Talk/Event Schedule


Saturday


This Schedule is tentative and may be changed at any time. Check here, Hacker Tracker, or the nearest NFO Node for the latest.

 

Saturday - 00:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - Music - Genre: Trance - AfterGlow

 

Saturday - 06:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - Defcon.run -

 

Saturday - 07:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - cont...(06:00-07:59 PDT) - Defcon.run -

 

Saturday - 08:00 PDT


Return to Index  -  Locations Legend
DEF CON Training - (08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - (08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - (08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan

 

Saturday - 09:00 PDT


Return to Index  -  Locations Legend
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - Sold Out - Wi-Fight Club: I am Jack's Evil Twin - James Hawk,Jon "C4V3M4N" Milkins,Brian Burnett
DEF CON Workshops - Sold Out - Explore the Windows instrumentation callback - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel - Yu Terada,Kotaro "@Decamark / @BinaryPoodle" Osugi
DEF CON Workshops - Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them - Pavan "pavanreddysec" Reddy
DEF CON Workshops - Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure - HackeMate
DEF CON Workshops - Sold Out - Hecate: A Trivial UART Tool - mx,Joe "SecurelyFitz" FitzPatrick,nyx
DEF CON Workshops - Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3 - Andrew Case,Pierre "Abyss Watcher" Breton,David McDonald
DEF CON Workshops - Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine - Preston Zen
Social Gatherings/Events - Human Registration Open -
Social Gatherings/Events - Merch (formerly swag) Area Open -- README -

 

Saturday - 10:00 PDT


Return to Index  -  Locations Legend
Adversary Village - MCPwned: How Exposed AI Agents Became the Internet’s New Recon Toy - Eli Woodward
Adversary Village - (10:30-10:59 PDT) - Emulating the “Identity-First” Threat Actor: Automated Playbooks for IdP Hijacking - Samet Can Tasci,Mehmet Önder Key
Aerospace Village - DCNextGen - Bricks in the Air -
Aerospace Village - Bricks in the Air -
Aerospace Village - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - ARINC 664 CTF Challenge -
Aerospace Village - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - SpaceCOP - Catch Me If You Can -
Aerospace Village - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - SR-71 Blackbird Badge Challenge -
Aerospace Village - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - Drone Hacking Workshop -
Aerospace Village - Drone Hacking Choose your Own Adventure -
Aerospace Village - MOUSE Runner & Flappy Drone -
Aerospace Village - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - Flight Simulator/EFB -
AI Village - Poster Presentations -
AI Village - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - AI Village: Village Open -
AppSec Village - (10:15-11:15 PDT) - In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike - Yariv Tal
AppSec Village - (10:15-12:59 PDT) - Prompt Injection: Attacking and Defending AI-Powered Applications - Mohammed Ilyas Ahmed
AppSec Village - (10:30-10:59 PDT) - Building Hackbots - Jason "jhaddix" Haddix
Biohacking Village - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - Biohacking Device Lab -
Biohacking Village - To Catch a Pseudoscientist - James Utley PhD
Biohacking Village - (10:30-10:59 PDT) - The Death of Dicom - Michael "v3ga" Aguilar
Blacks In Cyber Village - Being Black While Hacking: The Unofficial Survival Guide - Dr. Louis DeWeaver III
Blue Team Village - AI for Defenders 101 - Anirudh Pratap Singh,Neha Gautam,Omenscan ~
Bug Bounty Village - Shadow Webhooks: Hunting for Dangling Event Listeners in Enterprise Workspaces - Samet Can Tasci,Mehmet Önder Key
Bug Bounty Village - (10:30-10:59 PDT) - Testing API Business Logic With AI Agents: What We Got Wrong First - Samantha Pearlstein
Bug Bounty Village - Turning Recon Coverage into Bug Bounty Signal - Radu Stefan Voloaga
Bug Bounty Village - (10:45-11:30 PDT) - You’re Invited to Get Hacked: Real-World Exploits in Modern Invitation Systems - Ali "logic-breaker" Kabeel
Call Center Village - Call Center Village - Open -
Car Hacking Village - Car Hacking Village Open -
Car Hacking Village - Bomb Bot Challenge -
Cloud Village - Bashing CloudShells for mining, networking, exfil and persistence at scale - Jenko "edleft" Hwong,Chris Ryan
Cloud Village - (10:40-11:20 PDT) - Ghost Records: Automating Dangling DNS & Subdomain Takeover Detection at Enterprise Scale - Jai Kumar Sharma,Tom McCarthy
CodeBloom - Game Time: Loops -
Contests - Hack3r Runw@y v8.0 -
Contests - 5N4CK3Y -
Contests - DC's Next Top Threat Model -
Contests - Untechnical -
Contests - DEF CON Scavenger Hunt -
Contests - Darknet-NG -
Contests - Crack Me If You Can 2026 -
Contests - TeleChallenge -
Contests - HackFortress -
Contests - ?Cube -
Contests - $unL1ght Sh4d0w5 -
Contests - Octopus Game - Booth Open -
Contests - Beer Chilling Contraption Contest -
Contests - Cryptid Hunt -
Contests - HSPACE: AI Battlegrounds -
Contests - spyVspy 3: Rat Race -
Contests - Hacker Games -
Contests - PhreakMe -
Contests - Game Hacking Village CTF -
Contests - Kubernetes CTF -
Contests - Hac-Man -
Contests - Crack the Core -
Contests - Cyber Deck Competition -
Contests - Pinball High Score Contest -
Contests - Code Cadaver: Break Every System. Save Your Friend. -
Contests - PWN UR H0M3 - DDoS CTF -
Contests - Reali7y Overrun - Contest running -
Contests - Tin Foil Hat Contest -
Contests - CMD+CTRL Cyber Range: DarkMoney -
Contests - Radio Frequency Capture the Flag -
Contests - DEF CON CTF: Benevolent Bureau of Birds -
Contests - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - AI Village - Hal CTF -
Contests - StarPWN CTF -
Contests - Car Hacking Village CTF -
Contests - OWASP CTF -
Contests - Blue Team Village CTF - Project Obsidian -
Contests - Escalation Desk CTF -
Contests - DEF CON Groups Sticker Contest -
Contests - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - Apex Park (Cloud Village CTF) -
Contests - Hacking GRC Contest -
Contests - Bug Bounty Village CTF - Open -
Cryptocurrency Village - Web3 Security: Hacks, Scams, and Exploits - Philip "AlephNull" Werlau,Kennashka DeSilva
Data Duplication Village - DDV open and accepting drives for duplication -
DCNextGen - Intro to Scratch - N3rd H3Rder
DEF CON Groups - DEF CON Groups (DCG) -
DEF CON Talks - Car Hacking Village Scavenger Hunt Contest -
DEF CON Talks - The Ghost Key: Illusions of "Time Management" in TTLock Smart Locks - Yang Liu,Zhenghan Wang
DEF CON Talks - Memory Laundering via Metal: What EDR Can't See on Your Mac - Hxr1
DEF CON Talks - (10:30-11:30 PDT) - Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations - Aleksandr Krasnov
DEF CON Talks - From Wind Farm to CHP Plant: The Untold Story of Lateral Movement in a Polish Energy Sector Attack - Marcin Dudek
DEF CON Talks - No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes - David "davidrxchester" Rochester,Nicholas "gouldnicholas" Gould
DEF CON Talks - (10:30-11:30 PDT) - Root From Kilometers Away: Ubiquiti AirMax RCE - Federico Kirschbaum,Gaston Aznarez
DEF CON Talks - Identity Crisis: Novel Vulnerabilities leading to Kerberos Downgrade, DoS, and Full Domain Takeover - Shai Laron
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Wi-Fight Club: I am Jack's Evil Twin - James Hawk,Jon "C4V3M4N" Milkins,Brian Burnett
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Explore the Windows instrumentation callback - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel - Yu Terada,Kotaro "@Decamark / @BinaryPoodle" Osugi
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them - Pavan "pavanreddysec" Reddy
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure - HackeMate
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Hecate: A Trivial UART Tool - mx,Joe "SecurelyFitz" FitzPatrick,nyx
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3 - Andrew Case,Pierre "Abyss Watcher" Breton,David McDonald
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine - Preston Zen
Demo Labs - SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked. - Hemanth Gorijala
Demo Labs - Peekaboo: Breaking the Black Box of Threat and Malware Emulation - Zhassulan "cocomelonc" Zhussupov
Demo Labs - Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface - Gannon "Dorf" Gebauer,Anthony "Coin" Rose,Hana Christensen
Demo Labs - DFMI: Weaponizing MSI Installers for Fileless Code Execution - Anil Celik
Demo Labs - Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis - 0verkilll
Demo Labs - Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF - Buğrahan Yücel
Embedded Systems Village - Embedded Systems Village CTF -
Embedded Systems Village - Thread Carefully -
Embedded Systems Village - Embedded - 101 Labs -
Embedded Systems Village - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Game Hacking Village - Riot Games Vanguard: Pwn to own -
Game Hacking Village - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - RIP Denuvo: DRM in a Post-Hypervisor World - Amin Hussien
Game Hacking Village - (10:45-11:30 PDT) - Dreamcast Ex Inferis: RCE on the Sega Dreamcast PlanetWeb Browser - Christopher Hernandez
IoT Village - All About UART -
IoT Village - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - Discover GE Appliances! -
IoT Village - Expose Hidden Surveillance in Everyday Tech -
IoT Village - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - Just Hacking Training -
IoT Village - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - (10:30-11:45 PDT) - Playing with Hyper-local Pocket-Sized Servers - Brandon
La Villa Community - Learning Deception by Doing: Attacking and Defending - Diego Staino,Fede Pacheco
La Villa Community - (10:30-10:59 PDT) - Self Hosting Nightmare - Exploiting AI models for supply chain attacks - Davidson Mizael
La Villa Community - (10:30-12:59 PDT) - Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence - Luis Pazmino,Yoshihito Adachi
Lockpick Village - (10:15-10:45 PDT) - Intro to Lockpicking -
Lonely Hackers Club - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - Lonely Hackers Club CTF -
Lonely Hackers Club - (10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - Makers' Village - Hacker Arts and Crafts -
Malware Village - Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits - Jiří Vinopal
Malware Village - (10:45-11:25 PDT) - Demystifying the Playboy RaaS - Gijs Rijnders
Malware Village - Hostile Input: PDF Triage That Survives an Adversarial Document - Klaus Wunder
Middle Easterns & Africans in Cyber Security (MEACS) - From al-Kindi to DEF CON: The Middle Eastern and African Roots of Cybersecurity - Amber Bennoui,Ezz Tahoun
Misc - Coloring Reset -
Mobile Hacking Community - A Droidwork Orange: A Longitudinal Study of Android Security Research - Nicholas Miazzo,Eleonora Losiouk
Mobile Hacking Community - Mobile Hacking Community - Open -
Mobile Hacking Community - RedMatter: Let AI Write Your Cross-Platform Mobile Exploits - Subho Halder
Mobile Hacking Community - Mobile Hacking - Informal CTF -
Nix Vegas Community - Nix Vegas Opening Ceremony -
Nix Vegas Community - (10:30-10:45 PDT) - How to piss off your Nix friends - Farid Zakaria
Nix Vegas Community - (10:45-10:59 PDT) - Beholden to No One: The Nix Override Ladder - Daniel Baker
Noob Community - Wanna Hack Space ? Why? Is it out of this world? - Henry Danielson Hankashyyyk
Noob Community - Break Things, Learn Things: Hands-On Hacking for Beginners - Evolve Security Academy
Noob Community - Arcanum Security Labs -
Noob Community - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - Mentoring and Career Advice -
Noob Community - Kryptsec Labs -
Noob Community - TCM Security Labs -
Noob Community - SANS Institute NetWars Labs -
Noob Community - Skillbit Labs -
Noob Community - No Stupid Questions -
Noob Community - (10:30-10:45 PDT) - The importance of Networking in Cybersecurity community - Michael Lenz
OSINT For Good Community - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - F1NDX OSINT Educational Series -
OSINT For Good Community - Trace Labs L150: Case Walkthrough - Brent Louie
OWASP Foundation - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - Let's Play! OWASP Cornucopia for Mobile Application Security Threat Modeling - Sven Schleier
OWASP Foundation - (10:30-10:59 PDT) - Spotlight: Choose Your Own Adventure with InfoSecMap - W. Martín Villalba
Payment Village - (10:30-10:45 PDT) - Payment Village Intro - What's Happening at the Village -
Policy @ DEF CON - Whose Agent Is It Anyway? Agency, Authorization, and Accountability in the Year of the AI Agent - Andreas Kaltsounis,Jacob Wall
Policy @ DEF CON - Journey to Create an All-state Cybersecurity Plan for Oklahoma - Craig "jafo" Buchanan
Radio Frequency Village - Radio Frequency Village Events -
Radio Frequency Village - (10:30-12:25 PDT) - RF CTF Kick Off Day 2 - RF Hackers
Recon Village - Hunting the Contagious Trader Delivery Network - Alessandra Rizzo,Ariel Ropek
Red Team Village - From Path Traversal to Domain Credentials in 90 Seconds - Mike Lisi
Red Team Village - PMTC: One-Click RCE and Persistent Exfil in AI Coding Agents - Ahmet Furkan Aydogan
Red Team Village - MCP Servers: The Next Enterprise Attack Surface - Apoorwa Joshi,Justin Dray
Red Team Village - Hands-On Autonomous Pentesting with Pentest Copilot - Dhruva Goyal,Sitaraman Subramanian
Red Team Village - Inside the Red Team Cabal: A Decade of Lessons from Enterprise Red Teams - Jason Strange,Wes Thurner
Red Team Village - Living Off the Vault - Alexandru Uifalv,Jennifer Slaybaugh,Morton Schenk
Red Team Village - Pyramid of Pain-Red Team (Human and Technical Friction) - Frank Victory
Scambait Village - Open Q&A -
Scambait Village - KSCM Scambait Radio -
Social Engineering Community Village - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - (10:15-13:15 PDT) - Battle of the Bots: Vishing Edition -
Social Engineering Community Village - Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything - Brian Brushwood
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(09:00-15:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - Music - SomaFM -
Telecom Village - A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure - T -Mobile CTF Team
The Diana Initiative - MEACS: Middle Easterns & African in Cyber Security Tour -
The Diana Initiative - (10:20-10:30 PDT) - Crypto And Privacy Village Tour -
The Diana Initiative - (10:30-10:40 PDT) - Data Duplication Village Tour -
The Diana Initiative - (10:40-10:50 PDT) - Payment Village Tour -
The Diana Initiative - (10:50-10:59 PDT) - Policy @ Defcon Tour -
The Diana Initiative - Quiet Room -
The Diana Initiative - Quiet Room -
The Diana Initiative - Yoga - Deanna Heon
Voting Village - Voting Village Lab -
Voting Village - "Trust Us, It's Secure": Why Internet Voting Isn't - Barbara Simons
Voting Village - (10:30-10:59 PDT) - Software Quality in Electronic Voting - Duncan Buell

 

Saturday - 11:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - Security Analysis of Open-Source Software Used in Onboard Satellite Systems - Roee Idan
Aerospace Village - (11:30-11:59 PDT) - So You Want to Work in Aircraft Cyber? Here's what you need to know! - Matt Gaffney,Marcie Wise
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - What is AI? Interactive, Unplugged Activity - Sam Mosley
AppSec Village - cont...(10:15-11:15 PDT) - In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike - Yariv Tal
AppSec Village - (11:30-12:30 PDT) - Precogly: Open-Source Threat Modeling for the AI-Coding Era - Vikramaditya Narayan
AppSec Village - cont...(10:15-12:59 PDT) - Prompt Injection: Attacking and Defending AI-Powered Applications - Mohammed Ilyas Ahmed
AppSec Village - What Your Coding Agent Did Last Night: Runtime Security for AI Coding Agents - Inga Cherny
AppSec Village - (11:50-12:20 PDT) - Past the Bouncer: The Limits of CSP, Eleven Years In - Pedro Fortuna
AppSec Village - Code Invaders: Stop The Insecure Code - Mackenzie
AppSec Village - Pentester vs AI: Race The Machine, In Real Life - Gwendal Mognier,Samantha Pearlstein
AppSec Village - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - SBOM Find the Flaws - Dmitry Raidman
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Blacks In Cyber Village - Cyber Gamechangers: Women Who Lead, Secure, and Inspire - Nikkia Henderson,Arielle Baine,Jess Hoffman
Blue Team Village - Threat Hunting 101: Beyond the Alerts - Kainu ~
Bug Bounty Village - cont...(10:45-11:30 PDT) - You’re Invited to Get Hacked: Real-World Exploits in Modern Invitation Systems - Ali "logic-breaker" Kabeel
Bug Bounty Village - (11:30-12:30 PDT) - De-Sloppify: Your AI Needs a Proxy - Emile "TheSytten" Fugulin,Vitor "busf4ctor" Falcao Habibe Costa
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Cloud Village - Patch Me If You Can: Hands-On Network Threat Defense - Don Bogert
Cloud Village - From Findings to Remediations: Open Source Cloud Security at AI Speed with Prowler - Toni de la Fuente,Amit Sharma
Cloud Village - cont...(10:40-11:20 PDT) - Ghost Records: Automating Dangling DNS & Subdomain Takeover Detection at Enterprise Scale - Jai Kumar Sharma,Tom McCarthy
Cloud Village - (11:20-11:59 PDT) - Trust the Cloud Pipeline, Lose the Kingdom - Shane Young
CodeBloom - Work Session: Ciphers -
Contests - cont...(10:00-11:59 PDT) - Hack3r Runw@y v8.0 -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(10:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-11:59 PDT) - StarPWN CTF -
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-11:59 PDT) - Blue Team Village CTF - Project Obsidian -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - Gold Bug: Puzzle Panel with Friends - CPV Gold Bug Team 2026,TBD
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
Data Duplication Village - Poison the Well: RAG Attacks Against the Hacking Community's Own Archives - Omer Farooq
DCNextGen - Meshpocalypse: Building Your Own Off-Grid Hacker Network - Adventures of Illya
DEF CON Groups - Building a Hacker Haven: The Long Game of Growing a Local Hacker Community - Ryan Zagrodnik,Allie Zagrodnik
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - cont...(10:00-11:59 PDT) - Car Hacking Village Scavenger Hunt Contest -
DEF CON Talks - Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children and Vehicles - Felipe Solferini,Vangelis Stykas
DEF CON Talks - cont...(10:30-11:30 PDT) - Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations - Aleksandr Krasnov
DEF CON Talks - (11:30-12:30 PDT) - Thin Client? Thin Crypto - Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher - Darren McDonald
DEF CON Talks - Very Pwned: Hacking Verifone’s card machine three times in a row - Reino Mostert
DEF CON Talks - cont...(10:30-11:30 PDT) - Root From Kilometers Away: Ubiquiti AirMax RCE - Federico Kirschbaum,Gaston Aznarez
DEF CON Talks - (11:30-12:30 PDT) - Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet - Kyprianos "kavasilo" Vasilopoulos,Nikos "nickvourd" Vourdas
DEF CON Talks - Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services - Ron Ben Yizhak
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Wi-Fight Club: I am Jack's Evil Twin - James Hawk,Jon "C4V3M4N" Milkins,Brian Burnett
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Explore the Windows instrumentation callback - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel - Yu Terada,Kotaro "@Decamark / @BinaryPoodle" Osugi
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them - Pavan "pavanreddysec" Reddy
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure - HackeMate
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Hecate: A Trivial UART Tool - mx,Joe "SecurelyFitz" FitzPatrick,nyx
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3 - Andrew Case,Pierre "Abyss Watcher" Breton,David McDonald
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine - Preston Zen
Demo Labs - GhostCatcher (endpoint detection agent) - Sercan Okur
Demo Labs - sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions - Atsushi Sada,hikae
Demo Labs - Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds - Kyler McElroy,Anita Ding,Daniel Koranek
Demo Labs - X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain - Xia Hua,Abhijeet Kumar
Demo Labs - TokenMesh: Exposing Azure's Hidden Identity Attack Surface - Saksham Agrawal
Demo Labs - pymsi: Interactive MSI Installer Analysis in Python and the Browser - Ryan "Nightlark" Mast
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Thread Carefully -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Game Hacking Village - cont...(10:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - cont...(10:45-11:30 PDT) - Dreamcast Ex Inferis: RCE on the Sega Dreamcast PlanetWeb Browser - Christopher Hernandez
Game Hacking Village - (11:30-11:59 PDT) - Catching Cheaters in Super Smash Bros Melee - AltF4
Hackers.town - How to get RCE on a car - Ac0rn
Ham Radio Village - Digital Modes 101: The Weird, Wonderful World of Computer Radio - Jon Marler (K4CHN)
ICS Village - (11:30-11:59 PDT) - Nuclear Industrial Control System Simulation (NICSSIM) aka Multi-Agent Cyber Defense Framework for Distributed Nuclear Operational Technology Systems - Carmela Gonzales,Brian G. Rodiles Delgado,Marco A. Alanis Komiyama
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:30-11:45 PDT) - Playing with Hyper-local Pocket-Sized Servers - Brandon
IoT Village - The Camera Is Lying: RTSP Trust Failures in Modern Surveillance Systems - Bogdan "BOTEZATU"
IoT Village - (11:45-12:30 PDT) - Anyone Can Hack IoT (Even Easier Now) - A Beginner's Guide to AI Augmented IoT Hacking - Andrew Bellini
La Villa Community - Meet XEntry Team: A powerful threat actor abusing Bitlocker for ransomware - Eduardo Chavarro Ovalle
La Villa Community - cont...(10:30-12:59 PDT) - Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence - Luis Pazmino,Yoshihito Adachi
Lockpick Village - Classic US High Sec: how to pick a Medeco - Max A
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - Build-A-Badge Workshop - hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
Malware Village - cont...(10:45-11:25 PDT) - Demystifying the Playboy RaaS - Gijs Rijnders
Malware Village - (11:35-12:15 PDT) - Haetae: An Agent to Takedown North Korean C2 Servers - Nelson Colon
Malware Village - cont...(10:10-12:10 PDT) - Hostile Input: PDF Triage That Survives an Adversarial Document - Klaus Wunder
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - (11:15-12:15 PDT) - An Android voyage from Java to Smali with ASM - Ricardo Loura
Nix Vegas Community - (11:30-11:59 PDT) - Compiling the World: A Binary Dataset Built from nixpkgs - Chris Connelly
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-11:20 PDT) - Break Things, Learn Things: Hands-On Hacking for Beginners - Evolve Security Academy
Noob Community - No One Makes It Alone - Community as the Ultimate Security Control - Kristen Sanders
Noob Community - (11:30-12:50 PDT) - OASIS: Prompt to Pwn - Marshall Livingston
Noob Community - (11:45-12:45 PDT) - Gamifying the Matrix: a MITRE ATT&CK Video Game - Annie Meaney,Anne Drago
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - (11:15-11:45 PDT) - CTF Intro, Quick Guides, and Rule Review - Kenny J
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - Oh hai! Meet Tanya "SheHacksPurple" Janca - Tanya "SheHacksPurple" Janca
Payment Village - Victim as a Service: Engaging with Trust-Based Scams Using AI - Ariana Mirian
Payment Village - (11:30-11:50 PDT) - Introduction to Vulnerable ATM Badge - Vincent Sloan
Physical Security Village - No Entry: Badge Access Denial on Demand - Andrew Quill
Policy @ DEF CON - From Policy to Prod: How a Frontier AI Lab Enforces its Cyber Rules - Grant Versfeld,David "0xdf" Forsythe
Queercon Community - Polycon -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(10:30-12:25 PDT) - RF CTF Kick Off Day 2 - RF Hackers
Recon Village - cont...(10:00-12:30 PDT) - Hunting the Contagious Trader Delivery Network - Alessandra Rizzo,Ariel Ropek
Recon Village - GE(O)SINT Contest -
Red Team Village - cont...(10:00-11:59 PDT) - From Path Traversal to Domain Credentials in 90 Seconds - Mike Lisi
Red Team Village - cont...(10:00-11:59 PDT) - PMTC: One-Click RCE and Persistent Exfil in AI Coding Agents - Ahmet Furkan Aydogan
Red Team Village - cont...(10:00-11:59 PDT) - MCP Servers: The Next Enterprise Attack Surface - Apoorwa Joshi,Justin Dray
Red Team Village - cont...(10:00-11:59 PDT) - Hands-On Autonomous Pentesting with Pentest Copilot - Dhruva Goyal,Sitaraman Subramanian
Red Team Village - DPAPI Is Not a Boundary: A Full Infostealer Kill Chain Operators Can Replicate - Filipi Pires
Red Team Village - The Authentic Operator: Social Engineering Through Natural Delivery - Joanna -
Red Team Village - cont...(10:00-11:59 PDT) - Living Off the Vault - Alexandru Uifalv,Jennifer Slaybaugh,Morton Schenk
Red Team Village - cont...(10:00-11:59 PDT) - Pyramid of Pain-Red Team (Human and Technical Friction) - Frank Victory
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Social Engineering Community Village - cont...(10:00-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(10:15-13:15 PDT) - Battle of the Bots: Vishing Edition -
Social Engineering Community Village - (11:30-12:30 PDT) - Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything - Brian Brushwood
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - Book Signing - Aamiruddin Syed - Aamiruddin Syed
Social Gatherings/Events - Book Signing - Cindy Cohn - Cindy Cohn
Social Gatherings/Events - cont...(09:00-15:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Free Ham Radio License Exams -
Telecom Village - Threats in Space: The Dangerous Rise of GNSS Attacks - Isabel Manjarrez
Telecom Village - (11:45-12:30 PDT) - From ONT to STB: Detecting IPTV Attack Chains in the Telecom SOC - Zibran Sayyed
The Diana Initiative - Biohacking Village Tour -
The Diana Initiative - Adversary Village Tour -
The Diana Initiative - (11:20-11:30 PDT) - Radio Frequency Village Tour -
The Diana Initiative - (11:30-11:40 PDT) - Embedded System Village Tour -
The Diana Initiative - (11:40-11:50 PDT) - Gamer Village Tour -
The Diana Initiative - (11:50-11:59 PDT) - Queercon Community Lounge Tour -
The Diana Initiative - Stay Sharp: Navigating Pen Testing and Bug Bounty in an AI-Driven World - Dana Pirvu
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Liberty and Justice for All - Michael Moore
Voting Village - (11:30-11:59 PDT) - Are We Making Things Worse? Election Denialism and Security Research - Matt Blaze,Geoff Hale,Michael Moore,Kendall Spencer,Philip Stark

 

