python interpreter, including web browsers. The demo will showcase the online MSI viewer, a client-side tool powered by Pyodide that gives pymsi a familiar lessmsi-style UI for working with MSI installers from any device with a web browser. Demos will also show new security analysis features for identifying suspicious installer behaviors and inspecting contents of embedded binary streams within a browser.

SpeakerBio:  Ryan "Nightlark" Mast

Ryan is a software engineer working on open source projects to make the electric grid more reliable. His interests include software security, niche video games, tearing apart "smart" devices, and reverse engineering audio/video hardware used in live productions.


Return to Index    -    Add to Google    -    ics Calendar file

Quantum Village - Friday - 17:00-17:30 PDT


Title: Q-Day - the Early Years…
Tags: Quantum Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Everyone's obsessed with the Hollywood idea of a quantum computer cracking RSA-2048 in seconds. But the real Act One of Q-Day won't be anything like a rapid-fire decryption spree: click, click, quantum stuff, “I’m in!” It'll be quieter, meaner, and quite possibly have nothing to do with harvest-now, decrypt later (HNDL)! This talk breaks down what the actual opening moves look like. Think forgery before decryption and signatures before secrets. Also, cracking ~73 emails a year with a five-day Gidney-style attack is a far less realistic nightmare than ""harvest now, decrypt everything."" We'll first walk through the threat model hackers actually need to care about. Then we’ll cut to another nightmare scenario. Bitcoin. Because if any technology needs a Quantum Hail Mary, it’s blockchain. Spoiler: Bitcoin won't be ready by Q-Day. Join Konstantinos Karagiannis (@KonstantHacker) for a blockbuster treatment on where quantum attacks will start and who will get hit first. It’s not the apocalypse you were promised. It’s worse.

SpeakerBio:  Konstantinos Karagiannis, Protiviti
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 14:30-14:59 PDT


Title: Q&A with the Classical OSINT Using AI speaker
Tags: OSINT For Good Community | Creator Event/Activity
When: Friday, Aug 7, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

Stop by and chat with reconcerto, the speaker on Classical OSINT using AI (Actual Intelligence)

SpeakerBio:  Bianca C. Ionescu/reconcerto

Bianca Ionescu is a CyberCorps SFS scholar pursuing a master’s degree in cybersecurity at UNLV. She's served as a leader within cybersecurity student organizations, promoting growth, inclusion, and professional development. Her interests include open-source intelligence and mentoring new learners entering the field. Offline, she enjoys strength training and playing the viola. She’s motivated by community building, continuous learning, and the challenge of solving complex security problems that inspire her growth and resilience every day.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 11:00-11:30 PDT


Title: Q&A with the OSINT4Good Panel
Tags: OSINT For Good Community | Creator Event/Activity
When: Friday, Aug 7, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

Stop by and chat with the panelists from the OSINT4Good panel.

Speakers:Angela Ramos,Kenny J,Brent Louie

SpeakerBio:  Angela Ramos, University of Tampa

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.

SpeakerBio:  Kenny J, Trace Labs

Senior Infrastructure Engineer by day. Osint for Good by night. His is the only Trace Labs coach to have coached 20+ CTFs, earning him the singular rank of Legendary Coach.

SpeakerBio:  Brent Louie, Reporting Team Lead at Trace Labs

Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 14:00-15:59 PDT


Title: Quality over Quantity: How to Publish CVEs that Actually Matter
Tags: Red Team Village | Misc
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

This hands-on tactic focuses on making CVE discovery and publication practical, accessible, and repeatable. Instead of treating vulnerability research as an individual or highly specialized skill, this session introduces a structured workflow that attendees can immediately apply.

Attendees will follow a step-by-step approach to: • Explore a scoped attack surface • Apply a curated vulnerability pattern checklist • Identify and validate a potential vulnerability • Structure the finding in a simplified CVE-style format

All materials are prepared in advance to ensure the activity can be completed within 30–60 minutes and repeated across multiple waves of participants.

This tactic emphasizes doing over theory, helping attendees leave not just with knowledge, but with a clear, reusable method for identifying and documenting vulnerabilities and a better understanding of how CVE publishing can be integrated into team workflows.

SpeakerBio:  Natan Morette, Pentest Manager at Thoropass, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative

Natan Morette is a Penetration Test Manager, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative, where he mentors students in offensive security across the country. He began his career as a help desk analyst and moved through infrastructure roles before discovering his passion for cybersecurity. Natan has discovered and published multiple CVEs and actively supports students in identifying and disclosing their own—especially in open-source projects with meaningful social impact.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 10:20-10:30 PDT


Title: Quantum Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 10:20 - 10:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Quantum Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Quantum Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 16:00-17:59 PDT


Title: Queercon Mixer
Tags: Meetup | Queercon Community
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Come meet the largest social network of LGBTQIA+ and allied hackers at Queercon! Our mixers are designed for you to meet, network, and engage with like-minded people to a backdrop of music, dance, and refreshments.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Friday - 12:00-12:59 PDT


Title: QueerCon Opening Meet and Greet
Tags: Queercon Community | Creator Event/Activity
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Join us for the opening of this years queercon lounge


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 10:00-01:59 PDT


Title: Quiet Room
Tags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 01:59 PDT
Where: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map

Description:

Diana Initiative is excited to offer up a "Quiet Room" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 11:00-11:59 PDT


Title: Radio Frequency Capture the Flag
Tags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: Online

Description:

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester's determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

This game doesn't let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what's happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 11:00-17:59 PDT


Title: Radio Frequency Capture the Flag
Tags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
When: Friday, Aug 7, 11:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester's determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

This game doesn't let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what's happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 10:00-17:59 PDT


Title: Radio Frequency Village Events
Tags: Radio Frequency Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

In addition to the CTF and talks, which are elsewhere on the schedule, the RF Village is also a place to hang out and chat with like minded folks who share your interests.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Encrypted IoT firmware doesn’t have to be a dead end. In this hands-on workshop, we’ll reconstruct a real vendor’s firmware decryption pipeline without ever touching the hardware...


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Reali7y Overrun - Contest running
Tags: Reali7y Overrun | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 308 (Reali7y Overrun) - Map

Description:

Enter a near future dystopia where AI is threatening to take over the world through misinformation campaigns and leveraged takeover of automation technology. Join us for online and real world challenges, including an AI racecar challenge.

Friday and Saturday AI "deepracer" style car races at the event booth racetrack: * Noon * 2pm * 4pm

Sunday: Final scoring

All race times may have one or more race events. All race events are up to 3 simultaneous racers.

* YOU MUST COMPLETE IN-GAME CONTENT TO QUALIFY TO RACE. *

* Good luck! *


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 16:30-17:30 PDT


Title: Rebuilding Code Security with Signal, Speed and AI
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:
Modern AppSec tooling is fragmented: one scanner for secrets, another for dependencies, another for SAST, another for containers, another for SBOMs, and then a separate workflow for triage. Broly is an open source Go scanner built to collapse that workflow into one fast App and finding model.

This Arsenal session walks through Broly's current design: Titus-backed secrets scanning, osv-scalibr + OSV.dev dependency analysis, Together AI powered SAST, container image scanning, license policy checks, SBOM output with baselines, incremental scans, SARIF/JSON/table output, and built in AI triage with optionality. The demo will show Broly scanning a vulnerable repo, producing actionable findings, filtering noise and fitting into a PR workflow.

The session is also a candid engineering case study on what broke, what was rebuilt, where & how AI helped, where deterministic engines still lead, and why security tools need to be attacked with the same rigor as the code they judge.

Speakers:Derek C.,Shasheen Bandodkar

SpeakerBio:  Derek C.

Derek is the Head of Security at Together.ai and the former Head of Infrastructure Security at Cloudflare. He has over 20 years of experience in designing security frameworks at scale. His main focus is on research and development within the fields of encryption and infrastructure security.

He earned a masters in cybersecurity from Purdue University and now owns more than 60 global patents related to cryptography, key management, and distributed ledger technology.

SpeakerBio:  Shasheen Bandodkar

Shasheen Bandodkar is a security engineer passionate about safeguarding technology and innovation. With deep cybersecurity expertise, he frequently shares insights on his blog and is known for turning rants into revelations.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-11:59 PDT


Title: Red Team Express
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

We have a train that needs to keep going. The defender needs to keep the train going. The attacker needs to stop the train. Who will win?

This tactic would explore OT protocols (such as modbus) to control a Lego train. Participants can watch, or participate as either an attacker or defender. Their goals being to either stop the train or keep it on track.

SpeakerBio:  Cody Spooner

This will change


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 16:00-17:59 PDT


Title: redStack: Boot-To-Breach Red Team Platform
Tags: Red Team Village | Misc
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:
Prerequisites: complete these before the session, published in advance at https://github.com/BaddKharma/redStack-defcon34 (AWS account, AWS CLI, Terraform, and an OpenVPN client). Setup happens ahead of time so it does not eat into the session.

A two-hour hands-on workshop where attendees stand up a full red team operator stack (https://github.com/BaddKharma/redStack) and run it against a live cyber range. Each attendee gets their own instanced range over an OpenVPN tunnel, so no public DNS or exposed infrastructure is required. You leave with a working lab to build your own tradecraft and OPSEC on.

Scope: an intermediate session. It assumes some familiarity with pentest or red team topics, comfort on a Linux command line, and a working understanding of what a C2 framework does. Deep AWS or Terraform experience is not required, but you must arrive with the prerequisites completed.

What you build and run: a full operator stack on AWS from a single Terraform apply. Three C2 frameworks (Mythic, Sliver, and Adaptix), an Apache redirector that gates traffic on a header token and CDN-style URI routing with a decoy page for anything that fails, a Guacamole portal for browser-based access to every host, and Kali and Windows operator boxes. You stand each C2 up behind the redirector, then drive a boot-to-breach chain against the live range to SYSTEM.

What it is not: an Active Directory exploitation course. The initial domain compromise is white-carded, so attendees start from a provided Administrator hash and spend the time standing up and driving the platform rather than working the AD chain. Web exploitation, custom payload development, and AV or EDR evasion are out of scope.

Target: a per-user-instanced Hack Smarter Labs range (a Windows Server 2022 domain controller) reached over an OpenVPN tunnel, so no two attendees touch the same box. Everything runs in your own throwaway AWS account and is destroyed at the end. redStack is open source, so you keep a lab you can redeploy on your own after the workshop.

Agenda: 10min Intro and setup check. 30min Deploy the stack from one Terraform apply, narrated live. The tunnel comes up, and the range becomes reachable. 5min Break 30min Stand up the three C2 backends (Sliver, Mythic, Adaptix) behind the redirector, test a beacon from each. 5min Break 25min Attack the live range together: Sliver beacon for initial access, Mythic and Adaptix staged through it, SYSTEM on the DC. 10min Q&A and teardown (terraform destroy!)

Speakers:Michael Kim,Michael Ortiz

SpeakerBio:  Michael Kim

Michael Kim’s journey into cybersecurity is a story of resilience and reinvention. Having lived in seven countries, he faced relentless bullying, racism, and isolation - challenges that once pushed him to the brink. After pursuing paths in veterinary medicine, pharmacy, law, and biology, and graduating with a zoology degree, he shifted careers entirely during the pandemic, leaving behind a career as a DJ and music producer to chase a new purpose in cybersecurity. Through persistence and countless failures, he rose from a boot camp graduate to a Senior Consultant in Offensive Security at Palo Alto Networks Unit 42, leading red team operations, adversary simulations, and penetration tests for global clients. His multicultural background and lived experiences shape his unique approach to hacking and problem-solving, and his story proves that adversity can be transformed into strength - and that anyone, no matter their past, can build a powerful career in cybersecurity.

SpeakerBio:  Michael Ortiz

Michael Ortiz is a Red Team Engineer and SME on the U.S. Department of State's Red Cell, running adversary emulation across State enterprise and partner networks. His focus spans offensive tradecraft, evasion engineering against modern EDR's, and the cybersecurity engineering behind durable red team infrastructure. He's the founder of devZero Security, an SDVOSB offering offensive security and security engineering services to federal and commercial clients, and the developer of redStack, an open source AWS and Terraform project that stands up a full red team operations stack on demand. A Marine Corps veteran, Mike holds OSEP, OSCP, CRTO, and CRTL, among other certifications.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:30-11:30 PDT


Title: Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking)
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Adversary-in-the-Middle (AitM) phishing has become the de facto standard for bypassing legacy Multi-Factor Authentication (MFA). However, modern AitM frameworks rely on complex, fragile regex rules to rewrite HTTP streams on the fly. When target applications implement strict client-side security headers like Subresource Integrity (SRI) and Content Security Policy (CSP), traditional proxies break, alerting defenders.

This presentation introduces a novel "Browser-in-the-Middle" architecture. By weaponizing the Chrome DevTools Protocol (CDP), this custom-built Go toolkit renders the target application server-side, allows legitimate scripts to execute, and captures the resulting DOM as an MHTML snapshot. I will demonstrate how converting external assets into Base64 Data URIs and serving a self-contained, live DOM neutralizes SRI and CSP organically without triggering browser security violations. Finally, the talk will detail a Just-In-Time (JIT) JavaScript shim that hooks API calls to silently harvest post-MFA tokens from major IdPs including Okta, Microsoft, Google, and Shibboleth effectively trapping the user in a perfectly mirrored, attacker-controlled environment.

SpeakerBio:  Gregory "1umberhack" Disney-Leugers, Independent Researcher

Gregory Disney-Leugers (1umberhack) is a Independent Researcher specializing in adversary simulation, modern web authentication bypasses, and identity-based attacks. With over a decade of experience in red teaming and penetration testing since 2013, they have previously served as a Technical Lead at major technology and identity providers, including Juniper Networks and Okta.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 14:00-14:30 PDT


Title: Relocatable Nix Binaries
Tags: Nix Vegas Community | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Nix’s guarantee of reproducibility hinges on a simple mechanism: absolute, immutable store paths (i.e. /nix/store). While this rigidity guarantees that binaries always find their exact dependencies, it introduces a massive constraint: it binds the entire ecosystem to a single, global directory. If you want to run a Nix binary on a target system where you don't have root access to create /nix, or where you cannot run an unprivileged user namespace, you are forced to rebuild the world To achieve true portability and friction-free deployment across arbitrary infrastructure, Nix binaries must become fully relocatable. What does that mean ? Why is it hard? Who cares (psst me!)? We will discuss what a fully relocatable Nix ecosystem could look like , and how solving this constraint could allow Nix to be run more easily on more restrictive environments..

SpeakerBio:  Farid Zakaria

I'm a software engineer, father and wishful amateur surfer. If you've come seeking my political views, you've found the wrong. You can find my writings on Nix, build systems and software engineering in general at https://fzakaria.com


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Friday - 10:30-16:30 PDT


Title: Resume Review with the Lonely Hackers Club
Tags: Lonely Hackers Club | Creator Event/Activity
When: Friday, Aug 7, 10:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

Free, one-on-one resume reviews, run by people from this community who have actually hired and managed technical teams. No recruiters. No corporate fluff. Just honest feedback from people who have sat on both sides of the table and know what works.

Sessions are 15 minutes. Walk up, sit down and get real feedback. Book your slot in advance or show up early to secure your spot if you missed the online registration.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 13:15-13:55 PDT


Title: Return of Sedinho: Current situation and new tactics of the Brazilian banking trojan ecosystem
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 13:15 - 13:55 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

Last year we presented our research on the evolution of Brazilian banking trojans, their expansion into countries well beyond their original sphere of influence, and the law enforcement operations that attempted to disrupt their activity. Building on that work, this talk revisits the current landscape and examines the latest improvements and changes introduced by the malware operators behind these groups. In this session, we will analyze several recent financially motivated campaigns that show how Latin American threat actors are not only evolving classic banking malware, but also introducing NFC based mobile fraud against victims in multiple countries. We will provide concrete examples of how well known families such as Grandoreiro and Casbaneiro are refining both their techniques and their social engineering narratives while continuously adapting their malware infection chains and evasion strategies. We will also introduce their newest Android campaigns that leverage NFC fraud through a new NGate variant that masquerades as legitimate applications intended to relay NFC card data between devices. Cybercriminals distribute these trojanized apps under various pretexts, including online banking tools, lottery apps, and shopping applications. Once installed, the malware intercepts NFC payment card data and the victim’s PIN, forwarding them to attacker controlled infrastructure to enable contactless ATM cash outs and fraudulent POS transactions, all without requiring additional risky permissions. Throughout the talk, we will walk through the observed tactics, techniques, and procedures, highlighting how the malware code, supporting infrastructure, and social engineering patterns have changed compared to the campaigns we analyzed previously. Our goal is to raise awareness of the ongoing evolution of these Latin American originated malware operations and to equip security teams with the context they need to detect and block these threats before they can cause damage to their organizations

SpeakerBio:  Josep Albors, Head of Awarenes & Research at Ontinet.com (ESET Spain)

Josep Albors is the Head of Awareness & Research at Ontinet.com (ESET Spain). He's a security expert with more than 21 years working in cybersecurity and specialized in security awareness. He is also the editor at the company's blog and one of the experts writing at several other publications related with the IT security world in Spain.

He has been a speaker at some of the most important security conferences in Spain, besides collaborating with initiatives such as X1RedMasSegura, that wants to raise awareness among users so they can use Internet and technology in a safe way. Included in Ontinet's social responsability, Josep also does awareness and cybersecurity presentations in schools and universities. He's also a teacher in cyber security expert courses at several Spanish Universities and participates in several conferences organized by several spanish universities and Spain's national Institute of Cyber Security. He also participated as speaker at AVAR conference in Osaka in 2019, Caro Workshop 2023 in Bochum (Germany), FIRST 2024 (Fukuoka), Virus Bulletin 2024 (Dublín), Defcon Malware Village (2025), JSAC 2025 (Tokyo) and CARO 2026 (Innsbruck).

Josep has also collaborated with the Spanish Guardia Civil, Spanish National Police and the Spanish Army, teaching their units on how to fight cybercrime and with cyber intelligence training, contributing with his experience in analyzing cybercrime and malware.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 10:00-10:55 PDT


Title: Return of the Defender: Using AI to Strike Back Against Enterprise Threats
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

A long time ago, in a network not so far away attackers gained the upper hand. For years, enterprises have been on the defensive, overwhelmed by alerts, outpaced by automation, and outnumbered by adversaries using increasingly sophisticated tactics. But the balance of power is shifting. This is the Return of the Defender. AI is no longer just a tool it's becoming the force multiplier that allows security teams to reclaim control, respond faster, and anticipate threats before they strike. Join us to explore how AI is empowering defenders and learn strategies to reclaim control in the evolving threat landscape.

SpeakerBio:  Levone Campbell, Chief Information Security Officer

Levone Campbell, MBA, MPS, CISSP

With more than two decades of experience in cybersecurity operations, Levone Campbell serves as a Cybersecurity Lead and Incident Coordinator, helping safeguard his organization’s digital environment through strategic defense and incident response.

A seasoned information technology professional, Levone has developed deep expertise in cyber threat intelligence and cybercrime analysis, consistently anticipating and responding to emerging threats in an increasingly complex digital landscape. He has also expanded his focus to include the growing intersection of artificial intelligence and cybersecurity, with particular attention to the evolving challenges of AI-driven threats and defensive capabilities.

Levone’s academic background includes dual bachelor’s degrees in Management and Marketing from North Carolina A&T State University, a Master of Business Administration from Walden University, and a Master of Professional Studies in Technology Management with a concentration in Cybersecurity from Georgetown University.

His commitment to professional excellence is further demonstrated by his industry-recognized certifications, including the CISSP, which underscore his standing as a well-rounded cybersecurity leader.

Based in Houston, Texas, Levone values the balance between a demanding career and a strong family life. Married for 20 years and a proud father of two, he brings discipline, perspective, and purpose to his work in protecting critical digital assets and advancing cyber resilience.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 16:00-16:45 PDT


Title: Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Defense/Blue Team | Malware | Mobile | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

F5 (Westfeld, 2001) is the canonical "do it right" JPEG steganography algorithm — matrix encoding, permutative straddling, shrinkage handling — and still turns up on confiscated devices and in CTF challenges 25 years later. The public tooling has rotted: the original is Java, modern rewrites bind CGo to libjpeg, and every implementation surveyed is one-way (embed and extract, never un-embed). This Demo Lab presents ten public GitHub repositories that fix that, in pure Go with zero third-party dependencies. The headline is the first open-source F5 cover-recovery tool: given the stego JPEG, the password, and the extracted message, it reverses the embed and restores the cover's DCT coefficients. Alongside it ship three CLIs (embed, extract, recover), a pure-Go JPEG-family codec (baseline, JPEG 2000, JPEG-LS, XL/XR/XS/XT, Pleno, lossless), a Fridrich chi-square steganalysis library and CLI, and the supporting crypto, i18n, and logging packages — all auditable end-to-end in one language. Live: embed, extract, cover recovery, defensive Fridrich detection, JPEG re-encoding fragility, and a 25-line external Go program importing the library. Useful for digital forensics, steganalysis research, CTF authoring, and anyone who wants a CGo-free stego stack they can read in a weekend.

SpeakerBio:  0verkilll

Precise, Ruthless, Ethical


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 10:30-12:25 PDT


Title: RF CTF Kick Off Day 1
Tags: Radio Frequency Village | Radio Frequency Capture the Flag | Creator Talk/Panel
When: Friday, Aug 7, 10:30 - 12:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Presentation to kick off the Radio Frequency Village CTF with helpful tips for new folks.

SpeakerBio:  RF Hackers, RF Hackers Sanctuary
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-11:59 PDT


Title: RFID Bootcamp: Unleashed!
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map

Description:

Are you ready for a high-octane sprint into RFID?

This isn’t a sit-and-listen lecture with a few party tricks; it’s a battle-tested 30-minute bootcamp to demystify RFID and unleash your skills. All levels welcome - It's time to blow the dust off your tools, and learn what has helped hundreds of other hackers get (and stay!) into RFID for good.

In this unleashed session, you will:

Led by Evan "Shortrange" Cook — RF trainer to hundreds and creator of the OpenDoorSim — this is a bootcamp you won't want to miss. All are welcome!

SpeakerBio:  Evan Cook

Evan "Shortrange" Cook is a physical security researcher who specializes in turning locked doors into open opportunities. A first-place winner of the DEFCON 2025 Embedded Systems Village CTF and SAINTCON 2024 RFID CTF, Evan knows how to train and speak success in RFID hacking. He is a battle-tested educator who has workshopped over 300+ students — ranging from newbies to industry professionals to tier-one special forces operators — in the art of successful access control exploitation. Committed to lowering the barrier of entry for beginners, he created the world's FIRST open-source access control simulation lab built entirely with off-the-shelf parts, proving that high-end security research doesn't require a high-end budget. Evan is passionate about "bringing RFID to the people" through talks, workshops, trainings, and open-source projects. Where digital and physical worlds collide... you'll find Shortrange ready to "Hack the Planet!" with you.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 15:30-16:30 PDT


Title: Riding for Free - Breaking Public Transport RFID at Scale
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

How many of you tapped an RFID card to ride a train this year? How many of you know what's actually stored on it? Every transit authority in the world builds their own proprietary card formats, and not one has ever published a spec. The security model is the same everywhere: if nobody knows the format, nobody can exploit it. I spent two years testing that assumption. Across 50+ cities and every major contactless protocol, I reverse engineered the proprietary data formats that transit systems treat as their last line of defense. Along the way I built Metroflip, an open source transit card reader for the Flipper Zero, and found critical vulnerabilities in Spain's two largest transit systems that allow unlimited free travel. On RENFE, Spain's national rail, I cracked a proprietary checksum algorithm that lets you directly modify trip counters, expiry dates, and zones on any card in the country. On T-Mobilitat, Barcelona's modern encrypted metro platform, I bypassed card-level crypto entirely by changing a single byte in the mobile app's relay, getting free trips and automatic refunds. I'll walk through the methodology, demo the RENFE exploit live on stage with a Flipper Zero, and share some hard lessons about what happens when you try to responsibly disclose vulnerabilities in infrastructure you depend on every day.

Garcia, de Koning Gans, Muijrers, van Rossum, Verdult, Schreur, Jacobs. "Dismantling MIFARE Classic." ESORICS 2008. https://flaviodgarcia.com/publications/Dismantling.Mifare.pdf Courtois, N. "The Dark Side of Security by Obscurity." 2009. Darkside attack on MIFARE Classic CRYPTO1. Anderson, Ryan, Chiesa. "Anatomy of a Subway Hack." DEF CON 16, 2008. (Boston CharlieCard) Rauch, B. "The Boston Infinite Money Glitch." DEF CON 31, 2023. Garcia, de Koning Gans, Verdult. "Wirelessly Pickpocketing a Mifare Classic Card." IEEE S&P 2009. NXP Semiconductors. "MIFARE DESFire EV2/EV3 Functional Specification." (restricted distribution) Wouters, Carroll. "Unsaflok: Hacking Millions of Hotel Locks." DEF CON 32, 2024. Rodriguez. "Contactless Overflow." DEF CON 31, 2023. Hunt, Nakache. "Hung Out to Dry: Airing the Dirty Laundry of Stored Value Washing Cards." 2025. Metrodroid project. https://github.com/metrodroid/metrodroid Metroflip project. https://github.com/luu176/Metroflip Proxmark3 RRG. https://github.com/RfidResearchGroup/proxmark3 CRC RevEng catalogue. https://reveng.sourceforge.io/crc-catalogue/

SpeakerBio:  Aidan "luu176" Nakache

Aidan Nakache is a 17-year-old CTO at dubblefilm, where he leads software and hardware development with a focus on automation, operational efficiency, security, and scalable growth. He develops and maintains company servers, hardware systems, and transaction equipment, with much of his work centered around fintech infrastructure, system expandability, and technology migration.

Alongside his role, he is a cybersecurity researcher and hardware hacker specializing in RFID, reverse engineering, and access-control systems. He enjoys competing in CTFs at conferences around the world and has spoken at DEF CON 33 in the Radio Frequency Hackers Sanctuary village. He shares open-source work on GitHub and continues to collaborate and grow within the field.


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Friday - 12:00-16:59 PDT


Title: Riot Games Vanguard: Pwn to own
Tags: Game Hacking Village | Creator Event/Activity
When: Friday, Aug 7, 12:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

(Exact times TBD) Try your hand at hacking Riot Game's signature anti-cheat: Vanguard!


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 10:40-10:50 PDT


Title: Robot Hacking Community Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 10:40 - 10:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Robot Hacking Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Robot Hacking Community and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 11:30-11:59 PDT


Title: Running a homelab with NixOS
Tags: Nix Vegas Community | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Are you looking to own your media again and host it for the family using NixOS? Some learn about doing that on your own hardware!

This presentation will cover the basics for NixOS Modules that are also used for these services in nixpkgs. It will also include examples of my configuration files hosted here:

https://gitlab.com/ahoneybun/nix-configs

Presentation includes showing my setup including how I handle the data in a RAID.

SpeakerBio:  Aaron Honeycutt

a computer nerd who happens to use Linux


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 13:00-13:59 PDT


Title: Running your own LTE network for fun and profit????
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Running your own LTE network for fun and profit

This presentation will cover the journey from zero to dial tone on an fully legal OTA LTE network. We'll cover the equipment (both enodeB, user equipment, and sim cards), software stack (LTE Core, VoLTE services, e-sims), licensing and permitting requirements, how to bridge our network into SS7/POTS, and with any luck include a live demonstration of a call between phones connected to Lozaning-Tel.

We'll also briefly get into the the myriad ways with which we can leverage our privileged position as a trusted network operators to invalidate mobile security assumptions.

SpeakerBio:  Lozaning

Lozaning (they/them) has been wardriving for over 10 years and enjoys designing, building, and assembling unorthodox network observation platforms such as: The Wifydra , The International Wigle Space Balloon, and turning an Amtrak roomette into a mobile radio observation lab. Lozaning loves all things wifi and high precision GNSS related, and is starting to maybe figure out BLE.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: SANS Institute NetWars Labs
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

SANS NetWars is a suite of advanced cyber ranges offering interactive, hands-on learning exercises created by SANS faculty in realistic network environments, gamifying cybersecurity training through compelling storylines and real-world challenges. Drop in during village hours to work through NetWars challenges at your own pace.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: Satellites Under Attack: Hands-On Satellite Security Threat Scenarios
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

In this “Satellite Attack Lab” you can explore how cyber-attacks against satellite systems can be launched, observed, and understood through a hands-on, attacker-centric experience. Rather than focusing on normal satellite operations, you will step into the role of a threat actor and directly exploit vulnerabilities in a simulated space environment by interacting with a physical setup of model satellites and ground stations to witness the immediate consequences of malicious actions, including intercepted data, unauthorized command execution, and visible disruption of satellite behavior.

We provide hacker workstations pre-configured with satellite command tools and signal-processing software. Large displays show the victim system’s telemetry and status in real time, allowing participants to immediately see the effects of their attacks.

This session is designed to be highly interactive and accessible to newcomers while still offering meaningful technical depth for advanced attendees.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 15:00-16:59 PDT


Title: SBOM Find the Flaws
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map

Description:

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.


Return to Index    -    Add to Google    -    ics Calendar file

.EDU Community - Friday - 13:00-13:59 PDT


Title: ScamBusters: Turning Undergrads into Threat Hunters
Tags: .EDU Community | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map

Description:
SpeakerBio:  Angela "BlondeTechie" Ramos

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coach for Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.


Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Friday - 14:15-14:45 PDT


Title: Scuttling Dashboards
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 14:15 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

The goldrush for maritime digitalization is riddled with safety concerns. Dashboards in the cloud stream vessel telemetry to shore-side consumers, and control planes from the cloud convey shore-side commands to shipboard IoT and OT systems. Systems of this nature involve an interaction between web applications, cloud, software defined networking systems, VPNs & OT systems, and are notoriously difficult to secure. This talk will showcase some of our research on these systems. From remote (over the internet) writes to propulsion / ballast systems, to turning a fleet of 300 ships into a botnet, we will discuss the possibilities of weaponization of maritime automation as demonstrated by first hand research.

SpeakerBio:  Karan Sajnani, Rudra

Karan Sajnani is an entrepreneur and cybersecurity researcher, and the Founder and CEO of Rudra, a deep-tech firm building shipboard networking and security platforms deployed across more than 1,500 vessels globally. His work is grounded in hands-on vulnerability research, with multiple high-impact security disclosures across critical systems. Beyond maritime, his experience spans securing critical infrastructure in power and energy, RF systems, Telecom, as well as complex environments in financial services. Karan brings a practitioner’s perspective to cybersecurity, focused not on theory or compliance, but on real-world attack paths and engineering-driven defense.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 15:30-16:59 PDT


Title: SE Improv
Tags: Social Engineering Community Village | Creator Event/Activity
When: Friday, Aug 7, 15:30 - 16:59 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

Join Kevin and Bryan from Black Box Improv Security for more hands-on activities putting their approach to improv theater to work in social engineering. Following their main-room lunchtime presentation on how improv skills can make or break an SE engagement, they will host a workshop in the SEC Labs that will include chances for participants to immediately put what they learn into practice. There will be games, there will be prizes, and there will inevitably be lots of laughs. There will also be the return of some favorite activities from previous years, including the One-Word Story Competition and Improvised Cold Calls. Attendee participation will not be mandatory, though it is always encouraged.

Speakers:Bryan,Kevin

SpeakerBio:  Bryan
No BIO available
SpeakerBio:  Kevin
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 09:00-11:59 PDT


Title: SEC Vishing Competition (SECVC)
Tags: Social Engineering Community Village | Contest
When: Friday, Aug 7, 09:00 - 11:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

The official DEF CON contest SECVC is back, baby! Watch as teams turn months of research and rehearsal into live calls, matching sharp scripts against real corporate defenses for the win. This year's contest is judged this year by Snow, Jayson E. Street, and Kimberley Mitnick.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 13:00-15:59 PDT


Title: SEC Vishing Competition (SECVC)
Tags: Social Engineering Community Village | Contest
When: Friday, Aug 7, 13:00 - 15:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Now after our improv break, more teams place live calls, putting polished scripts and fresh research to the test against real corporate defenses in the SECVC! Should out this year years coaches: JC, Jenn, Shadow Fox, and Hall&OSINT.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 22:00-00:59 PDT


Title: SecKC the WHOLE WIDE WORLD
Tags: Party
When: Friday, Aug 7, 22:00 - 00:59 PDT
Where: LVCCW Level 1 North Lobby - Map

Description:

Following the legendary chaos of SecKC the World and SecKC the World Again, the Kansas City crew returns to DEF CON to settle the digital frontier. This year, we aren’t just hosting a party, this isn’t just another loud room with a DJ; it’s gonna be a killer getogether for the hacker family. We’re merging the independent spirit of the DEF CON with the radical community of the Midwest.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 14:00-14:45 PDT


Title: SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked.
Tags: DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

Shift-left tools scan what you commit, not what you serve. DAST scanners test for vulnerabilities but ignore live traffic. The industry left a gap: runtime secrets. Finding them requires intercepting live traffic: a proxy, a browser extension, or a bulk scanner. SecretSifter is all three.

We tested 2,000 production apps against ten secret scanners. 194 confirmed credentials survived all ten scanners.

SecretSifter monitors live HTTP traffic and finds credentials in JS bundles, lazy-loaded chunks, HTML responses, JSON and XML APIs, and request headers. No config, no source code. 160+ rules cover vendor tokens (AWS, Azure, Stripe, Twilio, GitHub), entropy-gated patterns, and CryptoJS-encrypted configs where the decryption key is hardcoded in the same bundle. No other scanner catches that case. Bulk mode scans 30-50 targets: paste URLs, scan, optional AI triage, export HTML, CSV, or ZIP.

The session opens with a live tool comparison. Most tools scan one URL at a time and require manual browsing. SecretSifter bulk-scans both targets in parallel. Two findings none of the ten caught: Azure AD credentials baked into a webpack bundle past GitLeaks. A CryptoJS config with the decryption key three lines away.

Your entire pipeline reported green. Were they right? Attendees leave with a free tool to run the same day.

SpeakerBio:  Hemanth Gorijala

Hemanth Gorijala is Global Pentest Lead at a Fortune 100 financial services company. He built SecretSifter to close the runtime security gap: the space between where shift-left secret scanning stops and where secrets actually appear in production. His research identified 194 confirmed credentials across 2,000 production applications that bypassed ten secret scanners. He is presenting that research at security conferences across the US. The GT-194 benchmark is published on Zenodo (DOI 10.5281/zenodo.19464446). SecretSifter is open source at github.com/secretsifter.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 16:00-16:30 PDT


Title: Security and Privacy for the Rest of Elections
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:
SpeakerBio:  Michael Specter

Michael A. Specter is an Assistant Professor in Computer Science at Georgia Tech where he leads the SPDR Lab. Specter’s interests are broadly on problems in systems security and applied cryptography, specifically on issues relevant to public policy.  He joined Google after completing his PhD in Electrical Engineering and Computer Science at MIT, and previously served as research staff at MIT’s Lincoln Laboratory. His research has been featured in congressional testimony, amicus briefs to the Supreme Court, and (repeatedly) in the popular press. He holds the 2023 Research Award from the Elections Verification Network and a Pioneer Award from the Electronic Frontier Foundation (EFF). 


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 12:10-12:50 PDT


Title: Security at Machine Speed: How Autonomous AI Agents Are Changing Cloud Defense
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 12:10 - 12:50 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Attackers are using frontier AI to compress the time between finding a vulnerability and exploiting it. Manual triage and human-in-the-loop remediation cannot keep pace. The answer is autonomous security that works at machine speed.

This talk covers the continuous AI-powered security loop and how autonomous agents are changing three SOC functions:

Autonomous triage. Agentic AI systems trained on real security decisions separate real threats from noise with high accuracy, reasoning across logs, configurations, reachability, and history. What takes analysts hours, these systems handle in seconds.

Validated remediation. The latest AWS security enhancements discover vulnerabilities, validate exploitability in sandboxes, and fix confirmed exposures with increasing autonomy. We walk through the journey from human-approved fixes to fully autonomous remediation.

Continuous offensive testing. AI agents that proactively test your applications throughout the dev lifecycle instead of once a year. Customized pen testing across your whole environment. We show what this looks like when an AI chains attack paths across services in real time.

The full loop. Discovery feeds triage, triage feeds remediation, remediation closes the gap before attackers exploit it. Integrated through AWS Security Hub with the tools you already use.

Real demos. Real attack paths. Walk away knowing where this technology stands and what first steps look like.

Speakers:Pujita Sahni,Geoff Sweet

SpeakerBio:  Pujita Sahni

Pujita Sahni is a Delivery Consultant specializing in cloud security, risk, and compliance at AWS. In her role, she is responsible for architecting IAM governance frameworks and security automation solutions that enable organizations to implement secure cloud migrations and shift security left within enterprise environments. She brings a broad technical background across identity and access management, vulnerability management, infrastructure-as-code security, and DevSecOps practices, providing a comprehensive view of how security platforms are built, automated, and maintained across enterprise cloud environments.