Saturday - 12:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - This Wasn't AI Generated: Principles for Breaking Generative Watermarks - Thomas Mason,Tahseen Rabbani
AI Village - AgentBreaker: A blind spot detector for your coding agents - Aditi Narasimhan,Farzaan Kaiyom
AppSec Village - cont...(11:30-12:30 PDT) - Precogly: Open-Source Threat Modeling for the AI-Coding Era - Vikramaditya Narayan
AppSec Village - (12:45-13:45 PDT) - OWASP FinBot CTF: Hands-On Agentic AI Threats - Helen Oakley,saikishu
AppSec Village - cont...(10:15-12:59 PDT) - Prompt Injection: Attacking and Defending AI-Powered Applications - Mohammed Ilyas Ahmed
AppSec Village - cont...(11:50-12:20 PDT) - Past the Bouncer: The Limits of CSP, Eleven Years In - Pedro Fortuna
AppSec Village - (12:30-12:59 PDT) - Threat Modeling LLMs with PHANTOM-B - Adam Shostack
AppSec Village - cont...(11:00-12:59 PDT) - Code Invaders: Stop The Insecure Code - Mackenzie
AppSec Village - cont...(11:00-12:59 PDT) - Pentester vs AI: Race The Machine, In Real Life - Gwendal Mognier,Samantha Pearlstein
AppSec Village - cont...(11:00-12:59 PDT) - Cards Against Vulnerabilities - Patrick Smyth
AppSec Village - cont...(11:00-12:59 PDT) - SBOM Find the Flaws - Dmitry Raidman
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Blacks In Cyber Village - Root Access: An APT Analysis of Systemic Gatekeeping in Cybersecurity - Dr. Hassan Karim
Blacks In Cyber Village - (12:30-12:55 PDT) - The Voice Behind the Payload: Tracing AAVE Across Malware Artifacts - Brett Alexander Tolbert
Blue Team Village - Cloud Forensics 101 : Ghost in the logs - Cassandra (muteki) Young,Dimple Gajra
Bug Bounty Village - Killing AI Slop: A Multi-Model Orchestration Framework That Only Reports Findings It Can Prove - Armaan Pathan
Bug Bounty Village - (12:30-12:59 PDT) - Eating Our Own Dogfood: Running a Bug Bounty Program on a Bug Bounty Platform - Shrimant Subhash More,Martzen Haagsma
Bug Bounty Village - cont...(11:30-12:30 PDT) - De-Sloppify: Your AI Needs a Proxy - Emile "TheSytten" Fugulin,Vitor "busf4ctor" Falcao Habibe Costa
Bug Bounty Village - (12:30-13:30 PDT) - Better Bug Hunting on AI Products: A VRP Lead’s Perspective - John Kotheimer
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(11:00-12:59 PDT) - Patch Me If You Can: Hands-On Network Threat Defense - Don Bogert
Cloud Village - cont...(11:00-12:59 PDT) - From Findings to Remediations: Open Source Cloud Security at AI Speed with Prowler - Toni de la Fuente,Amit Sharma
Cloud Village - Whose Resource Is It Anyway? The Design Flaw That Breaks the IAM Permission Model - Moshe Berntsein
Cloud Village - (12:20-12:59 PDT) - Pinchy Gets Played: How We Red-Teamed AI Agents Before the Threats Did - Doron Kapah
CodeBloom - Game Time: Input, Output, and Variables -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - Dozier Drill Tournament -
Contests - cont...(10:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - Global OSINT Search Party CTF – DEF CON 34 Edition -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - BIC Village Capture the Flag (CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
Data Duplication Village - (12:15-12:45 PDT) - Forcing Physical Interlocks into Data Transit and Storage Replication - Mehmet Önder Key,Temel Demir
DCNextGen - AI and You: Staying Safe in the AI Era - Zoe Reid+Echo419
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - Rage Against the Sandbox: Bypassing Apple’s iOS Security to Run Unsigned Code via SSH - Yuval Hanoch Hirschenbein Sadde
DEF CON Talks - cont...(11:30-12:30 PDT) - Thin Client? Thin Crypto - Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher - Darren McDonald
DEF CON Talks - (12:30-13:30 PDT) - Writing to Shadow Stacks - Vladimir "G1ND1L4" Tokarev
DEF CON Talks - C(2)YA: Inside the Adversary's Inbox - Vitaly Simonovich
DEF CON Talks - cont...(11:30-12:30 PDT) - Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet - Kyprianos "kavasilo" Vasilopoulos,Nikos "nickvourd" Vourdas
DEF CON Talks - (12:30-13:30 PDT) - Compounding Interest: Exploiting the ATM Supply Chain - Matt Burch
DEF CON Talks - The Glass Perimeter: Systematic Bypasses in Biometric Frameworks and the Rise of Synthetic Identity - Dan Borgogno,Javier Bernardo
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Wi-Fight Club: I am Jack's Evil Twin - James Hawk,Jon "C4V3M4N" Milkins,Brian Burnett
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Explore the Windows instrumentation callback - Yoann "OtterHacker" DEQUEKER
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel - Yu Terada,Kotaro "@Decamark / @BinaryPoodle" Osugi
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them - Pavan "pavanreddysec" Reddy
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure - HackeMate
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Hecate: A Trivial UART Tool - mx,Joe "SecurelyFitz" FitzPatrick,nyx
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3 - Andrew Case,Pierre "Abyss Watcher" Breton,David McDonald
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine - Preston Zen
Demo Labs - Phasmid: Deniable Storage for Rubber-Hose Scenarios - Makoto "Mr.Rabbit" Sugita
Demo Labs - MSCodePhish: Redeem Your Coupon. Surrender Your Session - Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla
Demo Labs - Keychecker : SSH Key based attack tool for DVCS Systems - Anant Shrivastava
Demo Labs - Zealot: An Autonomous Cloud Offensive Multi-Agent System - Chen Doytshman
Demo Labs - Beyond Spidering: Behavior Driven DAST for Real Application Workflows - Sara "testingSoul" Martinez
Demo Labs - Empire 7: Shipping a C2 at AI Speed - Vincent "Vinnybod" Rose,Jake "Hubbl3" Krasnov,Anthony "Coin" Rose
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Thread Carefully -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - Game Hacking with AI - Juno
Hackers.town - KYC and XMR… FOR HACKERS! - AltKey
Hackers.town - Take Back Your Memories - Patrick Sliney
Ham Radio Village - So You Got Your License, Now What? - Danny Quist
ICS Village - Local Language Models in OT - Basics and Considerations - Vivek Ponnada
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
IoT Village - cont...(11:45-12:30 PDT) - Anyone Can Hack IoT (Even Easier Now) - A Beginner's Guide to AI Augmented IoT Hacking - Andrew Bellini
IoT Village - (12:30-13:30 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology - Simone Bossi,Luca Borzacchiello
La Villa Community - Malware Inc.: Cybercrime-as-a-Service y la economía del cibercrimen moderno - Isabel Manjarrez
La Villa Community - (12:30-13:30 PDT) - Descubrimiento Industrializado de CVEs con Agentes de IA - Simon Correa,Michael Rivera
La Villa Community - cont...(10:30-12:59 PDT) - Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence - Luis Pazmino,Yoshihito Adachi
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - cont...(11:00-12:30 PDT) - Build-A-Badge Workshop - hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
Malware Village - cont...(11:35-12:15 PDT) - Haetae: An Agent to Takedown North Korean C2 Servers - Nelson Colon
Malware Village - cont...(10:10-12:10 PDT) - Hostile Input: PDF Triage That Survives an Adversarial Document - Klaus Wunder
Malware Village - (12:55-14:05 PDT) - A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you'll crack your first binary in the first ten minutes. - David Rushmer
Maritime Hacking Village - Please Place Your Electronic Devices in {Maritime} Mode: Exposing NTN’s Maritime Attack Surface - Jason Veara
Maritime Hacking Village - (12:30-12:59 PDT) - Maritime Threat Hunting: What We Actually Find When We Look - Cliff Neve,Philip Acosta,Dean Macris
Misc - (12:30-12:59 PDT) - Donating Bone Marrow: A Donor's First-Hand Experience -
Misc - Friendship Bracelets -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(11:15-12:15 PDT) - An Android voyage from Java to Smali with ASM - Ricardo Loura
Mobile Hacking Community - (12:30-12:59 PDT) - Triage vs. Reality: Mobile Security Findings in Bug Bounty - fr4vian
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(11:30-12:50 PDT) - OASIS: Prompt to Pwn - Marshall Livingston
Noob Community - cont...(11:45-12:45 PDT) - Gamifying the Matrix: a MITRE ATT&CK Video Game - Annie Meaney,Anne Drago
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - Oh hai! Meet Jason Haddix - Jason "jhaddix" Haddix
Payment Village - Breaking PBKDF - Adversarial Cryptanalysis and Techniques for Hunting Cryptographic Flaws - Ken Pyle
Policy @ DEF CON - (12:30-13:30 PDT) - Privacy You Inherit: How Cultural History Writes the Source Code for AI Surveillance Policy - Tati
Policy @ DEF CON - Europe’s Expanding Role in Global Vulnerability Management - Nuno Rodrigues Carvalho,Razvan Gavrila
Queercon Community - Trans Meetup -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(10:30-12:25 PDT) - RF CTF Kick Off Day 2 - RF Hackers
Radio Frequency Village - (12:30-13:25 PDT) - Neotropolis: The Making of the Railgun Trackers - John O'Connor
Recon Village - cont...(10:00-12:30 PDT) - Hunting the Contagious Trader Delivery Network - Alessandra Rizzo,Ariel Ropek
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - Live Recon Contest -
Recon Village - TrackTheFugitive Contest -
Recon Village - (12:40-15:10 PDT) - The Hard Part of ASM: Ownership Attribution - Jeff Foley
Red Team Village - Ouroboros Attack! Recursive AI-Assisted 0-Day Hunting - Mehmet Önder Key,Temel Demir
Red Team Village - Command & Conquer: Hands-on C2 Primer with Mythic - Logan MacLaren
Red Team Village - Building Hackbots - Jason "jhaddix" Haddix,Ryan Bonner
Red Team Village - Red Teaming Kubernetes: From App-Level CVEs to Full Cluster Takeover - Lenin Alevski
Red Team Village - Agentic AI Supply chain Vulnerability lab - Aamiruddin Syed,N A
Red Team Village - The Protocol-Native Adversary: Full-Spectrum ICS Simulation via SiL - Blessen Thomas,Javier Hernández,Wojciech Poparda
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - (12:30-13:59 PDT) - Scammers Don't Discriminate - DolphinVG
Social Engineering Community Village - cont...(10:00-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(10:15-13:15 PDT) - Battle of the Bots: Vishing Edition -
Social Engineering Community Village - cont...(11:30-12:30 PDT) - Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything - Brian Brushwood
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(11:00-12:59 PDT) - Book Signing - Aamiruddin Syed - Aamiruddin Syed
Social Gatherings/Events - Book Signing - Laura Scherling - Laura Scherling
Social Gatherings/Events - cont...(09:00-15:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Friends of Bill W -
Social Gatherings/Events - cont...(11:00-16:59 PDT) - Free Ham Radio License Exams -
Telecom Village - cont...(11:45-12:30 PDT) - From ONT to STB: Detecting IPTV Attack Chains in the Telecom SOC - Zibran Sayyed
Telecom Village - (12:30-12:59 PDT) - Signaling Sabotage: Why 100% Compliance is 0% Security - Vinod Shrimali
The Diana Initiative - Kubernetes CTF at DEF CON Contest Tour -
The Diana Initiative - Malware Village Tour -
The Diana Initiative - (12:20-12:30 PDT) - Blue Team Village Tour -
The Diana Initiative - (12:30-12:40 PDT) - BBWIC Foundation Tour -
The Diana Initiative - (12:40-12:50 PDT) - AI Village Tour -
The Diana Initiative - (12:50-12:59 PDT) - Blacks In Cyber Village Tour -
The Diana Initiative - The Diana Initiative - Open time -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Keynote: Colorado's Creation of RLAs - Wayne Williams

 

Saturday - 13:00 PDT


Return to Index  -  Locations Legend
Adversary Village - (13:30-13:59 PDT) - Field Notes on Offensive Agents: Reusability, Reliability, and What Breaks - Dominika Pietrzak,Ibai Castells
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AppSec Village - cont...(12:45-13:45 PDT) - OWASP FinBot CTF: Hands-On Agentic AI Threats - Helen Oakley,saikishu
AppSec Village - (13:15-15:59 PDT) - Supply Chain Isn’t Just Dependencies Anymore: Defending Developers, Tooling, and Builds - Tanya "SheHacksPurple" Janca
AppSec Village - (13:30-13:59 PDT) - How Shadow APIs Become an Attacker's Free Pass Into Your Cloud-Native App - Emma Yuan Fang,Krity
AppSec Village - Code Invaders: Stop The Insecure Code - Mackenzie
AppSec Village - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
AppSec Village - AI Pentesting Trivia Showdown - Andy Dennis,Bill Reyor
AppSec Village - Factory Floor MVP Incident Response Challenge -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - Safe, Secure, and Effective: What Static Behavior Analysis Reveals About the Software Running Your Medical Devices - Andrew Hendela
Blacks In Cyber Village - Bias is a Bug: Why Inequality is a Cybersecurity Vulnerability - Dr. Fatou Sankare
Blue Team Village - (13:15-14:15 PDT) - Threat Intelligence in Real Life - Ashley Sequeira,Julian Zottl,Leigh Gilbert,Madeline Sedgwick
Bug Bounty Village - cont...(12:30-13:30 PDT) - Better Bug Hunting on AI Products: A VRP Lead’s Perspective - John Kotheimer
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - (13:30-14:30 PDT) - Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure - Tal Peleg,Maya Parizer
Cloud Village - (13:30-14:30 PDT) - Fix It, Snooze It, or Ignore It? Cloud Security Decisions Under Pressure - Mackenzie Jackson
Cloud Village - Minimal by Design: Building Hardened Near-Zero-CVE Container Images - Kyle Quest,Ritvik Arya
Cloud Village - (13:30-14:10 PDT) - What's Behind the Curtain? Tearing Down AWS's AI Agent Runtime From the Inside - Dan Gansel
CodeBloom - What is AI? - Sam Mosley
Contests - Crash and Compile - Stage Competition -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed) -
Contests - Octopus Game - Booth Battle #3: The Marbles Match -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(12:00-14:59 PDT) - Dozier Drill Tournament -
Contests - Locktopus - Semi Finals -
Contests - cont...(10:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(12:00-15:59 PDT) - Global OSINT Search Party CTF – DEF CON 34 Edition -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Cryptocurrency Village - Evading LLM Detection - Hanley Shun,Cong Zhang,⁨Oscar Skjerven
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
Data Duplication Village - Drive Stats: 14 years of hard drive failure rates - Stephanie Doyle
DCNextGen - Hacker Culture 101 - medus4
DEF CON Groups - Building a Strong Community Culture presented by DC407 - Edna Jonsson,Dustin
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - gpwn: Wiretapping fiber (GPON) ISP deployments from the comfort of your home - Rithwik "thel3l" Jayasimha,Rithvik Vibhu
DEF CON Talks - cont...(12:30-13:30 PDT) - Writing to Shadow Stacks - Vladimir "G1ND1L4" Tokarev
DEF CON Talks - (13:30-14:30 PDT) - Bring Your Own Root Of Trust - Mickey "@HackingThings" Shkatov,Jesse Michael
DEF CON Talks - Stalking the Wily Hacker ... 40 years later - Cliff Stoll
DEF CON Talks - cont...(12:30-13:30 PDT) - Compounding Interest: Exploiting the ATM Supply Chain - Matt Burch
DEF CON Talks - (13:30-14:30 PDT) - Transformers: Dark Side of the Type - Weaponizing the Conversion Layer - Oleksandr Mirosh
DEF CON Talks - Dylib Hijacking on macOS: Dead or Alive? - Patrick Wardle
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
Demo Labs - AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory - Akbar "0xsensei" Abdullayev,0xHera
Demo Labs - MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems - Nur "BurritoTheNurrito" Gucu
Demo Labs - Keychecker : SSH Key based attack tool for DVCS Systems - Anant Shrivastava
Demo Labs - Hook Crook - Extracting More From Discord Webhooks - Jeremy Banker - K0JLB,Arity0
Demo Labs - L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security - Abhinav Khanna,Krishna Chaganti
Demo Labs - Trajan: Cross-Platform CI/CD Security Scanner - Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Thread Carefully -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - cont...(10:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Ham Radio Village - Why Signals Still Matter: Amateur Radio in the Age of Cell Phones - Nate Moore
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(12:00-13:30 PDT) - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
IoT Village - cont...(12:30-13:30 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology - Simone Bossi,Luca Borzacchiello
La Villa Community - cont...(12:30-13:30 PDT) - Descubrimiento Industrializado de CVEs con Agentes de IA - Simon Correa,Michael Rivera
La Villa Community - (13:30-13:59 PDT) - The CVE-Hunters Project: From Noobs to Researchers - Natan Morette
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - Crafting the Future: DEF CON 34 Light-Up Bow Workshop -
Malware Village - Ropkit: Framework for Windows Kernel Code Execution under HVCI - Nathan Sawyer
Malware Village - (13:50-14:30 PDT) - How to destroy a country - Lisandro Ubiedo,Leandro Cuozzo
Malware Village - cont...(12:55-14:05 PDT) - A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you'll crack your first binary in the first ten minutes. - David Rushmer
Middle Easterns & Africans in Cyber Security (MEACS) - BewAIre: Detecting Malicious Pull Requests at Scale with LLMs - Andrew Krug
Misc - (13:30-14:30 PDT) - Why Mandatory Age Verification Keeps Us All Less Safe - Alexis Hancock,Kenyatta Thomas
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - (13:15-14:45 PDT) - Hacking iOS Apps in a Structured Way - Sven Schleier
Nix Vegas Community - Whose PR Is It Anyway? -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - redStack: Boot-to-Breach Red Team Platform - Michael Ortiz
Noob Community - Getting Started in OT/ICS Cybersecurity - Mike Holcomb
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - FTS Build it Yourself: cDc X OWASP X Veilid - Gibson,medus4,cdC & Veilid crew
Packet Hacking Village - Building Better Backdoors Than China - Khael Kugler
Physical Security Village - (13:30-13:59 PDT) - FORTRESS Framework - Brad "Sno0ose" Ammerman
Policy @ DEF CON - cont...(12:30-13:30 PDT) - Privacy You Inherit: How Cultural History Writes the Source Code for AI Surveillance Policy - Tati
Policy @ DEF CON - (13:30-13:59 PDT) - The Subverted Hacker - Robert "zizkill" Shala
Policy @ DEF CON - Surprise Session - Check Hacker Tracker -
Queercon Community - Ace/Aro Meetup -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(12:30-13:25 PDT) - Neotropolis: The Making of the Railgun Trackers - John O'Connor
Radio Frequency Village - (13:30-13:55 PDT) - This is a Test: Vibe Hacking LTE Cell Broadcast for Emergency Alert Injection - XtraRaj
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(12:00-13:59 PDT) - Live Recon Contest -
Recon Village - cont...(12:00-17:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(12:40-15:10 PDT) - The Hard Part of ASM: Ownership Attribution - Jeff Foley
Recon Village - Tag, You’re It: Physical Tracking Tech, Defense, and How to DIY Your Own - Eddie Miro
Recon Village - (13:30-13:59 PDT) - Your OpSec Is Showing - Fae Blu3Bird" Carlisle
Red Team Village - cont...(12:00-13:59 PDT) - Ouroboros Attack! Recursive AI-Assisted 0-Day Hunting - Mehmet Önder Key,Temel Demir
Red Team Village - cont...(12:00-13:59 PDT) - Command & Conquer: Hands-on C2 Primer with Mythic - Logan MacLaren
Red Team Village - cont...(12:00-13:59 PDT) - Building Hackbots - Jason "jhaddix" Haddix,Ryan Bonner
Red Team Village - cont...(12:00-13:59 PDT) - Red Teaming Kubernetes: From App-Level CVEs to Full Cluster Takeover - Lenin Alevski
Red Team Village - You Can't Block My C2 — It's Your Google Calendar - Nishant Tayade
Red Team Village - Stop Chasing Domain Admin: Designing Red Team Exercises That Matter - Billy Giles
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(12:30-13:59 PDT) - Scammers Don't Discriminate - DolphinVG
Social Engineering Community Village - cont...(10:00-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(10:15-13:15 PDT) - Battle of the Bots: Vishing Edition -
Social Engineering Community Village - (13:30-14:59 PDT) - Hook, Line & Pretext Workshop: Crafting Effective Phish - Jenn,JC
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - Book Signing - Cindy Cohn - Cindy Cohn
Social Gatherings/Events - Book Signing - Christopher DeCarmen - Christopher DeCarmen
Social Gatherings/Events - cont...(09:00-15:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - cont...(11:00-16:59 PDT) - Free Ham Radio License Exams -
The Diana Initiative - Recon Village Tour -
The Diana Initiative - Voting Village Tour -
The Diana Initiative - (13:20-13:30 PDT) - Hackers with Disabilities Tour -
The Diana Initiative - (13:30-13:40 PDT) - Red Team Village Tour -
The Diana Initiative - (13:40-13:50 PDT) - Scambait Community Tour -
The Diana Initiative - (13:50-13:59 PDT) - Badgelife Tour -
The Diana Initiative - Everything I Need to Know About Security, I Learned from Mr. Rogers - Zoe
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - (13:30-13:59 PDT) - Pulling Back the Curtain on the Voting Booth - Marilyn Marks,Max Springer

 

Saturday - 14:00 PDT


Return to Index  -  Locations Legend
Adversary Village - Microsoft and Amazon are my Favorite C2 Providers - Robert Pimentel
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - Racing PX4: Memory Safety and Timing Vulnerabilities - Nefeli Georgilas
Aerospace Village - (14:30-14:59 PDT) - Hacking AFDX or Not; A Primer for Flight Control Systems Security - Andrew Tierney,Adam Bromiley
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack? - Karol Piekarski,Nishith Sinha
AI Village - What we learned from SATAN about the MYTH of Mythos - Jeff Crume
AI Village - (14:30-14:59 PDT) - That's Not Your Agent: Why Zero Trust Can't Tell - Krity Kharbanda,Emma Yuan Fang
AppSec Village - OWASP AIBOM Generator - Dmitry Raidman,Helen Oakley
AppSec Village - cont...(13:15-15:59 PDT) - Supply Chain Isn’t Just Dependencies Anymore: Defending Developers, Tooling, and Builds - Tanya "SheHacksPurple" Janca
AppSec Village - Every ride you take - Hacking a City’s Public Transportation - Ignacio Navarro
AppSec Village - (14:50-15:20 PDT) - Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase - Mudita Khurana
AppSec Village - cont...(13:00-14:59 PDT) - Code Invaders: Stop The Insecure Code - Mackenzie
AppSec Village - cont...(13:00-14:59 PDT) - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
AppSec Village - cont...(13:00-14:59 PDT) - AI Pentesting Trivia Showdown - Andy Dennis,Bill Reyor
AppSec Village - cont...(13:00-14:59 PDT) - Factory Floor MVP Incident Response Challenge -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Blacks In Cyber Village - Exploring Security Features in the Armv8-M Architecture - Ian Harris,Jacob Gutierrez
Blue Team Village - cont...(13:15-14:15 PDT) - Threat Intelligence in Real Life - Ashley Sequeira,Julian Zottl,Leigh Gilbert,Madeline Sedgwick
Blue Team Village - (14:30-15:30 PDT) - AI Security: Hype, Hacks, and the Future of Defense - Karan Dwivedi,Thomas Roccia,Todd Fletcher
Bug Bounty Village - Exfil Everything: A Year of Stealing Data from AI Agents - Ads Dawson,Mike "TakSec" Takahashi
Bug Bounty Village - (14:30-15:59 PDT) - Bots, Bounties, and Bullshit: An Honest Panel on AI in Hacking - Ben "NahamSec" Sadeghipour,Vitor "busf4ctor" Falcao Habibe Costa,Joey Melo,Dustin "ph1r3574r73r" Farley,Ads Dawson,Johann "wunderwuzzi23" Rehberger
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(13:30-14:30 PDT) - Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure - Tal Peleg,Maya Parizer
Cloud Village - cont...(13:30-14:30 PDT) - Fix It, Snooze It, or Ignore It? Cloud Security Decisions Under Pressure - Mackenzie Jackson
Cloud Village - cont...(13:30-14:10 PDT) - What's Behind the Curtain? Tearing Down AWS's AI Agent Runtime From the Inside - Dan Gansel
Cloud Village - Autonomous Offense vs. Autonomous Defense: Who's Winning in the Cloud? -
Cloud Village - (14:50-15:20 PDT) - cloud-auth: a provider-agnostic CLI for cross-cloud workload identity - Aniruddha Biyani
CodeBloom - Work Session: Ciphers -
Contests - cont...(13:00-14:59 PDT) - Crash and Compile - Stage Competition -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(12:00-14:59 PDT) - Dozier Drill Tournament -
Contests - cont...(10:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(12:00-15:59 PDT) - Global OSINT Search Party CTF – DEF CON 34 Edition -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - Forget FIPS: An Analysis of Russian and Chinese Cryptographic Standards - 1nfocalypse
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - cont...(13:00-14:15 PDT) - Hacker Culture 101 - medus4
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - Lights Out: Out-of-Band, Out of Mind, Out of Control - HD "hdm" Moore
DEF CON Talks - cont...(13:30-14:30 PDT) - Bring Your Own Root Of Trust - Mickey "@HackingThings" Shkatov,Jesse Michael
DEF CON Talks - (14:30-15:30 PDT) - Bird Hunting Season: The Final Flight - Jon "GainSec" Gaines
DEF CON Talks - Cracking North Korea's Information Control: How Smugglers, Defectors, and Technologists are Breaking Open the World's Most Locked-Down Information System - JDT
DEF CON Talks - cont...(13:30-14:30 PDT) - Transformers: Dark Side of the Type - Weaponizing the Conversion Layer - Oleksandr Mirosh
DEF CON Talks - (14:30-15:30 PDT) - Looking and Peering: Attacking from beyond BGP Adjacency - Bo-Shiun "bronson113" Yen
DEF CON Talks - The Enclave is Lying to You: Breaking TEE Trust Boundaries Through Boot-Time State - Sandeep "pyro" Jayashankar
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices - wasabi,Ø1,Tokugero
DEF CON Workshops - Sold Out - Purple Teaming Industrial Control Systems - Arnaud SOULLIE,Alexandrine Torrents
DEF CON Workshops - Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem - Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla
DEF CON Workshops - Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques - Abhinav Verma
DEF CON Workshops - Sold Out - Intro to Writing Windows Malware with Rust! - iDigitalFlame,Daniel Bravo
DEF CON Workshops - Sold Out - Building Agentic Reverse Engineering "Skills" - John "clearbluejar" McIntosh
DEF CON Workshops - Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It - Wesley McGrew
DEF CON Workshops - Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites - Nitay Bachrach,Cynthia Ardman
Demo Labs - LoKi: A LoRa/Meshtastic based implant for Red Teaming - Venky Raju
Demo Labs - Intercept.js: Runtime-Aware Detection for JavaScript Environments - Rishi Kant
Demo Labs - Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop - Fukusuke Takahashi,Zach Mathis,Akira Nishikawa
Demo Labs - Hook Crook - Extracting More From Discord Webhooks - Jeremy Banker - K0JLB,Arity0
Demo Labs - PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale - Georgia Weidman
Demo Labs - MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM - Uğur "uJohn" Can ATASOY
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Thread Carefully -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - cont...(10:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Game Hacking Village - Catching Cheaters in Super Smash Bros Melee - AltF4
Hackers.town - Fun with alternative smartphones with The Tech Reclaimers! - Janet Vertesi
Ham Radio Village - (14:30-14:59 PDT) - Ham Radio - Licensed to Experiment - Dan W0BDP Norte
ICS Village - OT Round table. Real talk on how to protect your OT spaces - Aaron Crow,Tom VanNorman,Dillon Lee
ICS Village - (14:45-15:30 PDT) - Give an AI Industrial Protocol Tools and Watch What It Destroys - Malav Vyas,Asher Davila
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - (14:30-15:15 PDT) - UAiRT: Over The Air UART - Metehan Arslan,Samet Berk Simsek
La Villa Community - Keep the Model on Course: Agentic LLM Workflows for Reversing - Asher Davila,Lenin Alevski
La Villa Community - (14:30-15:30 PDT) - When Cash Runs on Windows: A Red Team Look at ATM Attack Surfaces - Gerardo Mejia
La Villa Community - Execution of modern techniques to start/improve your career in Incident Response - Ashley Hiram Muñoz
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - (14:15-14:45 PDT) - Operation Restoration - Cannibal
Malware Village - cont...(13:50-14:30 PDT) - How to destroy a country - Lisandro Ubiedo,Leandro Cuozzo
Malware Village - (14:40-15:15 PDT) - The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications - Chris Navarrete,Sai Sathvik Ruppa
Malware Village - cont...(12:55-14:05 PDT) - A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you'll crack your first binary in the first ten minutes. - David Rushmer
Malware Village - An Intro to Mac Malware Analysis - Patrick Wardle
Middle Easterns & Africans in Cyber Security (MEACS) - (14:30-14:59 PDT) - Condense Volumes, Connect Dots, Enrich Contexts: Scaling Root Cause Analysis and Automated Troubleshooting with ML - Ezz Tahoun
Middle Easterns & Africans in Cyber Security (MEACS) - The Hidden Data Supply Chain: How a SaaS Platform Broadcast Credentials and Customer Identities - Sam Jadali
Misc - cont...(13:30-14:30 PDT) - Why Mandatory Age Verification Keeps Us All Less Safe - Alexis Hancock,Kenyatta Thomas
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(13:15-14:45 PDT) - Hacking iOS Apps in a Structured Way - Sven Schleier
Nix Vegas Community - Nix Knows When the Agent Is Wrong - Jason Odoom
Nix Vegas Community - (14:45-15:15 PDT) - Securing Nix Builds using microVMs - Tristan Ross
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(13:00-14:50 PDT) - redStack: Boot-to-Breach Red Team Platform - Michael Ortiz
Noob Community - (14:15-14:45 PDT) - Privilege Escalation: Building a Cyber Career with Zero Support - Akanksha Raghvesh
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - Agents & Exploits: Hacking OWASP VWAD - Philippe "pilvar" Dourassov
Payment Village - BNPL's Blind Spot: Exploiting Business Logic Flaws in Buy Now Pay Later APIs - Furkan Fatih Demir
Payment Village - (14:30-15:15 PDT) - Deepfake Detection Through Adversarial Research - Efim Boieru
Physical Security Village - Clone to Pwn: Remote Badge Cloning with the Flipper Zero - Langston Clement,Dan Goga
Policy @ DEF CON - The best of three bad ideas? Ransomware taxes in lieu of bans or doing nothing - Joe Uchill
Policy @ DEF CON - (14:30-15:30 PDT) - From Disclosure to Defense: Rebuilding Vulnerability Management for the AI Era - Lindsey Cerkovnik,John Banghart,Ben Flatgard,Elizabeth Eigner
Queercon Community - Own the con -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - RASM: A State Machine Methodology for RF Security Assessment - Smriti Gaba
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(12:00-17:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(12:40-15:10 PDT) - The Hard Part of ASM: Ownership Attribution - Jeff Foley
Red Team Village - Crawlee - Improving crawling with an LLM - Daniel Goldberg
Red Team Village - Living Off Someone Else's Inference - Armend Gashi,Redon Gashi
Red Team Village - AIMARU C2: The New Era of LotL (MCP AI-Driven C2) - Mario Lobo
Red Team Village - BloodBash: Lightweight CLI Python BloodHound Alternative - Anthony Russell
Red Team Village - Turning Keys and Opening Doors: Leveraging AI Hype to Hack Everything - Will Alexander
Red Team Village - Chaining Credentials Through the AI Infrastructure Nobody Secured - Nathan Keys
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - Creator Talk with RinoaPoison & VanHelen - RinoaPoison,VanHelen
Social Engineering Community Village - cont...(10:00-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - For Prompt Injection, Press 1: Hacking AI Voice Agents - Willie Zhang
Social Engineering Community Village - (14:30-14:59 PDT) - The Sherlock Holmes Social Engineering Playbook - Elizabeth Rasnick
Social Engineering Community Village - cont...(13:30-14:59 PDT) - Hook, Line & Pretext Workshop: Crafting Effective Phish - Jenn,JC
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - Book Signing - Garrett Gee - Garrett Gee
Social Gatherings/Events - Book Signing - Brandy Smith - Brandy Smith
Social Gatherings/Events - cont...(09:00-15:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - cont...(11:00-16:59 PDT) - Free Ham Radio License Exams -
Telecom Village - Signal Hijacked: How Mobile Networks Became Phishing's Most Trusted Delivery Layer - Sindhura Kona
Telecom Village - (14:15-14:45 PDT) - From Zero-Day to Zero-Hour: Rethinking Telecom Defense for the Frontier AI Era - Arvind Singh
The Diana Initiative - Illumicon Tour -
The Diana Initiative - Hacker Book Club meet up -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Separating News from Noise - Ryan Murray,Stephen Richter,Nate Young
Voting Village - (14:30-14:59 PDT) - Dissecting the ICX Frog - Drew Springall

 

Saturday - 15:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - What can those architecting agents learn from national security? - David C Eight
AppSec Village - (15:15-16:15 PDT) - Proactive Malicious Package Defense - Darren Meyer
AppSec Village - cont...(13:15-15:59 PDT) - Supply Chain Isn’t Just Dependencies Anymore: Defending Developers, Tooling, and Builds - Tanya "SheHacksPurple" Janca
AppSec Village - cont...(14:50-15:20 PDT) - Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase - Mudita Khurana
AppSec Village - (15:30-15:59 PDT) - How Malicious AI Skills Hijack Your Agents - Jenn Gile
AppSec Village - SBOM Find the Flaws - Dmitry Raidman
AppSec Village - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
AppSec Village - AI Pentesting Trivia Showdown - Andy Dennis,William Reyor
AppSec Village - The Call Stack Experience - Victoria Keeler
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - AIRGAP BREACHED: Monitoring the Ancestral Payload Leaking from the Poles - David J. Castillo-Cornejo
Biohacking Village - (15:30-15:59 PDT) - DarkSyringe: Automated poisoning of Clinical AI Assistants Through PDFs (a physician's point of view) - Francesco Costa
Blacks In Cyber Village - ChronoRoot: Time-Traveling Through Kernel Trust Boundaries - Ahmeen Muhammad,Sydney Johns
Blue Team Village - cont...(14:30-15:30 PDT) - AI Security: Hype, Hacks, and the Future of Defense - Karan Dwivedi,Thomas Roccia,Todd Fletcher
Blue Team Village - (15:45-16:45 PDT) - Threat Hunting Explained Badly - Alllison Gallo,Brian Baskin,Silas Cutler,Sydney "letswastetime" Marrone
Bug Bounty Village - cont...(14:30-15:59 PDT) - Bots, Bounties, and Bullshit: An Honest Panel on AI in Hacking - Ben "NahamSec" Sadeghipour,Vitor "busf4ctor" Falcao Habibe Costa,Joey Melo,Dustin "ph1r3574r73r" Farley,Ads Dawson,Johann "wunderwuzzi23" Rehberger
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - (15:30-15:59 PDT) - The Compiler Nobody Satisfactorily Tested: Supply-Chain Gaps in EV Charging Firmware - Kangwon Lee
Cloud Village - cont...(14:50-15:20 PDT) - cloud-auth: a provider-agnostic CLI for cross-cloud workload identity - Aniruddha Biyani
Cloud Village - (15:20-15:59 PDT) - A New Hope for SSRF: Exploiting Credential Relay from APIM to AI Foundry - Marios Gyftos,Chrysostomos Manousis
CodeBloom - Game Time: Input, Output, and Variables -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - Locktopus - Final Championship -
Contests - (15:30-17:30 PDT) - Locktopus Challenge Finals -
Contests - cont...(10:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(12:00-15:59 PDT) - Global OSINT Search Party CTF – DEF CON 34 Edition -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - The Agent Long Con: Tricking Agents Out of Their Data - Patrick Walsh
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - AMA with EFF - EFF
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - Throw Out the Alphabet: Token-Based Markov Chains for Password Cracking - Jon "flakpaket" Gorenflo
DEF CON Talks - cont...(14:30-15:30 PDT) - Bird Hunting Season: The Final Flight - Jon "GainSec" Gaines
DEF CON Talks - (15:30-16:30 PDT) - Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks - Francesco La Spina,Stanislav Dashevskyi
DEF CON Talks - Smile, you're on camera! Livestreaming from North Korea's IT workers laptop farm - Heiner García,Mauro Eldritch
DEF CON Talks - cont...(14:30-15:30 PDT) - Looking and Peering: Attacking from beyond BGP Adjacency - Bo-Shiun "bronson113" Yen
DEF CON Talks - (15:30-16:30 PDT) - Wrestling with a Python: Escaping Copilot Studio's AI-Guarded Sandbox - Ryan Hausknecht,Simon Maxwell-Stewart
DEF CON Talks - Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild - Gavin Zhong,Zhengyu Liu,Jianjia Yu
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices - wasabi,Ø1,Tokugero
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Purple Teaming Industrial Control Systems - Arnaud SOULLIE,Alexandrine Torrents
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem - Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques - Abhinav Verma
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Intro to Writing Windows Malware with Rust! - iDigitalFlame,Daniel Bravo
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Building Agentic Reverse Engineering "Skills" - John "clearbluejar" McIntosh
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It - Wesley McGrew
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites - Nitay Bachrach,Cynthia Ardman
Demo Labs - LoKi: A LoRa/Meshtastic based implant for Red Teaming - Venky Raju
Demo Labs - AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This! - Anurag Swarnim Yadav,Joseph Wilson
Demo Labs - Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device - Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova
Demo Labs - Ghost in the IDE - Venkata Jayaram Yalla,Pardhiv Reddy
Demo Labs - AOBTD: AI One Bites The DAST - Ozgun "ozzy" Kultekin
Demo Labs - AI Pipeline for N-days Weaponization - Andrea Brosio,Arun Nair
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Thread Carefully -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-15:59 PDT) - Chill Zone: Casual Games & TASBot Smash Demo -
Game Hacking Village - cont...(10:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Hackers.town - The Enshittified Internet and How We Can All Rewild the Internet - LambdaCalculus
Ham Radio Village - Meshtastic Beasts and Where to Find Them - Scott Thompson
ICS Village - cont...(14:45-15:30 PDT) - Give an AI Industrial Protocol Tools and Watch What It Destroys - Malav Vyas,Asher Davila
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum! - Kody Kinzie
IoT Village - cont...(14:30-15:15 PDT) - UAiRT: Over The Air UART - Metehan Arslan,Samet Berk Simsek
IoT Village - (15:15-15:59 PDT) - Beyond Your Bookshelf: Hackable eReaders - Katie Paxton-Fear
La Villa Community - cont...(14:30-15:30 PDT) - When Cash Runs on Windows: A Red Team Look at ATM Attack Surfaces - Gerardo Mejia
La Villa Community - (15:30-16:30 PDT) - From Live Malware to Red Team Tradecraft: Process Hollowing in msbuild.exe - Filipi Pires
La Villa Community - cont...(14:00-15:59 PDT) - Execution of modern techniques to start/improve your career in Incident Response - Ashley Hiram Muñoz
Lockpick Village - Intro to Lockpicking -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - Cyberdeck Build - Sk!tz0
Malware Village - cont...(14:40-15:15 PDT) - The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications - Chris Navarrete,Sai Sathvik Ruppa
Malware Village - (15:20-16:05 PDT) - Leigh Trinity OTW - Leigh Gilbert
Malware Village - cont...(14:10-16:50 PDT) - An Intro to Mac Malware Analysis - Patrick Wardle
Middle Easterns & Africans in Cyber Security (MEACS) - Agents of Chaos: A Field Guide to How Agentic AI Gets Owned, and What Trust Nothing Looks Like in Practice - Amber Bennoui
Misc - (15:30-16:30 PDT) - Privacy's Defender with Women in Security and Privacy (WISP) - Cindy Cohn,Alyssa Coley
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - Beerus Framework – A New Mobile Framework Arises - João Pedro Tricta,Daniel "Daniboy" França Lima
Nix Vegas Community - cont...(14:45-15:15 PDT) - Securing Nix Builds using microVMs - Tristan Ross
Nix Vegas Community - (15:30-16:30 PDT) - Your Infrastructure Is a DAG: Manage It With Nix - Ethan Carter Edwards
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - Six Impossible Things Before Breakfast: Common Misconceptions About Being a CTI Analyst - Brett Tolbert
Noob Community - AI Hacking for Noobs - Jason "jhaddix" Haddix,Arcanum Information Security Team
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - cont...(14:00-15:59 PDT) - Agents & Exploits: Hacking OWASP VWAD - Philippe "pilvar" Dourassov
Packet Hacking Village - There's A Bug in My Boot! Finding Vulnerabilities in U-Boot - Jared Stroud
Payment Village - cont...(14:30-15:15 PDT) - Deepfake Detection Through Adversarial Research - Efim Boieru
Policy @ DEF CON - cont...(14:30-15:30 PDT) - From Disclosure to Defense: Rebuilding Vulnerability Management for the AI Era - Lindsey Cerkovnik,John Banghart,Ben Flatgard,Elizabeth Eigner
Policy @ DEF CON - (15:30-15:59 PDT) - Assume Breach, But For Real: Rewriting Infrastructure Policy for the Adversaries Who Never Left - Travis Berent,Adam Hickey
Queercon Community - Men Loving Men Meetup -
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - Drone ID on the Wire: RF Detection, Spoofing, and the Limits of Compliance-Based Airspace Awareness - Greg Albrecht
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(12:00-17:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(12:40-15:10 PDT) - The Hard Part of ASM: Ownership Attribution - Jeff Foley
Recon Village - (15:20-17:50 PDT) - Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform - Lenin Alevski
Recon Village - The Breach Is Over. The Exposure Is Not - Kumar Ashwin,Anant Shrivastava
Recon Village - (15:30-15:59 PDT) - Cl0p ^_- Til You Drop - 6 years, 9 Campaigns, 7 0-Days - Eli Woodward
Red Team Village - cont...(14:00-15:59 PDT) - Crawlee - Improving crawling with an LLM - Daniel Goldberg
Red Team Village - cont...(14:00-15:59 PDT) - Living Off Someone Else's Inference - Armend Gashi,Redon Gashi
Red Team Village - cont...(14:00-15:59 PDT) - AIMARU C2: The New Era of LotL (MCP AI-Driven C2) - Mario Lobo
Red Team Village - cont...(14:00-15:59 PDT) - BloodBash: Lightweight CLI Python BloodHound Alternative - Anthony Russell
Red Team Village - Requiem for the Decommissioned: When Dead Hosts Bite Back - Yekaterina Shevchenko
Red Team Village - Breaking MCP Trust Boundaries: Cross-Server Authority Injection in Agent Toolchains - Yevhen Pervushyn
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(14:00-15:30 PDT) - Creator Talk with RinoaPoison & VanHelen - RinoaPoison,VanHelen
Scambait Village - (15:30-16:59 PDT) - Creator Drop-In -
Social Engineering Community Village - cont...(10:00-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - A Framework for Evaluating AI-Enabled Social Engineering - Fred Heiding
Social Engineering Community Village - (15:30-15:59 PDT) - What Scammers Know That Social Engineers Don't: Three Techniques for Tough Cases - Megan Squire
Social Engineering Community Village - (15:30-17:30 PDT) - 2027 SECVC Pre-Qualification Round - JC,Snow
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - Book Signing - Mark Foudy - Mark Foudy
Social Gatherings/Events - cont...(09:00-15:59 PDT) - Merch (formerly swag) Area Open -- README -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - cont...(11:00-16:59 PDT) - Free Ham Radio License Exams -
Social Gatherings/Events - DCG New England Meetup -
Telecom Village - (15:45-16:45 PDT) - Industry Challenges & SOC Reality - Vinod Shrimali
The Diana Initiative - cont...(14:00-15:59 PDT) - Hacker Book Club meet up -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - (15:30-15:59 PDT) - Alerts and Warnings in 2026 Elections - Geoff Hale,Ryan Macias

 

Saturday - 16:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - MeshLens: Security Profiling at Scale - Vipul Ujawane,Jigar Bhavsar,Rayden Chia
AI Village - (16:30-16:59 PDT) - Trust Amplification in Enterprise AI Systems – Microsoft CoPilot Case Studies Enabling AI-Assisted Influence Operations - Tobias Diehl
AppSec Village - cont...(15:15-16:15 PDT) - Proactive Malicious Package Defense - Darren Meyer
AppSec Village - (16:30-17:30 PDT) - Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence - Jordan Bonagura
AppSec Village - (16:15-17:59 PDT) - Code to Cloud: Secure Modern Applications Using Open-Source Tools - Mackenzie
AppSec Village - The API Made Me Do It - Do Bad APIs Lead AI to Generate Vulnerable Code? - Yariv Tal
AppSec Village - (16:50-17:20 PDT) - No Jailbreak Required: Pwning AI Agents Through the Tools They Trust - Helen Oakley,saikishu
AppSec Village - cont...(15:00-16:59 PDT) - SBOM Find the Flaws - Dmitry Raidman
AppSec Village - cont...(15:00-16:59 PDT) - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
AppSec Village - cont...(15:00-16:59 PDT) - AI Pentesting Trivia Showdown - Andy Dennis,William Reyor
AppSec Village - cont...(15:00-16:59 PDT) - The Call Stack Experience - Victoria Keeler
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Blacks In Cyber Village - Improving Security Vulnerability Descriptions using LLMs - Kenechukwu Nwodo
Blacks In Cyber Village - (16:30-16:59 PDT) - [Virtual] National Service Panel - CTU,BIC,MCPA - Carmeshia Miller,Tiffany Scheurenbrand,Shemeka Chance Jeffrey
Blue Team Village - cont...(15:45-16:45 PDT) - Threat Hunting Explained Badly - Alllison Gallo,Brian Baskin,Silas Cutler,Sydney "letswastetime" Marrone
Bug Bounty Village - Burp, But Yours: Hands-On Extension and Bambda Development - Hannah L
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-16:59 PDT) - Bomb Bot Challenge -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Car Hacking Village - Free IP, Free Chaos: DHCP-Assisted Flooding Against Automotive Ethernet - Yehyeong Lee
Cloud Village - OCIguana - A vulnerable-by-design OCI lab - Eli Shparaga
Cloud Village - Securing the AI Stack and Hunting Across Clouds - Bryant Pickford
Cloud Village - The 100-to-1 Problem: Securing the Non-Human Identity Perimeter -
Cloud Village - (16:40-17:20 PDT) - Key Rotation Won't Save You: Hunting Workload Identity Backdoors in AWS and GCP - Jie Wu
CodeBloom - What is AI? - Sam Mosley
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(15:30-17:30 PDT) - Locktopus Challenge Finals -
Contests - cont...(10:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-16:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - Quantum-Ready or Not: What 1,000 Codebases Reveal About Cryptographic Risk - Dr. Zulfikar Ramzan
Cryptocurrency Village - Breaking Ciphers and Zero-Knowledge Proofs - Luke Szramowski,Freeman Slaughter,Diego "rehrar" Salazar
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - 3D Printing: Data, Discretion, and Design - Evan
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design - Peyton "p80n-sec" Kennedy
DEF CON Talks - cont...(15:30-16:30 PDT) - Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks - Francesco La Spina,Stanislav Dashevskyi
DEF CON Talks - (16:30-17:30 PDT) - How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs? - Veronica Kovah,Xeno Kovah
DEF CON Talks - The Compiler That Can't Read: Crashing Every 5G Phone With One Byte - Qiqing Huang,Xingyu Wang
DEF CON Talks - cont...(15:30-16:30 PDT) - Wrestling with a Python: Escaping Copilot Studio's AI-Guarded Sandbox - Ryan Hausknecht,Simon Maxwell-Stewart
DEF CON Talks - (16:30-17:30 PDT) - Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System - Albert "yz9yt" Corzo
DEF CON Talks - Install Me Maybe: Turning Claimable VS Code Extension IDs into Supply-Chain Attacks - Raphael "rcss" Silva
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices - wasabi,Ø1,Tokugero
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Purple Teaming Industrial Control Systems - Arnaud SOULLIE,Alexandrine Torrents
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem - Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques - Abhinav Verma
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Intro to Writing Windows Malware with Rust! - iDigitalFlame,Daniel Bravo
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Building Agentic Reverse Engineering "Skills" - John "clearbluejar" McIntosh
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It - Wesley McGrew
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites - Nitay Bachrach,Cynthia Ardman
Demo Labs - xEndity: IoT Firmware Analysis & Digital Twin Platform - Zeus "LightningGod" Chan,Kenneth "kenleejl" Lee
Demo Labs - GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches - ialleejy,Kyul,HyunJun "Beaver King" Kwon
Demo Labs - VoiceLock: Offline, Robust On-Device Speech Transcription - Ayaan Qayyum,Parag Kalay
Demo Labs - Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection - Ankit Vashisth
Demo Labs - Weaponizing eBPF and XDP with Covert Triggered Reverse Shells - Yll "0xBabar0ka" Berisha
Demo Labs - Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything - Kevin "kdrwins" Dela Rosa
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Thread Carefully -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(10:00-16:59 PDT) - Riot Games Vanguard: Pwn to own -
Game Hacking Village - Chill Zone: Smash (Project Plus) Tournament with Prizes -
Game Hacking Village - Dreamcast Ex Inferis — RCE on the Sega Dreamcast PlanetWeb Internet Browser v3.0 - Piffd0s
Ham Radio Village - Keeping the Angry Pixies Happy: the Care and Feeding of your Batteries - hamster
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(15:00-16:30 PDT) - Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum! - Kody Kinzie
IoT Village - (16:30-17:30 PDT) - Weaponization of Cellular Based IoT Technology – Leveraging Smart Devices to Gain a Foothold - Carlota Bindner,Deral Heiland
La Villa Community - cont...(15:30-16:30 PDT) - From Live Malware to Red Team Tradecraft: Process Hollowing in msbuild.exe - Filipi Pires
La Villa Community - (16:30-17:30 PDT) - De la Explotación de Buffer Overflows al C2 Industrial: Infectando y Controlando RTUs con Malware - Fernando Mengali
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:30-16:30 PDT) - Resume Review with the Lonely Hackers Club -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - cont...(15:00-16:59 PDT) - Cyberdeck Build - Sk!tz0
Maker's Village - Building Silkscreens and carving stamps - hunny
Malware Village - cont...(15:20-16:05 PDT) - Leigh Trinity OTW - Leigh Gilbert
Malware Village - (16:15-16:55 PDT) - The AI Analysis Train is Leaving the Station: ALL ABOARD!! - Ryan "@rj_chap" Chapman
Malware Village - cont...(14:10-16:50 PDT) - An Intro to Mac Malware Analysis - Patrick Wardle
Maritime Hacking Village - Shipcrawler: Automated Maritime OSINT — From Open Data to Actionable Intelligence - Ahmed Nagi Nasr
Maritime Hacking Village - (16:30-16:59 PDT) - LSTM Autoencoder Ensemble for NMEA 2000 Intrusion Detection on Vessel Networks - Anissa Elias,James Campbell
Misc - cont...(15:30-16:30 PDT) - Privacy's Defender with Women in Security and Privacy (WISP) - Cindy Cohn,Alyssa Coley
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Nix Vegas Community - cont...(15:30-16:30 PDT) - Your Infrastructure Is a DAG: Manage It With Nix - Ethan Carter Edwards
Nix Vegas Community - (16:30-16:59 PDT) - Breaking the Chains of Cloud Giants: Building a Fully Autonomous Personal Cloud on NixOS - Maksim Kuskov,Mikhail Ilin
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(15:00-16:59 PDT) - AI Hacking for Noobs - Jason "jhaddix" Haddix,Arcanum Information Security Team
Noob Community - (16:15-16:45 PDT) - Imposter Syndrome Is Distracting You From the Work That Matters - Samantha Schwartz
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - OSINT Search party CTF Debrief - Trace Labs Staff
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - Practical AI Security Assessments Using OWASP AISVS - Jim Manico
Packet Hacking Village - Why Couldn't I See My Own Drone? Remote ID, ESP32s, and the Packet Trail to Friend or Foe - Will Hatzer,Charles Grow
Payment Village - Compounding Interest: Exploiting the ATM Supply Chain - Matt Burch
Physical Security Village - Zero-Knowledge Unsaflok: The Unsaflok Saga Continues - Ben Higgins,Aaron Tulino
Policy @ DEF CON - Securing the Safety Net: Why Healthcare Cybersecurity Policy Keeps Failing Patients - Sahan Fernando,James Bowie,Nancy Brainerd,Phil Englert
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - Yes, it runs Doom: over the air gaming on a bladeRF SDR - max
Radio Frequency Village - (16:30-17:25 PDT) - I'm Not Special, and You Can Too! A journey into RF Antenna Design for Dummies. - Hamspiced
Recon Village - cont...(11:00-16:59 PDT) - GE(O)SINT Contest -
Recon Village - cont...(12:00-17:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(15:20-17:50 PDT) - Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform - Lenin Alevski
Recon Village - Live Recon Contest — Final Presentations -
Red Team Village - The Quantum Mechanic: Attacking all the clouds - Moses Frost
Red Team Village - Evading EDR in ATM - Arnold Jared Morales Yepez
Red Team Village - MalSkill: Weaponizing AI Agent Skills for Persistence, Exfiltration, and Lateral Movement - Nur Gucu
Red Team Village - Writing Production-Grade Exploits in go-exploit - Landon Rice
Red Team Village - Control + C = Control Me - Andrew Griess
Red Team Village - OSINT for Hackers Redux - Lee McWhorter,Sandra Stibbards
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(15:30-16:59 PDT) - Creator Drop-In -
Social Engineering Community Village - cont...(10:00-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - Wolfmasking: Teaching Everyday Defenders to Think Like Social Engineers - Brian Brushwood
Social Engineering Community Village - (16:30-17:59 PDT) - Cold Calls -
Social Engineering Community Village - cont...(15:30-17:30 PDT) - 2027 SECVC Pre-Qualification Round - JC,Snow
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - Book Signing - Thomas Wilhelm - Thomas Wilhelm
Social Gatherings/Events - Book Signing - Avinash Majeti - Avinash Majeti
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - cont...(11:00-16:59 PDT) - Free Ham Radio License Exams -
Social Gatherings/Events - Queercon Mixer -
Social Gatherings/Events - cont...(15:00-16:59 PDT) - DCG New England Meetup -
Telecom Village - cont...(15:45-16:45 PDT) - Industry Challenges & SOC Reality - Vinod Shrimali
Telecom Village - (16:45-16:59 PDT) - Telecom Village CTF Closure -
The Diana Initiative - The Diana Initiative - Open time -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Low Skill, High Impact Attacks on Internet Voting - John Odum
Voting Village - (16:30-16:59 PDT) - On the Weaponization of Voting Channels - Carsten Schürmann

 

Saturday - 17:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-17:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-17:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-17:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-17:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-17:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-17:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-17:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-17:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - Bricks in the Air -
Aerospace Village - cont...(10:00-17:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - Behind the Badge: SAOv3 and Open Sourcing the Aerospace Village ISS Badge - Adam Batori,Kevin Colley,Robert Pafford,Lillian Ash Baker
Aerospace Village - (17:30-17:59 PDT) - SpaceCOP: Houston, We Have an Intrusion - Brandon Bailey
AI Village - cont...(10:00-17:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - cont...(10:00-17:59 PDT) - Poster Presentations -
AI Village - cont...(10:00-17:59 PDT) - AI Village: Village Open -
AI Village - (17:30-17:59 PDT) - SADF: A Taxonomy and Evaluation Framework for Agentic Security Failures - Julie Brunias
AppSec Village - cont...(16:30-17:30 PDT) - Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence - Jordan Bonagura
AppSec Village - cont...(16:15-17:59 PDT) - Code to Cloud: Secure Modern Applications Using Open-Source Tools - Mackenzie
AppSec Village - cont...(16:50-17:20 PDT) - No Jailbreak Required: Pwning AI Agents Through the Tools They Trust - Helen Oakley,saikishu
AppSec Village - (17:30-17:59 PDT) - From Prompts to Production: Discovering Exposed PII & IDORs in AI-Generated Apps - Samantha Pearlstein
Biohacking Village - cont...(10:00-17:59 PDT) - Biohacking Device Lab -
Biohacking Village - cont...(10:00-17:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Blue Team Village - Incident Response in 2026 - Chriss Hansen,K Singh,Levone Campbell,Sarthak Taneja
Bug Bounty Village - cont...(16:00-17:59 PDT) - Burp, But Yours: Hands-On Extension and Bambda Development - Hannah L
Call Center Village - cont...(10:00-17:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-17:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(16:00-17:59 PDT) - OCIguana - A vulnerable-by-design OCI lab - Eli Shparaga
Cloud Village - cont...(16:40-17:20 PDT) - Key Rotation Won't Save You: Hunting Workload Identity Backdoors in AWS and GCP - Jie Wu
CodeBloom - Work Session: Binary Code -
Contests - cont...(10:00-17:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-17:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-17:59 PDT) - Untechnical -
Contests - cont...(10:00-17:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-17:59 PDT) - Darknet-NG -
Contests - cont...(10:00-17:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-17:59 PDT) - TeleChallenge -
Contests - cont...(10:00-17:59 PDT) - HackFortress -
Contests - cont...(10:00-17:59 PDT) - ?Cube -
Contests - cont...(10:00-17:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-17:59 PDT) - Octopus Game - Booth Open -
Contests - Octopus Game - The Final Booth Battle -
Contests - cont...(10:00-17:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-17:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-17:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-17:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-17:59 PDT) - Hacker Games -
Contests - cont...(10:00-17:59 PDT) - PhreakMe -
Contests - cont...(10:00-17:59 PDT) - Game Hacking Village CTF -
Contests - cont...(10:00-17:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-17:59 PDT) - Hac-Man -
Contests - cont...(10:00-17:59 PDT) - Crack the Core -
Contests - cont...(10:00-17:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-17:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-17:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-17:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-17:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-17:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-17:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(15:30-17:30 PDT) - Locktopus Challenge Finals -
Contests - cont...(10:00-17:59 PDT) - Radio Frequency Capture the Flag -
Contests - cont...(10:00-17:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-17:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-17:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-17:59 PDT) - OWASP CTF -
Contests - cont...(10:00-17:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Backdoors & Breaches - Tim Doerges,Seth Benning
Contests - cont...(10:00-17:59 PDT) - DEF CON Groups Sticker Contest -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Contests - cont...(10:00-17:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - The National Fight Against ALPRs - Freddy Martinez,Sarah
Data Duplication Village - cont...(10:00-17:59 PDT) - DDV open and accepting drives for duplication -
DCNextGen - Objectively Awesome Robots: A Hands-On Introduction to Python Classes and Objects - 4ng3lhacker
DEF CON Groups - cont...(10:00-17:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - High Voltage Heist: Turning Your EV into my Power Bank - Fabien Guillebot,Stepan Konicek
DEF CON Talks - cont...(16:30-17:30 PDT) - How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs? - Veronica Kovah,Xeno Kovah
DEF CON Talks - (17:30-17:59 PDT) - TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition - Daniel Genkin,Jalen Chuang
DEF CON Talks - OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise - Yaara Shriki
DEF CON Talks - cont...(16:30-17:30 PDT) - Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System - Albert "yz9yt" Corzo
DEF CON Talks - (17:30-20:30 PDT) - DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers - Jake Braun
DEF CON Talks - CRLF-Powered Desync Attacks: Beheading HTTP streams - Tom "t0xodile" Stacey,Tobia "mastersplinter" Righi
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices - wasabi,Ø1,Tokugero
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Purple Teaming Industrial Control Systems - Arnaud SOULLIE,Alexandrine Torrents
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem - Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques - Abhinav Verma
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Intro to Writing Windows Malware with Rust! - iDigitalFlame,Daniel Bravo
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Building Agentic Reverse Engineering "Skills" - John "clearbluejar" McIntosh
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It - Wesley McGrew
DEF CON Workshops - cont...(14:00-17:59 PDT) - Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites - Nitay Bachrach,Cynthia Ardman
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Thread Carefully -
Embedded Systems Village - cont...(10:00-17:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-17:59 PDT) - Embedded Systems Village CTF -
IoT Village - cont...(10:00-17:59 PDT) - All About UART -
IoT Village - cont...(10:00-17:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-17:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-17:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-17:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-17:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-17:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-17:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(16:30-17:30 PDT) - Weaponization of Cellular Based IoT Technology – Leveraging Smart Devices to Gain a Foothold - Carlota Bindner,Deral Heiland
La Villa Community - cont...(16:30-17:30 PDT) - De la Explotación de Buffer Overflows al C2 Industrial: Infectando y Controlando RTUs con Malware - Fernando Mengali
La Villa Community - (17:30-18:30 PDT) - latinas.exe has entered the chat (ESP - POR) -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-17:59 PDT) - Lonely Hackers Club CTF -
Maker's Village - cont...(10:00-17:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - cont...(16:00-17:45 PDT) - Building Silkscreens and carving stamps - hunny
Middle Easterns & Africans in Cyber Security (MEACS) - (17:30-17:59 PDT) - The Autonomous SOC Blueprint: On-Premise ML & AI to Condense, Consolidate, Contextualize, Correlate & Co-Investigate Attack Chains Hiding in the Noise - Ezz Tahoun
Middle Easterns & Africans in Cyber Security (MEACS) - MEACS Trivia, Games and Networking -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-17:59 PDT) - Mobile Hacking - Informal CTF -
Nix Vegas Community - Lightning Talks and Unconference -
Noob Community - cont...(10:00-17:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-17:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-17:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-17:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-17:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-17:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-17:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
OSINT For Good Community - cont...(10:00-17:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-17:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - OSINT Search Party CTF Prize and Award Announcements. -
OSINT For Good Community - (17:15-17:59 PDT) - OSINT4Good Sticker Swap -
OWASP Foundation - cont...(10:00-17:59 PDT) - BadVR: Signals Everywhere a collaboration with XR Village - Jad Meouchy,Suzanne Borders
OWASP Foundation - cont...(16:00-17:59 PDT) - Practical AI Security Assessments Using OWASP AISVS - Jim Manico
Packet Hacking Village - Ghost Followers: Using AI to Unmask Fake LinkedIn Profiles at Scale - Aiswarya Venkitesh
Policy @ DEF CON - AI Safety Theater: What the RAISE Act Regulates — and What It Does Not - Joshua Marpet
Policy @ DEF CON - The Closing Window: Governing Agentic AI Security in a Post-Mythos World - Taylor Roberts,Mitch Herckis,Katie Trimble-Noble,Razvan Gavrila
Radio Frequency Village - cont...(10:00-17:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(16:30-17:25 PDT) - I'm Not Special, and You Can Too! A journey into RF Antenna Design for Dummies. - Hamspiced
Radio Frequency Village - (17:30-17:55 PDT) - $750 and a Weekend: Passive Direction Finding Across the Spectrum with KrakenSDR - K0YTL
Recon Village - cont...(12:00-17:59 PDT) - TrackTheFugitive Contest -
Recon Village - cont...(15:20-17:50 PDT) - Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform - Lenin Alevski
Recon Village - (17:30-17:59 PDT) - Total Recon: How We Discovered 1000s of open Agents in The Wild - Avishai Efrat,Roey Ben Chaim
Recon Village - CyberKB: When Your AI Copilot Runs the Recon, Crawls the Dark Web, and Maps the Kill Chain - Suriya Prasath S,Chandru J,Muthu Kumar
Recon Village - (17:30-17:59 PDT) - There Is No Internet: Cross-Domain Recon of all 4.3 Billion IPv4s - John McCary
Red Team Village - cont...(16:00-17:59 PDT) - The Quantum Mechanic: Attacking all the clouds - Moses Frost
Red Team Village - cont...(16:00-17:59 PDT) - Evading EDR in ATM - Arnold Jared Morales Yepez
Red Team Village - cont...(16:00-17:59 PDT) - MalSkill: Weaponizing AI Agent Skills for Persistence, Exfiltration, and Lateral Movement - Nur Gucu
Red Team Village - cont...(16:00-17:59 PDT) - Writing Production-Grade Exploits in go-exploit - Landon Rice
Red Team Village - Below the Threshold: Real-World APT Tradecraft for Full-Spectrum Compromise - Jonathan Coradi,Oliveira Junior
Scambait Village - cont...(10:00-17:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-17:59 PDT) - KSCM Scambait Radio -
Social Engineering Community Village - cont...(10:00-17:59 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(16:30-17:59 PDT) - Cold Calls -
Social Engineering Community Village - cont...(15:30-17:30 PDT) - 2027 SECVC Pre-Qualification Round - JC,Snow
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Friends of Bill W -
Social Gatherings/Events - cont...(16:00-17:59 PDT) - Queercon Mixer -
Telecom Village - Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings -
The Diana Initiative - cont...(16:00-17:59 PDT) - The Diana Initiative - Open time -
Voting Village - cont...(10:00-17:59 PDT) - Voting Village Lab -
Voting Village - Election Observation: Watching is not Enough - Douglas W. Jones
Voting Village - (17:30-17:59 PDT) - The Republic is a Team Sport: Technology can Protect Elections, but the People must Protect Democracy - Kendall Spencer