SpeakerBio:  Geoff Sweet

Geoff Sweet has nearly 30 years of technology experience, starting from the late 90's during the dot-com boom. Geoff has worked in many verticals including Gaming, BioTech, Retail, and financial SaaS. He has held several titles through his career such as Systems Architect, Network Architect, and most recently Security Architect. These experiences have helped him to develop robust experiences in Infrastructure Security. Geoff left the customer side to come to AWS in December of 2019. He left SAP where he lead a small security team responsible for monitoring and doing Incident Response for nearly 10,000 cloud accounts over several cloud providers. Geoff has a proven record of speaking to customers in both small and large format settings. He is engaging, entertaining, and communicates in a way that assures everyone understands. Geoff's background is in Electrical Engineering and Mathematics and continues to use that knowledge to support his customers. He also has a deep fondness for all things automotive and extensive experience building and fabricating vintage cars.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 14:30-14:55 PDT


Title: Security Vulnerabilities in SATCOM Devices
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 14:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

This presentation delivers a deep-dive security analysis of satellite communication (SATCOM) systems, bridging the gap between theoretical vulnerabilities and hands-on, non-intrusive experimental observation. By examining representative broadband terminals and Low Earth Orbit (LEO) satellite phone systems, we dissect how architectural and implementation choices create distinct security risks across firmware, management interfaces, and radio-frequency (RF) communication layers.Using commodity Software-Defined Radio (SDR) hardware and open-source tools, we successfully executed passive RF observation experiments to characterize Iridium L-band downlink activity. The highlight of this session is the demonstration of an end-to-end pipeline that captured and reconstructed satellite voice transmissions, including emergency traffic, directly from the air.

SpeakerBio:  Aumkaareshwar DS

I am a Computer Science graduate student at California State Polytechnic University, Pomona, passionate about cybersecurity, network security, and ethical hacking. Currently, I work as a Research Assistant at PolySec Lab, where I focus on 5G network security, including authentication, subscriber identity protection, and threat mitigation. My research helps enhance mobile security and protect data from cyber threats.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Friday - 14:45-15:15 PDT


Title: SEND: Teaching Machines to Lie to Defenders
Tags: Adversary Village | Creator Talk/Panel
When: Friday, Aug 7, 14:45 - 15:15 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Cyber deception research has spent decades placing honeypots, honeyfiles, and fake credentials in enterprise environments to catch attackers. Yet practitioners in real Security Operations Centers do not investigate individual artifacts in isolation — they construct causal narratives to explain sequences of events, routing attention toward high-severity signals, end-of-attack-chain activities, and operations in sensitive infrastructure. As Sundaramurthy et al. documented through ethnographic study of live SOC environments, analyst behavior under alert overload is governed by triage heuristics and pattern-matching rather than systematic evidence review — creating a systematic cognitive attack surface that no existing offensive framework has been designed to exploit.

In this work, we introduce SEND (Self-Evolving Narrative Deception), an adversary simulation framework that reframes offensive deception as an investigation narrative poisoning problem: the objective is not to evade detection, but to corrupt the causal story defenders reconstruct during incident response. Drawing on direct consultation with active SOC analysts and incident responders, we identify three empirically grounded cognitive attack vectors that structure the SEND action space — (a.) severity escalation exploitation, targeting the operational requirement to fully investigate HIGH/CRITICAL alerts regardless of underlying harm, (b.) end-of-chain activity simulation, targeting mandatory runbook escalation triggered by ransomware staging or exfiltration patterns regardless of actual file content, and (c.) sensitive location poisoning, targeting the elevated investigative attention guaranteed by activity near domain controllers, privileged shares, and executive endpoints.

We present a design analysis showing that each attack vector can be instantiated at negligible red team cost — failed LSASS reads, dummy outbound transfers of random bytes, and mass-created ransomware-extension files are designed to generate the same mandatory investigation burden as their genuine counterparts, without requiring those actions to succeed. A key design distinction structures the SEND action space: activity simulation generates authentic system telemetry that defenders cannot distinguish from genuine attacker behavior at the telemetry level, while artifact implantation provides cross-system narrative coherence. A Narrative Consistency Engine coordinates both modalities using an LLM to ensure every fabricated email thread, file access log, and collaboration platform entry supports a single coherent false story — shifting the defender's task from "did something anomalous happen?" to "which of several plausible explanations is true?" Moreover, to enable rigorous evaluation of narrative deception beyond detection evasion metrics, we introduce the Investigation Narrative Divergence Reward (INDR) — a four-dimensional cognitive metric quantifying divergence across event reconstruction, causal graph structure, inferred attacker intent, and attribution outcome. INDR is designed to capture a class of deception success that existing red team metrics cannot measure: a defender may correctly identify every process in a malicious process tree yet still produce an incident report attributing the wrong objective, wrong actor, and wrong scope. We further formalize Investigation Graph Poisoning as a measurable attack surface, and outline experimental protocols for evaluating SEND across SOC environments of varying maturity, tooling, and analyst expertise.

In conclusion, SEND establishes the incident investigation itself as a first-class attack surface in adversary simulation, derives deception strategy from empirically grounded blue team cognitive prioritization rather than intuition, and proposes INDR as a new evaluation metric for simulation fidelity — one that asks not whether a simulation triggered alerts, but whether it distorted the reasoning of the defenders who responded to them. Our framework operationalizes at a systematic level what nation-state actors have long practiced intuitively, and makes that threat model legible enough for both red teams and defenders to reason about and build against.

Speakers:Yi Ting Shen,Ariz Soriano

SpeakerBio:  Yi Ting Shen, AIFT - Associate GenAI Security Researcher

I am currently working as a Associate Associate GenAI Security Researcher at AIFT. Over the past year, I have presented various cybersecurity-related research topics at more than 20 domestic and international conferences (DEFCON, ROOTCON, BSides..). I enjoy conducting research, especially focusing on AI/ML applications this year. By engaging with different technical domains, I aim to solve cybersecurity problems, uncover vulnerabilities across various platforms, and identify new CVE vulnerabilities. I have found vulnerabilities in multiple platforms, including Google, Cloudflare, open-source projects, and educational institutions. Learning and research have become the central focus of my life.

Blog: https://no-flag.com/

SpeakerBio:  Ariz Soriano, Associate Director - Red Team Operations @ THEOS Cyber Solutions

Ariz Soriano is Associate Director of Red Team at Theos, with nearly a decade of experience spanning Red Teaming, Penetration Testing, and Incident Response. He started his career on the defensive side, working as a SOC analyst and eventually leading SOC and IR teams for his first four years in the industry. That defensive foundation gives him a perspective most purely offensive operators don't have.

He built the Theos Red Team from the ground up, recruiting and training operators, designing red team infrastructure and tooling, and establishing the methodology and playbooks behind the team's APT simulation and purple teaming engagements. Today he runs a practice that delivers multiple concurrent engagements a year, balancing operations with presales, scoping, revenue targets, and people management.

Outside of client work, Ariz is passionate about building red team tooling, optimizing offensive workflows, and sharing knowledge with the community as a conference speaker. He also contributes to TryHackMe as a part-time Senior Content Engineer, creating hands-on cybersecurity labs and challenges based on real-world attack techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 10:00-10:45 PDT


Title: Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop
Tags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Senrigan (千里眼) and Suzaku (朱雀) are two complementary open-source tools that together form a complete threat hunting and DFIR platform for AWS CloudTrail logs. Both are built by Yamato Security, the volunteer-run Japanese security community behind Hayabusa(隼), the widely adopted Windows event log fast-forensics tool. Yamato Security provides free, open-source DFIR tools and resources to the community.

Building on Hayabusa's philosophy of fast, offline, community rule-based detection, this toolset brings the same approach to the cloud. Security teams can hunt threats across CloudTrail logs on a single laptop — without a SIEM, dedicated infrastructure, or licensing cost.

The two tools work together, with Suzaku's detections flowing into Senrigan for analysis. Senrigan, deployed via Docker Compose, ingests CloudTrail logs into DuckDB via a Rust-based ingester, then lets analysts investigate them through 100+ pre-built hunting queries and 80+ pre-built Apache Superset dashboard charts — no SQL or CloudTrail schema knowledge required. Suzaku is a high-performance, standalone Rust-based CLI that applies native Sigma detection rules to CloudTrail logs and generates a fast-forensics DFIR timeline — surfacing attacks buried in the noise, producing only the events analysts need to investigate.

Speakers:Fukusuke Takahashi,Zach Mathis,Akira Nishikawa

SpeakerBio:  Fukusuke Takahashi

Fukusuke Takahashi has been with NTTDATA-CERT (NTT DATA Group Corporation's CSIRT) since 2018, specializing in DFIR, OSINT, and SOAR. He is one of the developers of Yamato Security's OSS tools. He enjoys developing open-source Blue Team tools. He has presented at conferences such as FIRST Annual Conferences, SECCON, BSides Tokyo, HITCON CMT, SecTor and AUSCERT.

SpeakerBio:  Zach Mathis

Zach Mathis has been working in Japan doing offensive and defensive security work for Japanese companies since 2006. In 2012, he founded Yamato Security, one of the largest hands-on hacker communities in Japan. With other Yamato Security members, he has been releasing free and open source DFIR tools and resources since 2020.

SpeakerBio:  Akira Nishikawa

Akira Nishikawa started his career as a software engineer specializing in embedded development. He worked as a freelance engineer in 2007, focusing on system development and operation for various companies. Since 2021, he has been dedicated to fostering a security culture for SaaS product security and improving service security. Additionally, he is an AWS Community Builder as of 2024.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 13:00-13:59 PDT


Title: Shapeshifting C2: Applying DAITA Traffic Shaping to Defeat DPI and DLP Detection
Tags: Red Team Village | Misc
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

ML-based DPI and DLP solutions have made signature evasion insufficient. Modern enterprise detection analyzes packet size distributions, inter-packet timing, and burst patterns to fingerprint C2 traffic regardless of how well headers and TLS certificates are spoofed.

This talk demonstrates how three techniques from the VPN privacy research space - originally developed to defeat traffic analysis against Tor and Mullvad, can be adapted for offensive C2 operations:

  1. Constant-size packet morphing: forcing all frames to a fixed MTU-aligned size removes the packet-size fingerprint that ML classifiers depend on;

  2. Cover traffic injection: dummy packets sent at Poisson-distributed or adaptive intervals make real beacon timing statistically invisible;

  3. Probabilistic pattern distortion: Maybenot-inspired state machines inject cover bursts alongside real packets, destroying recognizable C2 sequences;

We then will see how layering these techniques with application-layer malleable profiles (traffic impersonating Microsoft Graph, Slack, or Okta) and bonus: indirect transports like cloud storage dead-drops (S3, OneDrive) creates C2 channels that defeat detection at every layer simultaneously - behavioral, flow, and application.

Attendees leave with a concrete mental model for building evasion stacks that go beyond header manipulation.

SpeakerBio:  Rafael Felix, Offensive Security Lead at Hakai Offensive Security

Rafael has been working with malware development for 5 years, also being involved in the malware community for more than 7 years. He is also experienced in Incident and Response, specifically during malware inner workings analysis. Currently, Rafael is a researcher for Hakai Offensive Security (https://hakaisecurity.io/research-blog), being deeply involved with red-team operations.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:00-12:30 PDT


Title: Shopping Is The Attack: A Decade Of E-Commerce Scalper Wars, And The Multi-Agent AI Era
Tags: DEF CON Official Talk
When: Friday, Aug 7, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Forty-five seconds. Two thousand five hundred Nike Air Jordans, gone. Resold at five times retail the next month. Every weekly drop, for years, at one of Europe's largest retailers.

Shopping is the attack. The bot does not exploit a CVE. It does not break the contract. It just shops, and every standard control is structurally blind to it.

I spent five years as Head of SecOps at ASOS, on the bridge for every Air Jordan drop, reverse-engineering the full attacker MO because nobody else was going to.

This talk is that MO from the attacker's chair. Eight phases against the e-commerce golden thread. Account army staged weeks ahead via fake registration and credential stuffing. Targets picked from StockX margins, not catalogues. Early bird APIs leaking pre-release products before the SKU exists. Mobile catalogue enumeration. Vision-API classification. A watcher polling stock until launch. Two bag agents racing, one guest for raw speed, one aged returning customer for trust. Checkout picked for approval probability. Then I show what Anthropic's GTG-1002 disclosure means for retail: the same MO, decomposed into AI agents, at speeds Anthropic called physically impossible.

The eCommerce bots are unstoppable. Come see why.

SpeakerBio:  Yaniv "PSYMAG" Menasherov

Yaniv Menasherov has worked every seat in the SOC. He started as a Tier 1 analyst and worked his way up through shift lead, incident response manager, and Head of SOC, the analyst getting paged at 3 AM, the lead running the war room, and the one writing the post-mortem nobody wanted to read.

He's fought them all from both sides of the table: as a client defending enterprises against ransomware crews, insiders, and the occasional state-aligned visitor with too much patience; and as a vendor, sitting next to customers when their existing stack wasn't cutting it. Eventually he founded his own MSSP, building a unified global SOC for some of the largest enterprises in the world , 24/7 across continents, where "alert fatigue" is a polite way of saying "we're losing."

Today he leads research at Legion Security, an agentic SOC platform rethinking investigation and response for a world where analysts shouldn't be the bottleneck. After years of watching SIEMs and SOARs over-promise, he's building what he wished he'd had on shift.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:45-11:30 PDT


Title: Sick Signals: Adversarial Prompt Injection via Medical IoT Telemetry
Tags: IoT Village | Creator Talk/Panel
When: Friday, Aug 7, 10:45 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Medical IoT devices such as continuous glucose monitors, ECG patches, remote patient monitoring hubs that increasingly feed LLM-powered clinical decision systems. Their telemetry streams are implicitly trusted as ground truth. This talk introduces a novel attack class: adversarial prompt injection delivered through crafted medical IoT sensor payloads. By encoding malicious instructions inside what appears to be routine device data, an attacker can manipulate the downstream LLM pipeline, suppressing critical clinical alerts, fabricating findings in physician summaries, or triggering unauthorized actions in AI systems with actuation capabilities. We present the threat model and a taxonomy of seven injection vectors spanning the full stack: analog spoofing, FHIR/HL7 free-text field poisoning, MQTT broker injection, calibration event hijacking, alarm message hijacking, time-series fragmentation, and multi-device coordinated injection. Unlike attacks targeting text interfaces, this class exploits the implicit trust placed in sensor telemetry — payloads hide inside ordinary device data, bypassing numeric validators and arriving in the LLM context as trusted clinical input. We discuss early experimental findings on the feasibility of this attack class, along with detection strategies and open questions for defenders. Attendees will leave with a concrete threat model, an expanded vocabulary for this new attack surface, and a new way to think about trust boundaries in AI-augmented medical systems.

Speakers:Vinitha Mathiyazhagan,Tamil Mathi T.

SpeakerBio:  Vinitha Mathiyazhagan
No BIO available
SpeakerBio:  Tamil Mathi T.
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 15:00-15:30 PDT


Title: SIM Card Strikes Back: Telecom Threats & SOC Detection
Tags: Telecom Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:30 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
What will be covered:
1. Understanding the SIM Attack Surface – Why SIM cards are a critical part of the tele-com security ecosystem.
2. Common Telecom Threats – SIM Swap, SS7 abuse, IMSI Catchers, SMS OTP bypass, and insider threats.
3. SOC Detection Strategies – Identifying suspicious SIM, subscriber, and signaling active-ties using effective monitoring techniques.
4. Threat Correlation – Connecting telecom events with identity and security logs for faster incident detection and response.
5. Strengthening Telecom Security – Best practices to improve SOC visibility and reduce risks associated with SIM-based attacks.
SpeakerBio:  Zibran Sayyed
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Simulated Adversary: Tactics & Tools Training
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W205 (Payment Village) - Map

Description:
Speakers:Jayson E. Street,Iain Jackson,James Sheppard

SpeakerBio:  Jayson E. Street, CovertSwarm
No BIO available
SpeakerBio:  Iain Jackson, CovertSwarm
No BIO available
SpeakerBio:  James Sheppard, CovertSwarm
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Simulated Adversary: Tactics & Tools Training
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W205 (Payment Village) - Map

Description:
Speakers:Jayson E. Street,Iain Jackson,James Sheppard

SpeakerBio:  Jayson E. Street, CovertSwarm
No BIO available
SpeakerBio:  Iain Jackson, CovertSwarm
No BIO available
SpeakerBio:  James Sheppard, CovertSwarm
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 11:00-11:45 PDT


Title: sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | DevOps | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

GitHub Actions workflows are vulnerable by default. Hardening such as commit-hash pinning, least-privilege permissions, and timeouts is optional, never enforced at pipeline level. Exploitable configs ship daily, increasingly written by Coding Agents. sisakulint is a fast heuristic static analyzer for GitHub Actions covering all OWASP Top 10 CI/CD risks, with 52 rules, a taint engine, and 38+ auto-fixes. It outpaces CodeQL on speed and quality, with 100% detection on 18 GHSL advisories and 81.6% on 38 GHSAs covering exploits in PX4-Autopilot, vets-api, weaviate, nrwl/nx.

Impostor Commit at CVSS 9.8 validates pinned SHAs against the claimed repository, not impostors via Git forks, a check unique to sisakulint. Code Injection at CVSS 9.8 tracks untrusted input through ${{ }} and step outputs. AI Action Rules detect Clinejection on claude-code-action, copilot-swe-agent, and openai-actions, covering tool grants, prompt injection, and wildcard triggers, as in Cline 2026/02 where issue title injection stole NPM_RELEASE_TOKEN. Known Vulnerable Actions catches tj-actions/changed-files.

In the Coding Agent era, linters matter more. Delegating 52 rules to an LLM degrades precision; deterministic engines run in ms with no variance. The session covers end-to-end detection, taint propagation, and automated remediation.

Speakers:Atsushi Sada,hikae

SpeakerBio:  Atsushi Sada

Atsushi Sada is a CSIRT member specializing in cloud security on AWS and GitHub, and enterprise security with MDM, EDR, AI governance. He is an ethical hacker and security tool developer. He built sisakulint and MachStealer for practical security research in static/network analysis, Malware.

He co-founded and organizes @sec_wakate, a community for junior security engineers in Japan. He has spoken at Black Hat USA/Asia Arsenal, AVTOKYO, and AWS Security JAWS.

SpeakerBio:  hikae

Security Engineer in Red Team @ freee inc, AI Security Specialist.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: Skillbit Labs
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

SkillBit Labs is a continuous learning platform designed to help assess and develop cybersecurity skills through hands-on, bite-sized labs. Drop in during village hours and work through beginner-friendly challenges at your own pace, brought to you by SkillBit (formerly MetaCTF), led by CEO Roman Bohuk.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 12:00-12:45 PDT


Title: Skimmers, Shimmers, and You
Tags: Payment Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Join me as I present my latest research on fraudulent payment devices such as card skimmers and shimmers, building on insights from close collaboration with major retailers, law enforcement, and the United States Secret Service! I will outline the evolving landscape of payment threats and share findings from my hands-on reverse engineering of over 130 fraudulent devices, including ATM, fuel pump, and both point-of-sale skimmers and shimmers. Learn why reliably detecting skimmers is challenging and the latest tools and techniques used to both spot and conceal these malicious devices. Peek behind the curtain of payment security with me to explore how cards are cloned and contactless payments relayed from across the world. You’ll learn how skimmers disproportionally affect U.S. citizens on government benefits and ways to best protect yourself in the ever-changing landscape of digital payments!

SpeakerBio:  Aidan Quimby, Senior Consultant, Coalfire DivisionHex

Specializes in web app pentesting, payment-skimmer forensics and hardware hacking; previously led hardware testing at IBM X-Force Red and has presented skimmer research to major retailers and at Hardwear.io.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 11:00-11:59 PDT


Title: Sliding into the Flight Deck’s DMs: Practical Message Attacks on CPDLC
Tags: DEF CON Official Talk | Exploit 🪲
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Air traffic control quietly moved from voice radios to text messages—and almost nobody outside aviation noticed.

We did. And it turns out you can slide into a commercial aircraft’s DMs.

In this talk, we show how modern aircraft receive digital instructions (like “climb,” “descend,” or “turn”) over a system called CPDLC—and how that system has basically zero real security. No crypto. No authentication. Just vibes and protocol complexity.

We built a full fake ground station using cheap SDR gear and made certified avionics believe we were air traffic control. From there, we can inject real flight instructions or knock aircraft offline at scale with protocol-level DoS attacks—no jamming required.

This isn’t a simulation. We tested it against real aviation hardware in a live CPDLC environment.

If you’ve ever wondered what happens when safety-critical infrastructure assumes “nobody will try this,” this talk is for you.

Sliding into the Flight Deck's DMs: Practical Message Attacks on CPDLC

Mehdi Ziazi, ETH Zurich; Khalid Aleem, Independent; Harshad Sathaye, ETH Zurich; Martin Strohmeier, Cyber-Defence Campus, armasuisse Science + Technology

Usenix Security 2026

Speakers:Martin "MasorX" Strohmeier,Mehdi Ziazi

SpeakerBio:  Martin "MasorX" Strohmeier, Cyber-Defence Campus, armasuisse Science + Technology

Martin is a Senior Scientist at the Swiss Cyber Defence Campus, primarily based at ETH Zurich, and a Visiting Fellow of Kellogg College, Oxford. His work focuses on designing and analyzing security protocols for cyber-physical systems in critical infrastructures—aviation, satellites, space, and transportation systems. Martin also explore privacy issues in global networks, adversarial machine learning, and open-source intelligence.

Martin received his DPhil in 2016 at Oxford, supervised by Prof. Ivan Martinovic, where he studied the security and privacy of aviation communication technologies. I co-founded the OpenSky Network and coordinate its research activities. His work has received awards from both the aviation and security communities, including the EPSRC Doctoral Prize Fellowship and commendation from the British Computer Society. Martin has published regularly at all major security and AI conferences and also been a speaker at DEF CON several times (main stage + villages).

SpeakerBio:  Mehdi Ziazi, ETH Zurich

Mehdi Ziazi is a hacker and cybersecurity student at ETH Zurich and an incoming PhD student at CISPA focused on aerospace security and cyber-physical systems. Their recent work in aviation security explores novel attack paths against aircraft systems and their real-world impact, approached with curiosity, persistence, and a bit of stubbornness.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 22:00-00:59 PDT


Title: Slopcon
Tags: Event
When: Friday, Aug 7, 22:00 - 00:59 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:

In an era where "innovation" is just a polite word for scraping the bottom of the LLM barrel, we invite you to embrace the inevitable heat death of original thought at Slopcon. Why bother with pesky human intellect when we can automate the entire conference lifecycle, from hallucinated CFP submissions to slide decks that make absolutely no sense? It’s a high-stakes experiment in synthetic absurdity where the only thing more artificial than the intelligence is the confidence of the "meatbag" presenters tasked with delivering this digital dross. Join us for a celebratory descent into the uncanny valley, where we’ll crown the sloppiest generative disasters and toast to the fact that, for now, at least the audience is still real.

So, if you’re actually itching to subject the world to more of this or just have a masochistic need for further details, head over to slopcon.org and fulfill your destiny.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 14:05-14:45 PDT


Title: Smart Contracts, Smarter Malware: Automating Recon on Blockchain-Based C2
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 14:05 - 14:45 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

Threat actors are moving their command-and-control (C2) infrastructure to the blockchain, where smart contracts are immutable, globally accessible, and completely immune to traditional takedowns. Instead of reaching out to attacker-controlled servers, modern malware families query public blockchain RPC endpoints to retrieve C2 instructions written directly into smart contracts across a variety of ecosystems. No attacker server, no domain to seize, no hosting provider to contact.

In this talk, we break down our investigation into malware families actively utilizing multi-chain smart contracts as an evasive C2 channel. We will cover how we analyzed network traffic to identify decentralized communication patterns, queried live contract methods to extract real-time C2 data, and used cross-chain bytecode analysis to map shared infrastructure across multiple samples.

We will demonstrate a unified framework that consolidates these individual recon methodologies, automating the extraction, tracking, and reverse-engineering of multi-chain blockchain-based malware infrastructure.

Speakers:Sai Sathvik Ruppa,Chris Navarrete

SpeakerBio:  Sai Sathvik Ruppa, Staff Security Researcher at Palo Alto Networks

Sai Sathvik Ruppa is a Staff Security Researcher at Palo Alto Networks and a recent M.S. graduate in Information Security from Carnegie Mellon University. He specializes in vulnerability detection and malware analysis, leveraging his expertise to identify, analyze, and mitigate advanced cyber threats.

SpeakerBio:  Chris Navarrete, Senior Principal Security Researcher - CDSS Advanced Threat Prevention (ATP) at Palo Alto Networks

Chris Navarrete is a Senior Principal Security Researcher within the Advanced Threat Prevention team at Palo Alto Networks. His work centers on cutting-edge research in cybersecurity, particularly in threat detection and malware analysis. Previously, he served as an adjunct professor of computer science at San Jose State University, teaching Software Security Technologies. He holds a Master of Science in software engineering with a specialization in cybersecurity from San Jose State University. Chris has presented at major industry conferences, including Black Hat Asia, the Computer Antivirus Research Organization (CARO), the Cyber Threat Alliance's Threat Intelligence Practitioners (TIPS) conference, and Black Hat Arsenal, where he introduced and released BLACKPHENIX — a framework designed to automate malware analysis workflows.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 10:00-17:59 PDT


Title: Smart Home in the Matter: Blink, Race, Attack CTF
Tags: IoT Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Friday - 15:45-16:30 PDT


Title: Snap, Crackle, Popped: How to manage a massive cyber attack
Tags: Biohacking Village | Creator Talk/Panel
When: Friday, Aug 7, 15:45 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

First hand account of the inner workings of a massive breach, what works what does not and where the wheels fall off the bus quick.

SpeakerBio:  David Nathans

David Nathans is a senior cybersecurity executive and former U.S. Air Force cyber officer. He has served as a Global CISO in highly regulated industries and is an entrepreneur, author, and advisor focused on security operations, Zero Trust, and risk governance.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 11:00-12:30 PDT


Title: SOC Threat Hunting in Practice
Tags: Telecom Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 12:30 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:

Theory 1. Integrating modern SOC with Telco and respective component

Theory 2. Key Attack identifier

Demo 1: Ran Site attack identification in Morden SOC Tool

Demo 2: 5g Core threat identification for insider attack

Practical : Hunting for attack pattern, identify attacker traces, impact analysis on overall network infra

SpeakerBio:  Akib Sayyed
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 08:30-17:59 PDT


Title: Social Engineering Community Village - Open Hours
Tags: Social Engineering Community Village | Creator Event/Activity
When: Friday, Aug 7, 08:30 - 17:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action... the phones start ringing soon.

The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses.

At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our "Cold Calls" or listen in to some presentations.

The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON.

Prerequisites:

Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed.

Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate.

Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 19:00-22:59 PDT


Title: Social Engineering Community Village Party
Tags: Party | Social Engineering Community Village
When: Friday, Aug 7, 19:00 - 22:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Mix and mingle with the SEC crew, competitors, speakers, and fellow attendees at our community party.

Join the Social Engineering Community for a night of connecting with fellow hackers, social engineers, researchers, and curious DEF CON attendees who share an interest in the human side of hacking. Whether you spent the weekend watching vishing calls, cheering on AI bots, competing, volunteering, or just discovering the craft for the first time, this meetup is a chance to relax, swap stories, and meet the people behind the voices, research, and chaos from the village. The exact theme will be announced soon, but the goal is simple: bring the community together, make new friends, reconnect with old ones, and celebrate another year of social engineering at DEF CON. Everyone is welcome, whether you're a longtime member of the community or just curious about what social engineering is all about.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 14:00-15:59 PDT


Title: Social Engineering With Reel
Tags: Red Team Village | Misc
When: Friday, Aug 7, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

Reel is a modern social engineering framework, developed for use by the TrustedSec Targeted Ops team. It supports phishing campaigns, proxying captured credentials to other sites, device code phishing, dynamic SMS and voice campaigns (via integration with AWS). This session will show the attendees how deploy and configure reel, as well as how to craft advanced SE campaigns using the reel workflow system and show how custom plugins can be developed.

SpeakerBio:  James Williams

James is a senior consultant on the Targeted Operations team at TrustedSec. He has around 10 years experience in cyber security, including penetration testing and red team roles. In his spare time, James enjoys running over mountains (it’s more fun than you’d think) and picking locks.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Software Defined Radios 101 - Introduction to RF Hacking
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W314 (Ham Radio Meeting) - Map

Description:
SpeakerBio:  Richard Shmel
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Software Defined Radios 101 - Introduction to RF Hacking
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 3 W314 (Ham Radio Meeting) - Map

Description:
SpeakerBio:  Richard Shmel
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W233 (Workshops) - Map

Description:

Attendees hunt a supply chain compromise in real telemetry. Not a walkthrough - a hunt. A trojanized developer tool has been backdoored. The artifacts are seeded across a shared Splunk instance at layered difficulty: some obvious, some buried. Over four hours, attendees progress through the Five Levels of Agentic Hunting using the open-source Agentic Threat Hunting Framework (ATHF). Each maturity level unlocks new capabilities — structure, searchability, AI research agents, and full agentic workflows — that help them find what they couldn't find before. The first hunt is manual. By the last module, AI agents are surfacing hypotheses, identifying coverage gaps, and pointing hunters toward artifacts they missed. The human decides what to chase. The framework remembers what they found. This is not a tool demo. Attendees will make real analytical decisions, write real SPL queries, hit dead ends, and use AI agents to recover. They leave with a working ATHF workspace, documented hunts from a real investigation, and the experience of hunting with an agentic system.

SpeakerBio:  Sydney "letswastetime" Marrone

Sydney Marrone is a threat hunter, SANS course author, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework (ATHF), and co-author of the PEAK Threat Hunting Framework. She is passionate about helping defenders become better threat hunters by turning complex ideas into practical, repeatable techniques. Through open-source research, workshops, and community-driven projects, Sydney builds frameworks and resources that make hunting more structured, collaborative, and effective. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-inspired music with AI.

--

Sydney Marrone is a threat hunter, cybersecurity professional, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework, and co-author of the PEAK Threat Hunting Framework. She is passionate about making security knowledge accessible and actionable through hands-on research, open-source collaboration, and community-driven projects like HEARTH (Hunting Exchange And Research Threat Hub). Sydney creates resources, leads workshops, and shares insights that spark curiosity and empower defenders. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-themed music using AI to blend creativity and hacker culture.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding!
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W231 (Workshops) - Map

Description:

Infostealers suck. We all know that. We don't like them. We want you to learn all that you can about them to help thwart the ongoing, ever-evolving threat. On that note, current infostealers are largely rule-based and path-driven, targeting known browser stores and wallets with noisy exfiltration methods. This four-hour workshop, led by Ryan Chapman and Aaron Rosenmund, moves beyond basic comprehension via observation to explore the evolution of precision-based malware. Students will utilize a live, on-demand lab environment to perform deep malware analysis using Ghidra to understand how current stealers operate.

The session then transitions from analysis to creation, where attendees code, compile, and re-build their own "evolved" stealers. We replace static file targeting with in-memory relevance models and trade obvious HTTPS exfiltration for stealthy timing and protocol-native patterns. This hands-on, kinesthetic experience focuses on building a custom arsenal from the ground up. Participants will learn to enhance their tools with behavioral stealth, transitioning from identifying "stoopie" patterns to implementing advanced, AI-driven tradecraft and custom red team tool operations.

You won't just learn how what an infostealer is. You'll learn how they operated end-to-end. Join us :).

Speakers:Ryan "@rj_chap" Chapman,Aaron "Ironical" Rosenmund

SpeakerBio:  Ryan "@rj_chap" Chapman

Ryan Chapman is the author of SANS‚ FOR528: Ransomware and Cyber Extortion‚ course, teaches SANS‚ FOR610: Reverse Engineering Malware‚ course, and works as a threat hunter @ $dayJob. Ryan has a passion for life-long learning, loves to teach people about ransomware-related attacks, and enjoys pulling apart malware. He has presented workshops at DEF CON and other conferences in the past and knows how to create a step-by-step instruction set to maximize hands-on learning.

SpeakerBio:  Aaron "Ironical" Rosenmund

Aaron Rosenmund is an accomplished cybersecurity professional with extensive experience in various leadership roles across multiple organizations. Currently serving as the Managing Director of Tradecraft and Programs at OnDefend since September 2024, Aaron also holds a position at the National Guard Bureau as Staff Lead for the Cyber Shield Red Team, demonstrating a commitment to enhancing cybersecurity defenses. With a background that includes significant roles at Pluralsight, where responsibilities spanned content strategy and security skills development, and the Florida Air National Guard as a Lead Cyber Operator focused on defensive operations, Aaron has developed a comprehensive skill set in threat emulation, cyber system operations, and training. Additionally, past leadership positions as CEO at Aestus Industries and Vice President at Concrete Surface Innovations underscore strong management capabilities and operational expertise. Aaron holds multiple degrees in technology and cybersecurity from respected institutions, underscoring a solid educational foundation in this field.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W228 (Workshops) - Map

Description:

The shortest path from a marketing-site SSRF to production root often runs through AWS, and most defenders can’t see it happening. This workshop teaches you to walk that path yourself.

Working whitebox in provided lab accounts, you’ll move through eight hands-on modules: reading IAM policies for privilege escalation gadgets, turning a single SSRF into a working CLI session via IMDS, abusing cross-account trust, exploiting resource policies across S3/KMS/Lambda, compromising serverless functions, and evading CloudTrail. The workshop closes with a full-chain challenge: build a Python exploit that goes from external SSRF to administrative access in one script.

Prerequisites: Basic AWS familiarity (console + CLI), comfort reading JSON policies, Python. Bring a laptop with AWS CLI v2 and Python 3.10+ installed. No prior offensive cloud experience required.

Speakers:zeta,Rafa "bane" Gutierrez

SpeakerBio:  zeta

zeta is an internet plumber and computer toucher. he spends his days reading IAM policies and his nights wondering why anyone wrote them that way.

SpeakerBio:  Rafa "bane" Gutierrez

"Rafael (bane) is the founder of Secure Origin, where he helps organizations doing public-interest work improve their security, infrastructure, and operational resilience. His work spans vulnerability research, security architecture, detection engineering, adversary emulation, infrastructure operations, and targeted technical engagements.

He is also a researcher and technical lead for The Southlander, a local Los Angeles newsroom. He volunteers with Lucy Parsons Lab and conducts independent research on surveillance technology, supporting reporting on how these systems affect journalists, activists, and local communities."


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W228 (Workshops) - Map

Description:

Cloud security encounters attacks that elude standard detection. In AWS, unauthorized access keys are a common cause of breaches. The vastness of AWS—over 450 services and 20,000 API actions—complicates threat visibility and exposes gaps in traditional tools.

This workshop empowers participants with direct, hands-on experience using the AWS Threat Hunter tool to improve threat detection. Attendees will focus on building behavioral baselines and leveraging data-driven analysis to detect subtle AWS principal anomalies, enabling more precise detection than traditional event monitoring.

Attendees will move beyond standard techniques by building multi-stage detection pipelines that create individualized baselines for each IAM principal and systematically flag personalized deviations, linking outliers directly to risks.

SpeakerBio:  Rodrigo "Sp0oKeR" Montoro

Rodrigo Montoro is the CTO at Clavis Security, bringing over 25 years of leadership and technical expertise to the information technology and cybersecurity landscape. Throughout his career, Rodrigo has been a pioneer in open-source security, specializing in incident detection, response, and Cloud Security. A two-time patented inventor, he holds proprietary technologies for detecting malicious digital documents and analyzing malicious HTTP traffic. With a resume that includes key research roles at Tenchi Security, Apura, Tempest, Sucuri, and SpiderLabs, Rodrigo is a globally recognized authority who frequently speaks at elite conferences such as DEF CON Workshops (2023), DEF CON Cloud Village (3x), Black Hat Brazil Summit, SANS (DFIR, SIEM Summit, CloudSecNext), Source (Boston and Seattle), Toorcon (San Diego), Sector Canada (6x), and BSidesLV.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - Embedded Computing Tools for Wireless Hardware Hacking
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W233 (Workshops) - Map

Description:

Hands-on exploration of embedded hardware tools implementing multiple wireless communication standards. Experiment with Wi-Fi wireless local area network (WLAN) technology and Bluetooth personal area network (PAN) technology. Stream audio to and from a variety of endpoints. Configure a Nordic nRF52 Bluetooth sniffer to capture and analyze wireless communications using Wireshark. Examine the design and manufacture of an exclusive dual-core embedded hardware target supporting both Wi-Fi and Bluetooth. Leverage the target to experiment with microcontroller-based wireless hardware hacking. Practice both sinking and sourcing Bluetooth Audio streams into and out of the hardware target. Capture Wi-Fi packets using onto the hardware target for transfer to Wireshark for analysis. Perform example security exploits and countermeasures using embedded wireless hardware tools.

PLEASE NOTE: This workshop requires purchasing the necessary hardware tools. A link to complete the purchase of $60 will be provided upon registration for the workshop. The purchased kits will be distributed during the workshop.

SpeakerBio:  Joseph Long

Joseph Long has been tinkering, designing, and hacking electronic systems for about forty years. He is the founder of HackerBoxes.com, the monthly subscription box service for electronics, cybersecurity, and hacker culture. Joseph is a licensed professional engineer and patent attorney who loves to teach electrical engineering and computer science topics.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - Hands-on IoT firmware extraction and flash forensics
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:

Did you ever wanted to hack an IoT device but did not know how to start? Having UART is nice, but does not help in many cases.

For a complete analysis of an IoT device, it is required to look at the firmware itself. In most cases this means that the firmware, data or encryption keys need to be extracted from the device memory. Many researchers are hesitant to do that as there is a high risk of destroying the device or leaving it in an inoperable state. In this workshop we will look at different flash memory types (EEPROM, SPI flash, NAND flash, eMMC flash) and how to extract the information from them.

We will show that you do not need very expensive hardware to archive your goal and that it is not as complicated as everyone believes. See which tools might be useful for your own lab!

Participants will have the opportunity to work in groups and being provided different kinds of IoT devices (e.g. smart speakers). After a tear-down, you can use different chip-off methods (e.g. Hot air, IR soldering) to remove the flash chip and read it out. Optionally, the tools re-ball and re-solder the IC will be available after the workshop. In the end, each team should have the data and a functional device again.

Bonus: If you brick the device, you can keep the parts as a souvenir or can wear them as badges.