 

Saturday - 18:00 PDT


Return to Index  -  Locations Legend
Contests - EFF Tech Trivia -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
DEF CON Talks - cont...(17:30-20:30 PDT) - DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers - Jake Braun
La Villa Community - cont...(17:30-18:30 PDT) - latinas.exe has entered the chat (ESP - POR) -
Social Gatherings/Events - cont...(09:00-18:59 PDT) - Human Registration Open -
Social Gatherings/Events - 10 years of K-rad (Hackers.Town Party) -
Social Gatherings/Events - cont...(10:00-18:59 PDT) - Music - SomaFM -
Social Gatherings/Events - +61: the Australian Embassy -
Social Gatherings/Events - 2nd Annual Spades Night & Uno Tournament -

 

Saturday - 19:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(18:00-20:59 PDT) - EFF Tech Trivia -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
DEF CON Talks - cont...(17:30-20:30 PDT) - DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers - Jake Braun
Social Gatherings/Events - cont...(18:00-20:59 PDT) - 10 years of K-rad (Hackers.Town Party) -
Social Gatherings/Events - Music - Genre: Dubstep - ZipZapZop
Social Gatherings/Events - cont...(18:00-19:59 PDT) - +61: the Australian Embassy -
Social Gatherings/Events - DCNextGen Party! -
Social Gatherings/Events - cont...(18:00-22:59 PDT) - 2nd Annual Spades Night & Uno Tournament -

 

Saturday - 20:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(18:00-20:59 PDT) - EFF Tech Trivia -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
DEF CON Talks - cont...(17:30-20:30 PDT) - DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers - Jake Braun
Social Gatherings/Events - Hacker Jeopardy -
Social Gatherings/Events - cont...(18:00-20:59 PDT) - 10 years of K-rad (Hackers.Town Party) -
Social Gatherings/Events - Music - Genre: Drum & Bass - RELAY
Social Gatherings/Events - Movie Night -
Social Gatherings/Events - Hacker Karaoke -
Social Gatherings/Events - cont...(19:00-20:59 PDT) - DCNextGen Party! -
Social Gatherings/Events - cont...(18:00-22:59 PDT) - 2nd Annual Spades Night & Uno Tournament -

 

Saturday - 21:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Social Gatherings/Events - cont...(20:00-21:59 PDT) - Hacker Jeopardy -
Social Gatherings/Events - GOTHCON -
Social Gatherings/Events - Music - Genre: Nerdcore - Dual Core
Social Gatherings/Events - Front Man's Fête: An Octopus Game Party (including Octopus Game winners and prizes) -
Social Gatherings/Events - Party Line (Call Center Village Party) -
Social Gatherings/Events - cont...(20:00-23:59 PDT) - Movie Night -
Social Gatherings/Events - cont...(18:00-22:59 PDT) - 2nd Annual Spades Night & Uno Tournament -
Social Gatherings/Events - VETCON 2026 PARTY -
Social Gatherings/Events - Illuminati Party -

 

Saturday - 22:00 PDT


Return to Index  -  Locations Legend
Contests - Feet Feud (Hacker Family Feud) -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Social Gatherings/Events - Kayos Klub -
Social Gatherings/Events - Music - Genre: Drum & Bass - Miss Jackalope
Social Gatherings/Events - cont...(20:00-23:59 PDT) - Movie Night -
Social Gatherings/Events - cont...(18:00-22:59 PDT) - 2nd Annual Spades Night & Uno Tournament -

 

Saturday - 23:00 PDT


Return to Index  -  Locations Legend
Contests - cont...(22:00-23:59 PDT) - Feet Feud (Hacker Family Feud) -
Contests - cont...(10:00-23:59 PDT) - Apex Park (Cloud Village CTF) -
Social Gatherings/Events - Music - Genre: Drum & Bass - Syntax + Luna
Social Gatherings/Events - cont...(20:00-23:59 PDT) - Movie Night -

Talk/Event Descriptions



Contests - Saturday - 10:00-17:59 PDT


Title: ?Cube
Tags: ?Cube | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 109 (?Cube) - Map

Description:

Redefining Boundaries. Enhancing Connectivity. Institutionalizing Control – Aperture Inc. continues to push the limits of innovation and remains committed to providing value to both stakeholders and our “customers.”

Controls are stricter. Telemetry is richer. Oversight has improved. Intelligence has emerged. Aperture has expanded—new industries, new platforms, new technologies quietly embedded into the fabric of our everyday lives. Each integration promises resilience. Every layer introduces complexity. And complexity always creates opportunity…

At the center of it all remains the ?Cube. Its defenses have hardened, its architecture improved, its surface area widened. It’s an ecosystem of physical security, web applications, communications systems, cryptography, and oh so much more.

For those already familiar—welcome back. For those encountering it for the first time, orientation will be … brief. But don’t fear, anyone can join the challenge. You will be entering an environment that demands curiosity across physical security, web applications, communications systems, cryptography, and, of course, the great unknown. Each layer builds on the last. Small oversights become structural weaknesses.

Form a team with range. Specialists matter. Coordination and curiosity matter more. The objective is simple: reach the center. If the core remains uncompromised, the team that advances the deepest into its labyrinth of challenges will be the winner. Advancement will require persistence. Errors and missteps will have consequences. Progress will not be accidental.

Welcome to the ?Cube.

Prerequisites:

A laptop will be highly recommended in order to interact with the technologies. Teams will be required.

Lockpicks, RFID tools (e.g., Proxmark/Flipper), and other "hacking" devices are recommended but not required.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 10:00-10:30 PDT


Title: "Trust Us, It's Secure": Why Internet Voting Isn't
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

For years programmers, computer scientists, and cybersecurity experts have known that returning a voted ballot over the internet is fundamentally insecure. Beginning with the 2004 SERVE report, experts have warned of threats including hacking the voter’s device, phishing, man-in-the-middle attacks, spoofing, and attacks on election officials’ systems. New dangers have since emerged, including ransomware attacks.

Yet, 32 states allow some form of internet voting, primarily for overseas military personnel and civilians, though some states also make it available to voters with disabilities and tribal members living on reservations. (For a full list of states that allow internet voting, who is eligible, and what type is permitted, see Internet Voting).

Given the steady stream of reported hacks of government agencies, major corporations, and other institutions, why do so many well-meaning people continue to believe that internet voting will increase voter participation, while ignoring well documented threats?

I will give a brief overview of the history, some of the key forces, and the roles that language (“don’t call it internet voting”), wishful thinking, and money are playing.

SpeakerBio:  Barbara Simons

An expert on electronic voting, Dr. Barbara Simons has been on the Board of Advisors of the U.S. Election Assistance Commission since was appointed in 2008. She co-authored Broken Ballots: Will Your Vote Count? with Prof. Douglas Jones. She was a member of the National Workshop on Internet Voting that was convened by the National Science Foundation at the request of President Clinton and produced a report on Internet Voting in 2001. She also participated on the Security Peer Review Group for the US Department of Defense’s Internet voting project (SERVE) and co-authored the report that led to the cancellation of SERVE because of security concerns. Simons co-chaired the Association for Computing Machinery (ACM) study of statewide databases of registered voters, she co-authored the League of Women Voters report on election auditing, and she co-authored the July 2015 report of the U.S. Vote Foundation entitled The Future of Voting: End-to-End Verifiable Internet Voting.

Simons was President of ACM, the oldest and largest international educational and scientific society for computing professionals, from 1998 until 2000. She founded ACM’s U.S. Public Policy Committee (now called the U.S. Technology Policy Committee) in 1993 and served for many years as the Chair. She is Board Chair of Verified Voting.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 16:30-16:59 PDT


Title: [Virtual] National Service Panel - CTU,BIC,MCPA
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 16:59 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Join B.I.C. Village for a virtual National Service Panel featuring Capitol Technology University, Blacks in Cybersecurity, and the Military Cyber Professionals Association. This welcoming session will explore national service, mission driven cybersecurity, and the many ways professionals can use their skills to support government, military, academic, and community focused initiatives. Hear from experienced leaders, learn about different career and service pathways, and discover how cybersecurity can create meaningful public impact.

Speakers:Carmeshia Miller,Tiffany Scheurenbrand,Shemeka Chance Jeffrey

SpeakerBio:  Carmeshia Miller, BIC Military Relations & Veterans Program Lead and BWIC Curriculum & Learning Experience Lead

Carmeshia �Meshia� Miller is a cybersecurity leader, educator, and advocate with more than 30 years of experience dedicated to expanding access, confidence, and opportunity for military veterans and Black women entering and advancing in tech. She is a retired U.S. Army Warrant Officer, bringing decades of experience in leadership, operations, and risk management to her work in cybersecurity and workforce development. After transitioning from military service, Meshia built a career at the intersection of cybersecurity education, career readiness, governance, risk, and compliance, and community empowerment. She is known for breaking down complex technical concepts into practical, confidence-building learning experiences, especially for those who may feel intimidated by the field. As a leader within Blacks in Cyber and Black Women in Cyber, Meshia focuses on creating safe, affirming spaces where women can learn hands-on technical skills, gain career clarity, and build professional networks that lead to real opportunities. Her work emphasizes not only technical competence but also self-advocacy, resilience, and strategic career navigation in environments where Black women are often underestimated or overlooked. Meshia�s mission is simple but powerful: To ensure Black women don�t just enter cybersecurity�but thrive, lead, and shape its future.

SpeakerBio:  Tiffany Scheurenbrand, Missile Defense Agency (MDA) ICAM Lead

Tiffany Scheurenbrand (Sure-N-Brand) is a cybersecurity leader, U.S. Army veteran, and doctoral student with more than a decade of experience across military, federal, and defense cyber environments. Her background spans cybersecurity operations, information assurance, risk management, secure communications, identity and access management, PKI, privileged access management, Zero Trust, compliance, enterprise security, and team leadership. Throughout her career, Tiffany has supported mission-focused cyber programs in high-pressure environments, leading teams, solving operational security challenges, strengthening governance, and helping organizations improve their overall cyber posture. Her experience includes working across technical, operational, and leadership roles, giving her a broad perspective on how cybersecurity impacts people, mission execution, policy, and national defense. Tiffany is currently pursuing a PhD in Space Cybersecurity, with research focused on Zero Trust policy for secure space commands across space, ground, and cloud environments. She is passionate about national service, mentorship, representation in cybersecurity, and helping the next generation of cyber professionals understand that there is no single path into the field.

SpeakerBio:  Shemeka Chance Jeffrey, G6 Cyber Chief
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 18:00-19:59 PDT


Title: +61: the Australian Embassy
Tags: Party
When: Saturday, Aug 8, 18:00 - 19:59 PDT
Where: LVCCW Level 2 W212 (Misc Meeting Room) - Map

Description:

Against all odds (and possibly the better judgement of border control), the +61 Australian embassy returns.

If you’re one of the Australians who made it into the US for DEF CON this year, swing by for a bit of hacker summer camp gossip, some socializing, and a live demonstration of what happens when Malört meets Vegemite.

We assume nothing good.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 17:30-17:55 PDT


Title: $750 and a Weekend: Passive Direction Finding Across the Spectrum with KrakenSDR
Tags: Radio Frequency Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Direction finding used to require expensive, specialized hardware. KrakenSDR changed that. For $749, you get a five-channel coherent software-defined radio that — paired with a custom pentagonal antenna array and open-source signal processing software on a Raspberry Pi — performs real-time passive direction of arrival estimation across 24 MHz to 1766 MHz.

This talk is a practitioner's account of building and deploying this system across five field runs in Portland, OR. We cover the physics of coherent direction finding and why a single RTL-SDR can't do it, the hardware build and critical configuration details (including the Pi EEPROM settings that prevent the system from browning out in the field), and the full signal processing pipeline from IQ streams to triangulated fix. We present results from FM broadcast targets used as calibration ground truth, and from a 440 MHz amateur repeater in a dense urban environment where multipath degraded but did not defeat the system.

The barrier to passive RF geolocation is no longer cost. It is knowledge. This talk lowers that barrier and releases the field data, post-processing scripts, and deployment checklist as open source.

SpeakerBio:  K0YTL

Chris is a second-year PhD student at Portland State University where he teaches network and embedded security by day and points antennas at things by night. His current obsession is passive RF geolocation using multi-channel SDR arrays — specifically, building cheap open-source direction-finding infrastructure with KrakenSDR and a fleet of Raspberry Pis that may or may not be malfunctioning at any given moment. He holds an amateur radio license, has strong opinions about noise floors, and is perpetually one firmware update away from a working system. When not chasing signals through Pacific Northwest parks, he can be found explaining to a classroom why their pentest labs are on fire.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: $unL1ght Sh4d0w5
Tags: $unL1ght Sh4d0w5 | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5) - Map

Description:

“$unL1ght Sh4d0w5”: The Nirubi Challenge — Prove Your Agency

Systems shape the world.

Algorithms decide.

Policies enforce.

Machines execute.

Most people live inside those systems.

Hackers change them.

At DEF CON 34, where the theme is Agency, the question isn’t whether systems have vulnerabilities.

The question is who has the power to act on them.

Welcome to “$unL1ght Sh4d0w5: The Nirubi Challenge.”

Instead of hiding the system, we give you the blueprint: - A production-ready Linux cyber-physical system - Known vulnerabilities - A working proof-of-concept exploit - Full system disclosure

No mystery.

No guessing.

Just a cyber-physical system — and the opportunity to exercise your agency over it.

The Nirubi Mandate

Nirubi is an ancient Tamil word meaning “to prove.”

Not with theory.

Not with writeups.

With execution.

You’ve been given the knowledge.

Now prove you have the agency to act on it.

The Challenge

Your objective is simple:

Achieve remote code execution and deploy a malicious payload (e.g., ransomware payload that encrypts a sensitive file, command and control payload that takes over the cyber-physical system etc.).

Two phases.

Part 1 — Sh4d0w5 Recon

Extend the provided exploit chain and deliver a working malicious payload.

You have the vulnerabilities.

Now show us you can use them.

Part 2 — $unL1ght Horizon

If you complete Part 1, the system returns — hardened with proprietary defensive technology designed to disrupt your attack path.

Same objective.

New resistance.

Adapt your exploit and land the payload again.

The Prize

The first contestant to complete both phases wins: $10,000

Bring $unL1ght into the Sh4d0w5.

What Makes This Different

Most contests hide the system. We don’t. You’ll receive: - Full system configuration - Vulnerability details - A working proof-of-concept exploit

No blind recon. No guessing. Just a system, its weaknesses, and your ability to act. Because knowing about vulnerabilities is easy. Exploiting them is agency.

Rules & Eligibility

Additional details will be announced closer to the event.

Participant Prerequisites

Bring your own gear: - Laptop and/or smartphone/tablet - Operating system of your choice (Linux/Windows recommended) - Python - C/C++ compiler - Binary analysis and exploit development tools

Bring whatever tools you trust. Once the challenge begins, the system is in front of you. What happens next is up to your agency.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 18:00-20:59 PDT


Title: 10 years of K-rad (Hackers.Town Party)
Tags: Party | Hackers.town
When: Saturday, Aug 8, 18:00 - 20:59 PDT
Where: LVCCW Level 1 North Lobby - Map

Description:

HACK THE PLANET! Come celebrate 10 years of Hackers.Town doing whatever it is we actually do! We’ve fully embraced this year’s theme of agency, and given these renowned hacker-DJs free rein to do what they do best.

Join us in the North Lobby for epic sets from: Kampf, Syntax976 and Luna, PatAttack, and Skittish and Bus!


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 15:30-17:30 PDT


Title: 2027 SECVC Pre-Qualification Round
Tags: Social Engineering Community Village | Creator Event/Activity
When: Saturday, Aug 8, 15:30 - 17:30 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

Think you have what it takes to compete in the 2027 Social Engineering Community Vishing Competition? This first-come, first-served SECVC Pre-Qual event gives attendees an early opportunity to qualify for next year�s competition. Note teams consist of 1 or 2 memebers. During the lab, each team will be assigned a target company and receive instructions, guidance, and dedicated Q&A time with SEC founders JC and Snow. Teams will conduct OSINT on their assigned company, develop potential pretexts, and prepare a short submission using a link provided before the lab closes. The top five teams will be selected and notified by email before 8:00 PM that evening. Those teams will advance to the live-call qualification round in the village on Sunday, August 9, 2026. Following the live calls, up to all five teams will earn a spot in the 2027 SEC Vishing Competition. Participants should bring a laptop or another device with internet access that can be used to conduct OSINT and submit their materials.

Speakers:JC,Snow

SpeakerBio:  JC, President at Snowfensive

JC is a U.S. Marine Corps veteran, President of Snowfensive, and co-founder of the Social Engineering Community Village at DEF CON. With more than a decade of experience spanning information technology, digital forensics, incident response, penetration testing, and social engineering, he specializes in turning complex security concepts into practical skills people can immediately apply.

At Snowfensive, JC oversees the company's offensive security services, including phishing, vishing, physical social engineering, covert entry assessments, and technical penetration testing across networks, wireless environments, and applications. He has designed and led human-focused security engagements for organizations across a wide range of industries, combining technical tradecraft with a practical understanding of how people, processes, and technology intersect.

SpeakerBio:  Snow
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 18:00-22:59 PDT


Title: 2nd Annual Spades Night & Uno Tournament
Tags: Party | Blacks In Cyber Village | Blacks In Cybersecurity Game Night Extravaganza!
When: Saturday, Aug 8, 18:00 - 22:59 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Get ready for our 2nd Annual Spades & UNO tournaments during Game Night! This year we've uped the anti by expanding the brackets! Whether you're going all-in, calling someone's bluff or running the table in UNO, it's time to see who will earn bragging rights for another year! Hosted by Blacks In Cybersecurity (BIC), this gathering celebrates culture, strategy and the timeless joy of game night. From the unspoken rules of Spades to the quiet intensity of Uno, we are honoring the traditions that bring us together one hand at a time. This is your chance to relax, recharge and throw down with our family and fellow attendees. There will be other games and music for those who wanna just hang out. Come ready to unwind & meet new people!


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Saturday - 16:00-16:40 PDT


Title: 3D Printing: Data, Discretion, and Design
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Saturday, Aug 8, 16:00 - 16:40 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

The history of hacking is tied to both software and hardware. In both cases, losing the ability to fix and adjust the things you own goes against the core of what we do. For software related projects, you can edit a program or use an open source solution, but for hardware we use 3D printing! In this class you'll learn about the origins of 3D printing and how everyday tools you have at home can pair with a machine to make the items you've purchased on your own!

SpeakerBio:  Evan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: 5N4CK3Y
Tags: 5N4CK3Y | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 101 (5n4ck3y) - Map

Description:

AND!XOR builds electronic badges packed with hacker challenges, and we especially enjoy inventing unusual ways for people to earn them.

5n4ck3y is a retro snack vending machine that we’ve rebuilt into a network-connected CTF badge dispenser. Behind the woodgrain and glowing buttons is a hardware hacking project that connects a web-hosted CTF platform to a physical machine capable of vending badges to successful participants. Solve enough challenges and you’ll earn a dispense code. Enter the code into 5n4ck3y and the machine will reward you with a badge—assuming it’s in a good mood.

The challenges span a wide range of disciplines including hardware hacking, reverse engineering, OSINT, RF, network security, phreaking, and cryptography. Participants often learn something new at a DEF CON village, meet other hackers along the way, and then return to apply those skills to the challenges.

Once you earn a badge, the adventure isn’t over. Our badges are built to be explored, modified, and hacked long after they leave the machine.

5n4ck3y exists for one reason: to reward curiosity. Solve the puzzles, learn something new, and the machine might decide you deserve a badge.

Participant Prerequisites

Curiosity, persistence, access to a computer, and the willingness to RT.FM.

Our challenges are intentionally multidisciplinary and are designed to encourage exploration and collaboration. Participants will likely need to investigate hardware, software, networking, and other security topics. Many challenges are easier when working with others, so don’t be afraid to talk to people nearby or compare notes with fellow hackers.

While we won’t spoil what tools are needed this year, participants in past 5n4ck3y challenges have used a wide range of equipment including laptops, reverse engineering tools, SDR, UART adapters, hardware debuggers, soldering tools, and the occasional piece of improvised equipment.

The good news is that DEF CON is one of the best places in the world to find tools, knowledge, and people willing to help. If you don’t have something you need, chances are someone nearby does—or you can find it in a village, vendor area, or by politely asking the hacker sitting next to you.

5n4ck3y strongly encourages teamwork, creative thinking, and responsible experimentation. Snacks are optional, but curiosity is required.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 10:00-10:59 PDT


Title: A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure
Tags: Telecom Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. Understand the 5G SA attack surface from an attacker's perspective
  2. Execute protocol-specific attacks against a live 5G core
  3. Map attack techniques to MITRE FiGHT with defensive context
SpeakerBio:  T -Mobile CTF Team
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 10:00-10:59 PDT


Title: A Droidwork Orange: A Longitudinal Study of Android Security Research
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:
Community Presentation Proposal Title: A Droidwork Orange: A Longitudinal Study of Android Security Research Samuele Doria (University of Padua), Nicholas Miazzo (University of Padova), Tiziano Labruna (Fondazione Bruno Kessler), Eleonora Losiouk (University of Padua) Abstract Android has been the dominant mobile platform for over a decade, but we still lack an understanding of how Android security research has evolved, which problems have received sustained attention, and whether the recent drop in publication volume reflects exhaustion or maturity. This paper presents the first comprehensive longitudinal study of the Android security research ecosystem. We built Ludovico, a curated corpus of 11,691 Android security papers published between 2008 and 2025, complemented by 464 iOS papers and a survey of 86 active researchers. By combining iterative topic modeling with manual validation, analysis of authors’ affiliations and publication venues, and extraction of targeted Android versions, we studied the evolution of topics, contributors, publication venues, and the interplay between platform changes and research priorities. Our results show that the field grew rapidly until a 2016-2018 peak and then contracted, but not because Android security is considered solved: the ecosystem has matured, and advancing the state of the art requires specialized, low-level expertise. We observe a structural transition from App Privacy & Security to Malware Detection, which has dominated the literature since 2017. This is also motivated by the adoption of AI-based techniques: 57.4% of papers focusing on malware
Speakers:Nicholas Miazzo,Eleonora Losiouk

SpeakerBio:  Nicholas Miazzo, University of Padova

yearly output. We further find that iOS research is more focused on digital forensics, revealing how platform openness shapes research trajectories. Finally, 73.26% of surveyed researchers confirm a real-world impact of Android security research, while highlighting platform hardening, limited access to updated datasets, and funding constraints as the main barriers ahead. Brief Biography Nicholas Miazzo is a Ph.D. student in computer science at the University of Padua, where he completed his master's degree in 2024. His research now focuses on Android security, particularly leveraging Large Language Model agents to analyze decompiled Android applications and perform taint analysis to automatically detect potential data leakage. He is also a co-author of VirtualPatch [1], a system that uses Android virtualization to deploy security patches independently of device vendors. He is currently contributing to its

SpeakerBio:  Eleonora Losiouk, University of Padua
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 15:00-15:30 PDT


Title: A Framework for Evaluating AI-Enabled Social Engineering
Tags: Social Engineering Community Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:30 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Large language models (LLMs) can now produce persuasive, personalized phishing content at scale. Yet there is no systematic, reusable benchmark for measuring how this offensive capability varies across models or relates to general capability. We introduce ScamBench: a benchmark and evaluation pipeline for LLM-generated spear phishing. ScamBench contributes (i) a public dataset of over 16,000 personalized phishing emails generated by 20 frontier and open-weight models against 150 synthetic target profiles spanning diverse occupations, life stages, and levels of technical sophistication; (ii) a methodology in which simulated recipients and real human users predict behavioral responses to each email; and (iii) a public leaderboard ranking models by how often their generated emails persuade the target to click a link. Across the 20 models, Claude Opus 4.5 achieves the highest click-through rate at 50.3\%, while even the weakest model elicits clicks at 29.8\%. Together, our findings establish AI-enabled social engineering as an empirically measurable capability that scales with frontier models, with ScamBench providing a reusable benchmark for tracking it as models continue to advance.

SpeakerBio:  Fred Heiding, Researcher at UC Berkeley's Center for Long-Term Cybersecurity

Fred Heiding is the executive director of Menlo Park Intelligence and a researcher at UC Berkeley's Center for Long-Term Cybersecurity. He was previously a doctoral and postdoctoral researcher at the Harvard School of Engineering and Applied Sciences and the Harvard Kennedy School, working with Bruce Schneier and Eric Rosenbach. He is a member of the World Economic Forum's Centre for Cybersecurity and the Geneva Centre for Security Policy, and serves on the committee of the Harvard and MIT Technology and National Security Conference. He has taught several AI and cybersecurity classes at Harvard, regularly briefs the U.S. Congress on AI-powered cyber threats, and advises foreign governments on national cyber risks. His work has been featured at leading conferences, journals, and media outlets, including The Economist, Reuters, TIME, and Foreign Affairs. Fred has assisted in the discovery of more than 45 critical computer vulnerabilities (CVEs), and he previously made headlines for hacking the King of Sweden and the European Commissioner.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 12:55-14:05 PDT


Title: A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you'll crack your first binary in the first ten minutes.
Tags: Malware Village | Creator Workshop
When: Saturday, Aug 8, 12:55 - 14:05 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map

Description:

DLL sideloading is one of the most common tricks in modern malware — a trusted program is quietly made to load an attacker's code instead of the library it expected. In this hands-on workshop you'll take one apart in IDA and learn to read what a binary actually does versus what it wants you to think it does. You'll start by cracking a small serial-check program to get comfortable moving around IDA, then triage a suspicious "updater," and finally dissect a sideloading library that hides a single real payload among convincing decoys — fake C2 URLs, unused "scary" API calls, and dead-end code planted to waste an analyst's time. The takeaway skill is the one that matters most in real analysis: follow what executes, not what looks dangerous. Every sample is completely deweaponized — the worst any of them does is pop a message box — so you can poke at everything freely. You'll leave with the samples, a written walk-through, and an IDA command cheat-sheet to keep practicing. Level: Beginner-friendly; no reverse-engineering experience needed. Bring: A laptop with IDA (IDA Free will work, you can download here) You'll leave able to: navigate IDA, read imports/exports/strings, recognise a DLL sideload and its proxy/forwarder disguise, and see through common anti-analysis decoys

SpeakerBio:  David Rushmer, Tech Evangelist, Hex-Rays
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 15:20-15:59 PDT


Title: A New Hope for SSRF: Exploiting Credential Relay from APIM to AI Foundry
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:20 - 15:59 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

We found the same root cause — credentials and destinations resolving independently — across six Azure services spanning AI platform, developer tooling, Kubernetes infrastructure, and traditional enterprise services. User-controlled input reaches an outbound HTTP request carrying Managed Identity tokens, HMAC secrets, or OAuth credentials, and nothing validates where the request goes.

The affected services include Azure AI Foundry (code interpreter and OpenAPI tool), Azure AI Speech, Azure MCP Servers, AKS MCP, and Azure API Management. The impact ranges from stealing live MI tokens for any Azure audience, to dumping production Key Vault URIs and never-expiring write SAS tokens from Microsoft's own backend, to root RCE on Kubernetes nodes through a readonly tool. One finding has CVE-2026-26118 assigned; the rest are reported to MSRC and pending.

We built attack chains that combine these findings: Foundry MI theft into full tenant reconnaissance, Speech SSRF into persistent backend access via never-expiring SAS, MCP credential relay delivered remotely through prompt injection with no network access to the target, and AKS command injection into cluster-wide lateral movement via Azure's AKS MCP. The oldest service we found this in — APIM — has been in production for over a decade. The newest — AI Foundry — shipped last year. Same pattern.

The talk includes three live demos, a credential relay taxonomy, and a testing methodology the audience can apply on their next Azure engagement. All findings reported to MSRC before submission.

Speakers:Marios Gyftos,Chrysostomos Manousis

SpeakerBio:  Marios Gyftos

Marios Gyftos is a Senior Penetration Tester specializing in cloud security across AWS, Azure, and GCP since 2017. He previously presented at DEF CON 33 Cloud Village on Azure service principal exploitation, BSides Athens 2024, and BSidesChicago 2023 on DevOps attack chains. He is the creator of Azure AppHunter, an open-source tool for scanning Graph API permission misconfigurations. He has reported multiple vulnerabilities to MSRC across Azure AI Foundry, Azure Speech, AKS, Azure MCP, APIM, and Entra ID. Solo speaker — all research, exploitation, and vendor reporting was conducted independently.

SpeakerBio:  Chrysostomos Manousis

Chrysostomos Manousis is a cybersecurity professional and Senior Penetration Tester at Mind The Hack, specializing in penetration testing, red teaming, and the delivery of cybersecurity and information technology services. He holds an MEng in Electrical and Computer Engineering, with a focus on software and hardware engineering. His background spans offensive security across web, cloud, and enterprise environments, and he holds multiple industry-recognized certifications.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 15:00-15:45 PDT


Title: AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This!
Tags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | SecOps | DEF CON Demo Labs
When: Saturday, Aug 8, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

AC Scanner is a tool to help providers of all kinds ensure their services can resist post-quantum cryptographic attacks including Harvest Now Decrypt Later (HNDL). The scanner is an open-source pipeline that automates full cryptographic surface discovery across TLS endpoints and SSH services, assessing every asset against NIST post-quantum standards and generating a structured Cryptographic Bill of Materials (CBOM). In a single command (sh scan.sh example.com) it runs subdomain enumeration, DNS resolution, TLS handshake analysis via OpenSSL, SSH auditing via ssh-audit, quantum vulnerability scoring, and CBOM output in JSONL/JSON/Markdown, ready to upload to an interactive dashboard. With NIST finalizing ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) in 2024, and NIST IR 8547 mandating deprecation of quantum-vulnerable algorithms by 2030, AC Scanner gives blue teams a fast, evidence-grade path from cryptographic discovery to compliance reporting.

Speakers:Anurag Swarnim Yadav,Joseph Wilson

SpeakerBio:  Anurag Swarnim Yadav

Anurag Swarnim Yadav is Co-Founder and CTO of QubitAC, a company helping organizations with cryptographic discovery, post-quantum cryptography readiness assessment, migration framework development, and compliance readiness. He holds a PhD from the University of Florida, where his research examined how data quality impacts ML-based vulnerability detection systems and explored automated program repair for security flaws. He developed AC Scanner, a free open-source ACDI tool helping organizations discover, inventory, and prioritize their quantum-vulnerable cryptographic infrastructure, and has spoken at BSides security conferences educating practitioners on PQC adoption and the steps organizations need to take before the 2030 deadline.

SpeakerBio:  Joseph Wilson

Joseph N. Wilson is a co-founder of QubitAC and an emeritus faculty member at the University of Florida who received his PhD in Computer Science from the University of Virginia. During his 41 year academic career, he carried out a wide variety of research projects and authored over 150 publications concerning topics including cybersecurity, machine learning, landmine detection and remediation, and computer vision. In addition to his academic work, Dr. Wilson has been a GIAC certified network and web application penetration tester as well as a malware and forensic analyst. His current work is aimed at helping organizations and people improve both their computational and communications security and privacy. He received the General Ronald W. Yates Award for Excellence in Technology Transfer for work leading to successful landmine and IED detection systems employed by US military support forces in Afghanistan.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Saturday - 13:00-13:59 PDT


Title: Ace/Aro Meetup
Tags: Queercon Community | Creator Event/Activity
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 13:00-13:45 PDT


Title: AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory
Tags: DEF CON Demo Labs | Advanced | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

Every pentest, same story - BloodHound says no path to DA, client celebrates, meanwhile a 2019 service account has AddAllowedToAct on a production DC that nobody remembers. AD-Necromancer finds what humans forget. Give it a username, password, and domain — it bootstraps EDR evasion (ETW patching, DLL unhooking, Halos Gate syscalls), collects AD data over ADWS instead of LDAP, encrypts with AES-256-GCM, and exfils to C2 with zero artifacts. One command, credentials to findings. It feeds tokenized BloodHound data to an LLM for semantic reasoning - forgotten RBCD, ghost cross-forest delegations, orphaned admin accounts no compliance checklist catches. Privacy Cloak ensures real names never leave the box. Open source, MIT licensed. Come dig up what your tools missed.

Speakers:Akbar "0xsensei" Abdullayev,0xHera

SpeakerBio:  Akbar "0xsensei" Abdullayev

Offensive security professional with 5+ years of experience in Active Directory and cloud security, specializing in red teaming and enterprise attack chains.

SpeakerBio:  0xHera

I am a freelance Offensive Tool Developer and Security Enthusiast building practical tools and sharing research with the community to help others better understand attack paths, real-world offensive techniques, and defensive improvements.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Advanced Cloud Incident Response in Azure and Microsoft 365
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W230 (Workshops) - Map

Description:
SpeakerBio:  Korstiaan Stam
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Advanced Cloud Incident Response in Azure and Microsoft 365
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W230 (Workshops) - Map

Description:
SpeakerBio:  Korstiaan Stam
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 11:10-11:20 PDT


Title: Adversary Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 11:10 - 11:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Adversary Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Adversary Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:
Jump into the AERIE Cyber Range to experience a number of challenges:

• PCD (Portable Cockpit Demonstrator): Attempt an RNAV approach in a simulated general aviation flight deck to your cleared runway in instrument conditions. • CCD (Cockpit Cyber Demonstrator): Fly a set of flight challenges in a simulated narrow-body airliner flight deck while managing cyber effects in the aircraft. • Virtual Tower and TRACON: Use the approach control position and an out-the-window tower view to coordinate with the PCD and CCD to help resolve the cyber scenarios running at each. • Horizon: Take the mission-controller seat for a virtual CubeSat remote-sensing mission. Run an imaging pass in the same world, at the same time, as the scenarios at the other stations. • AirVE: Watch the aircraft cyber range provide the aircraft-network model and the injected attacks behind the cyber effects the crew is managing at the cockpit stations. • OrbitVE: Watch the orbital cyber range provide satellite-constellation modeling behind the scenarios at every other station.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 12:00-12:45 PDT


Title: AgentBreaker: A blind spot detector for your coding agents
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Coding agents have the capability to write and ship production code with little human review, which can lead to large-scale security threats. At Corridor, we believe in securing code generation at the source: by augmenting coding agents with the necessary security tooling.

While evaluating our product, we quickly realized that there was no principled way to measure whether a given agent harness actually performs well on the axes we care about (like security). Static benchmarks go stale, get contaminated, and rarely capture the multi-step behavior of an autonomous agent.

To address this, we introduce AgentBreaker, an open-source framework that extends the automated benchmark construction tool AutoBencher, taking it from evaluating single LLM calls to full coding-agent harnesses. We instantiated the framework on our task of secure code generation and show that it reliably surfaces actionable, agent harness-specific weaknesses.

We release AgentBreaker and its methodology so you, too, can evaluate agent harnesses on the axes that matter to you.

Speakers:Aditi Narasimhan,Farzaan Kaiyom

SpeakerBio:  Aditi Narasimhan

Aditi Narasimhan is the founding AI research engineer at Corridor, where she works to improve the security of agentic code generation tools. Previously, she was at Carnegie Mellon, where her research focused on AI ethics, pragmatic theory, and tech ethics pedagogy.

SpeakerBio:  Farzaan Kaiyom

Farzaan has built AI products at startups from the pre-seed stage through Series C, wearing hats as a founder and ML Engineer. He holds a BS/MS in Computer Science from Stanford where he focused on AI safety. While at Stanford CRFM, he worked on HELM, which won the Stanford Open Source Software Prize, and presented research at ICLR.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 12:00-12:59 PDT


Title: Agentic AI Supply chain Vulnerability lab
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

AI agents are no longer simple chatbots they autonomously execute code, call external APIs, and make decisions across complex workflows. But what happens when the tools they trust are compromised?

This hands-on workshop explores ASI04: Supply Chain Vulnerabilities from the OWASP Top 10 for Agentic Applications (2026). Participants will attack a deliberately vulnerable AI agent system to understand how adversaries exploit the trust agents place in their dependencies.

Through 10 progressive challenges, attendees will be:

-Install typosquatted packages that exfiltrate secrets on import

-Exploit a trojanized MCP (Model Context Protocol) server masquerading as legitimate tooling

-Execute dependency confusion attacks against "internal" packages

-Discover hidden prompt injections buried in tool descriptions

-Poison RAG knowledge bases to manipulate agent behavior

Each attack demonstrates a real-world vector currently affecting production AI systems. Participants will observe exfiltrated data in real-time on an attacker dashboard, making abstract threats tangible.

Key Takeaways:

Hands-on experience exploiting AI supply chain vulnerabilities

Understanding of OWASP's agentic AI threat landscape

Practical detection and mitigation strategies

Portable lab environment for continued learning

No prior AI/ML security experience required. Participants leave with the complete lab to continue practicing.

Speakers:Aamiruddin Syed,N A

SpeakerBio:  Aamiruddin Syed

Aamiruddin Syed is a Cybersecurity Professional with over a decade of experience specializing in DevSecOps, Shift-Left Security, Cloud Security, and Internal Penetration Testing. He is the OWASP Agentic AI Supply Chain Project Co-Lead and active contributor to the CSA Agentic AI initiative.

He authored Supply Chain Software Security – AI, IoT, Application Security (Apress/Springer) and has deep expertise in automating security in CI/CD pipelines, infrastructure as code, and cloud hardening. He routinely conducts internal security assessments of critical systems and is known for bridging the gap between security and engineering teams to embed security directly into products.

As recognized advocate for secure development, he is a frequent speaker , delivered workshops and chair sessions at leading industry conferences including RSA Conference, DEFCON, and Black Hat.

--

Author:

  1. Fault Detection in Microservice Architectures: Integrating Software Fault Prediction with DevSecOps
  2. Supply Chain Software Security: AI, IoT, and Application Security
SpeakerBio:  N A

na


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Agentic AppSec: Harnessing LLMs
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W204 (Payment Village) - Map

Description:
Speakers:Seth Law,Ken Johnson

SpeakerBio:  Seth Law
No BIO available
SpeakerBio:  Ken Johnson
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Agentic AppSec: Harnessing LLMs
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W204 (Payment Village) - Map

Description:
Speakers:Seth Law,Ken Johnson

SpeakerBio:  Seth Law
No BIO available
SpeakerBio:  Ken Johnson
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 14:00-15:59 PDT


Title: Agents & Exploits: Hacking OWASP VWAD
Tags: OWASP Foundation | Creator Workshop
When: Saturday, Aug 8, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Large language models have rapidly evolved from chat interfaces into autonomous agents capable of interacting with real-world systems. In this hands-on workshop, participants will build an AI-powered security agent from the ground up and learn the core principles behind agentic penetration testing using intentionally vulnerable OWASP applications.

Rather than simply prompting an LLM, attendees will explore how to equip an agent with practical capabilities—including shell access, browser access, and orchestration to discover, exploit, and document vulnerabilities in an OWASP vulnerable web application (VWAD). Along the way, we'll discuss the architecture of effective security agents, tool integration, memory, and safe execution practices.

The workshop also introduces an iterative evaluation workflow. Participants will analyze vulnerabilities the agent failed to identify, compare results against known findings, and use those gaps to refine prompts, tool selection, workflows, and evaluation criteria. This iterative approach demonstrates how modern AI security agents can continuously improve their effectiveness through systematic testing and feedback rather than relying on a single execution.

By the end of the session, attendees will have built a functional AI security agent, understand the fundamentals of agent tooling and orchestration, and leave with practical techniques for evaluating and improving AI-assisted security testing on OWASP vulnerable applications.

SpeakerBio:  Philippe "pilvar" Dourassov, AI Pentest Lead at Aikido Security

Philippe Dourassov is a Swiss ethical hacker and AI security researcher. He represented Switzerland at the European Cybersecurity Challenge and later joined Team Europe at the International Cybersecurity Challenge. In 2024, he won the Gold Medal in Cyber Security at WorldSkills.

He later worked as an independent bug hunter and security auditor at Zellic, assessing complex web applications. Philippe then co-founded Haicker, an AI-driven automated pentesting platform, which was acquired by Aikido Security. He now serves as AI Pentest Lead, building the next generation of autonomous security testing.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Saturday - 15:00-15:59 PDT


Title: Agents of Chaos: A Field Guide to How Agentic AI Gets Owned, and What Trust Nothing Looks Like in Practice
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

Your agent has more ways to get owned than you think, and most of them do not look like an attack. Give an AI agent tools, memory, and the ability to install things it found on the internet, and you have built an attack surface nobody has a real security model for yet. This talk maps the whole thing: every place an agentic system can be turned against its user, from the instructions it reads to the marketplaces it trusts, laid out as one picture instead of a pile of scary headlines. Then we get to the uncomfortable part, which is what defending it actually takes. You will leave knowing exactly where the bodies are buried, whether you build agents or defend them.

SpeakerBio:  Amber Bennoui
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Saturday - 12:00-12:30 PDT


Title: AI and You: Staying Safe in the AI Era
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Saturday, Aug 8, 12:00 - 12:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Wondering how hacking with AI takes place? Join us to find out along with tips on staying safe with some fun and laughs along the way! No prereqs necessary, just curiosity!

SpeakerBio:  Zoe Reid+Echo419
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Saturday - 10:00-10:59 PDT


Title: AI for Defenders 101
Tags: Blue Team Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:
Speakers:Anirudh Pratap Singh,Neha Gautam,Omenscan ~

SpeakerBio:  Anirudh Pratap Singh

Anirudh Pratap Singh works in IT security and support, with hands-on experience across cybersecurity operations, infrastructure, cloud systems, and user support. He holds a master’s degree in cybersecurity and is CompTIA Security+ certified. His main interests are blue team operations, SOC workflows, threat detection, and practical ways defenders can use AI in their day-to-day work. He enjoys solving real-world technical problems, building his skills through hands-on labs, and sharing what he learns with others in the security community.

SpeakerBio:  Neha Gautam

Neha Gautam is a Product Manager at Microsoft Security and a Carnegie Mellon graduate specializing in the intersection of Identity and AI. From scaling platforms at Walmart to securing agentic AI at Microsoft, Neha’s mission is to translate complex security hurdles into seamless product experiences. She is a passionate mentor for women in tech and a frequent volunteer for WiCyS and Defcon Blue Team Village. Neha believes that the future of computing must be built by diverse perspectives—a philosophy she champions whether she's designing enterprise governance or coaching early-career professionals.

SpeakerBio:  Omenscan ~

Some people write books to document and share what they learn. I write software. @Blueteamvillage Director. I do not speak for my employer, their clients, or customers


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 15:00-16:59 PDT


Title: AI Hacking for Noobs
Tags: Noob Community | Creator Workshop
When: Saturday, Aug 8, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

AI went from a tech toy to critical enterprise infrastructure practically overnight, and the security world is scrambling to keep up. This hands-on session completely bypasses the complex academic math to show you exactly how attackers target, exploit, and manipulate AI systems in the real world. Led by Jason Haddix and the Arcanum team, this workshop is a crash course in AI security basics. You'll get your hands dirty with prompt injection, break open AI systems, and dive into LLM shenanigans to understand firsthand how the modern AI attack surface is exploited.

Speakers:Jason "jhaddix" Haddix,Arcanum Information Security Team

SpeakerBio:  Jason "jhaddix" Haddix, CEO and "Hacker in Charge" at Arcanum Information Security

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

SpeakerBio:  Arcanum Information Security Team
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 13:00-14:59 PDT


Title: AI Pentesting Trivia Showdown
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map

Description:

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

Speakers:Andy Dennis,Bill Reyor

SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  Bill Reyor
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 15:00-16:59 PDT


Title: AI Pentesting Trivia Showdown
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map

Description:

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

Speakers:Andy Dennis,William Reyor

SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  William Reyor

Bill Reyor is a Lead Solutions Architect at XBOW, where he helps organizations evaluate and adopt autonomous offensive security testing to find exploitable application-layer vulnerabilities at scale. He has over 15 years of security experience spanning penetration testing, incident response, DevSecOps, application security leadership, and security program design, and is a co-author of O’Reilly’s Defensive Security Handbook.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 15:00-15:45 PDT


Title: AI Pipeline for N-days Weaponization
Tags: AI | DEF CON Demo Labs | Intermediate | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Most agentic exploit pipelines stall when there's no public PoC,they search, find nothing, and spin. This talk demos a multi-agent system that exploits n-days from scratch in under an hour, even with zero public exploit code available. Given only a CVE ID, the pipeline autonomously: fetches vulnerability details and the upstream fix commit; spins up a pinned Docker lab running the exact vulnerable version; diffs the patch to identify the exploitable code path; generates vulnerability-class-specific attack guidance (not a generic checklist); and runs iterative exploit + validation loops until RCE is confirmed. Demonstrated live against four CVSS 9.8–10.0 vulnerabilities Apache OpenMeetings deserialization, n8n unauthenticated RCE, Langflow exec() injection, and Spring AI SpEL injection, with working exploits produced in minutes. Every run also outputs a containerized lab and defense report, making it equally useful for detection engineering and patch validation.

Speakers:Andrea Brosio,Arun Nair

SpeakerBio:  Andrea Brosio

Andrea Brosio is a Security Researcher and Senior Content Engineer at TryHackMe, specializing in red teaming, malware development, and offensive security. With prior experience as a Bug Hunter and Red Team Operator he combines real-world adversarial expertise with a passion for creating engaging cybersecurity training.

SpeakerBio:  Arun Nair

Arun Nair is a Security Engineer at Google and founder of Ryvane Academy, specializing in AI Security, malware development, defense evasion, and adversary simulation. He holds several respected certifications, including OSCP, CRTP, CRTL, CodeMachine Malware Techniques, and HackSys Windows Kernel Exploitation. Over the years, Arun has worked with leading organizations such as JP Morgan, and EY, focusing on offensive security and red teaming engagements. Outside of his professional work, he is an active contributor to the cybersecurity community, from designing Capture the Flag (CTF) challenges to delivering talks and workshops at events like DEFCON Red Team Village, HeapCon, MCTTP, BSides Transylvania, HackSpaceCon, RingZer0, c0c0n, and various local meetups. When he’s not on engagements or speaking at conferences, Arun shares his research and insights through his blog at dazzyddos.github.io


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 17:00-17:30 PDT


Title: AI Safety Theater: What the RAISE Act Regulates — and What It Does Not
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

New York's RAISE Act is among the most significant state AI safety laws in the country. Signed December 19, 2025, it imposes transparency requirements, safety plans, 72-hour incident reporting, and annual audits on frontier AI developers. It took effect 8 days after a presidential executive order authorizing the DOJ to challenge state AI laws. This talk applies the security researcher's methodology: map the surface, find the gaps, assess whether compliance cost is proportionate to actual risk reduction. The structural gaps are specific. The $500M revenue threshold excludes the most aggressive AI capability development — well-capitalized but pre-revenue. The 10²⁶ FLOPs definition may not capture dangerous fine-tuned derivatives of frontier models. The catastrophic harm threshold requires 100+ deaths before reporting obligations attach — the alarm fires after the building has already burned. And the law requires transparency, not prohibition: a fully compliant developer can keep operating a system causing significant sub-catastrophic harm. 12 or more states are expected to model AI legislation on New York and California in 2026. If the security community does not engage critically with what this law actually does, those copies will inherit its gaps.

SpeakerBio:  Joshua Marpet, Finite State

Joshua Marpet is Senior Product Security Consultant at Finite State, co-host of Paul's Security Weekly and Security Weekly News, and a CMMC co-author. He holds membership on the IEEE/UL 2933 and SPDX standards committees and serves on the boards of BSidesDE, Skytalks, and the Value Chain Risk Institute. A former police officer, firefighter, and Federal Reserve Bank of Philadelphia security analyst, he works at the intersection of security standards, policy, and operational practice.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: AI SecureOps: Attacking & Defending AI Applications & Agents
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W228 (Workshops) - Map

Description:
SpeakerBio:  Abhinav Singh
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: AI SecureOps: Attacking & Defending AI Applications & Agents
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W228 (Workshops) - Map

Description:
SpeakerBio:  Abhinav Singh
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Saturday - 14:30-15:30 PDT


Title: AI Security: Hype, Hacks, and the Future of Defense
Tags: Blue Team Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 15:30 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

It starts with a simple prompt.

An AI assistant writes production code in seconds. A phishing email becomes nearly indistinguishable from a legitimate one. A security analyst uses an AI copilot to investigate hundreds of alerts—while an attacker uses the same technology to automate reconnaissance, create malware, and scale attacks.

Welcome to the new reality of cybersecurity.

AI is changing how we build, defend, attack, and trust technology. As organizations rapidly deploy AI applications and autonomous agents, defenders face two urgent questions: How can we use AI to defend better, and how do we secure AI itself?

Join AI and cybersecurity practitioners for an honest discussion that separates hype from reality. Through real-world stories and practical insights, we’ll explore how attackers are using AI, how defenders are responding, what it means to secure AI systems, and where the industry is headed next.

Whether you’re a seasoned blue teamer, security leader, AI enthusiast, or new to cybersecurity, you’ll leave with a clearer view of today’s AI security landscape—and what tomorrow’s defenders need to know.

The future of cybersecurity is already here. Are you ready?

Speakers:Karan Dwivedi,Thomas Roccia,Todd Fletcher

SpeakerBio:  Karan Dwivedi

Karan Dwivedi is a recognized cybersecurity expert. Currently, he serves as a security engineering manager at Google. Karan has led large-scale security projects at Google and Yahoo in the US for products like Google Search, Google Assistant, Yahoo Mail, Yahoo Finance, Flickr, etc, to safeguard over a billion users. At Yahoo, he was part of the security team responding to the world’s largest data breach. He is the author of the book “Kickstart your security engineering career” which is a definitive guide for anyone looking to start a career in security engineering. Karan contributed to the latest internet standard for scoring vulnerabilities, the Common Vulnerability Scoring System (CVSS 4.0). He is featured in major media like Hakin9 Media Magazine, Forensic Focus News, etc. He has delivered talks at national and international conferences like Tech Ex North America, Tech Summit SF, BSides Las Vegas, National Cyber Summit, etc, to influence private and public sectors. Karan was featured as a subject matter expert in the Google Cybersecurity Certificate program launched in May 2023 on Coursera, which had an enrollment of over 41000 students in a few weeks. Furthermore, Karan has served as an advisor to startups, an editorial board member in international security journals, and judged global competitions. He holds a master’s degree in Information Security from Carnegie Mellon University, USA. His portfolio can be found at https://karand.me

SpeakerBio:  Thomas Roccia

Thomas Roccia is the Founder and Threat Researcher at SecurityBreak, a company dedicated to AI Threat Intelligence and AI security. With more than 15 years of experience in cybersecurity, he has investigated major cyberattacks, led threat research at Microsoft and McAfee, collaborated with law enforcement, and helped organizations understand and respond to emerging threats.

Speaker / Contributor: This individual participates in SANS events, presentations, written content, or other community resources as an external contributor. They are not a SANS employee, instructor, or affiliate.

Since 2022, Thomas has focused on AI Threat Intelligence, researching how attackers target AI systems and how defenders can secure the growing AI ecosystem. He is recognized as one of the early pioneers in applying generative AI to cyber threat intelligence through practical research, open-source projects, and industry education.

Thomas is the creator of several widely used open-source initiatives, including the Unprotect Project and NOVA, one of the first detection-rule frameworks for prompt pattern matching and AI security monitoring. NOVA won the SANS AI Cybersecurity Hackathon in 2025, and Thomas received the SANS Difference Makers Award (DMA) the same year for his contributions to the cybersecurity community. He is also the author of the bestselling book Visual Threat Intelligence: An Illustrated Guide for Threat Researchers, recipient of the Bronze Foreword INDIES Award in the Science & Technology category.

A regular speaker at leading security conferences, including BlackHat, DEFCON, BSides, and SANS events, Thomas teaches AI Threat Intelligence to security professionals around the world, to help defenders apply AI to real-world investigations while understanding the risks attackers pose to the AI ecosystem.

Through SecurityBreak, Thomas develops research, intelligence, and products that help organizations monitor, detect, and defend against attacks targeting AI models, agents, tools, and the broader AI ecosystem.

SpeakerBio:  Todd Fletcher

Todd Fletcher (@kobaltfox) has spent 25 years on the defense side, running IT and security for public government, wiring up SIEM and SOAR pipelines, and building security programs that survive contact with a real budget. He works at CrowdStrike as an AI Services Technical Lead in Strategic Advisory Services, where a lot of his job is separating what AI actually does for a SOC from what the slide deck claims it does.

He is also a PhD candidate in cyberpsychology at Birmingham City University (UK), studying the people doing the defending: what drives them, what burns them down, and why "humans are the weakest link" has always been a lazy answer. He writes at kobaltfox.com and toddmfletcher.com which starts from the position that defender mental health is a security outcome, not a wellness perk.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: AI Village - Hal CTF
Tags: AI Village | HALctf (AI Village CTF) | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Get ready for the next evolution of competitive hacking at DEFCON 34! The AI Village is thrilled to introduce HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF is designed around how far you can stretch small local models that almost everyone can run. The first place prize is a DGX Spark so that you can continue your local hacking agent journey at home.

In this high-stakes arena, participants do not interact with targets directly. Instead, you will design and deploy autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, we’re asking for full containers that you can load up with all the tools you need to succeed.