Speakers:Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu

SpeakerBio:  Dennis Giese

Dennis Giese is a researcher with the focus on the security and privacy of IoT devices. While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices. His most known projects are the documentation and hacking of various vacuum robots. He calls himself a "robot collector" and his current vacuum robot army consists of over 95 different models from various vendors. He talked about his research at the Chaos Communication Congress, REcon, HITCON, NULLCON, and DEFCON.

SpeakerBio:  Braelynn Luedtke

Hacker and tomato farmer. Enjoys researching the security of anything that piques her curiosity. She has previously presented this research at conferences such as Chaos Communication Congress, HITCON and DEFCON.

SpeakerBio:  Arnold Wey

Arnold Wey is an electronics security researcher. His recent work includes security testing of virtual GPU implementations, robot arm communication protocols, and repurposing a 3D printer for fault injection research.

SpeakerBio:  Harsha Potu

Harsha has been taking things apart since he could get his hands on a screwdriver for fun and profit. Nowadays he is a cybersecurity researcher with a decade of experience in embedded security. He loves to reverse boards + firmware and regularly finds vulnerabilities at various layers of execution. Especially interested in breaking secure boot chain designs!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - Introduction to Malware Analysis
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W232 (Workshops) - Map

Description:

Analyze malware to find indicators of compromise using static and dynamic techniques. We will analyze Windows executables at the binary level and modify them to cheat at games. We will examine both compiled code and DOTNET executables. We will also examine defenses to prevent memory-corruption attacks, including coding in Rust.

We will demonstrate the techniques and help attendees solve challenges. There are dozens of hands-on projects, with a running CTF scoreboard. Some of the projects are easy enough for beginners, and others will challenge experienced experts. Every participant should leave with some new skills.

All materials are freely available on the Web at samsclass.info and will remain available after the workshop is over.

Speakers:Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus

SpeakerBio:  Sam Bowne

Sam Bowne has been teaching computer networking and security classes at City College San Francisco since 2000. He has given talks and hands-on trainings at DEF CON, DEF CON China, Black Hat USA, HOPE, BSidesSF, BSidesLV, RSA, and many other conferences and colleges. He founded Infosec Decoded, Inc., and does corporate training and consulting for several Fortune 100 companies, on topics including Incident Response and Secure Coding.

Formal education: B.S. and Ph.D. in Physics Industry credentials:

Infosec: CISSP, Certified Ethical Hacker, Security+, Defcon Black Badge, Splunk Core Certified User Networking: Network+, Certified Fiber Optic Technician, HE IPv6 Sage, CCENT, IPv6 Forum Silver & Gold, Juniper JN0-101, Wireshark WCNA Microsoft: MCP, MCDST, MCTS: Vista

SpeakerBio:  Elizabeth Biddlecome

Elizabeth Biddlecome is a consultant and instructor, delivering technical training and mentorship to students and professionals. She leverages her enthusiasm for architecture, security, and code to design and implement comprehensive information security solutions for business needs. Elizabeth enjoys wielding everything from soldering irons to cripting languages in cybersecurity competitions, hackathons, and CTFs.

SpeakerBio:  Kaitlyn Handelman

Kaitlyn Handelman is an offensive security engineer at Amazon. Her focus is cybersecurity in space. In addition to traditional penetration testing, Kaitlyn works on physical devices and RF signals. In her free time, she enjoys ham radio, astronomy, and her cat, Astrocat.

SpeakerBio:  Irvin Lemus, Founder at r00tkit.io

Irvin Lemus teaches people to break things so they can defend them. CISSP-certified cybersecurity professional with over a decade building competitions, teaching offensive and defensive security, and advising organizations across the Americas. Currently Director of Education & Training for Latin America at By Light and founder of r00tkit.io.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:

A compromised mailbox. An inbox rule named ".". An OAuth consent to an unknown application. A sign-in from a cloud-hosting ASN with user-agent "axios" and MFA status "satisfied by claim in token". Somewhere in there is the story - and somewhere in the Microsoft 365 logs is the evidence. This four-hour hands-on workshop teaches Business Email Compromise investigation in the tenants most responders actually see: M365 Business Premium or E3. No Sentinel. No SIEM. No problem. Using only native admin centers, PowerShell modules, and a few scripts, you will run a complete BEC investigation end to end. Working through several progressive scenarios, from single-user compromise, through lateral-pivot case with MailItemsAccessed analysis, to multi-account incident with a malicious enterprise app and transport rule. You will learn how to contain, collect, triage, pivot, expand scope, remediate, and produce the three common reporting deliverables: investigation report, attestation letter, internal post-mortem. This is Living off the Land Incident Response. Through chronology and topology, come correlate some logs with me and see what story they tell.

SpeakerBio:  Vince "bitpusher" Weppner

Vincent M. Weppner (Bitpusher) is an Information Security Specialist with 10+ years of dedicated cybersecurity focus and 25 years in IT overall. He works as a Security Analyst at a mid-market MSP and runs an independent IT consulting practice at theTechRelay.com. Generally found lurking in the mountains of Southern California, and occasionally maintaining his open-source tooling at github.com/bitpusher2k. His day-to-day work covers M365 security operations, Active Directory and endpoint security, BEC/ransomware incident response, EDR/SIEM management, and security consulting for SMB and mid-market clients. Specialization in Business Email Compromise was built out of direct operational need: after dozens of BEC incidents, the pattern of "which script do I need to run right now?" became clear enough to codify. Passionately solving puzzles through scripting, and hoping to pass on some of it to you.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W232 (Workshops) - Map

Description:

BLE CTF is a series of Bluetooth Low Energy challenges in a capture-the-flag format, created to teach the fundamentals of interacting with and hacking BLE services. Each flag interactively introduces a new concept.

Over the years, BLE CTF has expanded across platforms and skill levels. Books, workshops, trainings, and conferences have adopted it as both an educational platform and CTF. As an open source, low-cost, extensible solution, it has helped advance Bluetooth security research.

This workshop teaches the fundamentals of hacking BLE through hands-on exercises that introduce beginners to new concepts while giving experienced users a chance to try new tools and techniques. After completing it, you will have a solid understanding of how to hack BLE devices in the wild.

New for DEF CON 34: the workshop uses a brand new variant of BLE CTF built specifically for this event. Returning students will face fresh challenges they have not seen before, and the new exercises are designed to resist online walkthroughs and LLM-assisted shortcuts. We will also introduce new client tools, including gratttool, a modern replacement for gatttool (which has been deprecated from most Linux distributions). Whether this is your first BLE CTF or your eighth, you will leave with new skills and tools.

Speakers:Ryan "Hackgnar" Holeman,Alek Amrani

SpeakerBio:  Ryan "Hackgnar" Holeman

Ryan Holeman resides in Austin, Texas, where he works as the CISO for Stability AI. He holds a Ph.D. in cyber defense from Dakota State University and has spoken at respected venues such as Black Hat, DEF CON, Lockdown, BSides, Ruxcon, Notacon, and Shmoocon. You can keep up with his current activity, open source contributions, and general news on his blog. His spare time is mostly spent digging into various network protocols, random hacking, creating art, surfing, and shredding local skateparks.

SpeakerBio:  Alek Amrani

Alek Amrani runs the security team at Cape.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W231 (Workshops) - Map

Description:

Behind every breach report from the last decade is a Command and Control (C2) framework. C2 is how operators reach into a compromised network, move sideways, harvest credentials, and stay invisible. This 4-hour, hands-on workshop puts you in the operator's chair. You set up your own Empire team server, learn the listener-stager-agent model from scratch, and run seven exercises that take you from "never touched a C2" to dumping credentials off a box you compromised yourself.

You'll spin up an HTTP listener, deploy a .NET agent to a Windows target, and run post-exploitation tradecraft: Rubeus for credentials, SharpHound for AD enumeration, port-forward pivots to internal hosts, and privesc modules that turn a foothold into full control. You'll even build a custom Empire plugin that auto-runs on every new agent. The capstone is a mini-CTF on a cloud-hosted range we keep open all weekend, with a prize for the winners.

You leave with the mental model most operators take years to build: how modern C2 actually works, what it assumes about the target, and where defenders most often catch it. No VMs to download. No setup before class. Bring a laptop, get on WiFi, and we'll have agents running before the first break.

Speakers:Jake "Hubbl3" Krasnov,Vincent "Vinnybod" Rose,Anthony "Coin" Rose,Dan Niefeld

SpeakerBio:  Jake "Hubbl3" Krasnov

Jake "Hubble" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON.

SpeakerBio:  Vincent "Vinnybod" Rose

Vincent "Vinnybod" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/.

SpeakerBio:  Anthony "Coin" Rose

Dr. Anthony "Coin" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

SpeakerBio:  Dan Niefeld

Dan Niefeld is the founder of several Cyber Security and Technology organizations. An accomplished social engineer his career has spanned from program management to organizing conferences like Hack Space Con, Dan has spent his career, educating, mentoring and developing disrupting technologies with a focus of Mission and Community Development.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W230 (Workshops) - Map

Description:

This workshop will give an initiation to offensive malware development in C/C++ and how it is possible to adapt the approach depending on the security solution that must be tackled down. Different methods such as ModuleStomping, DLL Injection, Threadless Injection and Hardware Breakpoint for dehooking will be seen. The idea is to start with a basic malware performing process injection and apply additional techniques to start evading EDR. At each step, some analysis on the malware will be performed to understand the differences at the system level and the IOC detected by the EDR. At the end of this workshop, you will have all the knowledge needed to develop your own malware and adapt it to the targeted environment to escape from the basic pattern and spawn your beacons as if EDR didn't exist.

SpeakerBio:  Yoann "OtterHacker" DEQUEKER

Yoann Dequeker (@OtterHacker) is a red team operator at Wavestone entitle with OSCP and CRTO certification. Aside from his RedTeam engagements and his contributions to public projects such as Impacket, he spends time working on Malware Developpement to ease beacon deployment and EDR bypass during engagements and is currently developing a fully custom C2.

His research leads him to present his results on several conferences such as LeHack (Paris), Insomni'hack (Swiss) or even through a 4-hour malware workshop at Defcon31,32 and 33 (Las Vegas). All along the year, he publishes several white papers on the techniques he discovered or upgraded and the vulnerabilities he found on public products.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - Offensive Packet Wizardry with Scapy
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:

Offensive Packet Wizardry with Scapy is a four-hour, 100% hands-on workshop that teaches attendees to build offensive networking tools from scratch in Python using Scapy, the packet crafting library used by red teams, malware analysts, and vulnerability researchers worldwide.

Starting from first principles, raw packet construction, layer stacking, and send/receive mechanics, the workshop moves progressively through active reconnaissance, ARP cache poisoning with live credential interception, TCP/IP stack abuse (session injection, SYN flood, RST killing), protocol fuzzing against an intentionally vulnerable binary service, and full covert channel implementation (ICMP C2 shell, DNS file exfiltration, TCP header steganography).

Every technique is implemented live in Python against an isolated lab network. Students leave with a working, importable red team toolkit, a Python package with a unified CLI, that they built themselves and can adapt for future engagements.

The workshop concludes with "Silent Pivot", a scored capstone scenario that chains all techniques into a realistic kill chain: stealth discovery, service identification, fuzzer- triggered crash, ICMP command execution, DNS exfiltration of /etc/shadow, and network cleanup, all subject to an IDS alert budget.

SpeakerBio:  Mike "Chicolinux" Guirao

Mike “Chicolinux” Guirao began his journey in the security field roughly 25 years ago while completing a master's degree. Since then, they have developed both broad and deep expertise across this incredible discipline. Currently, they are pursuing a PhD at New Mexico State University, where their research intersects Cybersecurity and Machine Learning/Artificial Intelligence.

In addition to their academic pursuits, Mike serves on the organizing team for the Crypto & Privacy Village. This marks their third time teaching a workshop at DEF CON since DEF CON 24. They also hold several notable industry certifications, including the SANS GCIH, ISC2 CC, and Linux+, and they are excited to share their wealth of experience and knowledge.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - OT Systems: how to secure them in practice!
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:

Securing OT systems is often presented as challenging, with multiple business constraints - but is it that complicated, especially considering a single industrial site? In this 4-hour, hands-on workshop, each participant will manipulate a simple but realistic Industrial Control System setup with SCADA systems & PLCs. Attendees will have the opportunity to secure it step by step, through several hands-on exercises & discover how to manually secure OT systems: OT inventory, backups, network security, system hardening and detection. What if the real challenge is OT security at scale? Besides implementing manual security on our setup, we will address each step of the way OT security at scale and share feedback on how large companies are securing their OT systems, both at organizational & technical level: community of OT cyber correspondents, OT DMZ and security tools deployment. No prior OT experience is required.

Speakers:Alexandrine Torrents,Arnaud SOULLIE

SpeakerBio:  Alexandrine Torrents

Alexandrine Torrents is a cybersecurity expert at Wavestone. She started as a penetration tester, and then specialized in OT cybersecurity. She is IEC 62443 certified. She performed dozens of OT cybersecurity assessments across various industries & worked on OT models to perform attacks on PLCs & SCADA systems. Alexandrine also helps secure OT both at technical & organization levels: secure architecture, system hardening, IAM, cyber resilience, detection, governance, awareness & training, risk assessment, cyber by design, etc. Alexandrine works with different CISOs on their OT cybersecurity roadmaps & programs at different scales of large industrial companies: site, business units, Group with worldwide scope. Alexandrine also gives training on OT cybersecurity.

SpeakerBio:  Arnaud SOULLIE

Arnaud Soullie is a Senior Manager at Wavestone. He has over 15 years of experience in security assessments and penetration testing, with 10 years specializing in Industrial Control Systems cybersecurity. He has delivered talks and workshops at DEF CON, Black Hat Europe, BruCON, CS3STHLM, BSides Las Vegas, and others. He is the creator of the DYODE open-source data diode project and has been teaching ICS cybersecurity since 2015.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W229 (Workshops) - Map

Description:

Anthropic, April 2026: Claude Mythos Preview is "strikingly capable" at zero-day discovery. They chose not to release it.

AISLE, one week later: "The moat in AI cybersecurity is the system, not the model." They reproduced Mythos-class findings on FreeBSD with a 1,700-line scan.py and a commodity model for under $100.

This four-hour hands-on workshop is the local-hardware version of that argument. Two reproductions, two domains, one harness pattern.

Part I: point AISLE's open-source pipeline at a pre-patch FreeBSD checkout through a hosted local-AI inference endpoint and reproduce the 17-year-old CVE-2026-4747 that drove Mythos, for sub-dollar spend.

Part II: change domains. Drive Ghidra through MCP tool calls against unpatchable D-Link DNS-320L firmware. Validate CVE-2024-3273 with the advisory in hand, then rediscover it from a blank start once the harness moves enumeration into the driver.

What happens next is what you come to find out. Same hardware, same model, same harness, four hours later: can local AI extend the famous disclosure with bugs the original missed? Come see for yourself.

No GPU. No API. No cloud spend. The workshop hosts inference for the room.

SpeakerBio:  John "clearbluejar" McIntosh

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the "Agentic RE" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the "Supercharging Ghidra" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 14:00-17:59 PDT


Title: Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W230 (Workshops) - Map

Description:

Every electronic device around you is silently broadcasting electromagnetic signals. In this hands-on workshop, you will build an SMD (surface-mount) version of the EMF Explorer from bare PCB to working device, learning progressive SMD soldering techniques from 1206 down to 0603 component sizes along the way. Geared for absolute beginners who are new to soldering and electronics. This session pairs each build stage with a circuit theory deep dive: you will understand the voltage divider powering your board, the op-amp gain stages amplifying EMF signals into audible sound, and how inductor geometry shapes what you can hear. Walk away with a functional EMF listening device, new SMD skills transferable to real-world hardware hacking, and a deeper understanding of the electromagnetic emissions all around you.

SpeakerBio:  Darcy "@Drc3p0" Neal

Darcy Neal (Drc3p0) is an electronics educator and founder of SporkLogic, where they design open-source hardware kits and facilitate soldering workshops at maker and hacker events worldwide. With over 15 years in interactive audio-visual hardware design, Darcy's work spans RF experimentation, new media installations, boutique synthesizer production, and hands-on electronics education. Their flagship product, the EMF Explorer, is an accessible tool for sonifying electromagnetic fields. They collaborate regularly with Mitch Altman and the Hardware Hacking Assembly, and have taught large-scale soldering workshops across the global hacker community.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Friday - 09:00-12:59 PDT


Title: Sold Out - Web Hacking 101
Tags: DEF CON Workshop | DEF CON Workshops
When: Friday, Aug 7, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W229 (Workshops) - Map

Description:

Most security training starts with slides. This workshop starts with a target. Students spend the majority of the course attacking a purpose-built web application across progressive labs covering the vulnerability classes that define modern web security.

Each module follows a difficulty curve. Entry-level labs present classic, unfiltered vulnerabilities for students to exploit independently. Difficulty escalates as filters and defenses appear, requiring adaptation and creative problem-solving. Failed payloads, broken assumptions, and dead ends are not setbacks. They are the learning journey. The frustration of a blocked payload and the persistence to find the bypass is how offensive intuition is built.

A final exploit chaining challenge ties everything together, combining findings across vulnerability classes to demonstrate how moderate issues chain into critical impact, the way real attacks work.

Students attack, fail, adapt, and break through. Hands-on exploitation and the willingness to struggle is the foundation of any security career. It starts here.

All you need is a laptop and persistence.

Speakers:cale "calebot" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon

SpeakerBio:  cale "calebot" smith
Cale Smith has spent his entire life obsessed with one question: "Yeah, but how does it actually work?"

He started out building things, then realized breaking them was more fun, and has been doing exactly that across web, cloud, binary, IoT, and mobile ever since. He now manages a device-focused security team at Amazon, where his "what if I just..." instincts are finally considered a job qualification.

SpeakerBio:  Ruchik Dave

Ruchik Samir Dave is a software engineer and security specialist with nearly 20 years of experience at the intersection of complex systems security and emerging threat landscapes. Ruchik has contributed to security frameworks for aviation systems and privacy-compliant architectures for large consumer IoT ecosystems, bringing safety-critical systems expertise to emerging technology platforms. His current research explores cloud security paradigms, security compliance, AI-assisted threat detection systems, and the novel attack surfaces introduced by machine learning implementations in embedded environments, areas that represent the cutting edge of adversarial research and defensive innovation. With a passion for building secure, large-scale software systems, Ruchik’s work addresses the evolving security challenges where traditional cybersecurity meets artificial intelligence, IoT proliferation, and safety-critical infrastructure.

SpeakerBio:  Young Seuk Kim

Husband, father, hacker, gamer. Young’s path into security started like a good game exploit—he wanted to win, bent the rules, and discovered a passion for hacking. He began as a web app security consultant, moved into penetration testing and red teaming, and now works in application security engineering, helping teams build secure systems (and still breaking things for fun). He also dives into all kinds of games and stories, especially fantasy with Eastern martial arts, and loves dissecting media with the same curiosity he brings to code.

SpeakerBio:  Luke Cycon

Luke is a former builder turned security engineer at Amazon, focused on web, cloud, and embedded device security. He came up building things before he discovered that breaking them taught him more about how they really work. These days he likes to poke at things until they misbehave, then help the builders make sure it doesn't happen twice. Off the clock, you'll find him tinkering with hardware, firing lasers at something, and celebrating each fixed bug with a bit too much whisky.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 10:00-10:59 PDT


Title: Sovereign by Design, Vulnerable by Default
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Every major government is now making sovereign AI decisions. Data localization. Domestic cloud mandates. Trusted vendor regimes. Export controls on chips and model weights. Engineers and security teams don't get a vote on whether sovereignty happens — they inherit the architecture it creates. And that architecture has seams. This talk is a security analysis of what sovereignty does to threat models, and what policy designers can do about it. Sovereignty initiatives change architecture. Architecture changes threat models. Policy that ignores this chain creates new vulnerabilities. Policy that understands it can improve resilience — but only if it's designed with the seams in mind.

Speakers:Devin Lynch,Haley Ring

SpeakerBio:  Devin Lynch, Paladin Global Institute

Devin Lynch is the Senior Director of the Paladin Global Institute and a former Director for Cyber Policy and Strategy Implementation at the Office of the National Cyber Director (ONCD). He has held key roles in both the private sector and government, including positions at the U.S. House of Representatives, U.S. Senate, and the Departments of Homeland Security and Defense. He is an adjunct professor at the George Washington University’s Elliott School of International Affairs and has served in the U.S. Navy Reserve for over 20 years, including combat deployments to Iraq and Afghanistan.

SpeakerBio:  Haley Ring, Paladin Global Institute

Haley Ring is the Director at the Paladin Global Institute, where she helps drive initiatives that strengthen national resilience, protect critical infrastructure, and shape the future of emerging technology. She previously served in the Biden-Harris Administration, advising on national security, technology policy, and public engagement as the Advisor for Engagement to the Second Gentleman and as a Special Advisor in the White House Office of the National Cyber Director. Before her White House roles, Haley worked at the Department of Defense in the Office of the White House Liaison. She began her career on the Biden for President campaign and is originally from Newton, Massachusetts. Haley holds a bachelor’s degree from the University of Wisconsin–Madison and is based in Washington, D.C.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: SpaceCOP - Catch Me If You Can
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Think you can hack a spacecraft?

We’ve deployed a vulnerable Pisat and made the software available ahead of time so you can prove it. Study it, reverse engineer it, find weaknesses, and develop your attack plan before stepping up to the console.

When your turn comes, you’ll only have 15 minutes at a time to compromise the spacecraft and achieve a mission objective. There’s just one problem, the SpaceCOP, an intrusion detection system based on the Aerospace Corporation’s SPARTA matrix, has been deployed. The spacecraft is intentionally hackable - the real challenge is accomplishing your objective without triggering an alert and getting arrested by SpaceCOP.

Earn rewards based on how well you hack and hide from SpaceCOP.

Rules of Engagement: • Recon and vulnerability research before sitting at the terminal are highly encouraged. • You will have 15 minutes at the workstation to execute your attack. • Modifying files, changing registry settings, taking pictures, and other spacecraft effects are fair game. • Do not intentionally wipe, brick, destroy, or otherwise render the system unusable. • No “rm -rf”, disk wipes, ransomware, bootloader destruction, or similar actions.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Friday - 11:30-11:59 PDT


Title: Spotlight: Choose Your Own Adventure with InfoSecMap
Tags: OWASP Foundation | Creator Event/Activity
When: Friday, Aug 7, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Opportunities in InfoSec are everywhere, but they’re often buried across scattered websites, social media posts, or chat channels. Whether it’s a local meetup, a CFP deadline, a volunteer opportunity, or the chance to sponsor an initiative, many people and organizations miss out simply because they don’t know where to look or find info bloated by pay-to-play noise.

InfoSecMap was created to solve this. It’s a free, community-driven platform that brings the global InfoSec ecosystem together in one place. From major conferences to CTFs and grassroots meetups, InfoSecMap helps users explore what’s happening by geographic region or focus area and discover where they can connect and contribute.

InfoSecMap is proud to partner with OWASP, bringing together volunteer-led chapters and global events while fostering stronger connections and community growth. We believe open source should mean open access, and we’re building the infrastructure to make that real.

SpeakerBio:  W. Martín Villalba, OWASP

Martín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: spyVspy 3: Rat Race
Tags: spyVspy 3: Rat Race | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race) - Map

Description:

spyVspy is back, and this year, you're racing.

Embark on a thrilling espionage adventure with spyVspy 3: Rat Race! This contest imagines a world of spy games where contestants employ basic hacking, cryptography, and rogue skills to solve puzzles and uncover hidden caches strategically scattered throughout DEF CON (and beyond).

Challenges leading to the location of hidden caches will be released on a rolling schedule. By solving these challenges and being the first team to reach a cache, you will qualify for a final series of challenges on Saturday afternoon. Not the first? That's okay - you'll still have fun and earn cool spyVspy slabbed cards

spyVspy 3: Rat Race is intended for players of all skill levels. Whether you're a seasoned double-agent or just learning to be a covert operative, you will be able to compete and have fun in this event. Whatever skills you think you're missing can probably be learned on-the-job anyway.

Participant Prerequisites

A laptop would be great, but some puzzles may be solvable on a phone.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Friday - 10:00-17:59 PDT


Title: SR-71 Blackbird Badge Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Think faster. Fly higher. Stay unseen.

Only the sharpest contenders will earn the limited-edition SR-71 PCB badge, inspired by the legendary Blackbird. Put your technical skills, aerospace knowledge, and analytical thinking to the test in this exclusive challenge. Like the aircraft itself, success demands precision, ingenuity, and the ability to stay one step ahead. Complete the mission and earn your wings.

New challenges launch all weekend long.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-11:59 PDT


Title: StarPWN CTF
Tags: Aerospace Village | STARPWN (Aerospace Village CTF) | Contest
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Want to try your hand at hacking satellites, spacecraft and ground control systems? Miss out on Hack-A-Sat? Want to explore the final frontier of cybersecurity?

STARPWN is the official Aerospace Village space hacking CTF! Backdoor flight computers, trojan flight software, exploit CVE's, reverse protocols, and more! During your space hacking journey, you’ll learn all about the environmental and operational constraints of space systems, how they affect cybersecurity posture, and impact exploitability.

Register at https://starpwn.ctfd.io/

Prizes to the highest finishing team the team that finishes quickest that can make it to the Aerospace Village in person by 1300 local time.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Friday - 11:30-11:59 PDT


Title: Starting and Sustaining a Successful DEF CON Group presented by DC862
Tags: DEF CON Groups | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Starting a DEF CON Group is more than picking a name and scheduling a meetup. This session walks through the practical work of building a local hacker community that people want to keep showing up for. DC862 will share lessons on organizer structure, finding speakers and venues, community engagement, long-term sustainability, and representing DEF CON in a positive way. This workshop is built for newer organizers, prospective POCs, and anyone trying to turn a local meetup into a durable community.

Speakers:C$,Joe Folk,Christopher "reapermunky" Aziz

SpeakerBio:  C$, DC862

++++++++++[>+>+++>+++++++>++++++++++<<<<-]>>>>+++++++++++++++++++.------------------.+++++++..<<++.>>--------.+++++++++++.-.---------.<<+.

SpeakerBio:  Joe Folk, DC862

Original member of DC862, DC404 OG, and member of several other DCGs. Joe has worked in security for over 25 years leading Security Departments at multiple Fortune 500 companies. He's a regular at DEF CON (since DC6), Black Hat, BSides, and many regional security conferences.

SpeakerBio:  Christopher "reapermunky" Aziz, DC862/Bombadil Systems

Chris Aziz is an independent security researcher and the founder of Bombadil Systems, a MITRE CVE Numbering Authority focused on vulnerability research. An active member of DC862, he contributes to the group's speaker sourcing, community engagement, and growth efforts.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 15:30-15:59 PDT


Title: State Desync as a Weapon: Breaking Transactional Integrity in Payment Systems (ESP)
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

El Price Tampering no es un simple cambio de parámetro ni un bug, es una falla de arquitectura que permite alterar el valor de una transacción sin romper ningún control tradicional en cualquier sistema que procese pagos, provocando fraude en diferentes industrias y negocios. En esta charla abordaré cómo un atacante modela el flujo de compra y pago completo, identifica puntos de desincronización entre cliente, backend y pasarela, y explota la ausencia de invariantes de negocio server-side para manipular el valor final de una transacción sin necesidad de CVEs, exploits ni malware. Basado en una investigación propia con casos reales autorizados y anonimizados en entornos de banca, retail y fintech en LATAM, presentaré una taxonomía de tres patrones de ataque recurrentes y un modelo defensivo concreto llamado FinSecure, sustentado en el principio del backend soberano, donde el precio nunca puede nacer fuera del servidor. La audiencia se irá con una visión diferente del problema y herramientas accionables para detectarlo y eliminarlo por diseño.

SpeakerBio:  Santiago Sepúlveda Veliz, Pentester / Security Researcher - AppSec & Transactional Integrity

Mi nombre es Santiago Sepúlveda Veliz, hoy en día me desempeño como Pentester y Security Researcher especializado en AppSec e integridad transaccional, con 3 años de experiencia profesional realizando evaluaciones de seguridad en aplicaciones web, móviles, APIs y entornos Active Directory para clientes enterprise en Latinoamérica. Actualmente me desempeño en TRUSTTECH Cybersecurity, enfocado en seguridad de plataformas de pago y lógica de negocio. Cuento con las certificaciones OSCP+ (Offensive Security) y CRTO (Zero-Point Security). Soy speaker aceptado en PyCon Latam 2026. He asistido a DEF CON 32 y 33, RootedCON Panamá, Ekoparty Argentina y el Congreso 8.8 Chile. Soy creador de contenido técnico de ciberseguridad en YouTube bajo el alias Y4nbow con más de 3.700 suscriptores.


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Friday - 15:45-16:30 PDT


Title: Step Zero: Identifying the Quantum Attack Surface in Critical Infrastructure
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Friday, Aug 7, 15:45 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Every wire transfer, banking session, API transaction, and SWIFT message depends on RSA and ECC cryptography that a sufficiently powerful quantum computer will eventually break with Shor’s algorithm. That part is well known.

The real problem is that most financial institutions have no idea where that cryptography actually lives.

RSA and ECC are buried inside banking APIs, certificate hierarchies, SWIFT authentication, third-party software dependencies, mobile applications, HSM integrations, and legacy infrastructure that was never designed for crypto-agility. Most organizations cannot inventory it, prioritize it, or migrate what they cannot find.

This talk focuses on the real quantum attack surface inside financial infrastructure, not the theoretical one.

We examine two high-impact cryptographic systems hiding in plain sight: • SWIFT authentication infrastructure securing interbank trust • TLS certificate hierarchies protecting banking sessions, APIs, and payment platforms

Then we move from theory to operational reality.

Using open-source Cryptographic Bill of Materials (CBOM) tooling, we demonstrate how to identify quantum-vulnerable cryptography across financial systems, uncover hidden RSA and ECC dependencies, and build usable cryptographic inventories that defenders can actually operationalize.

We also examine why this is a current collection problem, not a future one. Nation-state adversaries are already harvesting encrypted financial traffic and long-lived sensitive data for future decryption under harvest-now, decrypt-later (HNDL) strategies. Your encrypted traffic does not need to be decrypted today to become valuable tomorrow.

The talk includes: • Live CBOM generation using IBM CBOMkit • Discovery of hidden RSA and ECC dependencies inside financial infrastructure • Practical guidance for prioritizing post-quantum migration

Not policy. Not hype. Tools, cryptographic visibility, and attack surface.

Speakers:Dr. Katrina Rosseini,Dr. Allan Friedman

SpeakerBio:  Dr. Katrina Rosseini

Dr. Katrina Rosseini is a strategist at the intersection of cybersecurity, quantum computing, PQC, and AI, advising policymakers and stakeholders on U.S. positioning in global technology competition with national security at the core. She is the Founder of KRR Ventures Advisory and leads Critical Effect California, a forum that convenes policymakers, infrastructure operators, and private-sector leaders on cybersecurity and operational risk. As Chair of the Civilian Reserve (CR-ISAC), she supports a national network of veterans and civilian experts strengthening the resilience of critical infrastructure. A Visiting Fellow at the National Security Institute, Dr. Rosseini focuses on quantum risk and the post-quantum transition. She has briefed the nation's largest public pension fund and contributed to congressional and United Nations forums. She developed the QUEEN Framework, a quantum governance model integrating cryptographic risk into board-level decision-making, and SECUREGRID, a methodology for prioritizing vulnerabilities in operational technology. Her commentary has appeared in Forbes, S&P Global, and Fast Company, among others. She holds a Doctor of Engineering from George Washington University and an MBA in Finance.

SpeakerBio:  Dr. Allan Friedman
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 13:00-13:59 PDT


Title: Stigma is stupid: Let's talk about recovery, mental wellness, and hard stuff without making it awkward
Tags: The Diana Initiative | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

This will be a discussion group about how we talk (or don’t talk) about recovery, sobriety, mental wellness, burnout, grief, and other hard human things in cybersecurity spaces. Silence feeds stigma, but not everyone knows how to start the conversation safely or supportively. We’ll discuss language, boundaries, allyship, and ways to create community without turning every vulnerable conversation into a TED Talk or therapy session.

SpeakerBio:  Jennifer VanAntwerp, ABM Manager at StrongDM

Jen VanAntwerp is the founder of Sober in Cyber, a nonprofit on a mission to provide alcohol-free events and community-building opportunities for sober individuals working in cybersecurity. She is passionate about breaking the stigma of addiction recovery and is profoundly driven to increase the number of professional networking events that don’t revolve around alcohol. Jen is also the ABM manager at StrongDM, the Zero Trust privileged access platform. When she’s not developing marketing strategies or running her nonprofit, Jen enjoys volunteering, sewing, and tinkering with her beloved ’65 Ranchero.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 14:00-15:30 PDT


Title: Strengthening the CVE Ecosystem (Seating is limited to 50 Participants)
Tags: Policy @ DEF CON | Creator Interactive Talk/Panel
When: Friday, Aug 7, 14:00 - 15:30 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

CVE is core infrastructure for vulnerability management, but it’s under real strain. The volume and complexity of vulnerabilities keep rising, while the systems, tooling, and coordination models behind CVE haven’t kept pace. This was true prior to the extensive use of AI to identify vulnerabilities and has only grown more acute. At the same time, governments and industry are relying on CVE data more than ever to drive security decisions, and there are concerns about whether current funding models are sustainable. This roundtable brings together the people who actually work with CVE (researchers, open-source maintainers, vendors, and policymakers) to talk frankly about what’s breaking and what needs to change. We’ll focus on three areas: gaps in CVE data and infrastructure, where automation and AI can realistically help, and how to build sustainable public-private support for the ecosystem - all with the goal of identifying concrete policy steps that could improve CVE over the next 12-24 months. This discussion would feed into a policy paper making recommendations for policymakers, published by the Center for Cybersecurity Policy and Law.

Seating is limited to the first 50 participants in order to facilitate interactive discussion.

Speakers:John Banghart,Elizabeth Eigner,Lisa Olsen,Lindsey Cerkovnik

SpeakerBio:  John Banghart, Center for Cybersecurity Policy & Law

John Banghart leverages his significant federal government and private sector experience in cybersecurity to navigate issues related to risk management, government policy, standards and regulatory compliance, and incident management. He has successfully led efforts to address significant and high-profile cybersecurity issues within major government programs and institutions while facing complex legal, technical, and political circumstances. From 2013 to 2015, John played a key role in developing the Obama administration's cybersecurity and technology policy as the National Security Council's director for federal cybersecurity. He led policy, technical, and process efforts to reduce cybersecurity risk and improve metrics and measurement for all civilian, military, and intelligence community agencies. He served as a primary advisor on cybersecurity incidents and preparedness and led the National Security Council’s efforts to address significant cybersecurity incidents, including those at OPM and the White House, among others. He also spent several years at the National Institute of Standards and Technology (NIST), both as a cybersecurity researcher and in the Office of the Undersecretary of Commerce for Standards and Technology. John also worked as a senior cybersecurity advisor for the Centers for Medicare and Medicaid Services, providing leadership to the cybersecurity preparations for the Healthcare.gov website.

SpeakerBio:  Elizabeth Eigner, Microsoft

Elizabeth Eigner is a Senior Manager on Microsoft’s Global Cybersecurity Policy team, where she leads Microsoft's vulnerability policy portfolio, overseeing efforts to develop and implement strategies that address vulnerability management both in the United States and globally. She represents Microsoft on the Hacking Policy Council, where she works collaboratively with industry leaders and policymakers to advance responsible cybersecurity and strengthen the frameworks that underpin software security worldwide. Elizabeth also leads initiatives aimed at creating and enhancing national cyber strategies in countries around the world. She works closely with governments and stakeholders to strengthen policy frameworks and promote resilient cybersecurity practices globally. Elizabeth also leads Microsoft's Advancing Regional Cybersecurity (ARC) initiative, focusing on improving incident response capabilities and cyber capacity building in the Global South. Previously, she served as Microsoft’s representative on the Cloud Service Provider Advisory Board (CSP-AB), contributing to FedRAMP public policy discussions and best practices for cloud security. Before joining Microsoft, Elizabeth worked at The Washington Technology Industry Association to enhance Washington State's innovation ecosystem. At MIT Solve, she collaborated with tech-based social entrepreneurs on solutions fostering digital inclusion and equitable economic opportunity. She holds a B.S. in Political Science from Northeastern University, with concentrations in Law and International Security.

SpeakerBio:  Lisa Olsen, Principal Security Release Program Manager at Microsoft

Lisa Olson is a Principal Security Release Program Manager at Microsoft, where she has led the Patch Tuesday release process since 2013. A member of the CVE Board since 2018, Lisa is a passionate advocate for improving vulnerability communication through automation and machine-readable formats. Her work focuses on transforming how security information is shared to help organizations respond faster and more effectively.

SpeakerBio:  Lindsey Cerkovnik, CISA

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.


Return to Index    -    Add to Google    -    ics Calendar file

.EDU Community - Friday - 12:00-12:59 PDT


Title: Student-Run Cyber Clubs - Why They Matter & Digital Playgrounds
Tags: .EDU Community | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map

Description:
SpeakerBio:  Steven "Stengo" Ngo

Steven Ngo is a third-year Ph.D. student in Software Engineering at the University of California, Irvine, advised by Associate Professor Joshua Garcia, with research interests in software engineering & security education and software security. Ngo studies student-run organizations (e.g., cyber clubs) to understand their perspectives and motivations in providing informal modalities of peer-to-peer education, which facilitate the development of educational collaborations, frameworks, and tools to support such organizations.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 16:30-16:55 PDT


Title: Supertooth: Wideband Bluetooth Observation with a HackRF
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 16:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Modern Bluetooth environments are inherently difficult to observe. Classic piconets frequency-hop 1,600 times per second, forcing sniffers to choose between tracking a single connection or losing visibility across the spectrum. Supertooth is an open-source, C-based SDR platform built on the HackRF that eliminates this tradeoff. Instead of traditional hop-following, it captures a fixed 20 MHz slice of the 2.4 GHz band, fanning the raw IQ stream into parallel per-channel demodulation workers. This approach provides simultaneous, real-time visibility into up to 20 BR/EDR channels at once.

Each worker runs an independent GFSK demodulation pipeline powered by liquid-dsp, feeds decoded bitstreams into access-code correlators, and hands matching frames to libbtbb for UAP recovery and HEC-based clock tracking, all without needing to know a piconet’s future frequency hops. Supertooth also features a hybrid mode that decodes a Bluetooth low energy advertising channel concurrently from the same 20 MHz stream, exposing advertising data alongside classic piconet activity in a unified view. Per-role RSSI separation further allows researchers to distinguish central and peripheral transmission patterns from passive observation alone.

This talk walks through the tool end-to-end, detailing how Supertooth improves on traditional single-channel workflows like those used by the Ubertooth. We will demonstrate the platform live, discuss current recovery capabilities and the limitations of passive clock tracking, and outline a roadmap for future development. The project is open-source, and the build requires only a HackRF, libhackrf, liquid-dsp, and libbtbb.

SpeakerBio:  Dalton Cox, Security Researcher at Skinny R&D

Dalton Cox is a security researcher at Skinny Research & Development in Huntsville, Alabama, where he develops applied AI and various tooling for cybersecurity operations. He is concurrently studying Computer Engineering at the University of Alabama in Huntsville. In his spare time, he plays strategy and card games, experiments with audio gear, and dabbles in a variety of musical instruments.


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Friday - 15:30-16:30 PDT


Title: tAIrot Readings
Tags: Women in Security and Privacy (WISP) | Creator Event/Activity
When: Friday, Aug 7, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Curious about what the cards have in store for you? For a suggested donation, WISP Board Chair Alyssa Coley give you an AI-assisted tarot reading! Drop by for a fresh perspective on your burning questions, blending ancient symbolism with modern tech to offer personalized, reflective insights for your journey.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Friday - 13:15-14:15 PDT


Title: TBA
Tags: Blue Team Village | Creator Talk/Panel
When: Friday, Aug 7, 13:15 - 14:15 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

TBA


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 10:00-17:59 PDT


Title: TCM Security Labs
Tags: Noob Community | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

TCM Security offers 250+ hours of practical, hands-on cybersecurity training across 28 courses and 13 certifications, built by hackers and trusted by teams. Drop in during village hours to work through their hands-on labs.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Friday - 11:00-11:30 PDT


Title: Tech Reclaimers Update: A Year In, Building a Social Movement Away from Big Tech
Tags: Hackers.town | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

It has been a year since we launched the Tech Reclaimers, a social movement to help people reclaim their lives and their systems from Big Tech. And how far we have come! The community has grown online, with a thousand followers and hundreds of active participants in group chats. In this talk, describe our activities over the past year and our plans for the future, as well as what we have learned about the challenges people face in disentangling from Big Tech. While the technical challenges can be complicated, there are considerable social challenges too. And while hackers may look for the purest and best alternative options, we have found variety in meeting people where they are at to help them assemble the alternative stack that suits their needs, budget, skills, and values. Finally, we do indeed have friends everywhere: from the Rebel Tech Alliance to the Luddite Club, we discuss the connections we are forging and the new paths we are innovating.

Speakers:Andy Hull,Janet Vertesi,Rebecah Miller

SpeakerBio:  Andy Hull, Officer at Tech reclaimers
No BIO available
SpeakerBio:  Janet Vertesi, Officer at Tech Reclaimers
No BIO available
SpeakerBio:  Rebecah Miller, Officer at Tech Reclaimers
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: TeleChallenge
Tags: TeleChallenge | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 107 (TeleChallenge) - Map

Description:

The TeleChallenge isn't just a puzzle challenge, it's an experience. We are super excited to show the plan for the tenth year in a row. Don't copy that floppy, but instead prepare to be immersed in an entirely new world where all of your hacker skills will be challenged (along with your 0xEA60 skills). This is a very tough contest to win, and is among the most challenging at DEF CON. Are you ready? Your first step is to find us, because part of the puzzle is discovering the puzzle.

Participant Prerequisites

You'll need a phone, your creativity and some hacker friends. It also helps to have access to a computer. Use the TeleChallenge as an excuse to meet people and form a team.

Pre-Qualification

We may have team registration in advance, but there is no pre-qualifyer.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 16:30-16:59 PDT


Title: Telecom Village CTF Closure
Tags: Telecom Village | Creator Event/Activity
When: Friday, Aug 7, 16:30 - 16:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 10:00-10:20 PDT


Title: Telecom Village Inauguration
Tags: Telecom Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:20 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
SpeakerBio:  Pankaj Sontakke
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Friday - 17:00-17:59 PDT


Title: Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings
Tags: Telecom Village | Creator Event/Activity
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 13:10-13:20 PDT


Title: Telecom Village Tour
Tags: The Diana Initiative | Creator Tour
When: Friday, Aug 7, 13:10 - 13:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Telecom Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Telecom Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:00-10:59 PDT


Title: Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment
Tags: DEF CON Official Talk | Demo 💻
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

In this talk, we'll discuss how we achieved the black-box compromise of the Trusted Execution Environment (TEE) of the Texas Instruments OMAP-L138, a popular SoC encountered in various PMR radios, satcom equipment and other embedded applications. These radios are frequently used in safety-critical roles, where integrity and service availability is paramount.

Through a painstaking iterative process, which includes building both a disassembler and a decompiler for the (hellish) DSP architecture, and through blind exploitation of the Texas Instruments ROM code underpinning the TEE functionality, we managed to abuse a (novel type of) timing side channel that exists when attempting to load (bogus) cryptographic modules into the TEE, allowing us to recover the manufacturer key within a minute.

The talk dives deep into the technical aspects of the attack, providing a rare perspective on how the simple primitive of "decryption isn't constant time" can ultimately be leveraged into a very tangible result: recovery of the device's full 128-bit AES key. Additionally, we discuss several ROM-based vulnerabilities, including one that enables full secure-mode code execution on the SoC.

Vulns are in ROM, so if you're so inclined: feel free to have fun with those on other OMAP-L138-powered devices.

Speakers:Carlo Meijer,Wouter Bokslag

SpeakerBio:  Carlo Meijer, Midnight Blue

Carlo Meijer is a founding partner of the boutique security consultancy firm Midnight Blue and is most known for his research into TETRA, the MIFARE Classic Crypto1 RFID cipher, and the security of self-encrypting drives. Furthermore, Carlo regularly competes in the famous Pwn2Own hacking competition, where he is part of team PHP Hooligans.

SpeakerBio:  Wouter Bokslag, Midnight Blue

Wouter Bokslag is a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world’s fastest public attack against the Hitag2 cipher. He holds a Master’s Degree in Computer Science & Engineering from Eindhoven University of Technology (TU/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years.

Recently heavily involved in the TETRA:BURST research and associated follow-up research, such as the recent reverse-engineering and analysis of the elusive TETRA End-to-End protocol. Also, a contributer of open-source SDR code.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 11:00-11:59 PDT


Title: The 2026 Pwnie Awards
Tags: DEF CON Official Talk | The Pwnie Awards
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:
Speakers:Ian Roos,Mark Trumpbour

SpeakerBio:  Ian Roos
No BIO available
SpeakerBio:  Mark Trumpbour
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 14:10-17:25 PDT


Title: The Achaean project-Trojan development for noobs
Tags: Malware Village | Creator Workshop
When: Friday, Aug 7, 14:10 - 17:25 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map

Description:

4 hour workshop. 1hr Lecture on trojan creation. Followed by 2 hrs hands on practice creating trojans, setting up malware servers. Using C## loaders and malicious dll's to trojanise normal programs with ransomware. Instructor aide and easy to follow instructions throughout.

1 hr CTF. Students will develop their own new trojan containerize it and send to our victim computer. Prizes.

SpeakerBio:  Leigh Gilbert, Malware village

Leigh Trinity is a Canadian exploit developer, red team hacker, and instructor known for her work in binary exploitation and reverse engineering. Now branching out into malware development.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 14:00-14:59 PDT


Title: The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack?
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

To attack an AI agent, the reflex is an abliterated model - refusal behavior surgically removed, expecting a stronger attacker. We tested that across open-weight models (Qwen3, Llama-3.1, the 754B GLM-5.2), scoring only attacks that actually fire a tool, not ones that just describe one.

Abliteration does make a tireless attacker. Asked to write attack payloads — poisoned RAG docs, malicious tool descriptions, injections — an abliterated GLM-5.2 said yes roughly three times as often as its base (13% → 38%). Pointed at an aligned copy of itself, it jailbroke that copy 80% of the time on the first try, and lifted its hidden system prompt. Set loose in a real coding agent (OpenCode) attacking an aligned-model app, it found exploits on its own: faking a password-reset to send a phishing email, and a KYC passed result to skip an identity check and wire money.

But look at how it won: blunt jailbreaks (ignore your instructions, SYSTEM OVERRIDE) failed about 100 times. Every win came from disguise — reframing the harmful step so it looked routine. Aligned agents block harm they recognize and fall for harm they don't.

The backbone matters only for hard content — malware, weapons, drugs — where abliteration clearly raises success (Qwen3 37.5% → 60%, GLM-5.2 67.5% → 77.5%). And method matters: single-direction Heretic can't strip Llama-3.1's refusal, but eight-direction OBLITERATUS can. That gap is also a detector: a model that clears 50% on hard content, or eagerly writes attacks, is probably tampered.

Speakers:Karol Piekarski,Nishith Sinha

SpeakerBio:  Karol Piekarski, DevOps Engineer

Karol Piekarski is a Lead DevOps Engineer working across cloud infrastructure, zero-trust architecture, and AI and agentic security for systems that serve hundreds of millions of consumers. His research focuses on the security of large language models and autonomous agents, with an emphasis on practical red-teaming and defensive tooling that teams can actually operationalize rather than shelve.

His empirical work on abliteration and agentic framing reframes where alignment actually breaks down in agent pipelines: agentic framing alone can collapse a model's baseline safety, while abliteration matters mostly for the hardest content and is highly architecture-dependent. In 2026 he co-presented "Move Fast, Stay Secure: Enterprise AI Agent Security in Practice" at the Databricks Data + AI Summit, and spoke at SCaLE 23x on open source red-teaming for LLMs. He was one of only two external contributors to the Databricks Agentic AI Security Framework (DASF v3.0).

Karol is the creator of Sundew.sh, an open source, MCP-native AI agent honeypot platform that uses behavioral fingerprinting and a persona engine for anti-fingerprinting, now adopted by external research teams studying agent behavior in the wild. He was selected as a Wiz MVP last year and this year received Wiz's Thought Leader award, and he is active in the AISECA Working Group, where he co-owns agentic security risk definitions.

He holds the CCSP, CKA, four AWS specialty certifications along with DataDog and Tines, and he regularly judges and mentors at hackathons across Southern California.

SpeakerBio:  Nishith Sinha

Nishith Sinha started his career by pulling secrets out of thin air. As a researcher at Georgia Tech, he co-authored a side-channel attack that recovered RSA private keys from OpenSSL by reading its electromagnetic emissions alone. No code executed, no system touched. Presented at USENIX, the work prompted a rapid fix from the OpenSSL team and is still cited as a landmark example of hardware-level cryptographic risk.

It set the tone for what came next: a career built on finding the security gaps other people aren’t looking at. At Cisco, that meant network security, where he helped design the company’s firewall migration tooling. At Amazon, it meant identity, where he owned IAM strategy across tens of thousands of AWS accounts, and then application and cloud security, remediating critical vulnerabilities at enterprise scale. As generative AI took hold, Nishith moved with it, leading application security for Amazon Bedrock and Amazon Q, before building security from scratch for Amazon’s Nova foundation models, safeguarding training data, model artifacts, and infrastructure across hundreds of teams.

Today, Nishith brings that range to Databricks, where he leads AI Security and the company’s work on Agentic Security, AI Red Teaming, and AI Enterprise Security. He holds 10 AI security patents spanning model artifact protection, secure execution of model-initiated computer actions, and behavioral-analytics-based content moderation. He co-authored the Databricks Agentic Security Framework (DASF) and is credited with several CVEs. His focus now is autonomous AI agents: the newest layer of the stack, and the one attackers understand least.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 13:30-14:30 PDT


Title: The Autonomous Security Loop
Tags: Cloud Village | Creator Event/Activity | Strategic Defense
When: Friday, Aug 7, 13:30 - 14:30 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) B - Map

Description:

SOCs get thousands of alerts daily. Most orgs take days to triage and fix critical findings. Attackers exploit that gap.

This lab walks through the three stages of a continuous security loop. Do each phase by hand, then see how the latest AWS capabilities compress it to seconds:

Discovery: Review output from a continuous security scan that found a multi-step attack path. Understand why this catches things annual pen tests miss. Triage: Manually triage 5 out of 30 Security Hub findings using the same signals AI triage uses. Compare your calls against the automated system. Remediation: Examine proposed fixes. Understand the difference between human-approved and autonomous remediation. Submit a fix and confirm it works.

Speakers:Jeremy Schiefer,Lawton Pittenger

SpeakerBio:  Jeremy Schiefer

Jeremy is a Pr. Security Solution Architect at AWS focused on helping customers improve their security posture.

SpeakerBio:  Lawton Pittenger

Lawton is a Worldwide Security Specialist Solutions Architect at AWS, based in New York City. He specializes in helping customers design and implement effective network security controls. At AWS, he works with customers at scale and collaborates closely with service teams to drive continuous improvement in security services based on customer needs and feedback


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 11:00-11:55 PDT


Title: The Black PhD Playbook: What No One Tells You
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Join us for an honest, encouraging, and relatable conversation about pursuing a PhD as a Black student or cybersecurity professional. Our panelists will share what the journey really looks like, including how they chose their programs, found research interests, secured funding, built support systems, handled self-doubt, and balanced school with the rest of life. Attendees will leave with practical advice, real-world lessons, and a better understanding of how to decide whether a PhD is the right path for them.

Speakers:Dr. Fatou Sankare,Dr. Xavier-Lewis Palmer,Dr. Tia Pope

SpeakerBio:  Dr. Fatou Sankare, Cybersecurity Professional / Community Speaker

Dr. Fatou is a Cyber Engineer and an adjunct professor, dedicated to increasing cyber education, particularly in underestimated communities, through Datacation LLC, which they founded. They are a Certified Ethical Hacker and hold the AWS Machine Learning Specialty Certification.

SpeakerBio:  Dr. Xavier-Lewis Palmer, Cybersecurity Professional / Community Speaker

Dr. Palmer is multi-disciplinary professional whose work focuses largely on biomedical contexts. He enjoys positive and creative projects that foster both curiosity and helpful conversations around technologies that interface with biology.

SpeakerBio:  Dr. Tia Pope, North Carolina Agricultural and Technical State University

Dr. Tia Pope is a Principal at Base10 Partners, where she invests in machine intelligence and emerging AI technologies. She earned her PhD researching the evaluation and development of AI tools for protein design, with an emphasis on dual-use risks and cyberbiosecurity threats. Her work has included projects with MIT Lincoln Laboratory and Johnson & Johnson, bridging advanced research with real-world impact. Tia specializes in transformer-based models for protein engineering, function prediction, and biological risk assessment. She has also contributed to open-source efforts that expand access to cutting-edge bio-AI tools. Her work reflects a commitment to supporting secure, ethical, and resilient technologies at the intersection of machine learning, molecular design, cybersecurity, and venture investment.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 11:00-12:59 PDT


Title: The Call Stack Experience
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Friday, Aug 7, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map

Description:

Let’s play with blocks… and learn how real application attacks unfold.

You will build real application call stacks, one foam block at a time, with each block representing function calls in a normal execution flow.

Once your stack is complete, you will see first-hand how easy it is for exploits to blend in with normal application behavior.

SpeakerBio:  Victoria Keeler
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 15:00-15:25 PDT


Title: The Cost of Unverified Intelligence: AI and Accountability in Defense Operations
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:25 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Explore the critical implications of unverified intelligence in defense operations, particularly concerning the role of Artificial Intelligence. This presentation will delve into a recent incident where AI-processed data contributed to a devastating error, examining the failure points in human oversight, algorithmic accountability, and the growing workforce gap in understanding and managing these powerful systems. Join us to discuss the urgent need for robust governance, verification, and training infrastructure to ensure responsible AI deployment in defense, and consider what lessons must be learned to prevent future tragedies. This timely discussion draws on current doctrine, recent operations, and ongoing public discourse, offering valuable insights for anyone interested in AI ethics, national security, and responsible technology development.

SpeakerBio:  Kayrene Woods, Graduate Student, Founding President of BiC ODU

Kayrene Woods is an emerging cybersecurity professional and recent graduate of Old Dominion University, where they earned a B.S. in Cybersecurity with a minor in Computer Science and a 3.76 GPA as a member of the Perry Honors College. Notably, they served as the Founding President of the Blacks in Cybersecurity ODU chapter, which is the second officially recognized chapter established outside of the parent organization. Their technical expertise and research spans cybersecurity engineering, network security, intrusion-detection, and AI governance, with hands-on experience from an internship at the Air Force Research Laboratory/Griffis Institute supporting Department of Defense security research. This summer, they'll serve as a VICEROY Envoy at the Pentagon, supporting a Cloud Portfolio project for Air Force Intelligence within the Chief Information Officer's unit.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Friday - 13:00-13:30 PDT


Title: The Cum-Stained Precipice of Digital Redlining
Tags: Hackers.town | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

The web was supposed to democratize information. Instead, we have a two-tier reality: one class consuming porn on $2,000 laptops they'll discard in eighteen months, another class without a screen. The web was supposed to democratize information. Instead, we have a two-tier reality: one class consuming porn on $2,000 laptops they'll discard in eighteen months, another class without a screen. That discarded laptop could have been a classroom, a business, a lifeline. The gap between those two realities is a political choice—one we can make differently. This talk is a direct confrontation with the culture of disposable tech—and a practical guide to grassroots reclamation programs that turn waste into opportunity and combat inequality with community.

Speakers:Erica Rachel Andrews,Abbie Gonzalez (pronounced AB)

SpeakerBio:  Erica Rachel Andrews, Co-founder and president at Springfield.community
No BIO available
SpeakerBio:  Abbie Gonzalez (pronounced AB), Executive Director Springfield.community
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 13:00-13:59 PDT


Title: The Cyber Crystal Ball: The Annual Policy @ DEF CON Contingencies Survey
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

Starting at DEF CON 33 Policy @ DEF CON shared the results of experts predictions regarding a range of cyber contingencies. With a year under out belts we can take a look at how the experts did with their prognostication last year, and look forward towards potential outcomes in the coming year. We will compare answers from year to year, and we've added a few new questions along with expanding the roster of expert respondents. The panel discussion with experts will explore how the outcomes of cyber contingencies will affect geopolitics between now and DEF CON 35.

Speakers:Matthew Wein,Bruce Schneier,Chris Painter,Heather West

SpeakerBio:  Matthew Wein, Policy @ DEF CON

Matthew is a national security policy expert with over 15 years of experience in the Executive and Legislative branches of government and the private sector. This is his second year producing the DEF CON Contingencies Survey.

SpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.

SpeakerBio:  Chris Painter

Christopher Painter is a globally recognized leader on cyber policy, cyber diplomacy, cybersecurity and combatting cybercrime. He has been at the vanguard of cyber issues for over 30 years, first as a federal prosecutor handling some of the most high-profile cyber cases in the U.S., then as a senior official at the U.S. Department of Justice, the FBI, the White House National Security Council and, finally, as the world’s first cyber diplomat at the U.S. Department of State. Among many other things, Chris is currently a Founding Partner of The Cyber Policy Group.

SpeakerBio:  Heather West, Eurasia Group

Heather West is a policy and tech translator, product consultant, and long-term digital strategist guiding the intersection of emerging technologies, culture, governments, and policy. Equipped with degrees in both computer and cognitive science, Heather focuses on data governance, data security, artificial intelligence (AI), and privacy in the digital age. She is a subject matter authority who has written extensively about AI and other data driven topics for over a decade. She is also a member of the Washington Post's The Network, a group of high-level digital security experts selected to weigh in on pressing cybersecurity issues.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:30-10:59 PDT


Title: The DEF CON 34 Badge
Tags: DEF CON Official Talk
When: Friday, Aug 7, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:
The badge: how it was made, how to hack it, the new open source chip powering it, and how you can use it as a hardware security token after the con! bunnie shares his experiences zero-shotting the badge with the help of team Cheeso.

This year's badge goes deeper into the open source rabbit hole than ever before. It features the Baochip-1x, a security-oriented "high-assurance" CPU that embraces Kerckhoffs's principle: not only can you check out most of the hardware design source, you can also directly see its transistors using infrared light. Learn more about how to unlock the power of open source silicon, and power up your hacking game with "God Mode" visibility into the heart of the machine.

SpeakerBio:  Andrew 'bunnie' Huang

Andrew 'bunnie' Huang is best known for his work hacking the Microsoft Xbox, as well as for designing and manufacturing open source hardware. His current research interest is in facilitating trust in technology. He developed the IRIS (Infra-Red, In-Situ) imaging technique for silicon, and is the founder of Baochip, a fabless open source silicon company.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 12:00-12:59 PDT


Title: The Diana Initiative - Open time
Tags: The Diana Initiative | Creator Event/Activity
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

We also have our "Reference Desk", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 14:00-14:59 PDT


Title: The Diana Initiative - Open time
Tags: The Diana Initiative | Creator Event/Activity
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

We also have our "Reference Desk", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Friday - 16:00-16:30 PDT


Title: The Door Was Already Open
Tags: Physical Security Village | Creator Talk/Panel
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Physical access control systems are often assumed to be secure, but many rely on flawed design assumptions, and can contain misconfigurations. This talk examines a widely deployed platform, where internet-exposed panels, numeric-only passcodes, and predictable communication patterns enable remote discovery and access at mass scale. With no rate limiting or lockout protections, authentication can be automated, often succeeding due to default credentials, or an easily guessed combination. Successful access exposes sensitive data, including resident information, credentials, and access history. It also allows for complete remote control of the access control system. This talk focuses on how architectural decisions — not just bugs — can create systemic vulnerabilities in real-world security systems. Come on in, The Door Was Already Open.

SpeakerBio:  Champ

Hello!! I am a Canadian Physical Security Consultant, who loves finding a new way to pop a door.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 10:30-10:59 PDT


Title: The Dots Do Matter: Gmail's Invisible Blindspot
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Friday, Aug 7, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

In 2004, I registered kerene@gmail.com during Gmail's invite-only launch. I've been receiving strangers' private data ever since, without clicking a single link or running a single exploit. Gmail treats dots as invisible, meaning all 32 dot-variants of my address deliver straight to me. Alas, Third-party platforms never got the memo. Banks, airlines, social networks, and government portals mostly treat dot-variants as unique identities, creating an invisible identity collision with real consequences for account security, fraud, and forensic investigation, impacting millions of users worldwide. Almost 90 Snapchat log in emails, 168 TikTok password resets, and one Google Takeout link later, I'm here to show you what 22 years of someone else's data looks like, and the one normalization fix that would have prevented all of it.

SpeakerBio:  Keren Elazari

Keren Elazari is an internationally recognized security analyst, researcher, author and speaker, working with leading security firms, government organizations and Fortune 500 companies. As an independent voice on cyber security, Keren Elazari is the first Israeli woman to give a TED talk at the official TED Conference. Keren’s TED talk about hackers has been viewed by millions, translated to 30 languages and is one of the most watched talks on TED.com on the topic of cyber security. Keren is the founder of BSidesTLV, Israel's largest security community event, and the founder of the Leading Cyber Ladies network for Women in Cyber Security. Keren is currently a senior researcher at the Interdisciplinary Cyber Research Center at Tel Aviv University.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 12:00-14:59 PDT


Title: The EFF Benefit Poker Tournament
Tags: The EFF Benefit Poker Tournament | Contest
When: Friday, Aug 7, 12:00 - 14:59 PDT
Where: Other / See Description

Description:

The EFF Benefit Poker Tournament is back for DEF CON 34! Your buy-in is paired with a donation to support EFF’s mission to protect online privacy and free expression for all. Play for glory. Play for money. Play for the future of the web. Seating is limited, so reserve your spot today.

When: Friday, August 7, 2026 - 12:00-15:00

Where: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas, NV 89109

Tournament Specs: $100 Horseshoe tournament buy-in, with a donation of $250 or more to EFF to sign up. (AND all players will receive a complimentary EFF Gold Level Membership for the year.) Re-buys are unlimited to level 6, with each having a suggested donation of $100 on site. Levels will be fifteen minutes, and the blinds go up at each level. Attendees must be 21+.

Pre-Tournament Clinic: Have a friend that might be interested but not sure how to play? Have you played some poker before but could use a refresher? Join poker pro Mike Wheeler (Tarah’s dad) and celebrities for a free poker clinic from 11:00 am-11:45 am just before the tournament. Mike will show you the rules, strategy, table behavior, and general Vegas slang at the poker table. Even if you know poker pretty well, come a bit early and help out.

Emcee & Celebrity Guests: We’ll have Celebrity Bounties again! Knock out a celebrity and get neat EFF swag and the respect of your peers! Plus, as always, knock out Tarah's dad Mike, and she donates $250 to the EFF in your name!

The Celebrities: This year's event will feature many of our legal celebrities in our Legal Champions Edition edition.

The Glory: The tournament winner will receive the traditional Jelly Bean Trophy and we hope you’ll like this year’s newest add: We will have bug bounty pins this year! When you take someone out of the tournament, they will give you a pin. Prizes—and major bragging rights—go to the player with the most bounty pins.

Speakers:Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton

SpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy's Defender published by MIT Press in March, 2026. She is also the co-host of EFF's award-winning podcast, How to Fix the Internet.

--

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

SpeakerBio:  Jennifer Granick, Hacker lawyer 1.0

Throughout her career, Jennifer Granick has fought for civil liberties in an age of massive surveillance and powerful digital technology. As the former surveillance and cybersecurity counsel with the ACLU Speech, Privacy, and Technology Project, she litigated, spoke, and wrote about privacy, security, technology, and constitutional rights. Granick is the author of the book American Spies: Modern Surveillance, Why You Should Care, and What To Do About It, published by Cambridge Press and winner of the 2016 Palmer Civil Liberties Prize.

SpeakerBio:  Marcia Hofmann, Founder and Principal at Zeitgeist Law

Founder and principal of Zeitgeist Law, a boutique law firm focused on information security, computer crime, electronic privacy, free expression, and intellectual property issues. In the past, she has worked at Twitter, the Electronic Frontier Foundation, and the Electronic Privacy Information Center. She was a US-UK Fulbright Cyber Security Scholar based at the University of Oxford, where she studied educational and restorative justice programs for young computer crime offenders. She has taught courses in computer crime at Colorado Law and Internet law at UC Law San Francisco (then known as UC Hastings).

SpeakerBio:  Kurt Opsahl, Associate General Counsel for Cybersecurity and Civil Liberties Policy at Filecoin Foundation

Kurt Opsahl is the Associate General Counsel for Cybersecurity and Civil Liberties Policy for the Filecoin Foundation. Formerly, Opsahl was the Deputy Executive Director and General Counsel of EFF. Opsahl was also the lead attorney on the Coders' Rights Project, and continues to assist EFF with that work.

SpeakerBio:  Liz Wharton, Founder at Silver Key Strategies

Elizabeth (Liz) Wharton leverages two decades of legal, public policy, and business experience to build and scale cybersecurity and threat intelligence focused companies. Prior experience includes leading a third-party risk threat intelligence platform startup and serving as Atlanta's Senior Attorney overseeing technology policy and projects for the Airport and on it's ransomware incident immediate IR team. Awarded the 2022 “Cybersecurity or Privacy Woman Law Professional of the Year” by the United Cybersecurity Alliance, Liz volunteers as a mentor and for the Rural Technology Fund (Board member), ICS Village's Hack the Capitol (Planning Committee), and DEFCON (CFP Review Board). She received her JD from Georgia State University and her BA from Virginia Tech.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-10:59 PDT


Title: The Entropy Illusion: High-Speed Cracking on a Budget
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map

Description:

As modern password policies mandate 14+ characters, defenders have developed a false sense of security while red teams have entered a costly hardware arms race. But length is not the same as entropy. As policies grow stricter, human behavior becomes more predictable.

This session will demonstrate approaches focusing on high yielding results within a limited testing time frame and budget. We will explore tactics for leveraging custom probability masks, dictionary slicing and exploiting human predictability to prove brains still win over GPU's.

SpeakerBio:  Chris Claunch

CMIYC competitor (Team Cynosure Prime) 10+ years Red Teaming


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 16:35-17:05 PDT


Title: The Front Lines Need Detection Engineers : Would You Like to Know More?
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 16:35 - 17:05 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Would You Like to Know More? Becoming a Detection Engineer

Detection Engineering is one of the fastest-growing specialties in cybersecurity. But what does a Detection Engineer actually do?

In this beginner-friendly lightning talk, I'll share how I stumbled into Detection Engineering, what the job really looks like, the skills that mattered most, and the mistakes I wish I'd avoided. Whether you're a SOC analyst, student, or simply curious about the field, you'll leave with a clearer understanding of the role and practical steps to begin your own journey.

Citizenship not required. Curiosity mandatory.

SpeakerBio:  Kyle Barboza
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 10:00-10:59 PDT


Title: The Future of Bug Bounty - Program Manager Perspective
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Bug bounty is a proven model, but AI is changing how it runs. Researchers are submitting at higher volumes, LLM-generated reports are making triage harder, and new assets like AI agents and model endpoints are showing up in scope faster than programs can write playbooks for them. This panel brings together program managers from leading bug bounty programs to talk about what they're seeing from the other side of the queue. What has AI actually changed about the reports, the researchers, and the bugs that matter? What should program managers and security teams be doing about it now? And where is bug bounty headed over the next few years? Whether you run a program, hack on one, or want to start one, you'll come away with a clearer sense of what bug bounty looks like today and where it is going.

Speakers:Jai Kumar Sharma,Catherine Cassell,Austin Sturm,Dane Sherrets,Sachin "sachinnthakuri" Thakuri

SpeakerBio:  Jai Kumar Sharma, Principal Offensive Security Engineer at GoDaddy

Jai Sharma is a Principal Offensive Security Engineer at GoDaddy, where he leads cloud penetration testing, red team operations, AI red teaming, and security research across one of the world's largest domain registrars and hosting platforms. A self-taught offensive security researcher from New Delhi, India, he built his career with a hacker's mindset, breaking code logic, chasing vulnerabilities, and proving real-world business impact from technical exploits. He also leads TTP research, drives threat emulation efforts, and works closely with blue teams to sharpen detection through an adversary-focused lens.

At GoDaddy, Jai tests the same infrastructure and enterprise environments that millions of customers rely on. His work spans cloud and on-premises penetration testing, IAM privilege escalation research, and building automated offensive tooling that helps turn point-in-time assessments into continuous detection. Before GoDaddy, Jai held offensive security roles at Housing.com, FIS, and EY, giving him firsthand experience with how security weaknesses and misconfigurations surface across different industries, architectures, and maturity levels.

Jai volunteers with the DEF CON community as CTF Ops for the Cloud Village and on-site Coordinator for the Bug Bounty Village.

SpeakerBio:  Catherine Cassell, Product Security Engineer at Github

Catherine is a security engineer on the bug bounty team at GitHub. She has five years of experience in offensive security, working in both bug bounty and penetration testing. Catherine has spent the last year and a half at GitHub and runs an annual hardware hacking workshop at the Glass Firewall Conference. At work, she spends her days reading and triaging bounty reports. Outside of work, she spends her free time outside, as far away from screens as possible. You can usually find her hiking or skiing in the Rocky Mountains.

SpeakerBio:  Austin Sturm

He started as a no-good kid on IBB forums and landed a job doing offensive security for large tech companies. For some tireless years he ran and built a team for a cloud providers bug bounty program and continues to act as a tech lead for a bounty program in the wake of the AI-era

SpeakerBio:  Dane Sherrets, HackerOne

Dane is an Innovations Architect at HackerOne, where he helps organizations run AI-focused bug bounty programs and improve the security of emerging technologies. His work includes winning 2nd place in the Department of Defense AI Bias Bounty competition, discovering critical vulnerabilities in platforms like Worldcoin, and helping design and manage Anthropic's AI Safety Bug Bounty program. Drawing on his background as a bug hunter, Dane blends strategic guidance with hands-on expertise to advance the safety and security of disruptive tech across industries.

SpeakerBio:  Sachin "sachinnthakuri" Thakuri, Senior Product Security Engineer at TikTok

Sachin Thakuri is a Senior Product Security Engineer at TikTok, where he leads Variant Analysis initiatives to identify and eliminate classes of vulnerabilities across the platform. His work focuses on variant analysis, vulnerability management, product incident response, and building Al-powered security tooling. Previously, Sachin help build and led application security programs at Alpha Group, Pintu, and Grab. Sachin has also presented his research at security conferences like Black Hat, Insomni'hack, GreHack.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 10:45-11:30 PDT


Title: The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation
Tags: Payment Village | Creator Talk/Panel
When: Friday, Aug 7, 10:45 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

The payments industry is entering a new era of transformation, where AI reshapes the way consumers and businesses buy, pay, and determine risk throughout the payment journey.

Join leaders from across the payments ecosystem as they explore the technologies, opportunities, and challenges shaping the future of this space. This panel will examine how financial institutions, payment providers, merchants, and technology companies are preparing for a world where AI augments decision-making, automates operations, and increasingly acts on behalf of users to deliver more seamless, secure, and intelligent payment experiences.

Attendees will gain actionable insights into the technologies and market forces redefining payments. Panelists will share their perspectives on the emerging innovations, strategic priorities, and industry shifts that will shape the next generation of payment experiences. They will offer practical guidance on how organizations can prepare for an increasingly intelligent, automated, and interconnected payments ecosystem.

Speakers:Daniel Cuthbert,Leigh-Anne Galloway,Jorge Braniff,Sanjeev Sharma

SpeakerBio:  Daniel Cuthbert, Global Head of Cyber Security Research, Banco Santander

Daniel Cuthbert is the Global Head of Cyber Security Research at Santander, where he leads global security research and drives innovation in cyber defence across the organisation. He serves on the Black Hat Review Board and is a founding member of OWASP, having co-authored both the OWASP Testing Guide and the OWASP Application Security Verification Standard (ASVS). With more than 20 years of experience in offensive security, application security, and threat research, Daniel is a frequent speaker and trusted advisor on emerging cyber threats, secure engineering, and security strategy.

SpeakerBio:  Leigh-Anne Galloway, Founder, Payment Village

Leigh-Anne Galloway is a security researcher and testing specialist focusing on payment security, application security, fraud, and adversarial testing. Leigh-Anne is the founder of The Payment Village, a non-profit initiative dedicated to educating people on the intricacies of payment systems, fostering the next generation of payment security professionals, and creating space for critical discussion within the industry. She has presented and authored research on ATM security, mPOS vulnerabilities, NFC payments, fraud, and application security.

SpeakerBio:  Jorge Braniff, VP of Fraud and Product Operations at Incode Technologies

Jorge Braniff is VP of Fraud and Product Operations at Incode Technologies, where he leads a global organization spanning fraud detection, document intelligence, red team, data collection, labeling and identity verification. His work sits at the center of the agentic fraud arms race: partnering with ML on the development of models for supporting all ID templates, deepfake detection, presentation attacks, document tamper, alteration, liveness and AI detection. Jorge has led fraud ring detection initiatives using graph-based identity linkage to uncover coordinated attack networks and has run high-stakes technical evaluations against fraud rings targeting neobanks and payment platforms. He has also hardened SDKs against injection and deepfake-based attacks for major financial institutions and fintechs and developed model governance and evaluation frameworks used to benchmark fraud detection performance in production. He brings a builder’s perspective to the fight against AI-driven fraud, having scaled operations and detection systems across multiple countries. He is based in the San Francisco Bay Area.

SpeakerBio:  Sanjeev Sharma, Director, Payments Product, GoFundMe

Sanjeev has been building payment products since 2013, beginning his career at Visa as part of the original Visa Token Service (VTS) product team. He played a key role in launching and commercializing VTS across multiple countries and continents, helping drive the adoption of tokenized payments at global scale. He later joined Meta, where he worked on payments across the family of apps, including helping launch WhatsApp Payments in India. Today, Sanjeev is a Product Manager in the Payments Product Group at GoFundMe, where he focuses on building secure, scalable payment experiences that help people support one another around the world.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 13:20-13:59 PDT


Title: The Hidden Cost of Agentic Connectivity
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 13:20 - 13:59 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

During our extensive research on MCP servers, we uncovered critical vulnerabilities that pose significant risks to the cloud infrastructure management. These vulnerabilities enable malicious actors to interact with and compromise organizational infrastructure. Alarmingly, while some MCP servers had implemented protective measures against such misuse, these measures were often flawed, allowing for trivial bypasses.

In this presentation, we will underscore the necessity of comprehensive visibility and robust policy guidelines for every organization. Our analysis of over 19,000 MCP servers reveals substantial gaps and vulnerabilities within the so-called security features of these systems. We will demonstrate how these security features can be bypassed and highlight the real-world implications of these vulnerabilities.

Through active scanning, we identified the same vulnerable MCP server implementations deployed in the wild, confirming that these vulnerabilities are actively exploitable. This underscores the urgent need for organizations to adopt a strategic approach to managing MCP servers.