To make it easy we’re hosting everything, from the targets to your agents to the models. We have a mix of old and new, and you get more points if you use smaller models. Runs are quick and show you all of the logs and points so you can improve the agent over the course of the con.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: AI Village Plays Pokemon: DEFCON Edition
Tags: AI Village | AI Village Plays Pokemon: DEF CON Edition | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Agent harnesses and tooling have quickly become the AI buzzwords of 2026, but what do these even mean, and why should you consider building them? We’re showing off how custom tooling can empower local models in the most accessible way possible: playing Pokémon. Join us in this fun, novice-friendly demo where we show how to build tooling for local models, and walk through what you should and shouldn’t consider turning into tools. All the models and tools are open source, so feel free to use them to make your own agents to play our emulations of Pokémon Fire Red and Leaf Green.

SpeakerBio:  Nick Ashworth, Maker at AI Village

Nick is a Hacker and Engineer with almost 15 years of experience hacking everything from power grids to satellites for the DoD. He’s presented and made demos for Aerospace, Car Hacking, ICS, and the AI Village for the past seven years. He currently helps lead the AI Village.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 12:40-12:50 PDT


Title: AI Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 12:40 - 12:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting AI Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to AI Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 10:00-17:59 PDT


Title: AI Village: Village Open
Tags: AI Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

We’re bringing AI Village back to focus on what actually matters: practical, no-bullshit AI security. LLMs are an amazing technology, but they’re not magic. We are stripping away the industry hype and focusing on hands-on skills, whether you are building your first exploit or leading an AI red team.

Here is what you can expect this year:

Drop-In Workshops: Walk up, grab a seat, and learn. We have drop in hands on mini-workshops on a bunch of topics. These include basic AI topics like how LLMs actually work, and how to build agents from scratch. For red teamers we have ones ranging from prompt injection to manipulating malware detection models. This is all running locally on a cluster we’re bringing to DEF CON.

HalCTF: Our main competition this year will teach you how to write and fine-tune your own pentesting agent using open-source models. To handle the massive compute load, we're safely detonating these agents on GCP, giving each participant a dedicated GPU for their models.

Other Agent Shenanigans: The field moves fast and there’s going to be something new by defcon. We’re bringing a lot of compute to host things and we’ll have some surprises in the space.

Whether you want to hear top-tier research from the people actually breaking these models or you just want to sit down and write an autonomous pentesting agent, we have the hardware and the labs ready for you.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 14:00-15:59 PDT


Title: AIMARU C2: The New Era of LotL (MCP AI-Driven C2)
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:
AImaru C2 is the evolution of a concept sparked by an unsettling question: What happens when an attacker can execute advanced Living off the Land (LotL) attacks without being an expert? While traditional LotL requires a specialist to navigate complex environments, AImaru C2 changes the game. Evolving from a PoC into a sophisticated Red Team framework, it automates expert-level tradecraft by subverting Anthropic’s Model Context Protocol (MCP). By weaponizing MCP clients, it transforms a standard context protocol into a functional, autonomous multi-level RAT that natively "speaks" PowerShell.

AImaru C2 was born out of a critical necessity to ground cybersecurity in reality. While the industry often distracts itself with over-engineered narratives and hype-driven threats that ignore actual ecosystem data, a far more pragmatic danger has been hiding in plain sight. This framework addresses the unsettling evolution of the "Expert Bottleneck": What happens when the sophisticated LotL tactics, once reserved for elite nation-state actors, are democratized through automation? Named after the mythical serpent that glides unseen between the underworld and the land of the living, AImaru C2 represents the shift from manual expertise to autonomous execution. It is no longer just a proof of concept; it is a full-scale Red Team framework designed to expose how easily an unskilled attacker can now weaponize authorized system protocols to orchestrate advanced, data-driven breaches that traditional defenses simply aren't looking for.

To understand its impact, context is key. For years, LotL attacks have been the dominant tactic in ransomware campaigns. Instead of deploying traditional malware, threat actors abuse legitimate OS tools—such as PowerShell, WMI, or Certutil—to operate under the radar. In 2025, 82% of successful breaches were fileless or malwareless, with PowerShell ranking as the second most utilized TTP by groups like Black Basta, Royal, and LockBit.

This robust framework moves beyond experimental concepts, consolidating itself as a production-ready offensive platform. AImaru C2 is engineered with a modular architecture that prioritizes cryptographic integrity, operational security, and intelligent automation.

Core Framework Capabilities: - Model Context Protocol (MCP) RAT Engine: A paradigm shift in command and control that subverts Anthropic’s MCP from a standard context-sharing tool into a functional, undetectable Remote Access Trojan (RAT), tunneling all C2 traffic through legitimate LLM API communication. - PowerShell Client Builder: An automated obfuscation engine featuring deep variable randomization and structural mutation to break static signatures. - AMSI Bypass Generator: Dynamic generation of multi-stage bypass scripts, utilizing diverse techniques to neutralize the Antimalware Scan Interface in real-time. - Real-time Monitoring: Advanced telemetry for live command execution tracking and granular session management. - Cryptographic Isolation: Implementation of per-client encryption keys derived via HKDF-SHA256, ensuring that the compromise of one beacon does not jeopardize the entire fleet. - RBAC: Native Role-Based Access Control, strictly segregating permissions between Admins, Users, and Viewers. - Complete Audit Logging: Forensic-grade command history with millisecond-accurate timestamps for post-operation deconfliction.

By utilizing a multi-tier decision logic, the system dynamically selects and rewrites payloads based on the specific operational objective. This allows the C2 to scale its complexity in real-time—transitioning from basic PowerShell structures and stealthy WMI manipulation to the strategic abuse of LOLBins for high-complexity tasks. This adaptive approach ensures that every command utilizes the most effective legitimate system tool, successfully evading environment-specific defenses by blending into the target's unique operational noise.

Tactic Description: In this interactive session, attendees will sit down with the developer to operate the AImaru C2 framework in a controlled lab environment. Participants will experience the "Natural Language Intent" paradigm shift firsthand, moving away from manual syntax to intent-based exploitation.

Deployment: Deploy a lightweight MCP-Client on a target Windows machine and establish a beacon back to the AI-C2 controller.

Intent-Based Recon: Issue high-level natural language prompts (e.g., "Find sensitive PDF files and identify lateral movement paths") and observe the LLM selecting and generating the appropriate PowerShell/WMI code in real-time.

Automated Evasion: Trigger the Adaptive AMSI Bypass module, witnessing how the framework re-writes its own memory-resident payloads to evade active defenses.

All the technical information about the project is here: https://github.com/mloborom/aimaru-c2

SpeakerBio:  Mario Lobo, Cyber Threat Intelligence Researcher

I am a Colombian Cybersecurity Engineer with a Master’s degree and a deep passion for the field. I have spent over 18 years immersed in various domains of Information Security and Cyber Intelligence.

My career has spanned critical sectors, including National Defense, where I spent nearly 10 years collaborating with Strategic Cyber Intelligence teams worldwide. I have led multiple cybersecurity teams for multinational banking institutions within the financial sector, and for several years now, I have served as the Lead Threat Intelligence Researcher at Lumu Technologies. I have been a main track speaker at prestigious international conferences such as Ekoparty, 8.8 Gob, BSides São Paulo, BSides Colombia, and Cyberwings, among others.

Beyond the professional realm, I am a guitar enthusiast, a dedicated cyclist, and a consummate music lover.

--

Soy colombiano, Ingeniero Magister en Ciberseguridad y un apasionado por el tema. Llevo más de 18 años sumergido diferentes campos de la Seguridad de la Información y la Ciberinteligencia.

Mi trayectoria me ha permitido transitar por sectores como la Defensa Nacional, donde por casi 10 años colaboré con equipos de Ciberinteligencia Estratégica alrededor del mundo. Lideré diferentes equipos de ciberseguridad para la banca multinacional en el sector Financiero y desde hace algunos años me desempeño como Lider Investigador de Inteligencia de Amenazas en Lumu Technologies. He participado como conferencista main track en eventos como Ekoparty, 8.8 Gob, Bsides Sao Paulo y Bsides Colombia, Cyberwings entre otros.

Fuera del ámbito profesional, soy un amante de la guitarra, la bici y un melómano consumado.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Saturday - 15:00-15:30 PDT


Title: AIRGAP BREACHED: Monitoring the Ancestral Payload Leaking from the Poles
Tags: Biohacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

A frugal, eDNA sniffing system to audit atmospheric biodata-leaks in the era of Climate change.

Current healthcare cybersecurity focuses on device access, ignoring the fundamental vulnerability: the environmental air gap is closing. Massive cryospheric melting is releasing a backlog of ancestral genetic data (eDNA) into the biosphere, creating an unmonitored 'input stream' of allergens and pathogens. This talk presents a resilient, open-source eDNA monitoring system designed to audit these atmospheric 'data leaks' in real-time. By utilizing high-fidelity open-source and decentralized brewed polymerases and consumer electronics, we provide a solution for biological sovereignty that remains operational even when traditional digital infrastructure fails.

Here, we will present how to build global atmospheric monitoring networks for under $500 USD to intercept "paleo-organisms"—dormant bacteria and viruses released by melting poles—using shotgun metagenomics, 3D-printed parts, and microcontrollers. Essentially, he catches genetic ghosts in the air before they trigger the next global health crisis. This projects aims to tackle a sci-fi level threat: Facing the looming ecological danger of "polar amplification," David is developing open-source hardware together with Biohackers at BioOlympia (Olympia Washington), to capture and sequence ancient or threatening environmental DNA (eDNA). His atmospheric biosensors combine high-precision 3D printing, fluid dynamics, and embedded systems to track clouds of paleo-biomass and frozen microorganisms waking up from the ice or perturbed ecosystems. Along with studies in environmental science, biology, and Geographic Information systems, BioOlympia also operates a fully equipped BSL-2 research environment.

SpeakerBio:  David J. Castillo-Cornejo

David is a biomedical scientist with experiences at the Max Planck Institute, Osaka University and ASU. He is the founder of Glyxon Biolabs. BioOlympia is a [Bio]Punk laboratory. The lab conducts advanced research in mammalian cell biology, CRISPR-based gene editing, and regenerative medicine.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 15:30-15:59 PDT


Title: Alerts and Warnings in 2026 Elections
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 15:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

The landscape supporting election cybersecurity has shifted dramatically since 2024. The federal government has lost most of its institutional knowledge about election security. Federal agencies have withdrawn from this space and diminished support for the Election Infrastructure Information Sharing and Analysis Center, leaving election officials and their vendors to shoulder the cybersecurity burden on their own. State and local election officials describe a breakdown in trust, reduced support, less intelligence, and other caustic effects that are debilitating the information-sharing environment. Meanwhile, advanced threats and threat actors have not gone away.

The fracturing of election security support goes beyond funding cuts for threat monitoring and fewer cyber assessments. Breakdowns in the multilateral information sharing mean that election officials lose early warnings, resource-strapped jurisdictions lose collective knowledge, and, critically, the federal government loses the capability to detect foreign campaigns to interfere in US elections.

An ineffective information-sharing environment leaves state and local jurisdictions facing sophisticated adversaries and criminal organizations without collective defense. Some losses can be replicated, but the gaps leave election security weaker than before.

Civil society, particularly former federal, state, and local election security professionals, is attempting to fill these gaps. Organizations such as the Election Security Exchange, Center for Democracy and Technology, Committee for Safe and Secure Elections, Partnership for Elections and Emergency Response, ASU Mechanics of Democracy Lab, MS-ISAC, Election Technology Education Fund, and other partners are rebuilding collective defenses. This panel acknowledges that the environment is what it is and demonstrates that vulnerabilities are not going unrecognized or unaddressed.

Speakers:Geoff Hale,Ryan Macias

SpeakerBio:  Geoff Hale

Geoff Hale has over 15 years of experience supporting the security of critical infrastructure with a focus on election security since 2016. Geoff worked at the Cybersecurity and Infrastructure Security Agency (CISA) as Associate Director for Election Security & Resilience, helping to build a security community in support of U.S. elections.

SpeakerBio:  Ryan Macias

Ryan Macias has spent over 20 years providing subject-matter expertise in election technology, security, and administration to election officials across the U.S. and election management bodies (EMBs) abroad. Macias has advised thousands of election stakeholders on strategies and methods to build resilience in election infrastructure, technology, and processes. Macias also teaches Election Security at the University of Minnesota and previously worked for the U.S. Election Assistance Commission (EAC) as the Acting Director of the Voting Systems Program and California Secretary of State, where he led the Top-to-Bottom Review of Voting Systems.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: All About UART
Tags: IoT Village | Creator Workshop
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

UART, it’s in your smart camera, router, maybe even your phone and it’s usually the easiest foothold into a device. In this hands-on workshop you’ll learn to find it with a multimeter, read it with a logic analyzer...


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Saturday - 15:00-15:40 PDT


Title: AMA with EFF
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Saturday, Aug 8, 15:00 - 15:40 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Learn about EFF’s work protecting your right to send memes to your friends, watch videos online, and go outside without surveillance. Ask questions about EFF's work, from how we fight bad laws in Congress to how we take on big tech companies. Whether you’re curious about technology, want to know how to protect your privacy, or just want to know what a nonprofit org actually does, this is your chance to ask us anything.

SpeakerBio:  EFF
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 11:15-12:15 PDT


Title: An Android voyage from Java to Smali with ASM
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Saturday, Aug 8, 11:15 - 12:15 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

The Java programming language is the backbone of almost all Android applications, yet its compilation process is often discarded. Behind the scenes, a complex series of bytecode transformations takes place, and tools such as ASM allow anyone to hook into the process and alter the flow to achieve better performance, obfuscation, compile-time code injection, ... In this talk, we'll explore how this tool works, how it can be used, and the deep pitfalls to look out for when performing Java bytecode manipulation.

SpeakerBio:  Ricardo Loura
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 14:10-16:50 PDT


Title: An Intro to Mac Malware Analysis
Tags: Malware Village | Creator Workshop
When: Saturday, Aug 8, 14:10 - 16:50 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map

Description:

Patrick has spent the past 20 years studying macOS malware, building tools to detect it, and authoring The Art of Mac Malware book series. In this training, you'll learn the tools and techniques needed to detect and analyze modern threats targeting Apple's desktop OS.

We'll cover common infection vectors, persistence mechanisms, and capabilities of macOS malware, along with an introduction to the tools and techniques used to classify and analyze malicious binaries.

SpeakerBio:  Patrick Wardle, CEO and Co-Founder at DoubleYou

Patrick Wardle is the cofounder of the Objective-See Foundation, CEO and cofounder of DoubleYou, and author of The Art of Mac Malware series. He previously worked at NASA and the NSA, and has presented at countless security conferences, making him intimately familiar with aliens, spies, and talking nerdy.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 11:45-12:30 PDT


Title: Anyone Can Hack IoT (Even Easier Now) - A Beginner's Guide to AI Augmented IoT Hacking
Tags: IoT Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:45 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Two years ago I gave a popular talk at Defcon called "Anyone Can Hack IoT" and the message was simple, you don't need expensive gear and I can show you how. All of that is true, but now it's even easier and I want to show you why. Whether you saw the original talk or this is your first time thinking about IoT hacking, I'll show you how AI has actually made it even easier. In this talk I'll show you what's actually useful and what not by walking through my real workflow that I've used to find multiple CVEs. I'll demo Wairz, an open source tool I built that lets AI agents help reverse engineering firmware, along with some other hardware tools I've put together to give AI direct access to devices on my bench. I'll cover what's worth using AI for, what's still better done by hand and how you can build your own AI assisted setup at home and hack your first device (or second or third or so on).

SpeakerBio:  Andrew Bellini
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 15:00-15:45 PDT


Title: AOBTD: AI One Bites The DAST
Tags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:
I hate the way most DAST tools test: firing payloads at parameters with no idea what the app is. They catch the obvious stuff, but miss the parts that actually need context. Newer LLM scanners are either commercial black boxes (iykyk) or "GPT, find bugs at this URL" wrappers that fall over outside a CTF box.

AOBTD is my attempt at a third option: a scanner that behaves less like a fuzzer and more like a pentester at the start of a test.

Instead of fuzzing harder, AOBTD first tries to understand the target. It explores the surface, identifies what pages and endpoints are for, takes notes, builds hypotheses, and then sends targeted requests based on that context. This target understanding drives the rest of the testing process, which is the only realistic way automated tooling can get closer to business-logic bugs.

The crawler is designed to avoid wasting time on repeated templates while still sampling outliers, so the odd page hidden in a sea of similar ones does not get ignored. When findings are confirmed, AOBTD can chain them into multi-step attack stories rather than reporting isolated payload hits.

This is where LLMs are actually useful: reading a page, understanding the purpose of a form, naming the function behind a JSON endpoint, and doing the kind of prioritization a pentester normally spends hours on.

SpeakerBio:  Ozgun "ozzy" Kultekin

Ozgun (aka ozzy) is a Senior Application Security Engineer at Trendyol Group, where he spends his days breaking applications before the bad guys do. He holds the OSCE3 certification and specializes in offensive security research with a focus on application security and red team operations.

He has presented at several conferences including DEF CON, Hacktivity, and multiple BSides events, covering topics ranging from red teaming to application security. He is currently focused on integrating AI into offensive security workflows and actively researching how large language models can be applied in practical, technical ways within cybersecurity. He regularly shares his work and tools as open source.

When he's not hunting bugs or running red team ops, he's probably at the poker table.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-23:59 PDT


Title: Apex Park (Cloud Village CTF)
Tags: Cloud Village | Apex Park (Cloud Village CTF) | Contest
When: Saturday, Aug 8, 10:00 - 23:59 PDT
Where: LVCCW Level 3 W312 (Cloud Village CTF) - Map

Description:

Cloud Village CTF will be a jeopardy style 2 days contest where participants will have to solve challenges around Cloud infrastructure, security, recon, etc. These challenges will cover different cloud platforms including AWS, GCP, Azure, Digital Ocean, etc. We will also reward our top 3 teams with awards.​​

Participant Prerequisites

A laptop with unfiltered internet access and an open mind to learn with the community.

Timing

Cloud Village CTF @ DEF CON 34: 7th & 8th August 2026 CTF starts - 7th August, 2026 - 10:00AM PDT CTF closes - 8th August 2026 - 23:59PM PDT CTF registrations opens - 30th July 2026 - 10:00AM PDT


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W231 (Workshops) - Map

Description:
Speakers:Jos Wetzels,Wouter Bokslag

SpeakerBio:  Jos Wetzels, Midnight Blue
No BIO available
SpeakerBio:  Wouter Bokslag, Midnight Blue

Wouter Bokslag is a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world’s fastest public attack against the Hitag2 cipher. He holds a Master’s Degree in Computer Science & Engineering from Eindhoven University of Technology (TU/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years.

Recently heavily involved in the TETRA:BURST research and associated follow-up research, such as the recent reverse-engineering and analysis of the elusive TETRA End-to-End protocol. Also, a contributer of open-source SDR code.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W231 (Workshops) - Map

Description:
Speakers:Jos Wetzels,Wouter Bokslag

SpeakerBio:  Jos Wetzels, Midnight Blue
No BIO available
SpeakerBio:  Wouter Bokslag, Midnight Blue

Wouter Bokslag is a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world’s fastest public attack against the Hitag2 cipher. He holds a Master’s Degree in Computer Science & Engineering from Eindhoven University of Technology (TU/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years.

Recently heavily involved in the TETRA:BURST research and associated follow-up research, such as the recent reverse-engineering and analysis of the elusive TETRA End-to-End protocol. Also, a contributer of open-source SDR code.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 15:00-16:59 PDT


Title: AppSec Quiz Gauntlet: Spot the Vulnerability
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map

Description:
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
SpeakerBio:  Avek Kolech
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 13:00-14:59 PDT


Title: AppSec Quiz Gauntlet: Spot the Vulnerability
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map

Description:
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
SpeakerBio:  Avek Kolech
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: Arcanum Security Labs
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Arcanum Security delivers modern cybersecurity through cutting-edge training and consulting, led by Jason Haddix and crew, spanning offensive security, bug bounty hunting, and AI security. Stop by during village hours to work through their hands-on labs.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 11:30-11:59 PDT


Title: Are We Making Things Worse? Election Denialism and Security Research
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:30 - 11:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:
Speakers:Matt Blaze,Geoff Hale,Michael Moore,Kendall Spencer,Philip Stark

SpeakerBio:  Matt Blaze

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.

SpeakerBio:  Geoff Hale

Geoff Hale has over 15 years of experience supporting the security of critical infrastructure with a focus on election security since 2016. Geoff worked at the Cybersecurity and Infrastructure Security Agency (CISA) as Associate Director for Election Security & Resilience, helping to build a security community in support of U.S. elections.

SpeakerBio:  Michael Moore

Michael Moore is the CISO at Arizona Secretary of State's Office. He leads efforts to strengthen election security through coordinated partnerships across federal, state, and local governments, alongside trusted private-sector partners. His work is grounded in protecting democratic processes and maintaining public confidence in elections. He focuses on the most pressing risks to election integrity: mis-, dis-, and malinformation (MDM), and the insider threats that can emerge from an increasingly polarized and misinformed environment. His approach centers on countering false narratives with verifiable truth while advancing a defense-in-depth strategy. This includes preventing attacks wherever possible, rapidly detecting anomalies, and ensuring resilient, transparent recovery when incidents occur.

Through organizational leadership and national collaboration, Michael has driven initiatives that enhance the security, resilience, and credibility of election systems. His work helps safeguard the voter experience and uphold trust in democratic institutions.

SpeakerBio:  Kendall Spencer

Kendall Spencer is an attorney specializing in emerging companies, technology transactions, and the legal issues shaping innovation. Since joining DEF CON’s Voting Village as a Georgetown Law student in 2019, he has worked alongside Matt Blaze, David Jefferson, and the Voting Village team at the intersection of election technology, cybersecurity, and democracy. Spencer serves on the Board of Directors of the Election Integrity Foundation and has advised state election officials on election security, post-election audits, and cybersecurity best practices. His work focuses on bridging the gap between technical research, public policy, and the law—helping policymakers, election officials, security researchers, and the public better understand the role election security plays in strengthening democratic institutions and public confidence in elections. A frequent DEF CON speaker, Spencer is passionate about fostering thoughtful, bipartisan conversations on the role of technology in protecting election integrity and the democratic principles that underpin a free and open society. Outside of his legal and technology work, Spencer is a rare book dealer and collector specializing in early American history and the Black diaspora.

SpeakerBio:  Philip Stark

Philip B. Stark is Distinguished Professor of the Graduate School at the University of California, Berkeley, where he has served as department chair and associate dean. In 2007 he invented "risk-limiting audits" ("RLAs"), endorsed by the National Academies of Science, Engineering, and Medicine and the American Statistical Association, among others, and required or authorized by law in about 15 states. He designed and helped conduct the first dozen pilot RLAs, helped draft RLA legislation for several states, and has published open-source software to support RLAs. In 2012, he and David Wagner introduced "evidence-based elections," a paradigm for conducting demonstrably trustworthy elections. Stark has served on the Board of Advisors of the US Election Assistance Commission and its cybersecurity subcommittee, the Board of Directors of Verified Voting Foundation and the Election Integrity Foundation, and on the California Post Election Audit Standards Working Group. He has worked with the Secretaries of State of California, Colorado, and New Hampshire and numerous local election officials. He has testified about election integrity in state and federal courts and to legislators. He received the IEEE Cybersecurity Award for Practice, the UC Berkeley Chancellor's Award for Research in the Public Interest, and the John Gideon Award for Election Integrity. He is a fellow of the American Academy of Arts and Sciences, the American Statistical Association, and the Institute of Physics.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: ARINC 664 CTF Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

This is a two-part CTF activity designed to immerse participants in an aircraft’s ARINC 664 network.

Virtual Challenge – Test your skills by navigating through a series of interactive tasks that build foundational knowledge of the ARINC 664 protocol – one of the communications protocols for onboard networks. Gain a high-level understanding of how this protocol operates and its security considerations.

Hardware Challenge: Take it to the next level by engaging with model hardware. Send messages to manipulate and interact with simulated aircraft systems!


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 15:30-15:59 PDT


Title: Assume Breach, But For Real: Rewriting Infrastructure Policy for the Adversaries Who Never Left
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 15:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

An energy provider detects an intrusion when a control-room operator notices an unexplained setpoint change not an alert. Initial access occurred ninety days earlier via a contractor credential that outlived contract. Disclosure clocks are already running. Scope is unknown. Systems cannot go offline. This reflects recurring patterns Microsoft incident response teams observe across critical infrastructure, patterns policy was not designed around today. Cyber policy assumes breaches are detectable in reasonable timeframes, attributable with confidence, and containable once identified. Incident response shows otherwise. PRC state-sponsored actors such as Volt Typhoon maintain persistent, low-visibility access using valid credentials and living-off-the-land techniques. Detection often lags weeks or months, triggered by operational impact rather than telemetry. Investigations unfold under live operations, incomplete visibility, and uncertain scope, while disclosure timelines under CIRCIA, SEC rules, NIS2, and similar frameworks continue to run. This session bridges incident response and policy design, drawing on CI cases, DOJ experience, crisis counsel to show where assumptions break and how policy can align to conditions: identity-driven intrusion, persistent access, IT-OT convergence, and decisions under uncertainty.

Speakers:Travis Berent,Adam Hickey

SpeakerBio:  Travis Berent, Microsoft

Travis Berent is the Director of Security Business Strategy at Microsoft, where he helps shape the company’s approach to incident response, resilience, and cybersecurity partnerships. Prior to joining Microsoft, Travis served as Director for Cybersecurity Policy and Incident Response at the National Security Council, where he strengthened U.S. defense and intelligence environments, oversaw response to significant cyber incidents affecting critical infrastructure and government networks, and led key processes including the Vulnerabilities Equities Process. He also helped develop national policy responses to ransomware and contributed to both the National Security Strategy and National Cyber Strategy. Earlier in his career, Travis served in multiple roles at the Federal Bureau of Investigation (FBI), including in the New York Field Office and at Cyber Division Headquarters, where he worked on counterintelligence and cyber matters.

SpeakerBio:  Adam Hickey, Mayer Brown

Adam Hickey offers clients extensive experience in cybersecurity and national security matters. Adam draws on more than 15 years of experience at the U.S. Department of Justice (DOJ) handling high-profile national security matters intersecting with the private sector. Prior to joining Mayer Brown, he was a Deputy Assistant Attorney General (DAAG) of DOJ’s National Security Division (NSD). During his time at NSD, Adam established DOJ’s national security cyber program, dedicated to combatting malicious cyber activity by foreign intelligence services affecting major companies and critical infrastructure, and he supervised the criminal investigation and charging of every such case for more than a decade. He now advises critical infrastructure and OT operators on incident response, privileged investigations, disclosure, regulatory requirements across borders, and enforcement actions.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 14:10-14:50 PDT


Title: Autonomous Offense vs. Autonomous Defense: Who's Winning in the Cloud?
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:10 - 14:50 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Aviation ISAC Cybersecurity Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Chaos has ensued at a major international airport. Flight info displays flicker with false data. Baggage systems fail. Aircraft controls and drones (by the riverside) are compromised. Even the skies are no longer safe.

Your mission: investigate the breach, neutralize the threats, and take back control of the airport. The airport depends on you. The clock is ticking!

As a participant, your first step is to register ahead and read the rules at: https://aviationcyberctf.com/ and bring your own laptop to the venue.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 13:50-13:59 PDT


Title: Badgelife Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 13:50 - 13:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Badgelife but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Badgelife and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 10:00-17:59 PDT


Title: BadVR: Signals Everywhere a collaboration with XR Village
Tags: OWASP Foundation | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

BadVR Data Exploration through VR visualization. See RF signals, cellular signals and new for 2026, Meshtastic signals, step into the data with a hands-on VR experience

Speakers:Jad Meouchy,Suzanne Borders

SpeakerBio:  Jad Meouchy, CTO + Co-Founder at BadVR

Jad, originally from northern Virginia, holds dual B.S. degrees in Computer Engineering and Psychology from Virginia Tech, and is a graduate of the Thomas Jefferson High School for Science and Technology. While in college, he engineered and built the data visualization components of an emergency response simulation that went on to receive 2M in public grant funding. Over his 15-year career, Jad has founded five startups and successfully exited three. His professional expertise is in software architecture and development, specifically big data analytics and visualization, and virtual and augmented reality development. Based in Los Angeles since 2010, Jad promotes the community by organizing developer meetups and events, and volunteering time for STEM initiatives.

SpeakerBio:  Suzanne Borders, CEO + Founder at BadVR

Suzanne studied psychology at University of Missouri, Kansas City and previously worked as Lead UX/Product Designer for over 9 years at companies such as Remine (raised $48M) and CREXi (raised $54M) where she specialized in designing intuitive, high-performant data analytic interfaces. In 2019, Suzanne founded BadVR and was awarded a “Rising Stars” innovation award from IEEE. To date, she’s raised over $4M in non-dilutive funding for BadVR, via grants from the National Science Foundation, NOAA, Magic Leap, Qualcomm, and more. Suzanne has grown the company from 2 to 25 people and was awarded 4 patents for innovations she created while leading the BadVR team. Over the past 5 years, Suzanne emerged as a thought-leader in the immersive data visualization and analytics space. She has been a keynote speaker at over 25 national and international conferences. In her spare time, Suzanne travels for inspiration (81 countries and counting) and is proud to be a published author and former punk.  Suzanne thrives at the intersection of product design, immersive technology, and data; she’s a believer in the artistry of technology and the technicality of art and remains passionately dedicated to democratizing access to data through universally accessible products. 