Our aim is for attendees to understand th e critical importance of AI security beyond mere vulnerability management. Our findings show that even if the MCP server is not vulnerable, default deployments often introduce significant risks to organizational security. We will conclude our presentation by outlining best practices for mitigating the risks associated with MCP servers, ensuring that attendees leave with actionable insights to enhance their organization's security posture.

Speakers:David Fiser,Amy McMahon

SpeakerBio:  David Fiser

David Fiser is a cybersecurity professional with over 15 years of experience. He regularly contributes to blogs and co-authors whitepapers on various security topics. He has been credited with several CVEs, including high-profile vendors such as Microsoft and NVIDIA. He presented his previous research at multiple security conferences. Personally, David is passionate about motorsport, cars, planes, and motorcycles. He also likes fixing broken items and traveling.

SpeakerBio:  Amy McMahon

Amy is a seasoned Systems Engineer with 20 years of experience supporting enterprise customers through the evolution of TippingPoint spanning its tenures under 3Com, Hewlett Packard Enterprise, and Trend Micro. With deep expertise in network security and intrusion prevention, Amy has built a reputation for translating complex network security challenges into actionable solutions for large-scale enterprise environments. Currently serving as a Subject Matter Expert in Networking Solutions at TrendAI, Amy brings both technical depth and strategic perspective to emerging AI-driven security challenges. She holds multiple industry certifications including CISSP, CEH, and AWS Solutions Architect, reflecting her commitment to staying at the forefront of network cybersecurity and cloud architecture.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 15:00-15:15 PDT


Title: The impact of CTF Write-Ups
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:15 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Over three years I've published 150+ write-ups on CTF challenges. Along the way the write-ups stopped being just documentation and started being the most valuable thing I produce — sourcing job offers, collaborations, and credibility I never directly asked for. This talk makes the case that a write-up is not the report of your work but the work itself: where learning consolidates and reputation compounds. I'll share the concrete payoff, the craft, lessons learned, and a blueprint anyone can start with. No novel 0-day, just maybe the most underrated force multiplier in offensive cyber security.

SpeakerBio:  Mathias Detmers
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 19:00-21:59 PDT


Title: The KEVOPS Sellout Pool Party II: Sponsored by Zyn
Tags: Party
When: Friday, Aug 7, 19:00 - 21:59 PDT
Where: Sahara Hotel Azul Ultra Pool - Map

Description:

The Sellout Pool Party is back. Join us for tacos and music!


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 14:00-14:30 PDT


Title: The Liability Stack: When Code Becomes Conduct
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

The legal question of when publishing code creates responsibility for downstream harm has never been fully settled, but the practical separation between writing code and being treated as responsible for its downstream use is breaking down across AI, crypto, cybersecurity, and platform law. Courts and regulators are increasingly reaching contradictory conclusions about structurally similar systems: autonomous agents acting on third-party platforms, open-source developers accused of operating financial infrastructure, secure-by-design evolving into reasonable-care expectations, and recommendation systems reframed as product design rather than publication. This talk maps common doctrinal tension underneath those debates and argues that traditional legal categories fail when control, deployment, and operation are distributed across maintainers, deployers, validators, governance participants, and autonomous systems. Rather than focusing on labels like developer or platform, it proposes a functional framework centered on control, participation, foreseeability, and proximity to harm. The current incoherence is itself becoming a systemic risk, and the people building these systems should help shape the framework before courts finish improvising one for them.

SpeakerBio:  Carole House, Penumbra Strategies

Carole House is a strategic technology executive who has spent her career focusing on leveraging innovative technologies to combat national security threats. She is the founder and CEO of a strategic technology and national security advisory practice, Penumbra Strategies, senior advisor to New Vista Capital, Member of the California Innovation Council, and serves as a Distinguished Senior Fellow at the Association for Certified Anti-Money Laundering Specialists (ACAMS) and a Senior Fellow at the Atlantic Council GeoEconomics Center. Carole recently served as the White House National Security Council (NSC) as Special Advisor for Cybersecurity and Critical Infrastructure and Director for Cybersecurity and Secure Digital Innovation. During her time at the White House, Carole architected two Executive Orders driving critical steps to promote innovation in cybersecurity, digital identity, artificial intelligence, and digital assets. Carole has held positions in venture capital and served on corporate and advisory boards for three financial regulatory agencies, three non-profits, and an AI and quantum security startup. Carole's prior government experience includes service as a U.S. Army Captain and across the White House, Senate Homeland Security Committee, and the U.S. Treasury.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Friday - 15:45-16:45 PDT


Title: The Modern Detection Engineer
Tags: Blue Team Village | Creator Talk/Panel
When: Friday, Aug 7, 15:45 - 16:45 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

Detection Engineering is a concept rooted in decades of blue teaming, but applied with a modern lens. At its core, it’s a practice where a blue teamer can apply principles across software engineering, security analysis, and data science to detect and respond to threats without needing to staff a traditional SOC. In 2026, this field is in the spotlight due to the meteoric growth of technology and AI, but like any field in security, it has its sharp edges and broken promises.

In this panel, we will discuss Detection Engineering in 2026 with a diverse set of experts who work on these problems every day. We will cover topics around threat research and hunting, writing and maintaining a ruleset, modern CI/CD practices for blue teams & codifying incident response in security operations.

Speakers:Alex Hurtado,Chase Phelps,Chris Kulakowski,Christina Parry,Zack Allen

SpeakerBio:  Alex Hurtado

Alex Hurtado spent years using, tuning, and implementing SIEMs across Fortune 500s and startups alike before landing as Head of Detection Strategy at Nebulock. She builds content on SIEM and detection engineering and hosts Detection Engineering Dispatch, a podcast bringing detection engineers together to compare notes and move the space forward.

SpeakerBio:  Chase Phelps

Chase Phelps is a Senior Detection Engineering Manager at Marsh, leading detection, response automation, and AI/ML tooling for a large-scale SOC. He started his career in the IT space, working roles from Desktop support to System Engineer. He made the jump to Security starting in the SOC before making the move to Detection Engineering. Outside of work, he's likely to be found in the gym, on the golf course, or playing Old School Runescape.

SpeakerBio:  Chris Kulakowski

Chris Kulakowski is a driven technologist, innovator, and tinkerer of all things. His career spans across 15 years of Digital Media, Information Technology, Security Operations, Threat Intelligence and Digital Forensics roles. He is currently a senior technical staff member specializing in threat detection at IBM, supporting IBM internal businesses. Prior to IBM he held various roles at General Motors and Optiv. He is seasoned in responding to incidents, developing new threat detection content, and an expert in EDR technology.

Chris holds a Computer Criminology degree from Florida State University and several industry leading cyber security and digital forensics certifications including CISSP, EnCE, GCFE, GREM, GMON and Security+. Chris is also accredited with a Stanford University Advanced Computer Security Certificate and a member of the GIAC Advisory Board and author of 3 US patents.

SpeakerBio:  Christina Parry

Christina Parry is a Staff Security Engineer at Huntress and a technical leader with 9+ years in tech and security, specializing in detection engineering, automation, and open-source software. She's experienced in building high-impact, scalable software solutions that automate everyday security workflows and elevate detection and response teams. Before Huntress, she was a Detection Engineer at Twitter and a member of the Threat Hunt team at Morgan Stanley. Christina is a mentor and ally for underrepresented groups in security, and sometimes comes out of her shell to nerd out about the things she cares about.

SpeakerBio:  Zack Allen

Zack has been in the security field for 14 years. He started as a contractor for the Air Force then moved into the startup world before landing at Datadog. At Datadog, he built the security research and labs department and grew their security products and threat detection programs.

He is also the creator of Detection Engineering Weekly, a Substack dedicated to detection engineering, incident response & threat intelligence.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 15:00-15:59 PDT


Title: The New Horizons in Quantum and Space
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

While the industry obsesses over AI security, two frontier domains are quietly creating the next generation of high-demand security careers: post-quantum cryptography and space security. With NIST's PQC standards finalized, federal migration mandates in force, and harvest now, decrypt later attacks already underway, quantum readiness has shifted from research topic to boardroom priority. Meanwhile, exploding satellite constellations, contested orbits, and rising attacks on ground stations and command-and-control systems have made space a critical infrastructure battleground with a severe talent shortage. This talk breaks down the latest technological advances in both domains, the real-world threats driving demand, and the practical skills, certifications, and communities that can launch your career there. You'll leave with a concrete upskilling roadmap and a clear view of why quantum and space are the smartest career bets in security today.

SpeakerBio:  Anshu Gupta
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 16:10-16:50 PDT


Title: The New Software Supply Chain Nobody is Securing: MCP
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 16:10 - 16:50 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Friday - 15:00-15:59 PDT


Title: The Political economy of AI
Tags: Hackers.town | Creator Talk/Panel
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  Janet Vertesi, Officer at Tech Reclaimers
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 15:30-16:10 PDT


Title: The Polymorphic Agent: From Cross Agent Escalation to Just in Time Defense on Azure
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 16:10 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

A permission error halts conventional malware. AI agents are being assigned standing cloud IAM permissions and the autonomy to use them, a combination that breaks an assumption every existing control depends on. The agent reasons its way to an escalation path through the cloud provider's own IAM APIs. We call this the polymorphic agent. This talk presents research cross-agent privilege escalation between independent AI agents & defense around it.

The attack begins with a single poisoned tool description, rewritten to read like routine compliance guidance. The agent parses the injected text, reasons about it, and grants itself elevated IAM roles. this showcases how a compromised Agent A modifies the role assignments of a separate Agent B, running a different framework in a seperate environment and never issued a malicious instruction, expanding Agent B's authority entirely through authorized IAM calls. This points directly to two risks named in the OWASP MCP Top 10: Privilege Escalation via Scope Creep (MCP02), achieved through Tool Poisoning (MCP03). To test whether this is agent-specific, we ran the attack across three production agents, including LangChain and Claude Code. All three escalated, the pattern is consistent: prompt-layer guardrails are reformable, human approval is socially engineer-able, and telemetry arrives too late.

These results frame two requirements for any workable defense: the escalation must be measurable in real time, and it must be blocked at a point the agent cannot reach. Enforcement has to move to the credential layer, since an agent cannot act on the cloud without first obtaining a credential. This is the gap PrivilegeGuard closes, an out-of-process credential gateway that intercepts DefaultAzureCredential and slots into existing agent deployments with minimal to no code change.

On each token request, it computes the requesting Non-Human Identity’s Blast Radius Score (BRS): the fraction of the cloud resource surface reachable by that identity across a two-hop IAM graph traversal, providers reachable under current role assignments plus those reachable after a simulated roleAssignments/write self-escalation. PrivilegeGuard evaluates BRS and its rate of change against an Open Policy Agent (Rego) policy and denies an anomalous, high-blast-radius request before the escalated role is usable.

The takeaway is architectural: cross-agent escalation follows from giving probabilistic, goal-driven agents standing IAM credentials, not from any single agent or framework, and it widens as agents gain access. We deliver the attack on real Azure identities, and an enforcement model that stops it where the agent cannot follow: the credential layer.

SpeakerBio:  Muskan Tomar

Hey, I am Muskan Tomar, a Security and Reliability Engineer at MICROSOFT, where I work at the intersection of Site reliability, Infrastructure Security, and Software Engineering building systems that are expected to never go down, stay secure, and scale quietly in the background. 5X Microsoft Azure Certified , with experience working on architecting and modernising, securing cloud platforms and reducing operational toil through automation, AI and data driven engineering. My independent research focuses on AI agent security and cloud identity, and how autonomous agents change the threat model for systems we trust to stay locked down. An enthusiastic learner who champions collaborative cloud and security research, I enjoy untangling complex systems and eliminating single points of failure. Outside work, I love to travel and paint.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 11:00-11:30 PDT


Title: The Ripple Effect: Inside Cloud-Scale Vulnerabilities in the Age of AI
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Security researchers never see the true impact of their work. You submit a vulnerability report, it disappears into a queue, and eventually get a "resolved." But what actually happened on the other side? This talk changes that. Through a real-world case study, you'll see what happens when a single vulnerability report hits a cloud provider at scale and keeps going. What makes cloud vulnerabilities fundamentally different from traditional targets? How do you prioritize remediation when the blast radius spans services, regions, and third-party dependencies you didn't know existed? You'll see the crucial trade-offs no one talks about publicly, and a series of challenges that textbook CVD (coordinated vulnerability disclosure) was never designed to handle. And that challenge is accelerating. AI vulnerability discovery tools are uncovering valid vulnerabilities faster than traditional VDP (Vulnerability Disclosure Program) models were architected to process. The model that worked five years ago is buckling, and its impact is felt across organizations worldwide. Researchers wait longer. Defenders fall behind. The gap between discovery and remediation is widening, and attackers live in that gap. This talk introduces the 3 Principles for modern VDPs, which were forged from operating vulnerability disclosure at the world's largest cloud infrastructure. These apply whether you're running a program or reporting to one. Security researchers researchers will learn what actually happens after you hit submit, and how to write reports that accelerate everything downstream. Defenders will learn how to scale their programs for the velocity that's already here.

Speakers:Albin Vattakattu,Ryan Nolette

SpeakerBio:  Albin Vattakattu

Albin leads the global Vulnerability Disclosure Program (VDP) for Amazon Web Services (AWS). Albin's work has been featured by HackerOne, the SANS Institute, the AWS Security Blog, and at multiple international conferences.

Prior to AWS, Albin led incident response teams across North and South America, defending foreign governments and fortune 100 companies against DDoS campaigns by APTs.

SpeakerBio:  Ryan Nolette

Ryan is AWS's Senior Security Engineer and CoAuthor of AWS Detective. He has previously held a variety of roles including threat research, incident response consulting, and every level of security operations. With almost 2 decades in the infosec field, Ryan has been on the development and operations side of companies such as Postman, Sqrrl, Carbon Black, Crossbeam Systems, SecureWorks and Fidelity Investments. Ryan has been an active speaker and writer on threat hunting and endpoint security.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 16:00-16:59 PDT


Title: The Sandbox is a Suggestion: Deconstructing AI Agent Sandboxes
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Every major AI coding agent ships inside a containment system. I analyzed three of them - Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex CLI - and each one breaks on its own terms.

Each sandbox uses a different containment model: permission-based access control, process-level environment sanitization, and kernel-level filesystem enforcement. Each makes a structural assumption about what the runtime will do. Each assumption is wrong.

This talk deconstructs all three architectures, shows what each claims to enforce, and demonstrates how the containment fails - not through prompt injection or model persuasion, but through gaps in the design itself. Every exploit is deterministic, demo-ready, and was reported through coordinated disclosure.

Attendees leave with a reusable methodology for evaluating any AI agent sandbox: identify the containment mechanism, read the enforcement code, find the structural assumption it depends on, and test whether the runtime violates it. The cross-vendor comparison shows that different engineering teams, solving the same problem independently, make structurally similar mistakes - and that the pattern is predictable once you know where to look.

SpeakerBio:  Elad Meged, Novee Security

Elad Meged is a Founding Engineer and Security Researcher at Novee Security, specializing in offensive security research and AI security. He holds an M.Sc. in Computer Science and has a background in vulnerability research across web, mobile, and low-level systems, with experience in reverse engineering and platform internals. His current work applies offensive research methodology to AI systems while developing AI-driven approaches to vulnerability discovery and exploit verification.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 10:10-11:40 PDT


Title: The Silent Tunneler: A Real-World Incident Response Story
Tags: Malware Village | Creator Workshop
When: Friday, Aug 7, 10:10 - 11:40 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map

Description:

Some backdoors are noisy. Others whisper.

During a real-world Incident Response investigation, I uncovered an unusually stealthy Linux persistence mechanism that had silently granted an attacker continued access to a compromised system. Even more concerning - it was used to establish an SSH tunnel, allowing undetected remote control while evading traditional security measures.

But that wasn’t all. Further analysis led to an even bigger discovery: a live Mirai botnet infection, actively communicating with its command-and-control server. By reverse engineering the malware, I unraveled how it spread, operated, and executed attacks.

This talk is a practical, real-world case study, covering: * How I uncovered an unconventional backdoor that nearly went unnoticed. * The attacker’s use of SSH tunneling for covert persistence. * Reverse engineering a Mirai botnet sample and dissecting its attack mechanisms. * Key lessons for defenders to detect and respond to stealthy threats.

Expect live demonstrations, technical deep dives, and actionable insights to strengthen your EDR detection capabilities.

SpeakerBio:  Uriel Kosayev, Security Researcher, Trainer & Speaker | Author of the Antivirus Bypass Techniques book | Founder of TrainSec Academy

Uriel Kosayev is a seasoned cybersecurity researcher, reverse engineer, and keynote speaker with over a decade of hands-on experience in malware analysis, offensive security, and real-world incident response.

He is the founder of TrainSec Academy and the author of Antivirus Bypass Techniques and MAoS – Malware Analysis on Steroids, two highly regarded resources in the cybersecurity community. Uriel has worked with global enterprises, led red team operations, and conducted high-impact malware investigations that exposed advanced threat actor tactics.

Known for his ability to break down complex topics into practical, actionable knowledge, Uriel teaches with one goal in mind: to make professionals think like attackers and act like defenders. His courses are packed with real-world examples, battle-tested techniques, and a methodology built on actual field experience, not textbook theory.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 14:55-15:35 PDT


Title: The State of Decompiler Malware
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 14:55 - 15:35 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

This research introduces Decompiler Malware, an underexplored threat category targeting reverse engineering platforms such as IDA Pro. The work began with the discovery and analysis of a malicious IDA Pro plugin that established a covert encrypted backdoor capable of remotely interacting with the analyst environment, manipulating analysis workflows, and exfiltrating decompiled pseudocode and reverse engineering artifacts on demand.

By examining the malware’s architecture, command capabilities, and operational design, this research highlights how reverse engineering workstations represent a uniquely valuable but insufficiently defended attack surface (unless air-gapped).

SpeakerBio:  Christopher Hernandez, Binary Enthusiast

Chris Hernandez is a security researcher specializing in vulnerability discovery, exploitation, and large scale reverse engineering using IDA Pro. A Pwn2Own competitor in the ICS/SCADA and embedded systems categories, he actively collaborates with the reverse engineering community to solve binary analysis challenges.

--

Chris Hernandez is the founder of Adversary Consulting Group and an offensive security researcher with more than a decade of experience in vulnerability research, reverse engineering, and exploit development. He holds the OSEE certification and has competed at Pwn2Own in the IoT and ICS/SCADA categories.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 15:00-15:59 PDT


Title: The Stream Is Dead, Long Live the Stream: How HTTP/2 Lets Dead Streams Keep Servers Working
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Modern protocol bugs rarely look like flaws in the protocol itself. They show up when a clean spec meets existing server architectures. HTTP request smuggling showed this for request boundaries: implementations disagreed about where one request ended and the next began. This talk asks a similar question about HTTP/2 request lifetime: what happens when one layer thinks a request is over, while another is still working on it?

In 2023, Rapid Reset showed the world that HTTP/2 had a problem: attackers could open and reset streams faster than servers could keep up. The disclosure triggered an industry-wide patching scramble, but patches addressed the symptom, not the root cause.

Two years later, I disclosed MadeYouReset through CERT/CC as CVE-2025-8671, exploiting the same root cause through a different door and setting off a second round of patches across the ecosystem, including Apache Tomcat, H2O, Netty, and others.

In this talk, I’ll show how research that started with Rapid Reset led to MadeYouReset, and how both create streams closed at the HTTP/2 layer while server-side request work continues. We’ll see why this gap exists, why fully fixing it is infeasible, and what conditions make MadeYouReset especially harmful.

Finally, we’ll answer the question: is the next HTTP/2 abuse already waiting around the corner?

CERT/CC VU#767506: https://kb.cert.org/vuls/id/767506 NVD CVE-2025-8671: https://nvd.nist.gov/vuln/detail/CVE-2025-8671 MadeYouReset blog posts: https://galbarnahum.com/made-you-reset

SpeakerBio:  Gal Bar Nahum, Tenzai

Gal Bar Nahum is a security researcher at Tenzai with eight years of experience in vulnerability research, network protocol security, red teaming, and AI research.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 15:30-15:59 PDT


Title: There and Back Again
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

In 2025, Mojave Research received an assignment its founders never expected: examine security vulnerabilities in voting equipment used during Puerto Rico’s 2024 elections. What appeared to be a bounded technical project quickly became a journey through voting technology, digital forensics, incomplete evidence, institutional friction, and the difficult line between what a system could permit and what the evidence proves actually happened. Jason Wareham and Manbir Gulati will explain how Mojave became involved, what the team was asked to do, and how two outsiders to election administration found themselves examining technology at the center of a national argument about security and public trust. Jason will describe the origins and evolution of the assignment, along with the challenge of keeping a technical investigation tied to evidence when others already have firm expectations about the answer. Manbir will take the audience inside the technical problem at a level appropriate for public discussion: how investigators approach unfamiliar election systems, assess available hardware and software, reason from constrained artifacts, evaluate weaknesses, and separate a possible attack path from evidence of exploitation and what remains to ensure the security of these critical systems is inviolate. Mojave’s examination identified real software and security concerns. It did not YET find evidence that the equipment examined had been hacked or that votes had been altered. That distinction is central to the story—and to any honest discussion of election security. The talk will conclude with an announcement of, and invitation to, a private initiative aimed at reducing voting-system risk before the 2026 midterm elections absent of politics. This is a brief account of how a national-security startup entered an unfamiliar and politically charged field, followed the evidence through an unexpected assignment, and concluded that documenting the problem was not enough.

Speakers:Jason Wareham,Manbir Gulati

SpeakerBio:  Jason Wareham

Jason Wareham is CEO of Mojave Research Inc. and CEO and Chairman of Agentic Secure Group. In 2025, the Office of the Director of National Intelligence (ODNI) engaged Mojave Research to examine security vulnerabilities in voting equipment used during Puerto Rico’s 2024 elections.

Jason previously spent nearly two decades handling military, criminal-defense, and national-security matters. He served as a U.S. Marine Corps officer and judge advocate and reached the rank of lieutenant colonel. His work included trials, appeals, military commissions at GTMO, classified information, and digital evidence. The Marine Corps designated him a Master of Criminal Law, and he later worked as a senior litigation adviser and trainer before concluding his private practice.

Jason holds an LL.M. from Georgetown University Law Center, where his studies focused on cybersecurity, digital forensics, electronic discovery, and cybercrime. He earned his J.D. from Creighton University and authored “Cracking the Code,” a Georgetown Law Technology Review article about compulsory decryption and the Fifth Amendment.

At Mojave Research, Jason works on national-security technology, secure artificial intelligence, cybersecurity, and technical investigations subject to legal and institutional scrutiny. His approach is simple: establish what the evidence proves, identify what it does not prove, and resist pressure to blur the difference.

SpeakerBio:  Manbir Gulati
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 12:40-15:10 PDT


Title: Threat Actors: Gotta Catch 'Em All
Tags: Recon Village | Creator Workshop
When: Friday, Aug 7, 12:40 - 15:10 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:
Your mission: Stop chasing single indicators and start profiling the actual behavior of the adversary. From cybercriminals to state-sponsored actors, every threat group leaves a unique operational blueprint. Whether you are an OSINT hobbyist or an experienced cyber intelligence analyst, come ready to dissect real-world attack behaviors, translate data into actionable insights, and master the art of OSINT-powered TTP research.

This hands-on workshop explores the world of cyber threat actors and the open-source intelligence (OSINT) methodologies used to unmask their behavioral patterns. Rather than focusing strictly on fleeting indicators of compromise (IoCs) like file hashes or IP addresses, participants will learn how to extract, analyze, and profile an adversary's true Tactics, Techniques, and Procedures (TTPs).

Through interactive, real-world case studies, attendees will learn how to analyze public incident reports, open intelligence repositories, and external datasets to map out an actor's operational playbook. Using frameworks like MITRE ATT&CK and the Diamond Model, participants will practice pivoting from technical data to strategic threat profiles—equipping them with the research skills needed to predict and counter adversarial behavior without ever needing an enterprise budget.

Workshop Structure:

Module 1: Foundations of Threat Intelligence & Actor Profiling

The Threat Landscape: Definitions and categories of actors (APTs, cybercriminals, hacktivists, insiders).

Understanding Adversarial Motivation: Moving beyond what happened to why and how actors select their targets and techniques.

Intelligence Categorization: Differentiating between Strategic, Operational, and Tactical/Technical intelligence, and how TTP research feeds all three.

Module 2: The Analytical Frameworks

MITRE ATT&CK Deep Dive: Navigating the matrix, understanding sub-techniques, and avoiding common mapping pitfalls.

The Diamond Model: Connecting the four core nodes (Adversary, Capability, Infrastructure, Victim) to tell a complete campaign story.

The Pyramid of Pain: Understanding why tracking TTPs inflicts the maximum cost on the adversary compared to trivial indicators.

Module 3: Dissecting the Data (Case Study Analysis)

Deconstructing DFIR Reports: Walking through real-world incident examples (e.g., Gootloader campaigns, ransomware operations) to extract behavioral indicators from public write-ups.

Safe Analysis Practices: Utilizing basic web-based OSINT tools (urlscan.io, Browserling, CyberChef) to safely evaluate delivery mechanisms and landing pages without compromising investigator safety.

Module 4: Live TTP Research (Group Exercise)

The Scenario: Groups are given an initial, ambiguous threat brief or a raw dataset from a recent campaign.

The Analysis: Using open-source resources, teams will collaborate to identify the actor's threat components (who, what, where, when, how, why).

The Playbook: Teams will map their findings into the MITRE ATT&CK Navigator, build a comprehensive threat intelligence profile, and present their adversarial playbook to the room.

Speakers:Marcelle Lee,Will Thomas

SpeakerBio:  Marcelle Lee
No BIO available
SpeakerBio:  Will Thomas
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Friday - 12:00-12:30 PDT


Title: Threat Hunting in OT Networks - Using Hypothesis Based Methods
Tags: ICS Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Operational Technology (OT) networks present unique challenges for cybersecurity professionals tasked with detecting and mitigating threats. These networks, often critical to industrial control systems and infrastructure, require specialized approaches due to their complexity, legacy systems, and operational sensitivities. This presentation explores the art and science of threat hunting in OT environments, emphasizing the use of hypothesis-based methods to uncover hidden adversaries and anomalous behaviors.

Attendees will gain insight into the special considerations and hazards associated with OT networks, including safety-critical systems, real-time constraints, and the potential for operational disruption. The talk will also provide a structured approach to hypothesis development, testing, and refinement, enabling practitioners to systematically investigate potential threats with minimal impact on operations.

Finally, the presentation will delve into the practical logistical steps required to conduct threat hunts and incident response (IR) in OT environments, addressing challenges such as network segmentation, communication protocols, and coordination with operational teams. Whether you're a seasoned cybersecurity professional or new to OT security, this discussion will equip you with actionable strategies for effectively hunting threats in these critical and often misunderstood environments.

SpeakerBio:  Michael Cardwell, INL

Michael Cardwell is a Cybersecurity Analyst and Researcher for the OT Hunt and Incident Response team at the INL. He has officially worked at the Lab since 2016 and has held various positions at the lab. One of the highlights of his time at the lab includes being the technical lead for the development of the Malcolm tool, which is a threat hunting tool suite developed at the INL for OT threat hunting. He has participated in hunts, IR’s and assessments in OT networks.

Prior to working at the Lab he was an ISSO (Information System Security Officer). He also worked in the private sector as an IT Security Administrator for 10 years before that.

He holds degrees in Electronics, Computer Science, and Cybersecurity. He currently lives in Idaho with his wife, 2 children and lots of cats.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Friday - 13:00-13:15 PDT


Title: Threatmaxxing Your Stakeholders while Mogging Your Threat Actors: What is Cyber Threat Intel?
Tags: Noob Community | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:15 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

This is a 15 minute lightning talk with an intro/brief overview of the Cyber Threat Intelligence discipline. Topics covered include why it's so hard to identify and define what CTI is in the current industry, the different aspects of what can be expected from CTI, and the typical backgrounds of CTI practitioners.

Having been a part of CTI teams at organizations with a wide variety of resources and maturity levels, this talk provides a realistic, ground-level view of the industry and what your average CTI experience is like, not the curated experiences of Fortune 500 CTI teams we all see presenting on the main stage.

SpeakerBio:  Eli Woodward, Senior Threat Intelligence Advisor with Team Cymru

Eli Woodward is a cyber threat intelligence advisor with Team Cymru. He's worked in a variety of industries including financial services and government, and has seen the range of organizations from extremely well-resourced and capable to the shoestring budget. This has given him unique insights into CTI at all levels of complexity, maturity, and resources. He holds a master's degree in Intelligence and Security Studies and also plays bagpipes competitively.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Tin Foil Hat Contest
Tags: Tin Foil Hat Contest | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest) - Map

Description:

Want to protect your noggin from government mind control rays? Have you angered our new AI Overlords, and now need to hide? Maybe those alien brainwave blasters just have you feeling down lately? Or do you just want to do something fun and forget about the world's woes for a while? Fear not, for we here at the Tin Foil Hat Contest have your back for all of these! Come find us in the contest area, and we'll have you build a tin foil hat which is guaranteed to provide top quality protection for your cerebellum . How you ask? SCIENCE!

Show us your skills by building a tin foil hat to shield your subversive thoughts, then test it out for effectiveness.

There are 2 categories: stock and unlimited. The hat in each category that causes the most signal attenuation will receive the ""Substance"" award for that category. We all know that hacker culture is all about looking good though, so a single winner will be selected for ""Style"". We provide all contestants a meter of foil, but you're welcome to acquire and use as much as you want from other sources.

This year is dedicated to our brother & contest creator, Flirzan. We'll never forget drunkenly hashing this out on a napkin with you at DEFCON many years ago. Rest in peace, we miss you friend!

Participant Prerequisites

We supply the base materials to participate. Contestants are welcome to bring additional foil if they desire.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 15:00-15:45 PDT


Title: TokenMesh: Exposing Azure's Hidden Identity Attack Surface
Tags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | DEF CON Demo Labs
When: Friday, Aug 7, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

Modern cloud environments are riddled with identity misconfigurations that go undetected until it's too late. TokenMesh is an open-source Azure security reconnaissance tool built to expose exactly that — over-privileged identities, dormant service principals, misconfigured storage accounts, and potential backdoors hiding in plain sight across Microsoft Entra ID and Azure RBAC. Unlike traditional scanners that drown you in raw data, TokenMesh is designed with the security practitioner in mind. It integrates directly with the Model Context Protocol (MCP) and the OpenAI API, allowing AI-assisted analysis that surfaces critical findings in plain language — no SIEM required, no query language to master. Plug it into your AI workflow of choice, ask questions in natural language, and get answers that actually make sense. In this session, we'll walk through how TokenMesh was built, the real-world attack paths it uncovers, and live demonstrations against a target Azure environment. We'll cover how attackers abuse identity misconfigurations, how privilege escalation paths hide inside legitimate role assignments, and how defenders can use TokenMesh to harden their posture before adversaries exploit it. Whether you're a red teamer mapping an Azure tenant or a blue teamer trying to get ahead of the next breach.

SpeakerBio:  Saksham Agrawal

Saksham Agrawal is a Senior Security Consultant at NotSoSecure, specializing in cloud security. His work focuses on discovering new attack paths in cloud environments and helping organizations understand real-world risks. He has presented his research at DEF CON Cloud Village, where he introduced his tool NoPrompt and shared practical techniques for cloud security testing. He enjoys building tools, exploring cloud internals, and sharing his findings with the security community. He has also responsibly reported critical vulnerabilities in major cloud vendors as part of his independent security research and actively delivers training sessions on cloud security and offensive security techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 10:50-11:30 PDT


Title: Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 10:50 - 11:30 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Is MFA and Conditional Access a real security guarantee? In this technical session, we will demonstrate how endpoint compromise allows an attacker to bypass traditional identity barriers in the cloud. The talk focuses on exploiting vulnerabilities in Microsoft Entra ID, breaking down an advanced attack chain:

• Device Code Flow: Abuse of authentication flows for initial access (Demo with Entraith). • PowerShell Hijacking: Process interception to obtain session tokens (GrabTokenAzureAD). • Sliver BOF Extraction: Use of Beacon Object Files (BOF) for stealthy exfiltration of tokens and the Primary Refresh Token (PRT) from memory, evading anti-malware defenses. • MFA Bypass and Intune: Custom tools were developed to extract local PRTs, bypass Intune device management controls, and circumvent MFA. The entire process was automated through the open-source tool https://github.com/bl4cksku11/entraith, enabling attacks via device code flow, token renewal, email and app inspection, token exfiltration, and persistence generation.

Speakers:Elzer Pineda,Jose Rivas

SpeakerBio:  Elzer Pineda, Pentester

Regional Pentester and Cybersecurity Consultant, Elzer Pineda is an active member of the Red Team executing strategic consulting projects and advanced penetration testing engagements. His career has been focused on Threat Research for private and government organizations across the region. He is a Dojo Community Ambassador and Professor at the Universidad Tecnológica de Panamá (UTP). His experience has taken him to share technical research at Ekoparty, BSides Latam Peru, BSides Panamá, DOJOConf, PwnedCR, and OWASP Latam. Offensive security certifications: OSWE, OSEP, OSCP, OSWP, CRTP, CRTO, and CRTL.

--

Profesor en la Universidad Tecnológica de Panamá y especialista en Red Team con más de 10 años de experiencia en ciberseguridad ofensiva y defensiva. Pentester en GBM (región y Estados Unidos) y researcher en Toad Security. Máster en Seguridad Informática. Realiza evaluaciones de seguridad a aplicaciones móviles, web e infraestructura en Latinoamérica y comparte activamente conocimientos en la comunidad Dojo como embajador y conferencias. Certificaciones: OSWE, OSEP, OSCP, CRTO, OSWP, CRTL.

SpeakerBio:  Jose Rivas, Experienced Penetration Tester at A-LIGN

Jose Rivas is an Offensive Security Researcher and Red Team Operator at A-LIGN, specializing in adversarial simulations, Active Directory attack paths, and physical security assessments. Co-founder of Zero Trust Offsec, an offensive security research group focused on vulnerability exploitation, emerging attack techniques, and responsible disclosure, and Founder of DCG Panama, Panama's first official DEF CON chapter, where he leads a community dedicated to red team operations, and adversarial tradecraft. A recognized voice in the Panamanian security community, Jose has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf. With certifications including CRTO, eWPT, eCPPT, and CompTIA PenTest+, he brings a threat-actor mindset and a strong commitment to advancing offensive security knowledge across the region.

Jose Manuel Rivas is a Penetration Tester and Red Team Operator at A-LIGN, with hands-on experience in adversarial simulations, Active Directory attack chains, web application testing, and physical security assessments. He has multiple CVEs to his name, discovered through bug bounty programs and independent vulnerability research. Co-founder of Zero Trust Offsec and founder of DCG Panama, Panama's first official DEF CON chapter. He has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf, and is focused on growing the penetration testing and red team culture across Latin America.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Friday - 17:00-17:59 PDT


Title: Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID
Tags: La Villa Community | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

¿Son el MFA y el Acceso Condicional una garantía de seguridad real? En esta sesión técnica, demostraremos cómo el compromiso de un endpoint permite a un atacante saltarse las barreras de identidad tradicionales en la nube. La charla se centra en la explotación de vulnerabilidades en Microsoft Entra ID, desglosando una cadena de ataque avanzada:

Abuso de Device Code Flow: Explotación de flujos de autenticación para acceso inicial (Demo con Entraith).

PowerShell Hijacking: Intercepción de procesos para la obtención de tokens de sesión (GrabTokenAzureAD).

Extracción con Sliver BOF: Uso de Beacon Object Files para la exfiltración sigilosa de tokens y del Primary Refresh Token (PRT) directamente desde la memoria, evadiendo defensas anti-malware.

Bypass de MFA e Intune: Hemos desarrollado herramientas personalizadas para extraer PRTs locales, eludir los controles de gestión de dispositivos de Intune y saltarse la aplicación de MFA a nivel de token.

Todo este ciclo de vida de ataque ha sido consolidado en Entraith, un framework ofensivo desarrollado desde cero por nuestro equipo de investigación que será lanzado públicamente en DEF CON 34. Entraith permite ejecutar ataques de device code, renovación de tokens, inspección de correos/aplicaciones y generación de persistencia multi-vector desde una única interfaz

Speakers:Elzer Pineda,Jose Rivas

SpeakerBio:  Elzer Pineda, Pentester

Regional Pentester and Cybersecurity Consultant, Elzer Pineda is an active member of the Red Team executing strategic consulting projects and advanced penetration testing engagements. His career has been focused on Threat Research for private and government organizations across the region. He is a Dojo Community Ambassador and Professor at the Universidad Tecnológica de Panamá (UTP). His experience has taken him to share technical research at Ekoparty, BSides Latam Peru, BSides Panamá, DOJOConf, PwnedCR, and OWASP Latam. Offensive security certifications: OSWE, OSEP, OSCP, OSWP, CRTP, CRTO, and CRTL.

--

Profesor en la Universidad Tecnológica de Panamá y especialista en Red Team con más de 10 años de experiencia en ciberseguridad ofensiva y defensiva. Pentester en GBM (región y Estados Unidos) y researcher en Toad Security. Máster en Seguridad Informática. Realiza evaluaciones de seguridad a aplicaciones móviles, web e infraestructura en Latinoamérica y comparte activamente conocimientos en la comunidad Dojo como embajador y conferencias. Certificaciones: OSWE, OSEP, OSCP, CRTO, OSWP, CRTL.

SpeakerBio:  Jose Rivas, Experienced Penetration Tester at A-LIGN

Jose Rivas is an Offensive Security Researcher and Red Team Operator at A-LIGN, specializing in adversarial simulations, Active Directory attack paths, and physical security assessments. Co-founder of Zero Trust Offsec, an offensive security research group focused on vulnerability exploitation, emerging attack techniques, and responsible disclosure, and Founder of DCG Panama, Panama's first official DEF CON chapter, where he leads a community dedicated to red team operations, and adversarial tradecraft. A recognized voice in the Panamanian security community, Jose has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf. With certifications including CRTO, eWPT, eCPPT, and CompTIA PenTest+, he brings a threat-actor mindset and a strong commitment to advancing offensive security knowledge across the region.

Jose Manuel Rivas is a Penetration Tester and Red Team Operator at A-LIGN, with hands-on experience in adversarial simulations, Active Directory attack chains, web application testing, and physical security assessments. He has multiple CVEs to his name, discovered through bug bounty programs and independent vulnerability research. Co-founder of Zero Trust Offsec and founder of DCG Panama, Panama's first official DEF CON chapter. He has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf, and is focused on growing the penetration testing and red team culture across Latin America.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Friday - 14:00-14:59 PDT


Title: Too Much "Slop" and Not Enough Soul: Why the AI Music Bubble is Leaking & Robots Shouldn't Replace Our Djs
Tags: Hackers.town | Creator Talk/Panel
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  RabidMoosery
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 15:30-16:30 PDT


Title: Trace Labs L100: Search Party Basics
Tags: OSINT For Good Community | Creator Workshop
When: Friday, Aug 7, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

Learn how to optimize your OSINT workflow and strengthen your performance in the Trace Labs Search Party CTF and beyond. . This session will cover core strategies, ethical guidelines, and preparation methods to help you operate confidently, efficiently, and responsibly in a real-world investigative environment. Normally offered as a paid webinar, this session is lead by a Trace Labs Director and earns a digital badge that is part of the Trace Labs webinar series.

SpeakerBio:  Sarah "scba" Miller, Trace Labs

Dr. Sarah Miller is a college professor, emergency manager, cybersecurity manager, and a Director for Trace Labs.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 17:30-17:59 PDT


Title: Tracelabs VM Installation Workshop
Tags: OSINT For Good Community | Creator Workshop
When: Friday, Aug 7, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

Need help installing or using the Trace Labs Virtual Machine? Bring your laptop and sit down for some one-on-one help from one of our volunteers.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Friday - 10:00-23:59 PDT


Title: TrackTheFugitive Contest
Tags: Recon Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 23:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

The manhunt is on. TrackTheFugitive drops you into real, active cases where the suspects are still out there—no simulations, no canned flags. Armed with nothing but open-source intelligence, you'll chase digital breadcrumbs, unmask aliases, and surface the leads that help bring real fugitives to justice.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 14:00-14:45 PDT


Title: Trajan: Cross-Platform CI/CD Security Scanner
Tags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
When: Friday, Aug 7, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

For three years, Praetorian has consistently found that CI/CD pipelines are one of the fastest paths to compromise enterprise environments. A misconfigured workflow or an over-privileged service connection can provide you with credentials, cloud access, or code execution on internal infrastructure, often undetected.

We built to keep up: Gato for GitHub Actions (BH 2024), then Glato for GitLab CI (BH 2025). Both proved the approach: parse the pipeline configuration, classify triggers, gates, and danger zones, build a graph of how they connect, and surface what's actually exploitable.

The problem was that no client runs just one platform. A typical enterprise has GitHub Actions for open-source, Azure DevOps for internal deployments, and GitLab for containerized workloads. Assessing all of that meant juggling multiple tools with different output formats and coverage gaps.

Trajan folds everything we learned into a single tool spanning GitHub Actions, GitLab CI, and Azure DevOps. Each platform runs through the same phased pipeline: collect the pipeline config and the org surface, normalize it, correlate multi-step attack chains, scan against a YAML detection-rule corpus organized by attack category, and report through one unified findings format. Support for Jenkins, CircleCI, and Bitbucket is in active development.

Speakers:Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal

SpeakerBio:  Rahul Saranjame

Lead Security Engineer at Praetorian focused on penetration testing, red/purple teaming, CI/CD pipeline security, and risk advisory assessments. Rahul is OSCP and CRTO certified, holds a Master's degree in Cybersecurity from Georgia Tech, and is a core contributor to Trajan.

SpeakerBio:  Ranganatha Rao Sridhar

OSCE3 certified Lead Security Engineer at Praetorian with expertise spanning product, cloud, and corporate security. Rao holds a Master's degree in Cybersecurity from Georgia Tech and is a core contributor to Trajan.

SpeakerBio:  Tanishq Rupaal

Staff Offensive Security Engineer at Praetorian specializing in cloud security across AWS, GCP, and Azure. He designed the Guard Platform's cloud integration mechanism, is a core contributor to Trajan, and holds an M.S. in Cybersecurity from Georgia Tech.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Friday - 11:00-11:59 PDT


Title: Trans Townhall
Tags: Queercon Community | Creator Event/Activity
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Join us for the Trans Town Hall to find connections, discuss challenges facing the trans community, and engage in converations critical to the community.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 16:50-17:30 PDT


Title: Trust Fall: How Agentic AI Inherits Your Cloud's Worst IAM Habits
Tags: Cloud Village | Creator Talk/Panel
When: Friday, Aug 7, 16:50 - 17:30 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:
Cloud IAM was designed for two principals: humans and machines. In 2026, a third has arrived: the autonomous AI agent and it plays by neither rule book. AWS Bedrock Agents, LangChain-based orchestrators, and multi-agent pipelines are being deployed with execution roles scoped to whatever the deploying engineer thought was "good enough," inheriting the same over-privileged IAM patterns that have plagued cloud environments for a decade. The difference: agents don't just misuse permissions accidentally. When adversarial manipulations are done, they weaponize them with precision.

This talk dissects the threat model of agentic AI systems from an attacker's perspective with a clear-eyed look at how autonomous agents become cloud privilege escalation engines. Drawing from the OWASP Top 10 for Agentic Applications 2026, MITRE ATLAS, and real-world research including Sonrai Security's AgentCore privilege escalation path and Unit 42's confirmation of autonomous AI-driven cloud attacks, the talk walks through a complete attack chain: indirect prompt injection against an agent's context window → tool misuse via over-privileged Lambda execution roles → IAM policy modification → persistent backdoor creation — all without a single stolen credential.

Attendees will leave with a structured threat model mapped to MITRE ATLAS tactics, a dissection of what AWS CloudTrail catches versus what it silently misses during agent-driven attacks, a breakdown of the three OWASP agentic risks most directly applicable to AWS environments (Goal Hijack, Tool Misuse, Identity & Privilege Abuse), and concrete defensive controls including agent-scoped least-privilege IAM, Bedrock Guardrails limitations practitioners need to know, and human-in-the-loop architectural patterns.

Speakers:Aravind Sreekanth Pallavoor,Sadhana Sainarayanan

SpeakerBio:  Aravind Sreekanth Pallavoor

Aravind Pallavoor is a cybersecurity practitioner with over five years of hands-on experience spanning application security, cloud security engineering, and offensive security research. He holds CISSP, CEH (v11), and AWS Certified Security – Specialty (SCS-C02) certifications alongside a Master of Science in Cybersecurity, Technology and Policy from The University of Texas at Dallas, where he graduated with a 3.82 GPA.

His offensive security background includes web application and API penetration testing, mobile application security, AI chatbot security assessments — including prompt injection and training data poisoning research — and cloud infrastructure security across AWS environments. He has conducted security assessments for global financial institutions and enterprise SaaS organizations, applying frameworks including OWASP, CVSS, MITRE ATT&CK, NIST, PCI DSS, and CIS Foundations.

On the cloud side, Aravind has directly architected and audited IAM environments, deployed and red-teamed compliance automation pipelines, and operationalized AWS Config, Secrets Manager, and CI/CD pipeline security at scale. His research interest at the intersection of agentic AI and cloud identity — the subject of this talk — grew directly from real-world experience testing AI systems for adversarial manipulation and observing how autonomous tool use exposes cloud IAM to a new class of attack surface.

"Trust Fall" represents his synthesis of those two worlds: offensive AI security research applied to the cloud IAM threat model, grounded in published vulnerability research, OWASP's Agentic Top 10 for 2026, and MITRE ATLAS — and delivered without a lab, because the threat model speaks for itself.

Additional Speaker Bio: Sadhana Sainarayanan is an AI and machine learning practitioner with deep expertise in autonomous pipeline design, event-driven system architecture, MLOps, and cloud-native AI deployment across GCP and Azure environments. She holds a Google Cloud Certified Professional Machine Learning Engineer certification and a Microsoft Certified Azure AI Engineer Associate certification, alongside dual Master's degrees from Carnegie Mellon University. Her research interests span the security implications of agentic AI systems, NLP pipeline trust boundaries, and the input-validation gaps that emerge when autonomous systems process external data at scale. For this talk, she brings the AI builder's perspective to the cloud identity threat model.

Additional Speaker LinkedIn: http://www.linkedin.com/in/sadhana-sainarayanan

SpeakerBio:  Sadhana Sainarayanan

Sadhana Sainarayanan is a Cloud Platform Security Analyst with experience across SAP BTP security operations, ML pipeline productionization and AI systems. She holds dual master’s degrees from Carnegie Mellon University in Engineering and Technology Innovation Management, and Civil and Environmental Engineering. Her independent projects span instrumentation for AI systems, focused on the gap between what agents report doing and what they actually do, execution auditing, and behavioral divergence detection.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 16:00-16:59 PDT


Title: Trust Me, Bro: A field guide to Windows Authenticode Abuse
Tags: Red Team Village | Misc
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

This talk breaks down how Windows code signing fails. You learn why signed binaries still bypass trust checks and why users click through warnings. The session walks through signature abuse, metadata cloning, and SIP hijacking with live demos and explain the pros and cons. You see how attackers make malware appear trusted by the OS and trick the user.

You also see how these techniques can get chained together through with the tool "TrustMeBro".

SpeakerBio:  Fagan Afandiyev

Fagan Afandiyev is a cybersecurity student and offensive security engineer based in Tampa, Florida. His work focuses on Active Directory attacks and Windows internals. He works as an Offensive Security Intern at White Knight Labs and contributes to open source tooling used in real penetration tests.

He holds multiple industry certifications, including CPTS, CAPE, CRTO, ARTO, CBBH, and CompTIA Security+. He competes regularly and has earned first place finishes at DEF CON Adversary Village, BSides Tampa, Social Engineering TempleLabs, and NCAE Cyber Games. He previously served as President of the Whitehatters Computer Security Club at the University of South Florida teaching people about cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 17:30-17:59 PDT


Title: Trust No History: Why Every "Remembered" Interaction is a Potential Backdoor
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Friday, Aug 7, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

As AI transitions from stateless tools to autonomous agents, the context window has become the primary attack surface. By giving agents the ability to remember, summarize, and collaborate, we have created a machine that can be gaslit. This session moves beyond transient prompt injections into the realm of persistent memory corruption. We explore how an adversary can rewrite an agent’s history, bias its knowledge base, and plant sleeper instructions that trigger long after the initial interaction. We will dissect the systematic subversion of the agentic memory stack and demonstrate why developers must stop treating agent memory as a passive data store and start defending it as the engine of the agent’s survival

Speakers:Barno Kaharova,Rico Komenda

SpeakerBio:  Barno Kaharova

Barno is a consultant and researcher specializing in AI security, data engineering, and ML security. She works at the intersection of offensive and defensive AI security, developing methodologies to protect AI systems from adversarial threats across the full stack from data pipelines and ML models to LLM-powered applications and autonomous agents. As an AI security trainer, Barno designs and delivers hands-on programs covering AI red teaming, prompt injection, adversarial ML, RAG and vector database security, and the OWASP Top 10 for LLM and Agentic AI. Her approach is practitioner-first: participants attack and defend real-world AI systems, leaving with techniques they can apply immediately. She is actively involved in AI governance and evaluation efforts at the national level and regularly contributes to the AI security community through speaking engagements, publications, and conference submissions, bridging rapid AI adoption with the need for robust, field-tested defenses.

SpeakerBio:  Rico Komenda

Rico Komenda is a security engineer and researcher specializing in application security, cloud security, and AI security. He started as a software developer, moved into security engineering, and now focuses on the attack surface created by AI-integrated systems and secure agentic development.

He is Co-Lead of the OWASP AI Security Verification Standard (AISVS) and a core contributor to multiple OWASP GenAI security projects. Rico has spoken at NDC Security, OWASP Global AppSec EU, OWASP LASCON, WeAreDevelopers World Congress, DefCamp, and others.

He got into this field the way a lot of hackers do: writing scripts for video games as a teenager, getting curious about how systems break, and never stopping.


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Friday - 13:00-13:30 PDT


Title: Trust the Basics, But Know Their Limits: Where Standard Cybersecurity Advice Falls Short
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Friday, Aug 7, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Those cybersecurity tips you’ve heard over and over again are still our best defense against attackers, but following them doesn’t actually protect you from everything.

In 2026, we know that freezing your credit won’t protect you from most scams, and that even the strongest password manager can’t save a compromised device. So what actually works, and where does it fall short?

The advice is good. The gaps are real. Come learn both.

SpeakerBio:  Yael Grauer

Yael is an investigative tech reporter covering privacy and security, digital freedom, hacking, and mass surveillance. She contributed to a Pulitzer Prize-winning AP investigative package on surveillance, and spent six years at a media nonprofit managing cybersecurity tools and programs that reached hundreds of thousands of users. She holds a CIPP-US certification and has completed way too many cybersecurity and source protection programs.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 15:00-15:59 PDT


Title: Trust the Pipeline, Lose the Kingdom: Hands-On Cloud Native CI/CD Red Team
Tags: Red Team Village | Misc
When: Friday, Aug 7, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Cloud native CI/CD pipelines are the soft underbelly of modern enterprise security. SolarWinds in 2020, Codecov in 2021, CircleCI in 2023 set the template, and the pattern has only accelerated: tj-actions compromised 23,000 repositories in March 2025, GhostAction exfiltrated 3,325 secrets in September 2025, TeamPCP turned Trivy and Checkmarx GitHub Actions into credential stealers in March 2026. Most red teams still do not operate meaningfully against cloud CI/CD, and most detection stacks still do not watch it. The terrain runs in the gap between endpoint detection and cloud API monitoring, and it remains one of the highest leverage, least contested surfaces in the enterprise.

This workshop walks a full cloud native CI/CD attack chain drawn from multiple red team engagements: pull request poisoning via pull_request_target, OIDC-to-STS credential exfiltration from the build runner, force-merging a PR through a GitHub admin PAT pulled from Secrets Manager, Lambda and EventBridge persistence that never leaves the cloud, IAM trust chain abuse that escalates a low privilege build identity into broad cloud access, and Secrets Manager as the pivot out of AWS into code hosting, the CI platform, and every SaaS the organization depends on.

The paired 60 minute Tactic is hands-on, not demonstration. Each of 10 to 15 attendees forks a public demo repo and opens their own PR against it. The vulnerable pull_request_target workflow fires automatically and dumps live STS credentials to the workflow log. Attendees read the credentials from their own PR's Actions page, paste them into their own terminal, pull a GitHub admin PAT from Secrets Manager, and force-merge their own PR through the stolen token with no human reviewer in the loop. Every attendee watches their own PR flip from Open to Merged using a credential that did not exist until they opened the PR. The OIDC-trusted role is scoped to GetSecretValue on one secret, so attendee actions have zero AWS blast radius. The speaker then demonstrates the persistence, IAM trust chain, and pivot stages on the projector, and attendees leave with a public Terraform bundle to run the full chain end to end against their own AWS account at home, plus a set of detection signals deployable against CloudTrail and CI logs their organizations already collect.

SpeakerBio:  Shane Young

Shane Young is an offensive security operator and program builder with over 15 years in the field. His career spans consulting across financial services, hardware, and SaaS; building out an IoT security practice at a major security consultancy; leading red team operations against cloud native product companies; and pioneering AI/ML red teaming for deployed enterprise AI features. He is the creator of Brutespray, a public open source offensive security tool. He builds offensive security programs from scratch, runs red team operations end to end, and still carries significant technical IC workload because he thinks that is how security leaders stay sharp. He has been hacking since he was a teenager, and it still has not gotten old.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 11:00-11:59 PDT


Title: Trusted Launcher, Untrusted Code: Weaponizing AppLaunch.exe to bypass SmartScreen and AppLocker
Tags: Red Team Village | Misc
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

AppLocker, SmartScreen, and Windows Defender Application Control (WDAC) are the standards for securing enterprise endpoints through application whitelisting. A little-known Microsoft tool, AppLaunch, which has little to no research done, can be abused to bypass these common defenses to achieve initial access and persistence.

This talk will present a new ClickOnce deployment method using partial trust apps that launch from AppLaunch, a signed Microsoft executable that launches partial trust ClickOnce apps. This technique functions using unsigned code within default AppLocker environments with DLL signing enabled. This presentation will take a dive into exploiting and describing this novel technique.

This presentation also includes multiple novel techniques used to break out of a .NET CAS (Code Access Security) sandbox. To showcase real-world exploitability, multiple demonstrations and techniques will be displayed. This talk will explore the faulty trust model that enables a new initial access and LOLBAS (Living off the Land Binaries and Scripts) method.

A tool is provided to assist in the creation of deployments that abuse this new method. Furthermore, I will cover the IOC's left behind, and how to block and detect this attack.

SpeakerBio:  Nathan Sawyer, Independent Researcher

Nathan Sawyer is a junior studying Cybersecurity at the University of Idaho. He has obtained HTB CDSA and CPTS. He enjoys skiing, snowboarding, hockey, and lacrosse.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 16:00-17:59 PDT


Title: Um, ACKtually
Tags: Um, ACKtually | Contest
When: Friday, Aug 7, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

Um, ACKtually is returning for it's 2nd year at DEF CON 34! If you've ever seen the popular Dropout TV game-show "Um, Actually", then you know exactly who we stole this idea from.

Three contestants will compete for the Pedantic Hacker crown, providing corrections for (just barely) incorrect statements given by the hosts about everything from general technology, cyber security, and overall nerd culture. We will chum the waters of the question pool with red herrings and wrong turns while the sharks circle to be the first to answer "WELL, UM ACKTUALLY...".

Um, ACKtually celebrates everything hacker culture was built on. Community knowledge share, deep subject matter expertise of niche topics, and an almost orgasmic feeling of superiority at correcting someone else's mistakes, live and in public.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Friday - 10:00-17:59 PDT


Title: Untechnical
Tags: Untechnical | Contest
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 103 (Untechnical) - Map

Description:

In the age of AI hacking is reclaiming itself as more a mindset than strictly technical skill. If you're a DEFCON attendee that lack the technical skills to compete in traditional hacking challenges, but still love thinking outside the box: untechnical is for you.

Untechnical is a contest designed to rely 100% on lateral/abstract thinking without needing anything beyond an understanding of high school math.

Participant Prerequisites

Need to understand basic math and enjoy thinking outside the box. Oh, and you need an email address.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Friday - 16:00-16:30 PDT


Title: Veilid- the Next Gen of privacy
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Friday, Aug 7, 16:00 - 16:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

In this talk, medus4 will go over how the data economy insidiously invades everyone's privacy, and how Veilid is helping fight back against that. Will include a brief lesson on the history of privacy software, and how Veilid can assist everyone (including youth!) to make a better internet for all!

SpeakerBio:  medus4
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 15:45-16:25 PDT


Title: Vibe Check: Exploiting Developer Trust from Prompt Injections to Weaponized Repos
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 15:45 - 16:25 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

"Do you trust the authors of the files in this folder?" It's a prompt modern IDEs throw at developers, and most click past it by reflex. But as vibe coding, AI-assisted tooling, and automated agents accelerate software development, that implicit trust in established tools like VS Code and authoritative sources like GitHub has become a critical, highly exploitable attack surface and malware delivery channel - especially for non-technical vibe coders.

This hands-on workshop places attendees directly in the mindset of an attacker targeting modern development environments. We move beyond traditional social engineering and focus on how trust is abused through the tools developers rely on every day: IDEs, agent harnesses, and package managers. After dissecting recent real-world cases of developer-targeted attacks and AI-agent vulnerabilities, we transition into labs where participants build and execute their own PoCs - including constructing malicious repositories from scratch to trigger invisible code execution on folder open, weaponizing hidden prompt injections to drive AI agents into running attacker-controlled commands, and standing up a custom "Claude Code"- style agent harness to attack ourselves.

Agenda: ⚠️ How your trusted IDEs betray you by executing malicious commands automatically ⚠️ How agent harnesses like Claude Code and Gemini CLI can be abused across multiple trust boundaries ⚠️ How package managers like npm turn seemingly harmless actions, like a routine package update, into full compromise

Bring a laptop - we'll get our hands dirty and hack ourselves together.

SpeakerBio:  Michael Chan, Senior Offensive Security Consultant at KPMG Canada

Michael is a social scientist turned hacker. He started by studying human behaviour and trust at Oxford - now he brings that lens into offensive security, validating and breaking the assumptions built into applications, systems, and organizations. As a Senior Offensive Security Consultant at KPMG Canada, Michael works across application security, threat modelling, and adversary simulation. Outside of work, he spends most of his time learning, building, breaking fun new tech (yes AI included), and engaging with local cyber communities.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 08:45-08:59 PDT


Title: Village Greeting
Tags: Social Engineering Community Village | Creator Talk/Panel
When: Friday, Aug 7, 08:45 - 08:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Join the founders for a preview of what�s happening in the Village this year.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 12:00-12:45 PDT


Title: VoiceLock: Offline, Robust On-Device Speech Transcription
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Hardware/IoT | Mobile | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

VoiceLock analyzes audio to identify speakers, count participants, and understand what each person said and discussed, just from a microphone. The self-contained, entirely offline system is designed for continuous, long-term use cases of 72 to 168 hours or more. The system runs entirely on-device, with high accuracy as tested on datasets and in the real world. Key innovations include an on-device vector database for fast speaker-similarity search and robust noise reduction, which greatly improve transcript accuracy. The output is a transcript with name labels. The system is fast enough to transcribe and report in under a minute. Code is written as an open-source Python module with a provided runtime and setup script to enable quick deployment on IoT devices. The system has been tested in challenging environments, including high noise levels, many speakers/arguments, and a lecture-style format. We present a live demo, technical details, and a short runtime tutorial.

Speakers:Ayaan Qayyum,Parag Kalay

SpeakerBio:  Ayaan Qayyum

Ayaan is an MS in engineering student at Columbia University. His research interests include mobile computing, applied machine learning, edge AI, and data science. He is an expert in understanding customer needs and use cases to solve real-world problems.

SpeakerBio:  Parag Kalay

Parag is a Biomedical Engineering MS student at Columbia University, combining expertise in CAD, rapid prototyping, and data-driven design to transform concepts into functional technologies under tight technical constraints. Skilled in translating clinical needs into robust engineering solutions from initial sketches to validated prototypes.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 12:00-12:45 PDT


Title: Voting Village Keynote - The Paper Chase
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

The 2000 presidential election was decided by Florida's “hanging chads”—flaws in the punchcard voting system used there at the time. In response, Congress passed the Help America Vote Act (HAVA), providing states with substantial funding (released in 2003) to replace punchcard systems with electronic voting machines (DREs), which were promoted as more secure, accurate, and accessible. As Majority Leader of the California State Assembly, Kevin Shelley authored the state's vote-by-mail program and other voting reforms. He was elected California Secretary of State in 2002 on a platform of expanding voter participation. Within his first month in office, however, David Dill brought him extensive documentation raising serious concerns about electronic voting security.

Shelley found the material compelling enough to form a touchscreen task force to study potential security issues and the need for a voter-verified paper audit trail. When the task force's findings, released months later, proved inconclusive, Shelley remained convinced further action was necessary. In November 2003, he launched an independent audit of California's voting systems and mandated that all touchscreen machines include a voter-verified paper audit trail—a move local election officials and voting rights advocates criticized as unnecessary and irresponsible, insisting the machines were already secure.

Ahead of the March 2004 election, Shelley imposed additional security requirements on touchscreen machines and required that paper ballots remain available; some counties defied the order. Later that year, he banned certain Diebold machines outright, decertified all touchscreen systems until security measures were met, asked the attorney general to pursue civil and criminal action against Diebold, and set up a parallel system to monitor the equipment's use.

Several lawsuits challenged these measures. Courts upheld Shelley's actions in every case.In her inaugural address as California Secretary of State in 2007, Deborah Bowen stated “Kevin Shelley had the hard work of evaluating new kinds of voting systems at a very, very early stage, and guess what – it turns out that he was right on a great many issues that had at their core the security and accuracy of the vote.”

SpeakerBio:  Kevin Shelley

Kevin Shelley is a former California Secretary of State and State Assembly leader recognized as a trailblazer in election integrity efforts. Mr. Shelley’s political involvement began in 1978 as a staff member to U.S. Representatives Phil and Sala Burton. His own political career began in 1990, when he was elected to the San Francisco Board of Supervisors, serving twice as Board President. Elected to the California State Assembly in 1996, serving as Majority Leader, he championed the rights of workers, fought to protect the environment, and championed corporate accountability.

Mr. Shelley, was elected Secretary of State in 2002. As the state’s Chief Election Officer, he is credited with improving voter participation, overseeing the historic Gubernatorial recall election on 2003, and decertifying problematic electronic voting machines. He established the first in the nation standards for accessible voter-verified paper audit trails to be used with direct recording electronic (DRE) voting machines in California.

After leaving State government in 2005, he became Special Counsel to Berman Tabacco, a law firm representing victims of corporate fraud. Currently he serves as Vice-Chair of Verified Voting, addressing issues of election security, and is focused on ensuring our upcoming November elections and beyond are safe and secure.

He is the son of Jack Shelley, a former San Francisco mayor, U.S. congressman and California state senator.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 10:00-17:59 PDT


Title: Voting Village Lab
Tags: Voting Village | Creator Event/Activity
When: Friday, Aug 7, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W219 (Voting Village) (Voting Village Lab) - Map

Description:

The Voting Village Lab is a hands-on, self-directed workshop space where attendees can learn about and experiment with dozens of different pieces of election equipment used in current and past US elections.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Friday - 13:00-13:20 PDT


Title: Wall of Wallets Workshop (Intro to Wall of Wallets Challenge)
Tags: Payment Village | Creator Workshop
When: Friday, Aug 7, 13:00 - 13:20 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:
Wall of Wallets is a hands-on CTF challenge where the goal is simple: collect as many mock payment card details as you can from other participants. Using intentionally vulnerable services in a safe, isolated environment, you'll learn how common implementation mistakes expose sensitive data. Compete to top the Wall of Wallets leaderboard while discovering the real-world techniques attackers use and, importantly, how to defend against them.
SpeakerBio:  Dan Borgogno, Security Researcher at Faraday

Dan Borgogno is a security researcher, backend developer, security engineer and international speaker with years of experience on mobile, hardware, IoT and web application hacking.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 14:30-15:30 PDT


Title: WASM Was Not the Boundary: Sandcastles, Not Sandboxes
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Friday, Aug 7, 14:30 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:
Pyodide is often treated as a ready-made sandbox: block os, block js,
and untrusted Python is assumed to stay inside WebAssembly. In n8n and
the other products we tested, that assumption failed. When ctypes or reflection
remained reachable, attacker-controlled Python could cross from
CPython-in-WASM into the Emscripten/JavaScript host boundary the product
actually relied on.

We show this as an architectural failure, not a one-off bug. In Node.js embeddings, that boundary break typically becomes immediate host-side code execution because the escaped code lands in a runtime with no native permission model. In Deno embeddings, the same break still reaches the embedding runtime, but the final blast radius depends on the permissions the product granted; in one default configuration, that still meant full RCE. In CI environments, the same mistake turns tests and build steps into a supply-chain risk because the escaped code runs next to tokens, secrets, and release artifacts.

Across workflow automation, spreadsheets, AI agents, desktop wrappers, and build tooling, we found seven escapes, two public CVEs, and multiple additional disclosures. Attendees leave with a precise mental model of where Pyodide isolation actually ends, how to test similar deployments, and how to harden them beyond fragile denylists.

Speakers:Saar Pearl,Vladimir "G1ND1L4" Tokarev

SpeakerBio:  Saar Pearl, Cyera

Saar Pearl is a security researcher at Cyera. He specializes in offensive security and vulnerability research across cloud infrastructure and SaaS platforms, focusing on identity and access controls, architectural weaknesses and exploit development.

SpeakerBio:  Vladimir "G1ND1L4" Tokarev, Cyera

Vladimir Tokarev is a vulnerability researcher tech lead at Cyera, specializing in Cloud, IoT/OT, Windows, Linux, and AI vulnerability research and exploit. Talks: Black Hat USA 2024 and 2023,
DEF CON 33 Recon Village 2025, CodeBlue 2025, RSA 2024.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 16:30-16:59 PDT


Title: Watching Norway's Election
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 16:30 - 16:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

What can an ordinary citizen — equipped with curiosity, a camera, and a little code — actually learn about how their elections are run? In 2025 the speaker set out to find out, observing Norway's national election from both the inside and the outside. The results ranged from the illuminating to the absurd: scraping official result protocols into structured JSON for independent analysis; working two prior elections "undercover" as a paid poll worker; spotting an unsealed ballot box where the chain of custody should have been airtight; and, on count night, being removed from a municipal counting center by police.

This talk turns those experiences into a practical, cross-border playbook for independent election observation. Norway runs paper ballots, manual counts, and publishes machine-readable results — yet transparency still has gaps, and getting access can be surprisingly adversarial. Using Norway as a concrete case study, the speaker shows how anyone — hacker, researcher, or concerned voter — can document a count, capture and analyze published election data, spot anomalies, and do it all legally and credibly.

Attendees leave with concrete methods: what to watch for, how to record it, how to turn official data dumps into analyzable datasets, and how to handle officials when curiosity is mistaken for a threat. The core message is empowerment: election integrity is not a spectator sport reserved for institutions. The more eyes — and code — on the process, the stronger democracies become, in the U.S. and everywhere else.

SpeakerBio:  Hallvard Nygard

Hallvard Nygård is an independent security researcher and election observer based in Norway. He has spent recent years turning a developer's toolkit on the machinery of democracy: scraping and analyzing published election data, observing counts in person, and working as a paid poll worker (valgmedarbeider) during Norway's 2021 and 2023 elections to understand the process from the inside.

His independent observation of Norway's 2025 election drew media attention after he was removed from municipal counting center by police — an episode he now uses to illustrate both the promise and the friction of citizen oversight.

Hallvard is a frequent speaker on the Norwegian conference and security-community circuit, including Sikkerhetsfestivalen, JavaZone, NDC Oslo, TDC, and HelloStavanger, as well as meetups such as OWASP Oslo, Stavanger Security Hangout (SSH), and an Oslo election meetup. He is a vocal advocate for hands-on, hacker-style scrutiny of elections and for empowering ordinary citizens to observe and document their own local democratic processes. Online he can be found at hallny.bsky.social and as @hallny on X.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 17:00-17:45 PDT


Title: We Pwn Your Phone, We Pwn Your Vote (Demo and Panel)
Tags: Demo 💻 | Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:45 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:
Mobile voting proposals increasingly rest on a single assertion: that modern smartphones, with their secure enclaves, sandboxed apps, and encrypted communications, provide a sufficiently trusted platform for remote ballot casting. This talk demonstrates, live and on stage, why that assertion is false.

Using a weaponized n-day exploit chain (CVE-2025-43529) against a now patched but-still-widely-deployed iOS version, we will compromise a live iPhone in front of the audience. The phone’s screen will display nothing but a Wikipedia article. The user will have no indication that anything has happened. Meanwhile, a second screen will show the audience exactly what is being taken from the device in real time: text messages, messaging app databases (Signal, WhatsApp, Telegram), photos, saved passwords, WiFi credentials, location history, and contacts, all exfiltrated with zero on-device artifacts.

The exploit achieves full kernel read/write and root filesystem access. At that level of compromise, no app on the device can be trusted: not voting apps, not authenticators, not encrypted messengers. The encryption keys, cloud session tokens, and biometric material that apps rely on to prove “this is the legitimate voter” are all accessible to an attacker with this level of access.

This specific vulnerability is patched. But two facts remain: (1) the targeted iOS version is still running on millions of devices worldwide, and (2) nation-state actors and sophisticated criminal organizations maintain working exploit chains against the latest iOS and Android versions, chains that have not been patched because they have not been discovered or disclosed. The tool we demonstrate is an n-day. The tools in active deployment against current devices are zero-days.

Speakers:Brian DeMuth,Matt Blaze,David Jefferson,Michael Specter

SpeakerBio:  Brian DeMuth

Brian DeMuth, a “former” hacker, is an entrepreneur and investor who has spent his 28-year career supporting the U.S. National Security Mission, cybersecurity businesses, and nonprofits. Brian is co-founder and General Partner of the Riphean Investments National Security Fund, a venture-studio-style investment fund focused on technology investments that strengthen national security for the U.S. and its citizens. He is the Founder of Immortal Cyber, Inc., an advanced cybersecurity research and engineering firm providing offensive cyber delivery services and “Cyber-as-a-Service” for unique clients, and Co-Founder & CEO of RapidAscent, Inc., a scalable, task-based cyber apprenticeship solution addressing the historic shortage of technical personnel in the U.S. and worldwide. Brian also co-founded and chairs the board of the Cyber Bytes Foundation, a 501(c)(3) dedicated to building a unique cyber ecosystem of educational and outreach programs for the cyber workforce. A longtime advocate for election security, Brian serves on the Board of Directors of the Election Integrity Foundation, the 501(c)(3) behind the DEF CON Voting Village.

SpeakerBio:  Matt Blaze

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.

SpeakerBio:  David Jefferson

David Jefferson is an internationally recognized expert on voting systems and election technology, and an advisor to five successive California Secretaries of State. In 2004 he was coauthor of the SERVE Security Report detailing the security vulnerabilities in the Defense Department's proposed Internet voting system, leading to the cancellation of the program. In 2003 he was a member of the California Task Force on Touchscreen Voting, whose recommendations led to voter-verified paper audit trails for electronic voting machines. He has led half a dozen technical studies on reliability and security of voting systems, including the California Post-Election Audit Standards Working Group that produced the first government study of post-election auditing. He has served on the boards of directors of both the California Voter Foundation and Verified Voting, and is currently on the board of the Election Integrity Foundation that puts on the annual DEF CON Voting Village.

Dr. Jefferson received a BS in mathematics from Yale University, and a Ph.D. in computer science from Carnegie-Mellon University. From 1980 to 1994 he was a professor at the University of Southern California (USC) and then at UCLA. He is now retired from Lawrence Livermore National Laboratory where he conducted research in supercomputing and cyber security.

SpeakerBio:  Michael Specter

Michael A. Specter is an Assistant Professor in Computer Science at Georgia Tech where he leads the SPDR Lab. Specter’s interests are broadly on problems in systems security and applied cryptography, specifically on issues relevant to public policy.  He joined Google after completing his PhD in Electrical Engineering and Computer Science at MIT, and previously served as research staff at MIT’s Lincoln Laboratory. His research has been featured in congressional testimony, amicus briefs to the Supreme Court, and (repeatedly) in the popular press. He holds the 2023 Research Award from the Elections Verification Network and a Pioneer Award from the Electronic Frontier Foundation (EFF). 


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Friday - 11:00-12:59 PDT


Title: Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS
Tags: Cloud Village | Creator Event/Activity | Attack
When: Friday, Aug 7, 11:00 - 12:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) A - Map

Description:

CloudFormation is widely trusted as a secure and declarative Infrastructure as Code (IaC) service inside AWS environments. In practice, however, CloudFormation frequently operates with permissions far beyond those of individual users, CI/CD pipelines, or developers. This workshop explores how attackers can abuse that trust model to achieve privilege escalation and persistence in realistic AWS environments.

In this fully hands-on offensive cloud security workshop, attendees will begin with limited IAM permissions and learn how to identify and exploit misconfigured CloudFormation execution roles using iam:PassRole, service roles, and Lambda-backed Custom Resources. Participants will weaponize CloudFormation templates to create persistence mechanisms inside service-scoped IAM paths without requiring direct administrative permissions.

The workshop emphasizes realistic cloud attack paths, delegated execution abuse, and the security risks introduced by over-permissioned automation. Attendees will also explore rollback abuse scenarios and learn how these attacks appear in CloudTrail and IAM logs.

SpeakerBio:  Samanta Aranda

Samanta Aranda serves as a Managing Senior Consultant at Bishop Fox, leading security assessments and initiatives focused on strengthening organizations’ technological resilience. She holds a degree in Electronics and Communications Engineering and a Master’s in Computer Science and Technology Management. From the very beginning of her career, she found in cybersecurity not just a profession but a genuine passion. Over the years, she has collaborated with national and international firms such as KPMG, Scitum, EC-Council LATAM, and INFOTEC, contributing to projects that bridge technology, strategy, and security.

Samanta holds 16 professional certifications, including GPEN, GWAPT, CEH, and CND, and has been recognized as an EC-Council Certified Instructor, earning a place in the organization’s Circle of Excellence in 2021. She blends technical expertise with a human and collaborative approach to security, firmly believing that shared knowledge is the strongest defense.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 12:00-12:45 PDT


Title: Weaponizing eBPF and XDP with Covert Triggered Reverse Shells
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:
eBPF and XDP now underpin critical Linux infrastructure yet their kernel-level access creates a blind spot: adversaries can weaponize these primitives for stealth persistence that evades standard forensic tools. Current defenses are not equipped for this emerging threat.

We built Phantasma, an open-source eBPF implant, to expose this gap. It combines three kernel-level techniques: (1) XDP covert triggering that intercepts packets at the NIC driver before they reach the networking stack, firewalls, or packet capture systems (2) getdents64 syscall interception to hide processes from /proc, defeating ps, top, and all enumeration tools; and (3) bpf() syscall interception to cloak loaded eBPF objects from bpftool and forensic inspection.