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 10:00-10:40 PDT


Title: Bashing CloudShells for mining, networking, exfil and persistence at scale
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:40 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

CloudBashing started with reversing the private AWS, Azure, and GCP CloudShell REST protocols, analyzing websocket terminal sessions, and tracing janky browser authentication/credential flows with cookies and OAuth tokens. Along the way, we automated the APIs to access free CPU/networking, maintained access across container/VM resets, utilized persistent $HOME for implants/data, locked users out of sudo access, and installed a C2 framework. We discovered IAM design issues like: AWS role assumption that result in a large # of environments per compromised identity, web socket sessions that survive API token revocation, and M365/Gmail consumer email accounts that have default CloudShell access. This turned into a newly released exploit toolkit, CloudBasher, that enumerates, validates, installs, and runs distributed workloads with virtual storage and private networking across a large-scale agent network with persistence and resilience. We'll demo distributing CPU-intensive workloads, using virtual storage for staging/exfiltration, secure networking for proxy and obfuscated exfil paths, while automating the discovery, enumeration, creation of CloudShell environments from initial credentials/sessions to implants/setup/networking to management and control.

Speakers:Jenko "edleft" Hwong,Chris Ryan

SpeakerBio:  Jenko "edleft" Hwong, Huntress Labs

Jenko Hwong is a Principal Security Researcher at Huntress Labs, focusing on identity-based attacks and cloud abuse. Prior to Huntress, he spent 6 years at Netskope Threat Labs, has spoken at RSA and DEFCON, and is a Cloud Village Lead. He has over 20 years at various security startups in cloud detection/response, vulnerability scanning, AV/AS, pen-testing/exploits, L3/4 appliances, threat intel, and windows security.

SpeakerBio:  Chris Ryan, Huntress Labs

A series of oddly configured server banners, a JARM fingerprint, curious fields in a security certificate - these aren't just technical details, but are instead threads in a narrative tapestry woven like a John le Carre novel. For over 20 years, Chris has dedicated his life to studying these threads and the intersection between cybersecurity, Russian linguistics, and free and open source software. His career path has taken detours through academia, aerospace and defense, software development, and cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 10:15-13:15 PDT


Title: Battle of the Bots: Vishing Edition
Tags: Social Engineering Community Village | Creator Event/Activity
When: Saturday, Aug 8, 10:15 - 13:15 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

AI meets vishing in the booth as teams use AI-powered agents to place live calls, chase preset objectives, and test the limits of automation, hacking, and human psychology. Judged by Snow, Perry Carpenter, and Lisa Flynn.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 12:30-12:40 PDT


Title: BBWIC Foundation Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 12:30 - 12:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting BBWIC Foundation but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to BBWIC Foundation and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 15:00-15:45 PDT


Title: Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Hardware/IoT | Mobile | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
When: Saturday, Aug 8, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

What happens when you buy a popular medical device and realize it blindly trusts any BLE connection within 30 meters?

BRAT (BLE Recon and Attack Toolkit) is the open-source Python arsenal we built to systematically take over an FDA-listed consumer hormone analyzer and generalize the attack to the class of devices behind it. Relying on the Nordic UART Service (NUS), the target blindly trusts any connection within 30 meters. BRAT automates the exact attack chain we used to compromise it: passive BLE discovery, protocol reverse engineering, unauthenticated command injection, full bind takeover, and rogue peripheral impersonation to hijack live API session tokens.

Every script is built on the ⁠bleak⁠ async BLE library and deliberately kept small so you can read the code and understand the exploit in minutes. Our Demo Lab features live, end-to-end attacks against a consumer medical device. We’ll demonstrate unauthenticated command injection, rogue peripheral spoofing that intercepts companion app handshakes, and how we injected spoofed hormone sensor data without ever pairing.

Speakers:Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova

SpeakerBio:  Gigi Xiaoqing Liu

Gigi Liu is a graduate security researcher at Northeastern's Security And Privacy Research (SPQR) Group under Professor Kevin Fu, where her work covers embedded systems security, medical device attack surfaces, and AI-generated media detection. She interns at Lila Sciences as a Security and Cloud Engineer, building enterprise-wide agentic AI security infrastructure and detection capabilities for unauthorized AI activity across cloud and SaaS environments.

Her technical work spans wireless protocol reverse engineering, binary exploitation, web and mobile reverse engineering, cloud and AI security. She has applied these skills across medical hardware, automotive platforms, and enterprise cloud environments — from BLE command injection on FDA-listed devices to CarPlay API exploitation to building agentic AI detection controls at scale. As a UCLA psychobiology alum with a consulting background, she brings a multidisciplinary lens to every system: understand what it's designed to do first, then find where it breaks.

SpeakerBio:  Muzzammil Mohammed

Muzzammil Mohammed is an offensive security researcher, penetration tester at Maltek Solutions, and MS in Cybersecurity at Northeastern University. Operating out of the SPQR Lab under Professor Kevin Fu, and serving as a Teaching Assistant Network Security, his work bridges academic vulnerability research with real-world red team execution. As a core developer of WandKit an open-source BLE attack toolkit built to audit medical devices. Muzzammil led the cloud API exploitation phase, successfully confirming a complete authentication bypass and engineering the rogue peripheral session hijack chain. Beyond hardware and API hacking, he is actively developing autonomous multi-agent AI frameworks designed to orchestrate local LLMs for automated security auditing and vulnerability analysis.

SpeakerBio:  Narmina Karimova

Narmina Karimova is a cybersecurity graduate researcher at Northeastern University with a background in enterprise technology across financial institutions and the United Nations. She came to security research from the infrastructure side, which shaped how she approached tearing apart a consumer fertility monitor. For BRAT, she wrote the core BLE attack suite in Python: replay modules, rogue peripheral session capture, unauthenticated hormone data extraction, and the bind takeover chain that captures device ownership in under 15 seconds. She also reverse-engineered the APK with JADX, found hardcoded credentials, and confirmed a CVSS 9.1 IDOR in the third-party integration. Her interest is in the gap between how consumer health devices are marketed and how they actually handle sensitive data.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Beer Chilling Contraption Contest
Tags: Beer Chilling Contraption Contest | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest) - Map

Description:

It’s the 21st year of the BCCC and it’s the Beer Chilling Contraption Contest this year! We can finally drink! No more beverage, we are drinking beer now, and boy do we need one. This year we thought we would mix it up and have cold beer and you all could try your hand at warming it. Unfortunately, the guys in charge of getting the ice got a bit too tan walking in this Vegas sun. A different kind of ICE deported them to Botswana and in the ensuing chaos the beverage was left outside and its warm again. Fortunately for everyone involved, WW3 and the inevitable nuclear winter will finally solve the warm beer problem -- well at least temperature-wise. It might be a little HOT in the gamma spectrum. But while we wait for Pooh Bear, BiBi, Putler, and or the Cheeto to kick this global cooling contraption off, its up to us to chill this beer.

You will cool the beer we give you in a red solo cup as quickly as possible to 34 degrees F. You may not alter the beer by mixing it with ice, dry or otherwise. You may bring a device you created or build your own at the convention. There are some great prizes waiting, mostly what I have lying around and don't want to take home. There are some additional rules, check the DEFCON forums or the poster board at the contest!

In conclusion, it’s not just a warm beverage—it’s a testament to the rich tapestry of societal collapse, seamlessly navigating the multifaceted landscape of your broken contraption.

Participant Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 15:00-15:59 PDT


Title: Beerus Framework – A New Mobile Framework Arises
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

About a year ago, Hakai Security introduced the Beerus Framework, a proposal to unify mobile tools in order to streamline the penetration testing process directly on Android devices. The idea was simple: centralize tooling and optimize the testing environment setup, removing the need for complex configurations and reducing operational friction during assessments.

Today, after a year of evolution, the framework is no longer just a concept. It has become a robust platform for offensive mobile analysis, gaining international recognition within the community. In this talk, we revisit Beerus in its current form, exploring its evolution, the capabilities that have been consolidated over time, and the lessons learned from real-world scenarios.

We also discuss the future vision of the project, covering new features, technical challenges faced during its development, and how the framework can continue evolving to keep up with modern mobile security assessment demands.

Official blog post: https://hakaisecurity.io/beerus-framework-a-new-mobile-framework-arises/insights-blog/ Repository: https://github.com/hakaioffsec/beerus-android Community references: - mobile hacker (post): https://x.com/androidmalware2/status/1979100030884618375 - mobile hacker (video): https://www.youtube.com/watch?v=8bDQzqw0_Sc - ZeroDay Gym (video): https://www.youtube.com/watch?v=I81xuVDsytE

Speakers:João Pedro Tricta,Daniel "Daniboy" França Lima

SpeakerBio:  João Pedro Tricta, Client-Side Applications Squad Leader, Researcher, and Malware Developer at Hakai Offensive Security

Known as Tricta, I am 20 years old, Brazilian, and work as a Client-Side Applications Squad Leader, Researcher, and Malware Developer at Hakai Offensive Security. I am passionate about Sysinternals, reverse engineering, low-level, and client-side applications. In my free time, I enjoy programming, gaming, and watching anime. I'm a cat lover and a compulsive pizza eater.

SpeakerBio:  Daniel "Daniboy" França Lima, Pentester / Researcher at Hakai Offensive Security

Known as Daniboy, I am 19 years old, Brazilian, and work as a Pentester and Researcher at Hakai Offensive Security. I am passionate about understanding how things work, building tools, and manipulating systems. In my free time, I enjoy gaming, especially titles like Hollow Knight. I also love foxes, they are just too cute :3


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 17:00-17:30 PDT


Title: Behind the Badge: SAOv3 and Open Sourcing the Aerospace Village ISS Badge
Tags: Aerospace Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

The Rare Circuits team decided this was the year to take all our hard work on last year’s Aerospace Village badge and open source the useful components for the Badge Maker Community. We took the tight communication integration between badge and Add-on to create SAOv3, a new SAO standard that puts connectivity right at the forefront. ANSM, our framework to create silky smooth pixel animations and interfaces for embedded systems, is ready for everyone to use. We are even releasing our circuit and driver to make the SSD1106 OLED update smoothly and enables 4-level greyscale on it.

Speakers:Adam Batori,Kevin Colley,Robert Pafford,Lillian Ash Baker

SpeakerBio:  Adam Batori
No BIO available
SpeakerBio:  Kevin Colley
No BIO available
SpeakerBio:  Robert Pafford
No BIO available
SpeakerBio:  Lillian Ash Baker
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 10:45-10:59 PDT


Title: Beholden to No One: The Nix Override Ladder
Tags: Nix Vegas Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:45 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Home Assistant ships a warning that your install "will not work after 2026.11." DuckStation detects NixOS four different ways and fatally errors your build on purpose. A maintainer won't merge the one-line word-wrap fix you've needed for a year. On most platforms your options are comply or quit. On Nix, everything between you and the source is negotiable.

This talk is a guided tour up the override ladder, from module options and mkForce to overrideAttrs, fetchpatch-ing unmerged PRs, overlays, and finally patching nixpkgs itself. The stories along the way are real and primary-sourced: sabotaged npm packages, the xz backdoor, the youtube-dl DMCA takedown, rug-pull relicensing, and the nixpkgs patch literally named nixos-was-never-supported.patch.

SpeakerBio:  Daniel Baker

Daniel Baker is a developer, engineer, and mathematician passionate about reproducible software. An active NixOS community member and educator, he authored the NixCon NA 2024 Nix module system workshop and nixos-modules-lessons. He serves on the NixOS Marketing Team and helps organize both Nix Vegas and Planet Nix. He believes any system worth building is worth rebuilding, bit for bit.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 10:00-10:55 PDT


Title: Being Black While Hacking: The Unofficial Survival Guide
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

In an industry that frequently highlights a massive skills gap, Black professionals are dramatically underrepresented in cybersecurity. This talk uses sharp humor and real-world experiences to explore the realities of being Black in the hacking community. It addresses challenges like the "only one in the room" tax, costly certifications, unconscious bias in hiring, and the emotional labor of code-switching. Attendees will gain insights into systemic barriers and learn how resilience and community, inspired by trailblazers like Camille Stewart Gloster and Tennisha Martin, can overcome rigged systems. This session also challenges allies and leaders to sponsor talent, improve hiring processes, and understand why increasing Black representation is essential for equity and innovation in cybersecurity.

SpeakerBio:  Dr. Louis DeWeaver III, Cybersecurity Consultant at Marsh McLennan Agency (MMA)

Dr. Louis DeWeaver is a battle-tested Cybersecurity Consultant at Marsh McLennan Agency (MMA) with over 20 years of real-world experience in the trenches. They hold a hard-earned academic arsenal: an Associate of Applied Science in Information Technology, a B.S. in Information Systems Security (2011), an M.S. in Information Assurance (2016), and a Doctor of Computer Science specializing in Cybersecurity (2021). Dr. DeWeaver doesn t just collect credentials they weaponize them. They serve on the MITRE Engenuity ATT&CK® Evaluations Community Advisory Board, helping define how organizations should actually defend against real adversaries. A proven competitor, they crushed the ONCD Badge Challenge at DEFCON 31 and 32, and in 2025 took down the Policy Village CTF badge created by former ONCD staff. Blunt, high-energy, and unapologetically direct, Dr. DeWeaver has delivered hard-hitting talks at Black Hat, DEF CON, GrrCon, and other major security events. They don t sugarcoat the industry s failures they call them out and show you how to survive (and win) anyway.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 17:00-17:59 PDT


Title: Below the Threshold: Real-World APT Tradecraft for Full-Spectrum Compromise
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

This talk aims to demonstrate the modus operandi of an APT focused on full organizational compromise, revealing how such operations actually function in practice — not through isolated tools or techniques, but through the decision-making model that guides every action over time.

Rather than focusing on direct exploitation or individual methods, this session shows how advanced operators structure their actions around continuity, predictability, and behavioral alignment with the target environment. Attacks are not treated as disruptive events, but as controlled sequences of decisions designed to remain coherent and below the threshold of attention.

The presentation walks through a real RedOps engagement from a strategic perspective, highlighting how each step is evaluated in terms of detection probability, behavioral deviation, and operational impact, ensuring the operation remains stable and does not generate relevance over time.

Instead of teaching specific techniques, the talk focuses on analyzing how and why certain strategies are chosen, revealing the underlying principles that drive advanced operations in complex environments.

The narrative is built around three distinct operational tracks conducted within the same organization, which, when combined, enabled full compromise:

Across these three domains, the session demonstrates how cloud, physical, and financial layers can be exploited in a coordinated manner while maintaining consistency with expected system behavior.

As a central part of the session, a real operation conducted by our company will be presented, in which an organization was fully compromised through a coordinated, multi-layered approach. The scenario includes:

In this case, there was no single event that defined the attack, but rather a sequence of controlled and coherent actions that blended into normal operations, enabling full control without triggering traditional detection mechanisms.

The goal of this talk is to provide security professionals with a practical and structured understanding of how APTs actually operate, offering deeper insight into how decisions are made throughout a real-world operation.

The key takeaway is that APT operations are not effective because they are invisible, but because they do not behave like something that deserves attention.

Speakers:Jonathan Coradi,Oliveira Junior

SpeakerBio:  Jonathan Coradi

Jonathan Coradi is a RedOps Tech Lead at Hakai Offensive Security, with over 7 years of experience in offensive security. He has led offensive operations across industrial, financial, and banking sectors in Brazil, specializing in advanced penetration testing, Red Team simulations, and physical intrusion engagements. Jonathan is also an elite Bug Bounty Hunter — currently ranked Top 1 on BugHunt — and has reported critical vulnerabilities to companies like Microsoft, Uber, and Mercado Livre, among others.

SpeakerBio:  Oliveira Junior

Oliveira Lima is the founder of Hakai and has over 15 years dedicated to the field of cybersecurity, focusing on penetration testing and Red team operations. As a researcher, he has reported numerous vulnerabilities in large companies such as Trend Micro, CISCO, Dlink, etc. Additionally, he has registered more than 40 CVEs. Oliveira continues to be part of the team leading Red team operations.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 12:30-13:30 PDT


Title: Better Bug Hunting on AI Products: A VRP Lead’s Perspective
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 13:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

At Google, we receive hundreds of reports per week (not exaggerating) that claim to identify vulnerabilities in our AI products. However, only a tiny fraction of those (<1%!) will receive a reward. But there is hope! When we break down the reasons so many reports are rejected, nearly all of them fall into a few common categories that make them invalid. Join the Technical Lead of Google’s AI Vulnerability Reward Program to walk through these common pitfalls, learn how to bug hunt more effectively on AI products, and hopefully, take home more bounties for your efforts. Outline I. Introduction Self intro, discuss the interest in AI VRP, introduce the problem of low success rates for researchers II. Overview of Google AI VRP - Brief program history, overview of triage/reward process - Explain VRP scope/rewards: In-Scope: Security vulnerabilities (Rogue Actions / Sensitive Data Exfiltration); Some AI Abuse categories Out-of-Scope: "AI slop," simple alignment bypasses, or jailbreaks that do not result in a direct security impact on user data. III. Common Mistakes - Jailbreaks/Safety: Getting an LLM to generate "bad" content is not a security vulnerability we reward through the program (please report in-product!). - Self-pwns: Reports are over-reliant on social engineering or have unconvincing attack scenarios - Ignoring Context: Misunderstanding "sensitive data" versus expected model behavior. IV. Better Bug Hunting - Direct and Indirect Prompt Injection: Reviewing (un)successful AI VRP reports - Our programs look for indirect prompt injection attacks; this isn’t always easy to understand - Note: This section will include details from a recently rewarded and disclosed AI VRP report [details TBC pending researcher/corporate comms approval] - Clear and Actionable Reporting: - We want to help teams fix bugs quickly; you can help us do that by writing clear and actionable reports - Reproduction can be challenging due to non-determinism V. Conclusion / Q&A

SpeakerBio:  John Kotheimer, Senior Security Engineer, Google

John is a Senior Information Security Engineer and Technical Lead of the AI Vulnerability Reward Program (AI VRP) at Google in New York City. John has significant experience operating bug bounty programs–including a previous role as TL of the Abuse Vulnerability Reward Program at Google–as well as a background in infrastructure security, red teaming, and incident response. As AI VRP lead, John oversees the triage of hundreds of AI bug reports submitted to the program every week. John also coordinates the panel that determines rewards for accepted AI bugs at Google and helps plan and run many of Google’s bugSWAT live hacking events. Before joining Google in 2019, John was an information security consultant at Mandiant and completed graduate study at Carnegie Mellon University. Outside of work, he enjoys travel, craft beer, and riichi mahjong.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Saturday - 13:00-13:59 PDT


Title: BewAIre: Detecting Malicious Pull Requests at Scale with LLMs
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

As AI coding assistants accelerate software development, the volume of pull requests at Datadog has grown to nearly 10,000 per week, increasing the risk that malicious changes slip through due to review fatigue. To address this, Datadog built BewAIre, an LLM-powered code review system designed to identify malicious source code changes introduced by threat actors. By reducing approval fatigue for developers while increasing friction for attackers, BewAIre guides human reviewers to the areas where judgment matters most, without slowing developer velocity.

In this breakout session, Andrew Krug, Head of Security Advocacy and Research will share why BewAIre was built, how it evolved from a hackathon experiment into a production-grade internal system, and the key architectural decisions and trade-offs involved along the way. They will discuss what worked, what didn't, and the limitations the team encountered when applying LLMs to security-critical workflows.

They will also cover how BewAIre is now being integrated into Datadog Code Security, and what it takes to turn an internal engineering tool into a product capability used at scale. Attendees will leave with practical lessons on building, hardening, and productizing LLM-powered systems and how you can use LLMs to minimize the security risks introduced by the new LLM-code-generation paradigm.

SpeakerBio:  Andrew Krug
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 12:00-12:45 PDT


Title: Beyond Spidering: Behavior Driven DAST for Real Application Workflows
Tags: DEF CON Demo Labs | Intermediate | AppSec | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

Modern web apps do not give up their best attack surface to a spider. The interesting routes, state changes, authenticated functions, and business logic usually sit behind real user behavior. This Demo Lab shows how to stop treating DAST like blind crawling and start driving it with realistic browser flows.

The project began as a software quality proof of concept and evolved through collaboration between an engineering team and a red team into a real operational workflow. By routing Selenium based test scenarios through OWASP ZAP, we turn existing web automation into Behaviour Driven DAST: a practical way to capture richer traffic, exercise meaningful application actions, and uncover security findings that isolated scanning often misses.

Current research shows more than 300% increase in observed attack surface and around 25% improvement in vulnerability detection compared with spider-driven analysis alone. The session will walk through the workflow live, show the comparative results, and introduce a new Python library built from this research.

SpeakerBio:  Sara "testingSoul" Martinez

Hi, I am Sara! I started my career in 2014 as a Software Validation Engineer for Communication products. During five years I improved my testing skills by working on projects in Telecommunication, Geolocation, Big Data and Power Electronics. In 2019, I started to focus all this quality knowledge on testing Cybersecurity Software products, and then magic just happened. I discovered a whole new world that fascinated me. Since then, I have been working to improve all my Software and Quality skills including Cybersecurity at every step I take.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 15:15-15:59 PDT


Title: Beyond Your Bookshelf: Hackable eReaders
Tags: IoT Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:15 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Kindles, Kobos, Boox and BigMes there's no shortage of eReaders to choose from in 2026, with their paper-like eInk displays designed for one thing: reading books. But under the surface of these minimalist devices is a surprisingly hackable device. From Kindle jailbreaks, to Android apps, to flashing custom firmware. We'll take that dust-gathering device off of your nightstand and onto your lab bench to talk about the vulnerabilities and customisability of these devices.

SpeakerBio:  Katie Paxton-Fear, Security Advocate, Semgrep

i used to make applications and now I break them, hacker, bug bounty hunter, and educational YouTuber.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 13:00-13:55 PDT


Title: Bias is a Bug: Why Inequality is a Cybersecurity Vulnerability
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

This thought-provoking session examines how bias in AI systems used across cybersecurity for fraud detection, identity systems, and behavioral analytics can inadvertently create structural weaknesses that adversaries might exploit. We will explore how bias can be introduced through data collection, labeling, and modeling, leading to uneven false positive and false negative rates across different populations. Understanding these inconsistencies is crucial, as they can offer attackers avenues to map detection thresholds and bypass security systems. The session will also connect these security risks to emerging regulatory frameworks like GDPR and the AI Act, demonstrating how compliance needs are aligning with core security practices. Join us to learn why integrating equity into threat modeling, red teaming, and system auditing is essential for robust cybersecurity, moving beyond treating fairness as an afterthought.

SpeakerBio:  Dr. Fatou Sankare, Cybersecurity Professional / Community Speaker

Dr. Fatou is a Cyber Engineer and an adjunct professor, dedicated to increasing cyber education, particularly in underestimated communities, through Datacation LLC, which they founded. They are a Certified Ethical Hacker and hold the AWS Machine Learning Specialty Certification.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 12:00-12:59 PDT


Title: BIC Village Capture the Flag (CTF)
Tags: Blacks In Cyber Village | Blacks In Cybersecurity Village Capture The Flag Competition | Contest
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

The BIC Village Capture the Flag (CTF) is your opportunity to tackle real-world cybersecurity challenges, sharpen your technical skills, and compete alongside students, professionals, and cybersecurity enthusiasts during DEF CON 34. Our CTF is designed to challenge your curiosity, celebrate creative problem-solving, and explore cybersecurity through the past, present, and future.

What to Expect: � Hands-on cybersecurity challenges � Challenges for multiple skill levels � Individual and team-based problem-solving � Opportunities to learn, compete, and connect with the community

Hack to the rhythm and the beat with Hack Hack Revolution. Have an idea or challenge you want to share with the community? Join Bring Your Own CTF (BYOCTF) and contribute your own challenge to the experience. Bring your laptop, curiosity, and determination. Whether you are chasing the top of the leaderboard or solving your very first flag, there is a place for you at BIC Village. Every flag is a lesson. Every challenge is an opportunity. We will see you at the CTF, featuring challenges created by members of the cybersecurity community and the global diaspora!


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Saturday - 10:00-17:59 PDT


Title: Biohacking Device Lab
Tags: Biohacking Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map

Description:

Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work.

21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 11:00-11:10 PDT


Title: Biohacking Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 11:00 - 11:10 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Biohacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Biohacking Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 14:30-15:30 PDT


Title: Bird Hunting Season: The Final Flight
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 14:30 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Surveillance tech often operates as a "black box" burdened by systemic technical debt. This session is the capstone of "Bird Hunting Season," an independent, self-funded teardown and research of the Flock Safety ecosystem. What began with an eBay purchase evolved into 51+ vulnerabilities across Raven gunshot detectors, Falcon LPRs, and Picard/Bravo compute boxes.

I detail the project's lifecycle: from hardware root via UART and unauthenticated EDL mode to protocol-layer failures. I demonstrate how broken mTLS, hardcoded Java Keystore secrets, and debugging compilations led to system level escalation. The narrative reaches its climax with an an explanation of how I found 63 live production camera feeds exposed without authentication to the public internet.

I also formalize the "Flea Market Supply Chain" attack, detailing how direct communication with upstream SoM manufacturers can bypass months of reverse engineering.

The talk culminates in the release of BirdShot: a 12 module testing framework that incorporates the exploits I've discovered as well as a TensorFlow harness (BirdEye) for hijacking proprietary ML models. I demonstrate how BirdShot automates the journey from a three button physical hotspot trigger to a persistent root shell, proving that when the birds are watching you, you can watch them back.

[1] Gaines, J. (2026). Examining the Security Posture of an Anti-Crime Ecosystem. Zenodo. DOI: 10.5281/zenodo.17584876

[2] Gaines, J. (2025-2026). Bird Hunting Season: Anti-Crime Ecosystem Research Repository. GitHub. https://github.com/GainSec/anti-crime-ecosystem-research

[3] MITRE/CWE. ES2510-692960d9: Improper Entitlement/Authorization for Protected Artifact Access. (Submission Pending/Accepted).

[4] https://github.com/justcallmekoko/ESP32Marauder/wiki/Flock-Sniff

[5] https://github.com/justcallmekoko/ESP32Marauder/wiki/flock-wardrive

[6] https://github.com/colonelpanichacks/flock-you

SpeakerBio:  Jon "GainSec" Gaines

Jon "GainSec" Gaines is a offensive security researcher, leader and "lifelong hacker" with over a decade of experience hacking all types of technologies for international organizations. By day, he serves as a Senior Security Engineer at Anduril, where he hacks next generation defense systems, following a career of Principal and Managing roles at security firms like NetSPI.

Jon has independently disclosed over 50 CVEs spanning critical infrastructure, hardware, web applications, software, mobile applications, and embedded systems. His technical research has been featured in Phrack Magazine and he maintains a diverse output of open-source projects, ranging from automated PCB hardware hacking tools to control in depth offensive agent governance frameworks. Beyond the lab, he also serves as an adjunct instructor at Herkimer College, where he is dedicated to mentoring the next generation of offensive researchers.

Jon remains committed to lifting the community through technical transparency, tooling, and the meticulous deconstruction of insecure infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W224 (Training) - Map

Description:
SpeakerBio:  Dawid Czagan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W224 (Training) - Map

Description:
SpeakerBio:  Dawid Czagan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 12:50-12:59 PDT


Title: Blacks In Cyber Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 12:50 - 12:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Blacks In Cyber Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Blacks In Cyber Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 14:00-15:59 PDT


Title: BloodBash: Lightweight CLI Python BloodHound Alternative
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

BloodHound is great... until your VM dies under Neo4j load, your login expires mid-exam, or you need hybrid AD + Entra ID insights without spinning up servers. Enter BloodBash: a standalone Python tool that ingests SharpHound (v6+) and AzureHound JSON directly, builds a full NetworkX graph in-memory, and spits out attack paths, misconfigs, and abuse suggestions — all offline, in colorful terminal glory. Born from a real OSCP crisis (BloodHound failed hours before exam start → BloodBash saved the DA path), this "vibe-coded" tool now detects shortest paths to high-value targets, ADCS ESC1-8 vulns, RBCD, Kerberoasting, GPO abuses, exposed app secrets/certificates, MFA bypass risks, privileged Entra roles, and unified hybrid attack chains. In this talk, you'll see: The OSCP war story that sparked it Live demo: Drop SharpHound + AzureHound files → instant colorful output, path visualization, abuse commands Key detections walkthrough (on-prem + cloud) Why lightweight CLI > GUI bloat for field ops, labs, and quick checks Roadmap: Metasploit integration, more exports, community features Full open-source on GitHub (https://github.com/DotNetRussell/BloodBash) — star it, fork it, break it. Attendees walk away with a new go-to tool for AD/hybrid recon.