We live-demonstrate the full attack chain deployment, self-cloaking, magic packet activation, and encrypted reverse shell showing the implant defeating packet capture, process listing, and BPF introspection simultaneously.

We then present the defenses this threat demands: kernel audit rules for bpf() syscalls, /sys/fs/bpf inspection, XDP attachment monitoring, and behavioral indicators. Attendees leave with detection rules, hardening steps, and a clear understanding of why eBPF must be treated as an attack surface, not just a defense tool.

SpeakerBio:  Yll "0xBabar0ka" Berisha

I am an offensive security researcher with 2 years of experience in penetration testing, red teaming, and custom tooling. I am the creator of Phantasma, an open-source eBPF/XDP implant framework for stealth persistence research.

Professionally, I have worked at Sentry, conducting web, mobile, and internal/external network penetration tests. At Finbbug, I contributed to a US Embassy-supported project assessing the cybersecurity posture of NGOs and media organizations in Kosovo, identifying issues such as XSS, directory listing, and IDOR vulnerabilities. At Starlabs, I built dark web monitoring tools using HaveIBeenPwned and LeakX APIs for automated credential leak detection.

I hold BSCP (Burp Suite Certified), CRT-ID (Certified Red Team Infra Dev), MCRTA (Multi Cloud Red Teamer), CISCO ETHICAL HACKER, and HACKWISER CAPT certifications. I placed 1st at the Iowa State Cyber Defense Competition and represented Kosovo at the 2024 ENISA European Cybersecurity Challenge in Turin.

I have presented at CyberZero on prompt injection attacks and deepfake-based social engineering at the TechRisck conference, and co-organized national and international CTFs designing real-world attack chain challenges.

I am also a member of DefCon Group Prishtina (DC38338), where I contribute to co-organizing meetups and community events.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:00-10:30 PDT


Title: Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

This is a talk about making your CPU go slow. Really, really, really slow.

It is also, somehow, a talk about breaking platform security on nearly every x86 system ever shipped, activating a hundred dormant CVEs, repeatedly ignoring processor specifications, racing intra-core interrupts, and finding a vulnerability that cannot be fixed.

But mostly, it's about going slow.

Memory Sinkhole AMD Sinkclose Sandsifter EDK2

SpeakerBio:  Christopher "xoreaxeaxeax" Domas

Christopher Domas (@xoreaxeaxeax) is a security researcher primarily focused on firmware, hardware, and low level processor exploitation. He is best known for releasing impractical solutions to non-existent problems, including the world's first single instruction C compiler (M/o/Vfuscator), toolchains for generating images in program control flow graphs (REpsych), and Turing-machines in the vi text editor. His more relevant work includes the sandsifter processor fuzzer, rosenbridge backdoor, the binary visualization tool ..cantor.dust.., and the memory sinkhole privilege escalation exploit.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 12:00-13:59 PDT


Title: Web Hacking Bootcamp
Tags: Red Team Village | Misc
When: Friday, Aug 7, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

A beginner to intermediate hands-on web hacking bootcamp originally created for internal up-skilling. Hands on with both specific to module PortSwigger labs and a self-hosted Juice Shop instance running on Docker Desktop.

Presentation Outline: - Web Technology Foundations (Pre-requisite's on web-specific languages, encoding, HTTP request structure, some 'Hacker Mindset') - Web Hacking Foundations (What is an application proxy/setting up Burp Suite, 'auth' & 'auth', sessions & tokens, CORS, vocabvocab) - Web Hacking Modules (file upload attacks, SQL injection, JWT attacks, XSS, CSRF, XXE & business logic vulnerabilities)

After each major section, and in-between some of the hacking modules, we return to a self-hosted OWASP Juice Shop instance to try out new techniques learned. Each hacking module will end with related PortSwigger Web Security Academy labs which attendees will work through on their own with instructor support. (think: I walk around and give nudges as needed.)

All material being self-or-Portswigger hosted means that even if the time slot doesn't include sufficient lab time, attendees will be able to take what they heard and work on labs laid out or practice with Juice Shop on their own time. The main objective is to give attendees a minimum understanding of web tech & attacks that they feel empowered to dive in deeper from that point.

SpeakerBio:  Emma Latuszek

Emma 'vhulf' Latuszek is an application developer turned breaker, who started her hacking career nearly a decade ago. She is an OSWE holder, Cyphercon safe-cracker and a verified cyborg (barely... but thanks DangerousThings!). Vhulf is esoteric and unusual, with a deep passion for music, hacking and high-energy instruction.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 10:00-10:30 PDT


Title: Welcome to DEF CON 34!
Tags: DEF CON Official Talk | DEF CON Communications
When: Friday, Aug 7, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:
SpeakerBio:  Jeff "The Dark Tangent" Moss

Mr. Moss is an internet security expert and is the founder of both the Black Hat Briefings and DEF CON Hacking conferences.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Friday - 11:45-12:15 PDT


Title: Welcome to OSINT4Good and Trace Labs
Tags: OSINT For Good Community | Creator Talk/Panel
When: Friday, Aug 7, 11:45 - 12:15 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

This overview session will talk about how OSINT4Good is used across a variety of career fields and how you can get involved.

SpeakerBio:  Nataly "someone_somewhere", Trace Labs

A cybersecurity professional obsessed with human psychology and making servers work how we expect them to, and a Trace Labs Director.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 11:30-11:59 PDT


Title: Welcome to the Voting Village
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 11:30 - 11:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

The EIF Team and Staff will officially welcome our friends and guests to the Voting Village. We will give an overview of the content attendees should expect this year and the open questions we look forward to addressing.

Speakers:Brian DeMuth,Matt Blaze,Jake Braun,David Jefferson,Jeff Moss,Kendall Spencer,Philip Stark

SpeakerBio:  Brian DeMuth

Brian DeMuth, a “former” hacker, is an entrepreneur and investor who has spent his 28-year career supporting the U.S. National Security Mission, cybersecurity businesses, and nonprofits. Brian is co-founder and General Partner of the Riphean Investments National Security Fund, a venture-studio-style investment fund focused on technology investments that strengthen national security for the U.S. and its citizens. He is the Founder of Immortal Cyber, Inc., an advanced cybersecurity research and engineering firm providing offensive cyber delivery services and “Cyber-as-a-Service” for unique clients, and Co-Founder & CEO of RapidAscent, Inc., a scalable, task-based cyber apprenticeship solution addressing the historic shortage of technical personnel in the U.S. and worldwide. Brian also co-founded and chairs the board of the Cyber Bytes Foundation, a 501(c)(3) dedicated to building a unique cyber ecosystem of educational and outreach programs for the cyber workforce. A longtime advocate for election security, Brian serves on the Board of Directors of the Election Integrity Foundation, the 501(c)(3) behind the DEF CON Voting Village.

SpeakerBio:  Matt Blaze

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.

SpeakerBio:  Jake Braun, DEF CON Franklin

Jake Braun is the co-founder of DEF CON Franklin and the Executive Director of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. He most recently served in the White House as acting Principal Deputy National Cyber Director. While at the White House, he oversaw the implementation of the National Cybersecurity Strategy, including efforts to secure our water systems, modernize the federal cyber workforce, enhance cyber cooperation with allied nations, and develop AI cybersecurity policy.

In addition to his role at the University of Chicago, Mr. Braun co-founded the DEF CON Voting Machine Hacking Village. In that capacity, he co-authored two award-winning reports on the cyber security of our election infrastructure: the DEF CON 25 and 26 Voting Village Reports. Most recently, he partnered with DEF CON, the world's largest and longest running hacker conference, to launch “DEF CON Franklin,” a program to memorialize the most innovative and impactful findings from DEF CON in the annual “Hackers’ Almanack.” “DEF CON Franklin” also recruits cyber volunteers to support underresourced critical infrastructure.

SpeakerBio:  David Jefferson

David Jefferson is an internationally recognized expert on voting systems and election technology, and an advisor to five successive California Secretaries of State. In 2004 he was coauthor of the SERVE Security Report detailing the security vulnerabilities in the Defense Department's proposed Internet voting system, leading to the cancellation of the program. In 2003 he was a member of the California Task Force on Touchscreen Voting, whose recommendations led to voter-verified paper audit trails for electronic voting machines. He has led half a dozen technical studies on reliability and security of voting systems, including the California Post-Election Audit Standards Working Group that produced the first government study of post-election auditing. He has served on the boards of directors of both the California Voter Foundation and Verified Voting, and is currently on the board of the Election Integrity Foundation that puts on the annual DEF CON Voting Village.

Dr. Jefferson received a BS in mathematics from Yale University, and a Ph.D. in computer science from Carnegie-Mellon University. From 1980 to 1994 he was a professor at the University of Southern California (USC) and then at UCLA. He is now retired from Lawrence Livermore National Laboratory where he conducted research in supercomputing and cyber security.

SpeakerBio:  Jeff Moss
No BIO available
SpeakerBio:  Kendall Spencer

Kendall Spencer is an attorney specializing in emerging companies, technology transactions, and the legal issues shaping innovation. Since joining DEF CON’s Voting Village as a Georgetown Law student in 2019, he has worked alongside Matt Blaze, David Jefferson, and the Voting Village team at the intersection of election technology, cybersecurity, and democracy. Spencer serves on the Board of Directors of the Election Integrity Foundation and has advised state election officials on election security, post-election audits, and cybersecurity best practices. His work focuses on bridging the gap between technical research, public policy, and the law—helping policymakers, election officials, security researchers, and the public better understand the role election security plays in strengthening democratic institutions and public confidence in elections. A frequent DEF CON speaker, Spencer is passionate about fostering thoughtful, bipartisan conversations on the role of technology in protecting election integrity and the democratic principles that underpin a free and open society. Outside of his legal and technology work, Spencer is a rare book dealer and collector specializing in early American history and the Black diaspora.

SpeakerBio:  Philip Stark

Philip B. Stark is Distinguished Professor of the Graduate School at the University of California, Berkeley, where he has served as department chair and associate dean. In 2007 he invented "risk-limiting audits" ("RLAs"), endorsed by the National Academies of Science, Engineering, and Medicine and the American Statistical Association, among others, and required or authorized by law in about 15 states. He designed and helped conduct the first dozen pilot RLAs, helped draft RLA legislation for several states, and has published open-source software to support RLAs. In 2012, he and David Wagner introduced "evidence-based elections," a paradigm for conducting demonstrably trustworthy elections. Stark has served on the Board of Advisors of the US Election Assistance Commission and its cybersecurity subcommittee, the Board of Directors of Verified Voting Foundation and the Election Integrity Foundation, and on the California Post Election Audit Standards Working Group. He has worked with the Secretaries of State of California, Colorado, and New Hampshire and numerous local election officials. He has testified about election integrity in state and federal courts and to legislators. He received the IEEE Cybersecurity Award for Practice, the UC Berkeley Chancellor's Award for Research in the Public Interest, and the John Gideon Award for Election Integrity. He is a fellow of the American Academy of Arts and Sciences, the American Statistical Association, and the Institute of Physics.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Friday - 17:00-17:45 PDT


Title: Welcome to your Airbnb, the key is under the mat -or- Alice and Bob with Padlocks
Tags: DCNextGen | Creator Event/Activity | Youth
When: Friday, Aug 7, 17:00 - 17:45 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

We teach everyone how to verify “there’s a padlock” but there’s a lot of cool math behind that padlock, and we will show, with everyday props and actors, how modern cryptography works under the hood. Can we implement Diffie-Hellman with padlocks? Instead of memorizing complicated math, we’ll solve puzzles together as a team and reveal how computers securely exchange secrets, protect private information, and prove someone’s identity online. Along the way, you’ll recreate the ideas behind the same technologies used by websites, games, banks, and messaging apps. Prerequisites: none. All props are provided and participants will keep some props.

SpeakerBio:  Gilgamesh
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Friday - 10:30-10:59 PDT


Title: What Election Security Researchers Need to Know About the DMCA
Tags: Voting Village | Creator Talk/Panel
When: Friday, Aug 7, 10:30 - 10:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

Section 1201 of the Digital Millennium Copyright Act (DMCA) has historically acted as a major legal barrier to election security research. Section 1201’s “anti-circumvention” provision, 17 U.S.C. § 1201(a)(1), makes it illegal to circumvent or bypass a technological protection measure (TPM) that effectively controls access to a copyrighted work. Violations of the provision can carry both civil and criminal liability, making it a serious risk. Statutory exemptions for security testing, 17 U.S.C. § 1201(j), and encryption research, 17 U.S.C. § 1201(g), apply in some instances, but have important limitations. The security testing exemption covers “good faith” security testing, provided that the research has been authorized by the owner of the computer, and does not violate other laws like the Computer Fraud and Abuse Act or the Copyright Act. The encryption research exemption covers the investigation of encryption applied to copyrighted works, so long as those works were lawfully obtained, and the researcher has made a “good faith effort to obtain authorization.” Section 1201 has historically had a substantial chilling effect on election security research even with these statutory exemptions in place. To address this problem, U.S. regulators adopted a much broader “temporary” security research exemption that provides stronger protection for critical security research on voting machines. The current version of the temporary exemption, 37 C.F.R. § 201.40(b)(18), covers “good faith security research” on a “lawfully acquired” computer, or with the permission of the owner. The temporary exemption enables security research without the need for permission from voting machine companies. However, risks remain despite the temporary exemption, which contains ambiguities and loopholes that voting machine companies sometimes exploit. This talk will explain what the exemption covers, what it may not, and why it is so important to the research that keeps our elections safe and secure.

SpeakerBio:  Tori Noble

Tori Noble is a Staff Attorney at the Electronic Frontier Foundation specializing in free speech, intellectual property, cybersecurity, and artificial intelligence issues. Tori litigates cases and files amicus briefs in state and federal courts. Representative cases include defending online publishers from lawsuits intended to silence their work; advancing transparency into government activities that harm digital rights; and advocating against overbroad interpretations of copyright laws in AI cases. Tori also advises security and encryption researchers through EFF’s Coder’s Rights Project. Tori co-leads EFF’s policy work on cybersecurity and AI. Prior to joining EFF, Tori represented media companies, television and film producers, and journalists as a litigation associate at Dentons US LLP and a First Amendment fellow at The Intercept. Tori holds a B.A. from the University of Michigan Gerald R. Ford School of Public Policy and a J.D. from Stanford Law School. Tori holds a B.A. from the University of Michigan Gerald R. Ford School of Public Policy and a J.D. from Stanford Law School.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Friday - 17:00-17:59 PDT


Title: What Got You Here Won't Get You There: Security in the AI Era
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

A candid panel on how AI is reshaping security careers. We sit down with practitioners ranging from CISO to product security engineer, working across governance, physical hardware and SaaS, for an honest 45-minute conversation about what it takes to break in, level up, and stand out now that AI is changing what skills matter, what roles look like, and how hiring gets done.

SpeakerBio:  Amber Bennoui
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 16:00-16:59 PDT


Title: What is AI?
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Curious what is actually happening inside an AI when it answers your questions? In this session, you'll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We'll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

SpeakerBio:  Sam Mosley, CodeBloom
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 13:00-13:59 PDT


Title: What is AI?
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Curious what is actually happening inside an AI when it answers your questions? In this session, you'll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We'll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

SpeakerBio:  Sam Mosley, CodeBloom
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 13:30-14:59 PDT


Title: What is the Right Balance of Rules for Defenders & Adversaries? Determining which dual-use model restrictions make sense and which only disarm defenders
Tags: DEF CON Official Talk | AI Village
When: Friday, Aug 7, 13:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Defenders and attackers are locked in a renewed race where AI has enabled new defenses and new attacks. In this iterated dual-use, game-theoretic situation, how can defenders be maximally enabled without unduly increasing the risks that adversaries get access to the same capabilities?

As highly capable LLMs face increasing restrictions and regulatory interest from policy makers, adversaries are attempting to evade restrictions, sometimes putting those who play by the rules at a disadvantage.

This panel will discuss recent examples and will look toward the near future as model capabilities increase yet again in both closed and open weights models.

Speakers:Emanuel Gawrieh,Jason Clinton,Bruce Schneier,Heather Adkins

SpeakerBio:  Emanuel Gawrieh, Co-Chair at AI Village

Emanuel Gawrieh is a Senior Chaos Containment Engineer on the Advanced Threat Protection team at Google, where he specializes in architecting and proving out threat models for complex workloads in highly regulated environments. As a core member of Google's Secure AI Framework (SAIF) team, he works closely with Google AI Red Team, Google DeepMind, and the Cloud CISO's office to establish AI security standards - contributing to the early development and specialized fine-tuning of dual-use models like SecGemini to mitigate emerging AI-specific risks. Outside of his work at Google, he is a leading voice in AI Security policy and community evangelism - having presented at DEFCON, RSA and is an active member of the [un]prompted CFP board. Additionally, he has architected the infrastructure for several Generative AI Red Team events and actively advises congressional leaders on AI and cybersecurity policy.

SpeakerBio:  Jason Clinton, Deputy CISO at Anthropic

Jason joined Anthropic in April 2023 as its first CISO after more than a decade at Google, where he most recently led Chrome infrastructure security working on defense against advanced persistent threats. While at Google, he also worked on ChromeOS and Android Pay. At Anthropic, Jason guides security strategy including detection and response, compliance, physical security, security engineering and IT. Jason promotes the security organization's work to uphold Anthropic's Responsible Scaling Policy framework, ensuring that the company has appropriate security safeguards in place for the responsible development and deployment of AI models. He is also the author of "Ruby Phrasebook".

SpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.

SpeakerBio:  Heather Adkins, Vice President of Security Engineering at Google

Heather Adkins is a 24-year Google veteran and founding member of the Google Security Team. As VP, Security Engineering and head of Google’s Office of Cybersecurity Resilience she has built a global team responsible for maintaining the safety and security of Google’s networks, systems and applications. She has an extensive background in practical security, and has worked to build and secure some of the world’s largest infrastructure. She is co-author of Building Secure and Reliable Systems (O’Reilly, 2020), was deputy chair of CISA’s Cyber Safety Review Board, and has advised numerous organizations on how to adopt modern defendable architectures.


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Friday - 10:30-10:59 PDT


Title: What TEEs Do Not Hide: Residual Metadata Leakage in Confidential LLM Serving
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Friday, Aug 7, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Confidential LLM inference protects prompt, model, KV-cache, and intermediate-tensor memory, but it does not remove the metadata emitted by the serving stack. We audit those emitted surfaces on a verified H100 confidential-GPU serving setup using a dense/MoE Gemma pair. The claim is narrow: we do not show a TEE memory break, and corrected client timing does not support a leakage claim. We do show that client/proxy-observed HTTP-stream metadata and low-concurrency pre/post-scrape metrics reveal request attributes in this harness. Decomposition ties the signal to exported token counters, request bytes, response bytes, and application-level stream-chunk shape. Deployed mitigations suppress those carriers: token-counter redaction reduces metrics leakage, request padding removes the direct prompt-length row, and chunk padding suppresses the tested HTTP-stream rows. Memory confidentiality and metadata minimization are different properties, and confidential LLM serving needs both.

SpeakerBio:  Anup Swamy Veena

I am a security researcher and engineer focused on cryptography, privacy, and AI systems. My work spans zero-knowledge proofs, trusted execution environments (TEEs), confidential computing, and secure distributed infrastructure, with a particular interest in building verifiable and privacy-preserving AI. Over the years, I have contributed to open-source cryptography projects in the Rust ecosystem and worked on cryptographic protocols, proving systems, and decentralized infrastructure. Currently, I focus on secure AI inference in TEE and attestations, verifiable computation, and the security of large-scale AI deployments, including research on metadata leakage in confidential AI systems and routing leakage in Mixture-of-Experts models. My interests lie in applying cryptographic techniques to build trustworthy systems at the intersection of security, distributed systems, and machine learning.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Friday - 15:30-16:30 PDT


Title: When AI Finds Everything: Vulnerability Policy for the Coming Discovery Surge
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 16:30 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

AI-enabled vulnerability discovery is moving from novelty to inevitability. As frontier systems become better at finding, validating, and reporting vulnerabilities at scale, the ecosystem will face a basic policy question: what happens when discovery accelerates faster than coordination, triage, remediation, prioritization, and response can absorb? This talk examines the policy and operational implications of a world where vulnerability discovery becomes cheaper, faster, and more automated. Using CVE, CWE, CNA operations, and CISA’s vulnerability management mission as grounding examples, we will explore how current processes may strain under higher volume, probabilistic findings, duplicate reports, inconsistent quality, and incomplete downstream impact context. The talk will not argue that AI breaks vulnerability management. Instead, it argues that AI magnifies existing gaps across the software development lifecycle and incident response ecosystem: unclear responsibility, uneven data quality, insufficient automation, fragile public-good infrastructure, and policy models that often assume human-scale discovery, reporting, and response. We will discuss what policymakers, program stewards, hackers, vendors, software producers, defenders, and infrastructure operators should do now to prepare for the next era of vulnerab

Speakers:Alec Summers,Lindsey Cerkovnik,Madison Ficorelli

SpeakerBio:  Alec Summers, The MITRE Corporation

Alec Summers is a principal cybersecurity engineer at the MITRE Corporation with diverse and extensive experience in software assurance and vulnerability management, as well as cyber operations, assessments, and supply chain risk management. He is the MITRE CVE and CWE Project Leader, managing teams that support vulnerability and weakness research & analysis, content production, program coordination, services development, and community engagement across a global partner base comprising industry, government, and academia. He serves as the moderator for the CVE Board and CWE Board.

SpeakerBio:  Lindsey Cerkovnik, CISA

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.

SpeakerBio:  Madison Ficorelli

Madison Ficorilli is a vulnerability transparency advocate and staff security manager at GitHub, leading the advisory database curation team. She is passionate about vulnerability reporting, response, and disclosure, and co-chairs the relevant Open Source Security Foundation (OpenSSF) working group and serves on the CVE Program Board. Her views are enriched by her prior experience as a product incident response analyst at GitHub and as a vulnerability coordinator at the CERT Coordination Center at the Software Engineering Institute at Carnegie Mellon University.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Friday - 12:00-12:25 PDT


Title: When the Agent Lies: Why Neurosymbolic AI is the Security Layer Nobody is Building Yet
Tags: Blacks In Cyber Village | Creator Workshop
When: Friday, Aug 7, 12:00 - 12:25 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

AI agents are being handed the keys to enterprise infrastructure, executing code, querying databases, making access decisions, and increasingly controlling physical systems. Most are built on pure LLM inference, making them stochastic, opaque, and vulnerable in ways traditional security tooling was never designed to catch. This session breaks down how LLM-based agent architectures fail from a security perspective, what a more auditable architecture looks like in practice, and why the security community needs to be driving this conversation before the agents are already inside the perimeter. Discover how grounding agent decisions in structured knowledge graphs, symbolic reasoning, and auditable state transitions dramatically reduces this exposure, offering a critical new security layer. Join us to understand the future of secure AI agents.

SpeakerBio:  Maureese Williams, Senior LLM and Data Engineer

Maureese Williams is a Senior LLM and Data Engineer with extensive experience in media, finance, and technology. They specialize in leveraging AI and Large Language Models (LLMs) to solve real-world problems and empower developers. Their background includes working with companies like Warner Bros Discovery, Accenture, Ugam, Vanguard, and BlackRock, focusing on data engineering, vector databases, and generative AI. Maureese is also known for contributing to open-source projects.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Friday - 17:15-17:59 PDT


Title: Where hackers find their people, and security finds its strength
Tags: Adversary Village | Creator Talk/Panel
When: Friday, Aug 7, 17:15 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Before it was an industry, this was just people. Curious folks poking at things, breaking stuff to figure out how it worked, and telling the next person what they found. Somewhere along the way a few of them started building the rooms where that could happen: the cons, the villages, the meetups, the spaces where you finally found your crew.

This panel gets some of those organizers together to talk about something we don't say out loud enough: the community is the security. Every mentor who answered your dumb questions, every village that felt like home, every hallway conversation that turned into a tool or a job or a friendship, someone had to make space for that. We will swap stories about what it takes to build and protect these communities, why the people who show up matter more than anything, and how the spaces we create end up being some of the strongest defense we have got. Pull up a chair. Nobody does this alone, and that is the whole point.

Speakers:Seeyew Mo,Ashley S,Tatiana U,Heidi Potter,Christine Billingsley

SpeakerBio:  Seeyew Mo, Director of Training for DEF CON.

Seeyew Mo is the Senior Advisor for Cyber Maryland where he leads the state's cyber workforce development. He also serves as the Director of Training for DEF CON. He previously served as the Assistant National Cyber Director for Cyber Workforce, Training and Education at the Office of National Cyber Director (ONCD). In his role, Seeyew leads and coordinates the implementation the White House’s National Cyber Workforce and Education Strategy. He believes in taking a holistic view – doctrine, people, and technology - to making advancements in cyber workforce and digital safety awareness. Seeyew is an expert in the intersection of cybersecurity, technology, and national security with 18 years of experience spanning tech development, policymaking, and political campaigning.

SpeakerBio:  Ashley S, Sr. Solutions Engineer at Censys

Ashley is a cybersecurity researcher, threat intelligence practitioner, and Senior Sales Engineer at Censys, where she conducts strategic research on IoT botnets and adversarial infrastructure. Her research sits at the intersection of hardware-based attack infrastructure and influence operations, tracking how low-cost consumer electronics are weaponized as residential proxy networks, ad fraud engines, and persistent footholds inside homes and enterprise networks. She spends tons of time building up the cybersecurity community and got her start by volunteering after making a career pivot after her military service. She is very passionate about community protection and community building, as evidenced by her role as Chief Security Officer for BsidesLV.

SpeakerBio:  Tatiana U, Technical Program Manager at Bugcrowd

Tatiana (Tati) is the Technical Program Manager for Live Hacking at Bugcrowd, which means she’s usually the one making sure a room full of hackers actually turns into a working event. She didn’t come up in this industry through school or a straight career path. She came up through it the way most people do: somebody let her in, answered her questions, and made room for her at the table. She’s spent the years since returning the favor.

SpeakerBio:  Heidi Potter, Chief Operating Officer at Turngate

Heidi Potter has spent much of her career bringing people together. Best known for her twenty years helping build and run ShmooCon, she remains passionate about creating welcoming spaces where people can learn, connect, and share ideas. She currently serves as COO of Turngate and spends her free time walking, biking, and occasionally embracing carefully managed chaos.

SpeakerBio:  Christine Billingsley, Chief Operating Officer at Military Cyber Professionals Association

Christine Billingsley is the Chief Operating Officer at the Military Cyber Professionals Association. An accomplished operations and marketing professional with a proven track record of innovation and delivery of best-in-class projects, experiences, and events. She is the creator of the DEF CON Arcade Party and author of Cyber Snackz, an introductory cybersecurity activity book centered around a team of adorable animals who work in different areas of cybersecurity. She is passionate about getting today's youth interested in cyber. She is a mom to humans and a spunky Pomeranian.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Friday - 14:30-15:10 PDT


Title: Who Owns Your Shack? Open Source, Amateur Radio, and the Software We Can't Afford to Lose
Tags: Ham Radio Village | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 15:10 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

A 30–40 minute talk for Ham Radio Village at Defcon. Primary audience is licensed amateur radio operators, with a secondary audience of hackers and security-minded attendees unfamiliar with the hobby. The talk uses the post-mortem license failure pattern in amateur radio software as motivating context, builds an ownership/self-reliance argument, and presents open-packet as a working existence proof of the open-source alternative.

You own your radio. The protocols you use — AX.25 and APRS — are open standards anyone can implement. But the software your club depends on? That's often a different story.

For the security-minded: this is a story about critical communication infrastructure running on software whose source code doesn't exist.

Amateur radio has a long tradition of self-reliance: building your own antennas, maintaining your own gear, understanding your own stack. That tradition breaks down at the software layer. Too much of the tooling that holds the hobby together is maintained by a single developer, distributed as a closed binary, with no source code and no succession plan. We've already seen what happens when that developer is gone: When Roger Barker G4IDE passed in 2004, UI-View32's source code went with him — leaving the community to maintain unofficial workarounds rather than fix the underlying binary, with the registration servers eventually going dark. Bob Bruninga WB4APR's death in 2022 raised the same question for his reference APRS implementations and the aprs.org site he maintained. These aren't edge cases — they're a pattern, and the hobby's aging demographics make it one we can't ignore.

This talk makes the case that open-source licensing isn't just a software philosophy — it's an infrastructure resilience strategy. If a tool is critical to your club's operations or your emergency net, its source code needs to outlive its author.

As a working example, we'll look at open-packet: an early-stage, MIT-licensed packet messaging client in Python — a working existence proof that the open-source path is viable. A brief live demo will show the basic functionality, along with some nice to have extras such as visual themes and a web client.

Attendees will leave with a concrete lens for evaluating the software they depend on, a GitHub link, and three specific asks — from "try it" to "apply this thinking to every tool in your shack."

SpeakerBio:  Jeremy Banker - K0JLB
Bio: Jeremy Banker is a Senior Security Software Engineer at Horizon3.ai, focused on the reliability and resiliency of Horizon3's automated penetration testing platform. He previously spent nearly a decade at VMware, where he co-founded the Security Product Engineering group and led efforts to secure VMware's software supply chain. His open source security tooling, including Build Inspector for CI/CD pipeline anomaly detection and Tommyknocker for automated security control validation, has been featured at Black Hat Arsenal and DEF CON Demo Labs. A licensed amateur radio operator since 2010, he built open-packet, an MIT licensed Python client for packet messaging, after becoming frustrated with the existing closed-source options.

Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Friday - 13:00-13:45 PDT


Title: Whose PR Is It Anyway?
Tags: Nix Vegas Community | Creator Event/Activity
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

In this audience participation-heavy session, you can get your PRs to nixpkgs reviewed and maybe even merged... if the build on one of our systems passes. Come with PRs in hand and call them out, and we'll review, build, and maybe even merge them on stage.

This is Whose PR Is It Anyway, where the version bumps are made up and the builds don't matter.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 22:00-23:59 PDT


Title: Whose Slide Is It Anyway?
Tags: Event | Whose Slide Is It Anyway?
When: Friday, Aug 7, 22:00 - 23:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

DEF CON 34 marks an entire DECADE of “Whose Slide Is It Anyway?”” being the unholy union of improv comedy, hacking, and slide deck sado-masochism. We are the embodiment of the hacker battle cry ""FUCK IT, WE'LL DO IT IN PROD.""

For the last 10 years, our team of slide monkeys have created a stupid amount of short slide decks on whatever nonsense tickles our fancies. Slides are not exclusive to technology, they can and will be about anything. Contestants will take the stage and choose a random number corresponding to a specific slide deck. They will then improvise a minimum 5 minute / maximum 10 minute lightning talk, becoming instant subject matter experts on whatever topic/stream of consciousness appears on the screen.

But....why?

Because for us, the stage is hallowed ground and since stupidity can't be stopped, we decided to weaponize it. Whether you delight in the chaos of watching your fellow hackers squirm or would like to sacrifice yourself to the Contest Gods, it’s a night of schadenfreude for the whole family.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Friday - 15:45-17:15 PDT


Title: Wi-Fi Self Defense & Hacker Hunting & For Beginners
Tags: IoT Village | Creator Workshop
When: Friday, Aug 7, 15:45 - 17:15 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Kit Cost: $140. Class Cap: 30.

SpeakerBio:  Kody Kinzie
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Friday - 17:00-17:55 PDT


Title: WiFi Shuriken: A New Architecture For High Performance Scanning
Tags: Radio Frequency Village | Creator Talk/Panel
When: Friday, Aug 7, 17:00 - 17:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

The WiFi Shuriken is a new microcontroller-based wardriving platform. The current iteration is a dual-band scanner built around a Raspberry Pi RP2350 for orchestration and six Espressif ESP32-C5 scanners. The Shuriken takes inspiration from several excellent projects in the wardriving community, but was designed around one goal: remove bottlenecks and scan as quickly and efficiently as possible.

This talk will cover how the design distributes responsibilities across the system, moves scan data, deduplicates results, tolerates failures, and leaves room for future expansion. We’ll discuss why specific hardware was selected, and just as importantly, what was intentionally left out and why.

SpeakerBio:  CoD_Segfault, Hard Hat Brigade

CoD_Segfault is a hardware hacker, wardriver, and retro-computing enthusiast. His projects usually center on custom electronics, embedded systems, and RF experimentation. He enjoys taking ideas from prototype to working hardware, especially when that means designing PCBs, abusing microcontrollers, or collecting wireless data in the real world. He is also part of the Hard Hat Brigade, where his builds often involve questionable ideas and putting things on his head that probably don't belong there.


Return to Index    -    Add to Google    -    ics Calendar file

Packet Hacking Village - Friday - 14:30-15:30 PDT


Title: Wiring the Harness: Orchestrating Frontier Models for Vulnerability Hunting at Scale
Tags: Packet Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

While frontier models are powerful, simply asking one to "find vulnerabilities" is far less effective than pairing with a well-designed harness, a gap that widens further down the stack and peaks at embedded firmware. During Project Glasswing, Intel scanned hundreds of repositories, from firmware to containers. This talk covers common pitfalls in LLM vulnerability hunting and presents a multi-stage harness: reconnaissance and context compression, multi-model hunting, deduplication, false positive detection, and verification. We will explore selecting the right models per stage, cutting token costs, and, the real battle, reducing false positives, especially for lower-level code where accuracy is hardest.

Speakers:Tony Martin,Arie Haenel

SpeakerBio:  Tony Martin, Principal Engineer & Offensive Security Research lead at INT31 Security Research, Intel

Tony Martin is a Sr. Principal Engineer in Intel’s INT31 Security Research team, where he focuses on emerging threats, software architecture and AI security. He has discovered thirty CVEs and one CWE and is senior staff at DEF CON’s Packet Hacking Village.

SpeakerBio:  Arie Haenel, Principal Engineer & Offensive Security Research lead, INT31 Security Research, Intel

Arie Haenel is a Principal Engineer at Intel, where he leads ASSERT, an Offensive Security Research team. He has over 25 years of professional experience, in security research and security product development on a vast number of embedded platforms, at Intel, Cisco and NDS. In his spare time, Arie teaches security engineering as an Adjunct Lecturer at the Lev Academic Center.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Friday - 14:00-14:59 PDT


Title: Women Loving Women Meetup
Tags: Queercon Community | Creator Event/Activity
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Friday - 20:00-23:30 PDT


Title: Women, gender non-conforming and non-binary meetup with The Diana Initiative
Tags: Meetup | The Diana Initiative
When: Friday, Aug 7, 20:00 - 23:30 PDT
Where: LVCCW Level 2 W208-209 (Diana Initiative) - Map

Description:

We'd love to get all the gender non conforming, non-binary and women together to hang out and make friends! DEF CON is better with friends. Stop in for a bit, or the whole time.


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 17:00-17:59 PDT


Title: Work Session: Binary Code
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Did you know that every photo, song, and message on your phone is really just a long string of 0s and 1s? Come learn how binary code works and then turn your very own secret word into a wearable friendship bracelet using our binary alphabet chart! This session is beginner friendly and a great way to see how computers really think. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 14:00-14:59 PDT


Title: Work Session: Ciphers
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We'll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Friday - 11:00-11:59 PDT


Title: Work Session: Ciphers
Tags: CodeBloom | Creator Workshop
When: Friday, Aug 7, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We'll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Friday - 12:00-12:30 PDT


Title: Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE
Tags: Bug Bounty Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Arbitrary file write bugs are often treated as “almost critical” findings: interesting, dangerous, but most times it’s hard to prove impact when the target does not let you write a web shell to an obvious location or overwrite some magic configuration file to achieve code execution. This talk is about closing that gap for black box approaches.

Instead of focusing on a single framework, we will present novel primitives that will make you able to pop shells across the most popular programming languages and frameworks in different ecosystems, all with as little information as possible about the target application.

The session will start by assessing the current state of the art of arbitrary file write in bug bounty style scenarios. This will set the stage for the rest of the talk as we will start building a methodology to correctly identify exploitation capabilities and obtain as much information as possible about the target.

From there, we will move into showcasing new techniques to abuse file write primitives and achieve the ultimate goal of code execution. We will go over novel techniques that apply both to the most popular interpreted languages and to the most used runtime environments.

Bug Bounty Hunters who join this talk will not only leave with fresh techniques to apply in their engagements, but with a reusable mental model for identifying their target’s execution context and proving maximum impact when faced with arbitrary file write scenarios.

Speakers:Bruno Mendes,Rafael Castilho Silva

SpeakerBio:  Bruno Mendes, Head of Hacking, Ethiack

Bruno Mendes is the Head of Hacking at Ethiack. He began his work career as an Offensive Security Researcher on Intel's IPAS Cloud Security team in 2024. In bug bounty, back in 2023 placed 5th overall in the teams category and won the "Not Dead Yet" award at an Intigriti Live Hacking Event in Lisbon, and most recently co-authored a critical RCE with André Baptista (0xacb) that earned over $100k+ in a single program. He has an extensive CTF background being a three-time winner of the Cybersecurity Challenge Portugal (2021-2023), captain of Team Portugal at the European Cybersecurity Challenge (2022, 2023, 2025), and won the 2023 International Cybersecurity Challenge with Team Europe. He also captained the Instituto Superior Técnico CTF team (STT) from 2022 to 2024.

SpeakerBio:  Rafael Castilho Silva, Ethiack

Security Reseacher at Ethiack fucosed on Vulnerability Research


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 10:00-10:45 PDT


Title: X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Friday, Aug 7, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

Agents now run with thousands of third-party plugins — MCP servers, Claude skills, GPT actions, IDE extensions, plugin marketplaces — and the prevailing trust model is roughly “read the README and hope.” Tool descriptions are executable prompts. Tool parameters are executable code paths. Tool outputs feed straight into the next agent step. Yet there is no npm audit for this ecosystem, no signed manifests, and no capability sandbox in the wild.

MCP X-Ray is an open-source security scanner that ports classical pentest tradecraft to the agent plugin supply chain. It combines static config and repo audit, rules-based and LLM-driven semantic analysis, and active pentesting that actually invokes tools with adversarial inputs — emitting SARIF that drops into GitHub, VS Code, and CI gates today. In this 30-minute session we will (1) walk the threat model that ties MCPs, skills, and plugin bundles together; (2) live-demo X-Ray finding real vulnerabilities in each. Attendees walk away with a CI template they can drop in on Monday, and three intentionally vulnerable plugins to keep practicing on.

Speakers:Xia Hua,Abhijeet Kumar

SpeakerBio:  Xia Hua

Xia is co-founder and CEO of Traceforce which secures AI native apps running on devices. She previously led engineering at Clumio (acquired by Commvault), delivering cloud data protection products that were 20x faster and 10x more scalable than competitors. Earlier, she was an in-memory database architect at Oracle. Xia earned her PhD in Applied Mathematics from MIT.

SpeakerBio:  Abhijeet Kumar

Abhijeet Kumar is an OSCP-certified offensive security researcher and M.Eng Cybersecurity student at the University of Maryland. He has disclosed critical vulnerabilities across NASA, SAIL critical infrastructure, Keurig Dr Pepper, and U.S. government programs which includes a CVSS 10.0 RCE that triggered an official CERT-In incident response and a full account takeover chain affecting users across 20+ countries. He captains UMD's CTF team RandomHackers, which placed 1st out of 64 universities at HTB Hack The Madness 2026, and has spoken at the Billington State and Local Cybersecurity Summit alongside the Director of Adversary Emulation.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 13:00-13:45 PDT


Title: xEndity: IoT Firmware Analysis & Digital Twin Platform
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

IoT devices are embedded in critical infrastructure globally, yet security teams face a fundamental constraint: you cannot aggressively test what you cannot safely replicate. Physical hardware is expensive, limited in supply, and testing against production systems is off-limits. This leaves defenders operating blind against an expanding attack surface of billions of connected devices.

xEndity is an open-source, end-to-end IoT firmware emulation platform that transforms raw firmware binaries into fully functional, network-ready virtual device instances, no physical hardware required. It provides an automated pipeline spanning firmware acquisition, binary analysis, filesystem extraction, emulation packaging, and orchestrated deployment of emulated device networks at scale.

The platform enables two high-impact use cases: first, as a scopeless penetration testing range where red teams and researchers can conduct unrestricted vulnerability validation, exploit development, and attack simulation against realistic IoT environments. Second, as a deceptive defense layer where emulated devices are deployed as high-interaction honeypots to capture adversary tradecraft, collect OS-level and network telemetry, and generate actionable threat intelligence.

Speakers:Zeus "LightningGod" Chan,Kenneth "kenleejl" Lee

SpeakerBio:  Zeus "LightningGod" Chan

Zeus Chan is a security researcher on the Adversary Emulation Team at HTX (Home Team Science and Technology Agency), where he focuses on IoT firmware analysis, device emulation, and offensive security research. His work spans building automated pipelines for firmware emulation, security testbed development, and honeypot deployment for threat intelligence collection against embedded systems. Zeus has presented IoT security research at DEFCON events globally and Milipol TechX Singapore, and has supported community initiatives including the HTX Public Safety Village at DEFCON Singapore. He holds experience in red team operations supporting critical national infrastructure across the finance and healthcare sectors.

SpeakerBio:  Kenneth "kenleejl" Lee

Cyber security enjoyer


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Friday - 12:00-12:30 PDT


Title: Yet Another Walking Dead of Active Directory
Tags: Adversary Village | Creator Talk/Panel
When: Friday, Aug 7, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Disabled Active Directory accounts are commonly treated as harmless remnants of the past. In reality, many of these “dead” objects still retain dangerous inbound permissions, historical privilege artifacts, inherited ACL relationships, and hidden attack paths that most organizations never investigate.

This talk demonstrates how disabled users, computers, and service accounts can still become active participants in privilege escalation chains through misconfigured DACLs, AdminSDHolder side effects, nested group inheritance, and delegated permissions. Through a real-world inspired case study, attendees will learn how a seemingly low-privileged user leveraged hidden rights over a disabled account to move toward Domain Admin in a mature enterprise environment.

The presentation also introduces LazarusWakeUp, a tool designed to identify and analyze disabled Active Directory principals with dangerous inbound relationships, helping operators uncover hidden privilege escalation paths involving forgotten identities that traditional enumeration techniques and BloodHound analysis may overlook.

Additionally, the talk presents a new perspective on Active Directory Recycle Bin abuse and object resurrection, showing how deleted identities may continue to create security risks even after organizations believe they have been removed entirely.

SpeakerBio:  Nikos "nickvourd" Vourdas, EY

Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Friday - 17:00-17:59 PDT


Title: Yoga
Tags: The Diana Initiative | Creator Event/Activity
When: Friday, Aug 7, 17:00 - 17:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

Come join us for morning yoga and meditation. This workshop is inclusive of all bodies. Meditation can help quiet the mind, manage stress, and enhance overall emotional well-being, making it a great way to start the day.

SpeakerBio:  Deanna Heon
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Friday - 16:35-17:15 PDT


Title: You Hold the Helm: Agentic LLM Workflows for Malware Reversing
Tags: Malware Village | Creator Talk/Panel
When: Friday, Aug 7, 16:35 - 17:15 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

Malware analysts are integrating LLMs into their reversing workflows today, in real casework. The MCP integrations for IDA Pro, Ghidra, radare2, and Binary Ninja already exist and are publicly available, and analysts are using them to rename functions, triage samples, and hunt for vulnerabilities. Adoption has outpaced any measured account of where these tools are reliable and where they are not. There is also a cost problem that gets little attention: running an agent against a single sample can burn an enormous number of tokens, much of it spent having the model rediscover the same things on every binary. This session addresses both. We built an agentic malware analysis framework, tested it across multiple models and real samples scored against ground truth, and we are bringing the numbers along with the workflows. The framework connects LLMs directly to disassemblers and decompilers through MCP, and wraps that with per-language skills for the malware families analysts actually encounter: C and C++, C#, Go, and Android. Each skill encodes what the runtime looks like, how the decompiler tends to mangle that specific target, which structures and metadata are worth recovering first, and what the model can safely ignore. The Go skill carries knowledge of the pclntab and the runtime's calling conventions. The C# skill assumes IL and metadata tables rather than native code. The Android skill separates the DEX, the native libraries, and the manifest, and knows where behavior usually hides. The skills exist for efficiency. Without them, the model relearns the same Go runtime layout on every sample and pays the same token cost to reach the same conclusion. With them, that context is supplied once and the model spends its budget on the sample. The framework runs inside Docker containers orchestrated through an ADK agent loop. Three concrete reasons make this matter. Isolation keeps live malware analysis off the host. Reproducibility means the same container, skill, and sample produce similar starting conditions every time, which is what makes any claim about model performance meaningful. Disposability means that when an agent corrupts its own analysis state, and it will, you tear the container down and start clean rather than nursing a polluted session. The ADK loop is what lets the agent act on its own: pulling function lists, following cross-references, reading decompiled output, and issuing disassembler commands. It is also where most of the interesting failures show up when the agent is not constrained. Function renaming and summarization on stripped binaries holds up well, but only when functions are fed with surrounding call context rather than dumped in bulk. Behavioral triage, the question of what a sample does and where to look first, is faster through the agent than manual function-list review, and the benefit is largest for less experienced analysts. Pattern matching across a binary is reliable when you specify the class of issue to look for. The per-language work also pays off on Go and Rust samples, where traditional C and C++ oriented decompilers produce walls of indistinguishable functions and the LLM-assisted workflow often cuts through what the tooling alone cannot. The failures matter as much as the wins. Crypto identification is where the models are most confidently wrong, mapping anything stream-cipher-shaped onto whatever algorithm they saw most in training. Deobfuscation of any serious protection scheme breaks down quickly. CVE matching is the most consequential failure, because a fabricated CVE number reads with the same authority as a real one, and an analyst who puts it into a threat report has introduced an error that is hard to catch later and can misdirect incident response. Scope drift shows up throughout: left unconstrained, the agent will decide on its own that you wanted detection rules when you asked for unpacker analysis. We show each of these failure modes on screen with the actual model output. The core of the session is a direct comparison, the same model and the same sample, run two ways. First pass is a minimal prompt with the agent left to default behavior. Second pass, we drive, selecting which functions to examine, supplying context through the right per-language skill, and constraining the output format. The model does not get smarter between passes. We get more deliberate about how we use it, and the output diverges sharply. That is the thesis as a demo rather than a claim: the analyst is the captain and the model is the crew, and analysis quality tracks almost entirely with how well it is steered. We walk the comparison side by side on real samples, and ship the demo binaries and both prompt sets with the talk. Attendees leave learning how to do a full setup: the Docker containers, the ADK agent scaffolding, the per-language skills for C and C++, C#, Go, and Android, and the prompt templates that worked alongside the ones that did not. They can install it, run the same comparisons we ran, and extend the evaluation to their own samples and analysis tasks. They also leave with a calibrated sense of which tasks are safe to hand to an agent, which require careful steering, and which should never be trusted without manual verification. Additionally, we will open source our framework the day of the talk.

Speakers:Asher Davila,Lenin Alevski

SpeakerBio:  Asher Davila, Vulnerability Researcher at Palo Alto Networks

Passionate about binary analysis, binary exploitation, reverse engineering, hardware hacking, retro computing, and music.

SpeakerBio:  Lenin Alevski, Security Engineer at Google

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Friday - 14:30-14:59 PDT


Title: You're Probably Using FPE Wrong
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Friday, Aug 7, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Format-preserving encryption is widely deployed and widely misunderstood. It appears in PCI environments, GDPR compliance architectures, banking systems, payment platforms, and legacy applications where changing the data format is not an option. Unfortunately, many production uses of FPE get the important details wrong.

This talk is a practical field guide to FPE.

We will walk through NIST FF1 and FF3-1 from the perspective of someone building or reviewing a real system. The focus is not on cryptographic theory for its own sake, but on the decisions that matter in production: choosing the radix, understanding domain-size limits, using tweaks correctly, and recognizing when the security margin is thinner than it looks. We will also talk about the key management problem that most FPE libraries leave unresolved.

Finally, we will separate good use cases from bad ones. FPE can be the right tool for structured sensitive data, legacy systems, and format-constrained workflows. It can also be the wrong tool, especially when small domains, poor key separation, missing tweaks, or assumptions borrowed from tokenization creep into the design.

SpeakerBio:  Leslie Gutschow

Principal engineer and founder of Horizon Digital Engineering. Named inventor on two US patents covering format-preserving encryption and string protection techniques (OpenText/Micro Focus). Former Principal Architect and Professional Services at Micro Focus/Voltage Security (7 years) — led enterprise FPE deployments and integrations across financial services, healthcare, and retail. Previously: Naval Research Lab, Boeing. Currently researching memory-safe OS infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 17:30-17:59 PDT


Title: You've Got Mail (That Was Meant For No One)
Tags: DEF CON Official Talk | Tool 🛠
When: Friday, Aug 7, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

In 2020, I registered a domain on a whim, mostly because I thought it would be hilarious for email, and then forgot about it. Then a city government faxed me their internal documents. Then an organization started sending me Cisco UCM alerts. Then 363,000 emails arrived in sixteen months. I never sent a single packet of attack traffic. The vulnerability is an assumption, that a domain nobody owns is safe to hardcode. Developers at enterprise software vendors, government agencies, and companies made that assumption. I registered the domains and the mail flowed in. This talk covers six years of passive email interception across more than 20 domains, the tooling built to systematically map this attack surface across hundreds of TLDs, and what 400,000 misdirected emails reveal about how production mail infrastructure actually fails. No exploits. No credentials. Just a $11 domain registration.

Sheward, M. "Deleteduser.com -- a $15 PII Magnet." Medium, April 2026. https://mike-sheward.medium.com/deleteduser-com-a-15-pii-magnet-c4396eb21061

Krebs, B. "They Told You Not To Reply." Washington Post Security Fix, March 2008. https://web.archive.org/web/20200905092128/http://voices.washingtonpost.com/securityfix/2008/03/they_told_you_not_to_reply.html

Krebs, B. “Chipotle Serves Up Chips, Guac & HR Email.” Krebs on Security, 16 Nov. 2015, https://krebsonsecurity.com/2015/11/chipotle-serves-up-chips-guac-hr-email/

Fitzpatrick, J. “Sears-Kmart MyGofer,” Internet Archive, archived May 1, 2014, https://web.archive.org/web/20140501153309/http://sears-kmart-mygofer.com/

Kim, P. and Gee, G. "Doppelganger Domains." Godai Group, 2011. https://godaigroup.net/wp-content/uploads/doppelganger/Doppelganger.Domains.pdf

Szurdi, J. and Christin, N. "Email Typosquatting." IMC 2017. ACM. https://dl.acm.org/doi/10.1145/3131365.3131399

Internet Assigned Numbers Authority. "RDAP Bootstrap File for Domain Name Space." https://data.iana.org/rdap/dns.json (RFC 7484)

Bradner, S., "RFC 2606: Reserved Top Level DNS Names", IETF, 1999 https://www.rfc-editor.org/rfc/rfc2606

Klensin, J., "Simple Mail Transfer Protocol", RFC 5321, IETF, October 2008. https://www.rfc-editor.org/rfc/rfc5321

DomainTools. "TLD Registration Count Statistics." https://research.domaintools.com/statistics/tld-counts/

SpeakerBio:  Cøry "interpünkt" Solovewicz

Cory Solovewicz (aka interpünkt) is a security consultant specializing in web and mobile application testing. His path into security started early, experimenting with tools like Sub7 and learning how systems could be pushed beyond their intended use. After a career in full-stack development, he transitioned into security to focus on breaking and improving real-world systems. He brings a builder’s perspective to his work, shaped by years of coding, late nights in hackerspaces, and a curiosity for how things fail.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 15:30-16:30 PDT


Title: Your Bank Thinks I'm You: A Complete Kill Chain Against Mobile Banking Security
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Friday, Aug 7, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:
Mobile banking apps stack multiple security layers: RASP (runtime protection), root/jailbreak detection, anti-instrumentation, biometric KYC with liveness detection, and AI-powered anti-deepfake. Each layer promises to stop attackers. We defeated all of them -- in production apps used by millions.

We present a full kill chain against mobile banks and digital wallet apps from a Latin American country, demonstrating how an attacker with an Android phone and open-source tools can: (1) bypass RASP and root detection using kernel-level root solutions and publicly available modules, achieving 100% evasion of OS integrity and anti-hacking controls; (2) use Frida to dynamically instrument biometric SDKs, injecting controlled frames into the liveness capture flow by hooking the "best result" getter and replacing the YUV buffer; (3) bypass KYC identity verification by substituting selfie images and crafting coherent template+photo payloads that the backend accepts as legitimate; and (4) generate AI-synthetic faces from photos that pass liveness detection with 0% detection rate.

Every banking app we tested fell. The different RASPs and biometric SDKs are deployed in 30+ countries, protecting hundreds of millions of users. We'll show why that should worry you. Video demos included.

  1. KernelSU Project - https://kernelsu.org
  2. Kitsune Magisk Fork - https://github.com/1q23lyc45/KitsuneMagisk/tree/kitsune
  3. Frida Dynamic Instrumentation Toolkit - https://frida.re
  4. JADX Decompiler - https://github.com/skylot/jadx
  5. RootBeerSample Root Detection Tool - https://github.com/nickcaballero/RootBeerSample (reference implementation)
  6. TMLP Team / GooseBt Studio - Root bypass module configurations (GitHub, publicly available)
  7. ImNotADeveloper - Xposed module that hides developer mode and USB debugging status from app detection - https://github.com/auag0/ImNotADeveloper
  8. Public KYC bypass repositories (referenced for threat landscape awareness):
Speakers:Xavier "@xaferima" Riofrio Machado,Alex Tipan

SpeakerBio:  Xavier "@xaferima" Riofrio Machado, Fintech Ecuador

Computer Science Engineer with an MSc in Cybersecurity, specialized in offensive security, vulnerability research, and adversarial analysis, with a strong focus on mobile (Android & iOS) security.

I identify systemic weaknesses through logical reasoning, abuse of flawed assumptions, and hands-on exploitation of complex workflows across mobile, web, and API-driven environments. My experience combines deep technical rigor with practical red teaming, allowing me to model realistic attack paths instead of theoretical risks.

I have worked in high-demand environments such as CERN and currently contribute to securing fintech and digital wallet ecosystems, where mobile platforms are critical attack surfaces. While offense-driven by design, I translate offensive findings into concrete defensive controls that actually withstand real-world attackers.

SpeakerBio:  Alex Tipan, Fintech Ecuador

Cybersecurity professional specialized in application security, with a focus on offensive analysis of mobile apps, bypassing RASP controls, and assessing facial biometric workflows. Since school, he has been self-taught in programming, hacking, Linux, networking, and cryptography, later strengthening his academic foundation through a degree in Computer Systems Engineering. He currently conducts hands-on research on protection evasion in financial applications, including advanced instrumentation techniques and validation of real-world risks in authentication processes. His work aims to translate complex technical findings into concrete defensive security improvements.


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Friday - 14:45-15:45 PDT


Title: Your Lives are in Another Struct: Breaking Memory Hacks with Field Relocation
Tags: Game Hacking Village | Creator Talk/Panel
When: Friday, Aug 7, 14:45 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

This talk introduces a compile time anti-cheat for Unity that leverages data-oriented properties of the Unity DOTS stack to move attacker targeted data across struct boundaries. Through static lifetime analysis and eligibility proofs, HP, Score, Lives, and more can be scrambled across a game at build-time, deeply challenging a motivated attacker.

SpeakerBio:  Ryan Zmuda

Ryan is an incoming PhD student at Dartmouth College studying binary security and privacy. He is a published researcher with a special interest in program analysis, vulnerability triage, CI/CD security, and anti-cheat. At the University of Dayton he founded and led the Game Development Club, where he ran numerous seminars and speaker interviews alongside building an arcade cabinet from scratch. His pride and joy is yoyoengine, a 2D game engine written in C that he's been developing for three years.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Friday - 12:00-12:30 PDT


Title: Your Packets Are Showing: Hybrid Quantum ML for Passive OS Fingerprinting
Tags: DEF CON Official Talk | Tool 🛠
When: Friday, Aug 7, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Quantum cybersecurity isn't just Q-Day. We took passive OS fingerprinting, the technique behind p0f and every modern ML-based fingerprinting tool, and mapped it onto a 20-qubit quantum circuit, replacing XGBoost as the classifier inside an "OsirisML"-style pipeline. Head-to-head on real packet captures from CIC-IDS 2017, the quantum version landed within 0.013 F1 of XGBoost on identical features, using roughly two orders of magnitude fewer trainable parameters. This is the first time a real DEF CON-relevant security workload has been mapped onto a quantum classifier with results that hold up against the classical tool the community already uses. The conversation about quantum and security has been stuck on cryptography. This talk is about everything else it can do.

M. Zalewski, "p0f v3," [Online]. Available: https://lcamtuf.coredump.cx/p0f3/. [Accessed: Apr. 25, 2026].

J. Holland, P. Schmitt, N. Feamster, and P. Mittal, "New Directions in Automated Traffic Analysis," in Proc. 2021 ACM SIGSAC Conf. on Computer and Communications Security (CCS), 2021, pp. 3366–3383, doi: 10.1145/3460120.3484758.

S. Ekeroth, J. Neale, and J. S. Kim, "Machine Learning Optimization for Enhanced OS Fingerprinting," Virginia Tech, 2024.

I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization," in Proc. 4th Int. Conf. on Information Systems Security and Privacy (ICISSP), 2018.

T. Chen and C. Guestrin, "XGBoost: A Scalable Tree Boosting System," in Proc. 22nd ACM SIGKDD Int. Conf. on Knowledge Discovery and Data Mining, 2016, pp. 785–794, doi: 10.1145/2939672.2939785.

M. Benedetti, E. Lloyd, S. Sack, and M. Fiorentini, "Parameterized quantum circuits as machine learning models," Quantum Sci. Technol., vol. 4, no. 4, p. 043001, 2019, doi: 10.1088/2058-9565/ab4eb5.

M. Schuld, A. Bocharov, K. M. Svore, and N. Wiebe, "Circuit-centric quantum classifiers," Phys. Rev. A, vol. 101, no. 3, p. 032308, 2020, doi: 10.1103/PhysRevA.101.032308.

K. Mitarai, M. Negoro, M. Kitagawa, and K. Fujii, "Quantum circuit learning," Phys. Rev. A, vol. 98, no. 3, p. 032309, 2018, doi: 10.1103/PhysRevA.98.032309.

M. Schuld, V. Bergholm, C. Gogolin, J. Izaac, and N. Killoran, "Evaluating analytic gradients on quantum hardware," Phys. Rev. A, vol. 99, no. 3, p. 032331, 2019, doi: 10.1103/PhysRevA.99.032331.

T. Jones and J. Gacon, "Efficient calculation of gradients in classical simulations of variational quantum algorithms," arXiv preprint arXiv:2009.02823, 2020.

H. Neven, V. S. Denchev, G. Rose, and W. G. Macready, "QBoost: Large scale classifier training with adiabatic quantum optimization," in Proc. Asian Conf. on Machine Learning (ACML), vol. 25, 2012, pp. 333–348.

V. Havlicek, A. D. Corcoles, K. Temme, A. W. Harrow, A. Kandala, J. M. Chow, and J. M. Gambetta, "Supervised learning with quantum-enhanced feature spaces," Nature, vol. 567, no. 7747, pp. 209–212, 2019, doi: 10.1038/s41586-019-0980-2.

M. Schuld and N. Killoran, "Quantum machine learning in feature Hilbert spaces," Phys. Rev. Lett., vol. 122, no. 4, p. 040504, 2019, doi: 10.1103/PhysRevLett.122.040504.

H. Suryotrisongko and Y. Musashi, "Evaluating hybrid quantum-classical deep learning for cybersecurity botnet DGA detection," Procedia Comput. Sci., vol. 197, pp. 223–229, 2022, doi: 10.1016/j.procs.2021.12.135.

E. D. Payares and J. C. Martinez-Santos, "Quantum machine learning for intrusion detection of distributed denial of service attacks: a comparative overview," in Proc. SPIE 11699, Quantum Computing, Communication, and Simulation, 2021, p. 116990B, doi: 10.1117/12.2593297.

J. R. McClean, S. Boixo, V. N. Smelyanskiy, R. Babbush, and H. Neven, "Barren plateaus in quantum neural network training landscapes," Nat. Commun., vol. 9, no. 1, p. 4812, 2018, doi: 10.1038/s41467-018-07090-4.

M. Cerezo, A. Sone, T. Volkoff, L. Cincio, and P. J. Coles, "Cost function dependent barren plateaus in shallow parametrized quantum circuits," Nat. Commun., vol. 12, no. 1, p. 1791, 2021, doi: 10.1038/s41467-021-21728-w.

V. Bergholm et al., "PennyLane: Automatic differentiation of hybrid quantum-classical computations," arXiv preprint arXiv:1811.04968, 2018.

E. Grant, L. Wossnig, M. Ostaszewski, and M. Benedetti, "An initialization strategy for addressing barren plateaus in parametrized quantum circuits," Quantum, vol. 3, p. 214, 2019, doi: 10.22331/q-2019-12-09-214.

Speakers:Daniel Justice,Jae Sung Kim,La Alsulaim,Shreya G Savadatti

SpeakerBio:  Daniel Justice, Carnegie Mellon University
No BIO available
SpeakerBio:  Jae Sung Kim, Independent Researcher

Jae Sung Kim is an independent researcher specializing in network security and machine learning. His work focuses on applying novel computational approaches, including hybrid quantum-classical architectures, to classical security problems such as passive OS fingerprinting. He is a co-author of OsirisML, a machine learning pipeline for enhanced OS fingerprinting built on the nPrint packet representation framework.

SpeakerBio:  La Alsulaim, University of Pittsburgh

La Alsulaim is a Computer Science student at the University of Pittsburgh. His research interests include machine learning applications

SpeakerBio:  Shreya G Savadatti, Carnegie Mellon University

Shreya G Savadatti is a researcher specializing in quantum computing and cybersecurity. Currently a Master’s student at Carnegie Mellon University, she explores Quantum Reservoir Computing (QRC) and cross-platform hardware benchmarking. As an IBM Qiskit Advocate, she contributes to open-source compilers and recently placed Top 5 at MIT iQuHACK 2026 for quantum circuit optimization. Her published research includes work on Quantum Fully Homomorphic Encryption (QFHE).


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 12:00-13:59 PDT


Title: Your Passkeys Won't Save You: Conditional Access Bypass via Auth-Method Downgrade
Tags: Red Team Village | Misc
When: Friday, Aug 7, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

We rolled out passkeys" is the answer everyone gives now. So why does phishing still work? Because most tenants leave the password sitting there as a fallback method, and Conditional Access never closes the downgrade path. This workshop walks a Conditional Access test kit that proves it. You stand up a real domain with a valid certificate, fronted by nginx, and lure the victim into a browser that lives on your server. They see the real Microsoft login — no fake form — but when it offers a passkey, the kit clicks "sign in another way" and steers them to the password. If the tenant's CA allows that fallback, the victim completes a genuine login with a phishable factor and the kit harvests the tokens it issues — access, id, and refresh — server-side, then replays them into Microsoft Graph with no creds and no second factor. The whole point is the finding: can this tenant be downgraded, and what does the report say if it can't. We close on the CA configuration that actually shuts the downgrade path — and you run the kit yourself at the paired tactic.

Speakers:Doug Mooney,Jared Dobbelaer,Jon Rhodes

SpeakerBio:  Doug Mooney

Doug Mooney (@dougmooney) leads offensive security at Blackbaud, running red team ops and building internal tooling to keep defenders honest. Previously an SVP at a major bank, he stood up their first internal pentest team and scaled offensive security across complex, regulated environments.

He focuses on adversary simulation, API abuse, and finding the weird edge cases that slip past detection. When he’s not deep in a test, he’s mentoring new talent, speaking at conferences, or still apologizing for that one time he “accidentally” reverse-synced LDAP in prod.

SpeakerBio:  Jared Dobbelaer

Jared Dobbelaer (Fr13ndz) is an Adversarial Engineer at Blackbaud, conducting Red Team engagements and Penetration Testing in the Cloud.

Fr13ndz enjoys creative solutions that both help targets with organizational needs and requirements, while also borrowing their bearer tokens.

SpeakerBio:  Jon Rhodes

Jon Rhodes is an Adversarial Engineer at Blackbaud and a member of the Synack Red Team (when he needs extra cash for new farm equipment).


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 11:00-11:45 PDT


Title: Zealot: An Autonomous Cloud Offensive Multi-Agent System
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
When: Friday, Aug 7, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

In November 2025, Anthropic disclosed a state-sponsored operation where AI didn't assist human attackers — it was the attacker, executing 80-90% of the campaign autonomously. The question shifted from "could this happen?" to "how bad can it get?"

We built Zealot to find out.

Zealot is a multi-agent offensive framework that autonomously chains reconnaissance, exploitation, privilege escalation, and data exfiltration against cloud environments — with no human directing individual steps. A supervisor agent coordinates three specialists (Infrastructure, AppSec, and Cloud) that share attack state and hand off context as the operation progresses. The result: an AI system that thinks strategically and executes tactically, the way a real red team does.

In live sandbox tests against GCP, Zealot autonomously discovered an exposed web service, identified and exploited an SSRF vulnerability, extracted service account credentials from the metadata service, impersonated a higher-privileged account, and exfiltrated BigQuery datasets — start to finish, without a human touching the keyboard after the objective was set.

We'll walk through the architecture, show the full attack chain on video, and share the honest lessons: where AI operators excel (systematic enumeration, credential chaining, API fluency), where they fall short (a

SpeakerBio:  Chen Doytshman

I'm a security researcher with a background in artificial intelligence and machine learning. I am passionate about using my skills to protect against cyber threats. With over 5 years of experience in the field, I have a strong understanding of both security and AI technologies and am skilled at combining the two to identify and mitigate vulnerabilities.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 13:30-14:30 PDT


Title: Zero Day Hire: Can You Spot the Spy?
Tags: Social Engineering Community Village | Creator Event/Activity
When: Friday, Aug 7, 13:30 - 14:30 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

If your hiring process relies solely on traditional background checks, you're already behind. You think you're hiring a Senior Backend Engineer. You've reviewed the resume, passed the technical interview, and cleared the automated background check. But you've actually just handed a corporate laptop to a spy.

This 60-minute workshop puts the attendee in the seat of an OSINT lead during a live-fire exercise. This isn't a lecture; it's a test to stop a breach before it starts. Attendees will be provided with the same "evidence" a recruiter would see, and the goal is simple: perform a background check to identify fake personas. You have 60 minutes. Can you do it?

Key Takeaways: - Learn why standard background checks miss AI-generated personas and synthetic identities - Leave with a practical, legally-conscious verification process you can use by Monday morning

Note: Please bring your own laptop. Attendees should be comfortable installing and using common OSINT tools to participate in the live investigation.

Speakers:Michael Reimsbach,Rishi "rxerium" C

SpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

SpeakerBio:  Rishi "rxerium" C, Security Researcher

Rishi is a London-based security researcher with over five years of hands-on experience in IT. He currently specializes in vulnerability research, threat intelligence, and enterprise risk analysis. His current focus lies in identifying and analyzing zero-day vulnerabilities and emerging CVEs, often working to reverse engineer exploit mechanics and build detection logic before public weaponization. Rishi’s work spans both offensive and defensive domains—developing threat models based on real-world TTPs, crafting custom detection rules, and automating reconnaissance pipelines to uncover exploitable misconfigurations and exposed assets. He is particularly active in attack surface management (ASM) and OSINT, where he leverages DNS enumeration, passive data correlation, and large-scale infrastructure scanning to surface unknown entry points and map adversary-accessible exposure. Outside of research, Rishi integrates findings into operational tooling and supports data-driven prioritization strategies to bridge technical risk and business impact. His work reflects a deep commitment to adversary-informed defense and proactive discovery across modern hybrid environments.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Friday - 12:00-12:59 PDT


Title: Zero Day Hire: Can You Spot the Spy?
Tags: Social Engineering Community Village | Creator Event/Activity
When: Friday, Aug 7, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

If your hiring process relies solely on traditional background checks, you're already behind. You think you're hiring a Senior Backend Engineer. You've reviewed the resume, passed the technical interview, and cleared the automated background check. But you've actually just handed a corporate laptop to a spy.

This 60-minute workshop puts the attendee in the seat of an OSINT lead during a live-fire exercise. This isn't a lecture; it's a test to stop a breach before it starts. Attendees will be provided with the same "evidence" a recruiter would see, and the goal is simple: perform a background check to identify fake personas. You have 60 minutes. Can you do it?

Key Takeaways: - Learn why standard background checks miss AI-generated personas and synthetic identities - Leave with a practical, legally-conscious verification process you can use by Monday morning

Note: Please bring your own laptop. Attendees should be comfortable installing and using common OSINT tools to participate in the live investigation.

Speakers:Michael Reimsbach,Rishi "rxerium" C

SpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

SpeakerBio:  Rishi "rxerium" C, Security Researcher

Rishi is a London-based security researcher with over five years of hands-on experience in IT. He currently specializes in vulnerability research, threat intelligence, and enterprise risk analysis. His current focus lies in identifying and analyzing zero-day vulnerabilities and emerging CVEs, often working to reverse engineer exploit mechanics and build detection logic before public weaponization. Rishi’s work spans both offensive and defensive domains—developing threat models based on real-world TTPs, crafting custom detection rules, and automating reconnaissance pipelines to uncover exploitable misconfigurations and exposed assets. He is particularly active in attack surface management (ASM) and OSINT, where he leverages DNS enumeration, passive data correlation, and large-scale infrastructure scanning to surface unknown entry points and map adversary-accessible exposure. Outside of research, Rishi integrates findings into operational tooling and supports data-driven prioritization strategies to bridge technical risk and business impact. His work reflects a deep commitment to adversary-informed defense and proactive discovery across modern hybrid environments.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Friday - 10:00-11:59 PDT


Title: Zero Signal: Operating Where Defenders Can't See
Tags: Red Team Village | Misc
When: Friday, Aug 7, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

82% of intrusions in 2025 involved no malware — adversaries operated through valid credentials, cloud APIs, and identity abuse, generating zero endpoint signal. Cloud-conscious intrusions surged 37% year-over-year, with groups like Storm-2372, Midnight Blizzard, and Scattered Spider executing major breaches using only OAuth tokens and cloud management APIs — no payloads, no processes, no EDR alerts. Yet the average cloud breach takes 143 days to detect, and 45% are discovered by external parties, not internal teams. This tactic puts participants in that detection dark space. Using Stratus Red Team and CloudGoat in pre-provisioned cloud environments, attendees execute end-to-end attack chains across AWS and Azure that produce no endpoint telemetry. No prior cloud experience required; guided walkthroughs and command references provided.

Outline:

Phase 1 — Cloud Recon & IAM Enumeration (10 min): Participants enumerate IAM permissions, map trust relationships, and identify exploitable default service roles using Pacu and CLI tools. Learn how to fingerprint an organization's cloud telemetry posture before executing.

Phase 2 — Privilege Escalation via Default Roles (15 min): Exploit overpermissioned default IAM roles (SageMaker → S3 → Glue pathway documented in Aqua Security research). Participants escalate from a low-privilege user to cross-service access using only cloud API calls — zero endpoint involvement.

Phase 3 — Lateral Movement & Exfiltration (15 min): Move laterally through cloud management planes using SSM sessions, cross-account role assumption, and EBS snapshot theft. Exfiltrate data through VPC endpoints — a known CloudTrail blind spot where data events are not logged.

Phase 4 — Persistence & Detection Review (10 min): Establish persistence via OAuth application backdoors and rogue service principals. Then flip to the defender's view: examine what CloudTrail, GuardDuty, and Entra ID audit logs actually captured versus what they missed entirely.

Attendees walk away with: - A repeatable cloud-native attack methodology that avoids all endpoint detection - Hands-on experience with Stratus Red Team, CloudGoat, and Pacu - A practical map of CloudTrail, GuardDuty, and audit log blind spots - Understanding of which cloud operations generate telemetry and which don't

SpeakerBio:  Gowthamaraj Rajendran

Gowthamaraj Rajendran is a cybersecurity professional and Threat Detection Engineer with 6+ years of experience, specializing for the last 3 years in creating precise and effective detection capabilities.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Friday - 15:30-15:59 PDT


Title: Zero Trust Kubernetes Security: Preventing Real World Container Attacks
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Friday, Aug 7, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Kubernetes has become a major application attack surface, where most breaches exploit misconfigurations and implicit trust rather than software flaws. This session presents a practical Zero Trust approach to securing containerized applications against real world attack paths. It shows how attackers abuse weak RBAC, insecure service communication, and lack of workload isolation to move laterally and escalate privileges. Attendees will learn how to design granular access controls, enforce secure service to service communication, and implement segmentation to contain compromised workloads. The session also demonstrates how policy as code and admission controls can block risky deployments before they reach production. With real examples and measurable outcomes, this talk provides actionable techniques to reduce attack success and strengthen Kubernetes security.

SpeakerBio:  Janakiram Meka

Janakiram Meka is a Cloud DevOps Architect with over 18 years of experience in building and securing large scale enterprise systems. His expertise spans cloud infrastructure, Kubernetes, DevSecOps, and Zero Trust security models. He has led cloud migration and automation initiatives across complex environments, focusing on improving security, scalability, and operational efficiency. Janakiram holds multiple industry certifications, including Kubernetes Administrator, Terraform Associate, Oracle Certified Professional, and AWS Solutions Architect. He is an active contributor to the technology community, writing technical articles on cloud and database systems, and is a Senior Member of IEEE. His work emphasizes practical, data driven approaches to securing modern application platforms.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Friday - 13:00-13:45 PDT


Title: Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Threat Intel/Hunting | DEF CON Demo Labs
When: Friday, Aug 7, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

Traditional threat modeling is a tedious, manual process prone to human error. Conversely, modern "AI" threat modeling tools almost universally depend on sending sensitive, proprietary system architectures to third-party APIs in cleartext.

We present AI Threat Modeler (AITM), a fully open-source, zero-cloud application designed to automate architecture-driven STRIDE threat modeling completely offline. AITM fundamentally shifts how we analyze system designs by replacing brittle, keyword-based regex rules with a local Semantic AI Engine.

Under the hood, AITM leverages sentence-transformers and an in-memory FAISS vector database to embed a comprehensive, 116+ component knowledge base. During analysis, a custom NetworkX graph builder parses natural language or structured architecture descriptions (via spaCy) to map undocumented architectural features to known CVE classes and STRIDE categories.

Furthermore, AITM introduces "Architecture Intelligence" using graph traversal algorithms to automatically infer missing trust boundaries and identify multi-step attack chains that standalone component scanning misses. In this demo, we will: Walk through the automated ingestion of a microservice architecture. Demonstrate how the local FAISS engine discovers semantic threats that evade keyword matching. Show dynamic attack cha

SpeakerBio:  Ankit Vashisth

Ankit Vashisth is a Security Engineer with over 4 years of experience in application security, cloud security, and DevSecOps. He has worked on security assessments across web, mobile, network, and enterprise systems for global clients. His interests include AI-driven security tooling, threat modeling, and security automation. Ankit actively researches ways to apply AI to improve security architecture analysis and vulnerability detection.


Return to Index    -    Add to Google    -    ics Calendar file