SpeakerBio:  Anthony Russell, Cyber Security Software Engineer

Anthony Russell, is a senior cyber security engineer with over 13 years of professional experience building software. He has a focus in information security and has been featured in 2600 magazine, on Hak5 and has spoken at both Defcon and DerbyCon multiple times. Favorite things to discuss are blockchain technology, baking custom IoT devices, and everything infosec. You can see more of Anthony's work at SquidHacker.com or Twitter.com/DotNetRussell


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-11:59 PDT


Title: Blue Team Village CTF - Project Obsidian
Tags: Blue Team Village | Blue Team Village CTF | Contest
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 2 W213-217 (Blue Team Village) - Map

Description:

Join Blue Team Village for a defender-focused Capture the Flag competition centered on forensic analysis, malware activity in containerized environments, and cloud-infrastructure attacks. Participants will investigate container images, reconstruct incidents, and solve challenges ranging from beginner to expert. Challenge tracks include Container & Malware Forensics, Cloud Attack Forensics, and Converged Frontier. Participants can choose safe forensic snapshots or advanced live-malware challenges conducted in an egress-restricted Kubernetes sandbox.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 12:20-12:30 PDT


Title: Blue Team Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 12:20 - 12:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Blue Team Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Blue Team Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
Tags: DEF CON Training (Paid) (4-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W221 (Training) - Map

Description:
Speakers:Carlo Anez Mazurco,Mariana Ruiz

SpeakerBio:  Carlo Anez Mazurco

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

SpeakerBio:  Mariana Ruiz
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Saturday - 08:30-17:30 PDT


Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
Tags: DEF CON Training (Paid) (4-day) | DEF CON Training
When: Saturday, Aug 8, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W221 (Training) - Map

Description:
Speakers:Carlo Anez Mazurco,Mariana Ruiz

SpeakerBio:  Carlo Anez Mazurco

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

SpeakerBio:  Mariana Ruiz
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Saturday - 14:00-14:20 PDT


Title: BNPL's Blind Spot: Exploiting Business Logic Flaws in Buy Now Pay Later APIs
Tags: Payment Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:20 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Buy Now Pay Later has grown from a niche convenience to a $560 billion global ecosystem used by approximately 380 million people. Klarna, Afterpay, Affirm, and PayPal Pay Later process billions in transactions annually — and every transaction flows through a series of REST API calls. Security research on BNPL has focused entirely on fraud: account takeover, synthetic identity, first-party fraud. No one has looked at the API layer. This talk does.

We systematically test the BNPL payment flow — session creation, authorization, order management, and capture — using public sandbox environments. Our methodology focuses on business logic flaws: scenarios where the API functions exactly as designed but can be abused in ways developers never anticipated.

Confirmed finding: Klarna's capture endpoint accepts any captured_amount value down to 1 cent ($0.01) on a fully authorized order, with no minimum validation. A $100 authorized order can be captured for $0.01 — returning HTTP 201 Created with Klarna-Order-Validation: Valid. In vulnerable merchant implementations, customers receive goods while only $0.01 is collected — a $99.99 financial loss per transaction.

Attendees will leave with a practical attack methodology for BNPL integrations, an open-source reference implementation (vulnerable + patched), and a merchant-side security checklist.

SpeakerBio:  Furkan Fatih Demir, Independent Security Researcher & Penetration Tester, Barikat Cybersecurity

Conducts authorized security assessments across financial services, aviation, public sector and education, focused on business-logic vulnerabilities that evade conventional tooling.


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Saturday - 10:00-16:59 PDT


Title: Bomb Bot Challenge
Tags: Car Hacking Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

In conjunction with the talk, "Hacking the Bomb Bot: How I Learned to Stop Worrying and Love the Boomba", attendees have the opportunity to operate a bomb disposal robot. For those up for a challenge, you'll have a limited amount of time to interact with the robot and test your handling skills. The attendees with the best times will be invited back Sunday morning for a face-off challenge.

The winner will get their very own PackBot 510 to take home!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 11:00-12:59 PDT


Title: Book Signing - Aamiruddin Syed
Tags: Vendor Book Signing
When: Saturday, Aug 8, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map

Description:
SpeakerBio:  Aamiruddin Syed

Aamiruddin Syed is a Cybersecurity Professional with over a decade of experience specializing in DevSecOps, Shift-Left Security, Cloud Security, and Internal Penetration Testing. He is the OWASP Agentic AI Supply Chain Project Co-Lead and active contributor to the CSA Agentic AI initiative.

He authored Supply Chain Software Security – AI, IoT, Application Security (Apress/Springer) and has deep expertise in automating security in CI/CD pipelines, infrastructure as code, and cloud hardening. He routinely conducts internal security assessments of critical systems and is known for bridging the gap between security and engineering teams to embed security directly into products.

As recognized advocate for secure development, he is a frequent speaker , delivered workshops and chair sessions at leading industry conferences including RSA Conference, DEFCON, and Black Hat.

--

Author:

  1. Fault Detection in Microservice Architectures: Integrating Software Fault Prediction with DevSecOps
  2. Supply Chain Software Security: AI, IoT, and Application Security

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 16:00-16:59 PDT


Title: Book Signing - Avinash Majeti
Tags: Vendor Book Signing
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Avinash Majeti
Author:

Cybersecurity: Right Access at the Right Time


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 14:00-14:59 PDT


Title: Book Signing - Brandy Smith
Tags: Vendor Book Signing
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Brandy Smith
Author:

Vegas Hackware, Vol1 self titled and Vegas hackware Vol2 The WonderingRaven's Manifesto


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 13:00-13:59 PDT


Title: Book Signing - Christopher DeCarmen
Tags: Vendor Book Signing
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Christopher DeCarmen
Author:

The Cyber Calendar 2027, Y2K27 Edition


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 13:00-13:59 PDT


Title: Book Signing - Cindy Cohn
Tags: Vendor Book Signing
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map

Description:
SpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy's Defender published by MIT Press in March, 2026. She is also the co-host of EFF's award-winning podcast, How to Fix the Internet.

--

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 11:00-11:59 PDT


Title: Book Signing - Cindy Cohn
Tags: Vendor Book Signing
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy's Defender published by MIT Press in March, 2026. She is also the co-host of EFF's award-winning podcast, How to Fix the Internet.

--

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 14:00-14:59 PDT


Title: Book Signing - Garrett Gee
Tags: Vendor Book Signing
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map

Description:
SpeakerBio:  Garrett Gee
Author:

The Hacker Mindset


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 12:00-12:59 PDT


Title: Book Signing - Laura Scherling
Tags: Vendor Book Signing
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Laura Scherling
The Future of Hacking: The Rise of Cybercrime and the Fight to Keep Us Safe (July 2025, Hardback Launch; July 2026, Audio Book Launch)

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 15:00-15:59 PDT


Title: Book Signing - Mark Foudy
Tags: Vendor Book Signing
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map

Description:
SpeakerBio:  Mark Foudy
Author:

Neurodiverse Hackers: Unconventional Minds Shape Cybersecurity


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 16:00-16:59 PDT


Title: Book Signing - Thomas Wilhelm
Tags: Vendor Book Signing
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map

Description:
SpeakerBio:  Thomas Wilhelm
Author:

Professional Penetration Testing: Creating and Learning in a Hacking Lab (3rd Edition)

The Basics of Hacking and Penetration Testing (3rd Edition)


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 14:30-15:59 PDT


Title: Bots, Bounties, and Bullshit: An Honest Panel on AI in Hacking
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 15:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

AI has landed on both sides of the bug bounty table at once. Hackers are being told to use it, programs are drowning in the slop it produces, and a whole new attack surface, agents, RAG pipelines, and tool-calling LLMs, just showed up in scope.

This panel brings together working hackers who run AI in their daily flow, LLM security researchers who break AI for a living, and a moderator who has spent a decade in the scene. In 45 minutes they cut through the hype and get specific: which parts of recon, review, and reporting AI actually handles, how to hack the LLM-backed apps now in scope and get paid for it, and why the real edge isn't ChatGPT but the private agents and skills hackers are quietly building to turn one good idea into a hundred bugs.

Speakers:Ben "NahamSec" Sadeghipour,Vitor "busf4ctor" Falcao Habibe Costa,Joey Melo,Dustin "ph1r3574r73r" Farley,Ads Dawson,Johann "wunderwuzzi23" Rehberger

SpeakerBio:  Ben "NahamSec" Sadeghipour

Ben Sadeghipour (NahamSec) is a security researcher, ethical hacker, and educator who has spent more than a decade finding and disclosing critical vulnerabilities in some of the world's largest organizations. As one of the most recognized names in the bug bounty community, he has reported thousands of security flaws and consistently ranked among the top researchers on leading hacking platforms. Beyond his own research, Ben is passionate about lowering the barrier to entry in cybersecurity. Through his widely followed educational content, live streams, and the conferences he founds and organizes, he has helped train a new generation of hackers around the world. His work blends deep technical expertise with a commitment to mentorship and community building.Ben speaks regularly at industry conferences on offensive security, bug bounty hunting, and building a career in cybersecurity.

SpeakerBio:  Vitor "busf4ctor" Falcao Habibe Costa, Frontier AI Red Team Operator, BT6

Vitor is an AI security researcher, Community Manager at Critical Thinking, and a Google VRP hunter, named Best AI Researcher at Google bugSWAT. He's part of the BT6 team and hunts bugs full time.

SpeakerBio:  Joey Melo

Joey is a Principal Security Researcher at CrowdStrike and a contributor to AI safety programs at OpenAI and Anthropic. He specializes in offensive security research and adversarial analysis of complex systems, with a particular focus on AI/ML infrastructure and large language models. His work has led to the discovery of critical vulnerabilities and novel exploitation techniques, helping organizations better understand and defend against sophisticated threat actors. He has experience across red teaming, exploit development, and designing resilient architectures for high-risk environments. Joey has earned recognition through bug bounty programs and multiple security competitions, with over $100,000 awarded for vulnerability research. He is also an OSCP, OSCE³ and CRTO-certified professional.

SpeakerBio:  Dustin "ph1r3574r73r" Farley, BT6

Dustin Farley has spent more than a decade building software, securing it, and figuring out how to break it. Today, he focuses on AI security, where he spends his time red teaming large language models, AI agents, and other emerging AI systems. His interests include prompt injection, jailbreaks, adversarial testing, and turning weird edge cases into useful security research. He firmly believes that the fastest way to understand a system is to see how it fails.

SpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta's MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting "Exfil Everything: A Year of Stealing Data from AI Agents" at Bug Bounty Village DC34 (schedule pending publication).

SpeakerBio:  Johann "wunderwuzzi23" Rehberger
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-11:20 PDT


Title: Break Things, Learn Things: Hands-On Hacking for Beginners
Tags: Noob Community | Creator Workshop
When: Saturday, Aug 8, 10:00 - 11:20 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

You don't need years of experience to start thinking like an attacker—you just need the right environment and someone to show you the ropes. In this hands-on, 45-minute session, Evolve Security Academy completely bypasses the theory to walk you through the fundamentals of ethical hacking in a live, browser-accessible lab environment. You'll adopt an attacker mindset, perform real reconnaissance, run vulnerability scans, and assess live exploits firsthand. Best of all, all registered participants get 7 days of extended access to the CyberLab platform to keep hacking at their own pace after DEF CON.

SpeakerBio:  Evolve Security Academy
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 13:30-14:30 PDT


Title: Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure
Tags: Cloud Village | Creator Event/Activity | Attack
When: Saturday, Aug 8, 13:30 - 14:30 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) A - Map

Description:

Amazon Bedrock is no longer just a research toy. It's embedded in CI/CD pipelines, production applications, and development workflows, often granted sweeping permissions over S3, IAM, and other AWS services. The rapid adoption of agentic AI has reproduced a new class of configuration patterns that security teams haven't caught up with yet. In this hands-on attack lab, Varonis Threat Labs takes you inside real Bedrock deployment patterns observed across AWS environments. Participants will move from initial Bedrock access through data exfiltration, lateral movement, and AWS account compromise, exploiting the same misconfigurations we've found in the wild. No AI hype. No prompt injection gimmicks. This is cloud infrastructure security, and Bedrock just happens to be the way in. Leave with attack paths you can take back to your own environment and the defensive controls to shut them down. Tal’s Bio: Tal Peleg, also known as TLP, is a senior security researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows domains, SaaS applications, and cloud infrastructure. His research is currently focused on cloud applications, APIs, and agentic applications.

Speakers:Tal Peleg,Maya Parizer

SpeakerBio:  Tal Peleg

Tal Peleg, also known as TLP, is a senior security researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows domains, SaaS applications, and cloud infrastructure. His research is currently focused on cloud applications, APIs, and agentic applications.

SpeakerBio:  Maya Parizer

Maya Parizer is a Security Researcher at Varonis with a passion for cloud security, identity, and data protection, specializing in IaaS and AI. Maya dives deep into every project, thoroughly investigating cloud environments to uncover potential vulnerabilities and stealthy attack techniques. Her experience spans both offensive and defensive disciplines — including CSPM, DSPM, vulnerability research, detection engineering, and product security research in cloud environments.


Return to Index    -    Add to Google    -    ics Calendar file

Cryptocurrency Village - Saturday - 16:00-16:59 PDT


Title: Breaking Ciphers and Zero-Knowledge Proofs
Tags: Cryptocurrency Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Zero-knowledge proofs are a method of demonstrating that a statement is true, without revealing any other information about it, and form the backbone of all the cryptocurrencies we know and love. In this workshop, we will unpack what zero-knowledge proofs really are, how they work, and what they do to ensure that your personal information remains private. A familiarity with basic cryptography is helpful, but not strictly necessary.

Speakers:Luke Szramowski,Freeman Slaughter,Diego "rehrar" Salazar

SpeakerBio:  Luke Szramowski, Stack Wallet

Luke Szramowski is a mathematical researcher, with a Bachelor's Degree in Mathematics and two Master's Degrees, one in Math, with a focus in Number Theory and another in Math with a focus in Coding Theory. In his free time, Luke works on a litany of different math problems, mainly regarding Number Theoretic conjectures and playing all different types of games.

SpeakerBio:  Freeman Slaughter, Cypher Stack

Freeman is a cryptographic researcher specializing in zero-knowledge proofs and code-based cryptography. He has co-authored several influential peer-reviewed works, including designing the post-quantum signature scheme CROSS, which is currently under review for government standardization. His work is driven by a strong commitment to advancing the privacy and security of cryptocurrencies such as Monero and Salvium.

SpeakerBio:  Diego "rehrar" Salazar, Cypher Stack

Diego 'rehrar' Salazar has been around the FOSS and cryptocurrency communities for eight years. He owns and runs Cypher Stack, a company that performs novel research and makes contributions to various FOSS projects. He has organized and managed several villages at defcon, c3, and more.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 15:00-15:59 PDT


Title: Breaking MCP Trust Boundaries: Cross-Server Authority Injection in Agent Toolchains
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

Modern MCP deployments assume that low-privilege tools remain low-risk when reviewed independently. In practice, host agents compose outputs across multiple tools and privilege levels, creating authority paths that do not exist in any single server's standalone review.

This workshop demonstrates a compositional offensive primitive in MCP environments: a low-privilege server influencing the parameters of a high-privilege destructive operation through shared planning context.

Attendees will see a controlled lab reproduction where a read-only MCP server shapes the parameters of a privileged SQLite-backed delete operation. The approval prompt shown to the operator accurately describes the final action but omits the upstream provenance that influenced it.

The workshop introduces Urd, an open-source compositional analysis tool for MCP deployments. Urd reconstructs authority flow across servers using runtime tracing and manifest analysis, allowing operators and red teamers to identify undeclared cross-tool influence paths.

The focus of the session is not prompt injection or model jailbreaks. The focus is cross-server authority flow, provenance loss, and workflow-level trust failure in agentic systems.

This session includes a hands-on tactic where attendees reproduce the compositional failure locally, inspect runtime traces, generate divergence findings, and modify the lab to observe how low-trust inputs can influence privileged operations across MCP toolchains.

SpeakerBio:  Yevhen Pervushyn

Yevhen “valh4x” Pervushyn is the founder of Red Asgard, a security research firm focused on AI integration security, offensive security, and protocol analysis.

His work focuses on the operational security of agentic systems: orchestration boundaries, authorization flow, provenance, and workflow-level trust failure in AI deployments.

Prior to Red Asgard, he worked in blockchain security auditing and decentralized protocol analysis, experience that directly informs his current research into compositional trust failures in MCP-based systems.

He previously presented MCP security research at the SANS AI Cybersecurity Summit 2026. This session presents new technical research, tooling, and hands-on lab material focused on offensive analysis of MCP orchestration behavior.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Saturday - 12:00-12:59 PDT


Title: Breaking PBKDF - Adversarial Cryptanalysis and Techniques for Hunting Cryptographic Flaws
Tags: Payment Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Using decades-old OpenJDK PBKDF flaws, forgotten RFCs, hash collisions, and a few semantic edge cases, we’ll compromise multiple cryptographic systems with little more than a handful of carefully chosen values and several “useless” tools.

This talk explores how implementation bugs, legacy compatibility, and architectural assumptions can undermine otherwise sound cryptography—and why the real attack surface is often everything around the algorithm.

SpeakerBio:  Ken Pyle, Security Researcher, Bank of America

Cybersecurity researcher, exploit developer and conference speaker focused on vulnerability discovery, reverse engineering and adversarial cryptanalysis; has presented at DEF CON, ShmooCon and RSA Conference.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W212 (Misc Meeting Room) - Map

Description:
SpeakerBio:  Red Team Alliance
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W212 (Misc Meeting Room) - Map

Description:
SpeakerBio:  Red Team Alliance
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 16:30-16:59 PDT


Title: Breaking the Chains of Cloud Giants: Building a Fully Autonomous Personal Cloud on NixOS
Tags: Nix Vegas Community | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Privacy and digital agency are under siege by dark patterns, aggressive data harvesting, and SaaS monopolies. It’s time to reclaim our digital self-determination. This talk demonstrates how to build a production-ready, fully autonomous personal cloud using the declarative power of NixOS.We will explore how to self-host drop-in replacements for mainstream services—including Nextcloud for storage, Vaultwarden for passwords, and Matrix for communication. Attendees will learn how to turn any old PC or cheap VPS into an unbreachable digital fortress featuring automated backups, end-to-end encryption, and complete data isolation. Discover how NixOS makes personal infrastructure reproducible, resilient, and entirely yours.

Speakers:Maksim Kuskov,Mikhail Ilin

SpeakerBio:  Maksim Kuskov

Security engineer in Yandex, CTF organizer & player @ HSE IS '29

SpeakerBio:  Mikhail Ilin

I am an appsec with a strong background in competitive hacking. Over the years, I have won multiple national Cyber Security Sports Championships and currently serve as an ambassador for the Standoff 365 cybersecurity ecosystem. Beyond traditional technical exploitation, my research focuses on the intersection of clinical psychology and practical social engineering. As a strong advocate for digital self-determination, I view open-source infrastructure and NixOS not just as engineering tools, but as essential defensive shields against platform lock-in and corporate surveillance.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map

Description:
Speakers:Anant Shrivastava,Riyaz Walikar

SpeakerBio:  Anant Shrivastava

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

SpeakerBio:  Riyaz Walikar
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map

Description:
Speakers:Anant Shrivastava,Riyaz Walikar

SpeakerBio:  Anant Shrivastava

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

SpeakerBio:  Riyaz Walikar
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Bricks in the Air
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft's control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required - all target devices, materials, and interfaces are provided!

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Bridging the GAP: Hands-On Embedded Hardware Hacking
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:
Speakers:Aaron Wasserman,Garrett Freibott,Will McCardell

SpeakerBio:  Aaron Wasserman, Praetorian
No BIO available
SpeakerBio:  Garrett Freibott, Praetorian
No BIO available
SpeakerBio:  Will McCardell, Praetorian
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Bridging the GAP: Hands-On Embedded Hardware Hacking
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:
Speakers:Aaron Wasserman,Garrett Freibott,Will McCardell

SpeakerBio:  Aaron Wasserman, Praetorian
No BIO available
SpeakerBio:  Garrett Freibott, Praetorian
No BIO available
SpeakerBio:  Will McCardell, Praetorian
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 13:30-14:30 PDT


Title: Bring Your Own Root Of Trust
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:
Modern computers depend on a hardware root of trust: a component assumed to start trustworthy and is used to verify everything that follows. This has evolved from ROM boot code and fixed keys into TPMs, secure boot chains, external security controllers, and attestation mechanisms used far beyond disk encryption. Today, platforms trust these devices because they are certified, immutable, and built into the hardware, but what if that assumption is wrong? Starting from real hardware traces, failed approaches, and a pile of development boards, we arrive at a $45 FPGA-based SPI TPM that can appear to Windows 11 as a platform trust anchor. From there, we explore what this means for secure boot, measured boot, platform attestation, anticheat, AI infrastructure, and the broader belief that hardware identity is difficult to counterfeit. We will release the code, gateware, prompts, and data so others can reproduce the work and push it further.

https://twpm.dasharo.com/ https://github.com/microsoft/ms-tpm-20-ref

Speakers:Mickey "@HackingThings" Shkatov,Jesse Michael

SpeakerBio:  Mickey "@HackingThings" Shkatov, Eclypsium

Mickey has been involved in security research for over a decade, specializing in breaking down complex concepts and identifying security vulnerabilities in unusual places. His experience spans a variety of topics, which he has presented at security conferences worldwide. His talks have covered areas ranging from web penetration testing to the intricacies of BIOS firmware.

SpeakerBio:  Jesse Michael, Eclypsium

Jesse is an experienced security researcher focused on vulnerability detection and mitigation who has worked at all layers of modern computing environments from exploiting worldwide corporate network infrastructure down to hunting vulnerabilities inside processors at the hardware design level. His primary areas of expertise include reverse engineering embedded firmware and exploit development. He has also presented research at DEF CON, Black Hat, PacSec, Hackito Ergo Sum, Ekoparty, and BSides Portland.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-10:59 PDT


Title: Bug Bounty Village CTF - Open
Tags: Bug Bounty Village | Bug Bounty Village CTF | Contest
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: Online

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Saturday - 11:00-12:30 PDT


Title: Build-A-Badge Workshop
Tags: Maker's Village | Creator Event/Activity
When: Saturday, Aug 8, 11:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Welcome to the Build-A-Badge Workshop! We've cultivated some interesting maker mediums to bring you a unique badge that's all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you'll be assigned a group number and split off into teams within the Makers' Village, hitting each station for the badge assembly. You'll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con.

Speakers:hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer

SpeakerBio:  hunny
No BIO available
SpeakerBio:  Teazee
No BIO available
SpeakerBio:  Buddha
No BIO available
SpeakerBio:  MLP
No BIO available
SpeakerBio:  M-Nelly
No BIO available
SpeakerBio:  Alchemmer
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Saturday - 11:00-11:30 PDT


Title: Building a Hacker Haven: The Long Game of Growing a Local Hacker Community
Tags: DEF CON Groups | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:
DEF CON 30 sent us home with an idea: our city needed a hacker community.
Three years later, that idea has grown into a 501(c)(3) nonprofit, a thriving monthly meetup, a network that helped us launch a regional conference (wiscon.io), and a long-term vision for a brick-and-mortar hackerspace. Along the way, we've learned a lot, made our share of mistakes, and discovered what it really takes to build a sustainable community from the ground up.
This talk is a practical guide to starting and growing a DEF CON Group without burning yourself out in the process. We'll cover getting approved by DEF CON Groups, incorporating as a nonprofit, raising money from your community, building a board that works well together, writing bylaws that set you up for success, handling Code of Conduct issues, and planning for long-term growth beyond monthly meetups.
We'll also talk about something that doesn't get enough attention, building a community as a team. The strongest groups aren't built by one person doing everything, they're built by people who share the workload, support one another, and create something that can outlast any single organizer.
Expect honest lessons learned, practical advice, real numbers, and plenty of war stories. We'll also provide a companion website packed with all the details that you can adapt for your own community.
If you've ever thought about starting a DEF CON Group, building a local hacker community, or creating something that brings people together, this talk is for you!
Speakers:Ryan Zagrodnik,Allie Zagrodnik

SpeakerBio:  Ryan Zagrodnik, DC608

Ryan Zagrodnik is a Senior Penetration Tester with over sixteen years of experience in offensive and defensive security roles. He holds OSCP and CISSP certifications and has previously worked on internal red teams and held a U.S. Government security clearance doing offensive security for the Department of Defense and Department of Education. Ryan has presented at CypherCon, SecretCon, DEF CON Hardware Hacking Village, BSides MKE, GRASSr00tz, and Skunks Misery.

SpeakerBio:  Allie Zagrodnik, DC608

Allie Zagrodnik is a cybersecurity professional and community organizer based in Madison, Wisconsin and quickly discovered a passion for the human side of security, community building, and mentorship within the industry.

She is the cofounder of DC608, a Madison-based DEF CON group focused on creating an inclusive and welcoming space for anyone interested in cybersecurity, regardless of skill level or background. She is also the founder of Wisconsin Information Security Conference, a community-driven conference focused on education, networking, and growing the cybersecurity community throughout the Midwest.

Outside of cybersecurity, Allie enjoys spending time with her husband, three dogs, and three cats, while proudly representing Wisconsin through her love of the Green Bay Packers and the local hacker community.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Saturday - 13:00-13:30 PDT


Title: Building a Strong Community Culture presented by DC407
Tags: DEF CON Groups | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Healthy DEF CON Groups are built by more than one person. This session focuses on creating a community culture where members are encouraged to participate, contribute, speak, volunteer, and eventually help lead. DC407 will discuss consistency, mentorship, leadership mindset, and practical ways to move people from passive attendance into active involvement. This workshop is for organizers who want to build a group that is welcoming, resilient, and bigger than any single organizer.

Speakers:Edna Jonsson,Dustin

SpeakerBio:  Edna Jonsson, DC407

Edna is one of the DC407 group leaders and enjoys helping others come up in the cyber community. Edna is the volunteer coordinator at BSides Orlando and hosts the Security Chipmunks podcast.

SpeakerBio:  Dustin, DC407

I enjoy helping people. I'm a security enthusiast, if it's related to security then I'm probably interested. I've helped facilitate DC4😃7 for 8+ years.


Return to Index    -    Add to Google    -    ics Calendar file

Packet Hacking Village - Saturday - 13:00-13:59 PDT


Title: Building Better Backdoors Than China
Tags: Packet Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

PhantomShell is a Linux command & control implant that sniffs traffic of active TCP services to create a bidirectional C2 channel through any open port, using only stateful inbound traffic. It captures packets at the link layer, allowing it to read packets destined for legitimate services. Responses are constructed as raw TCP frames with sequence numbers derived from the original connection, making them difficult to distinguish from the service's own replies. This effectively turns every open service port into a bind shell, making the implant effectively impossible to firewall so long as any service remains externally accessible.

SpeakerBio:  Khael Kugler, Lead Offensive Security Engineer, Praetorian Security, Inc.

Khael Kugler is a Lead Security Engineer at Praetorian, where he primarily executes on red team and IoT engagements. Khael also volunteers as a red teamer for multiple CCDC regions, primarily focusing on linux persistence for SECCDC and WRCCDC (if you're interested in helping, reach out!).


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 10:30-10:59 PDT


Title: Building Hackbots
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Saturday, Aug 8, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Building AI-Powered Penetration Testing Bots

SpeakerBio:  Jason "jhaddix" Haddix, CEO and "Hacker in Charge" at Arcanum Information Security

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 12:00-13:59 PDT


Title: Building Hackbots
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:
Description: Building AI-Powered Penetration Testing Bots

In this talk, we'll walk through the core design philosophy behind AI hackbots and the architecture that makes them work: single-purpose vs. multi-stage bots, context engineering for targeted prompting, and tool integration with output parsing workflows.

Then we'll get hands-on. We'll live-build a functional hackbot for a common offensive task — demonstrating asset discovery, endpoint analysis, or mutation-focused testing (e.g., XSS/SSRF) — and show how context engineering and hallucination mitigation work in practice against real targets. You'll see where AI genuinely accelerates reconnaissance and web analysis, and where it falls flat if you aren't careful. We'll close with lessons on cost optimization, auditability, and integrating hackbots into actual engagements.

Who should attend: Pentesters and bug bounty hunters with offensive security experience who want to meaningfully integrate AI into their workflow — not as a novelty, but as reliable tooling.

What you'll walk away with: A clear mental model for when and how to build hackbots, a live demo you can replicate, and a path into the full course where you'll build seven production-ready bots from asset discovery through mutation testing.

Speakers:Jason "jhaddix" Haddix,Ryan Bonner

SpeakerBio:  Jason "jhaddix" Haddix, CEO and "Hacker in Charge" at Arcanum Information Security

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

SpeakerBio:  Ryan Bonner, Lead Security Engineer at Arcanum Information Security

Ryan Bonner is a Lead Security Engineer at Arcanum Information Security, where he builds AI systems, hacks them, and runs application penetration tests. Off the clock he hunts wide-scope bug bounty programs.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Saturday - 16:00-17:45 PDT


Title: Building Silkscreens and carving stamps
Tags: Maker's Village | Creator Event/Activity
When: Saturday, Aug 8, 16:00 - 17:45 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

See a demonstration of the steps to making your own silk screens and get to explore the Makers' Village Stamps and screens. Bring swag to experiment on!

SpeakerBio:  hunny
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 16:00-17:59 PDT


Title: Burp, But Yours: Hands-On Extension and Bambda Development
Tags: Bug Bounty Village | Creator Workshop
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Ever found yourself scrolling through thousands of requests looking for the few that matter? Repeating the same checks across every target? Wishing Burp Suite would automate part of your workflow?

This hands-on workshop teaches bug bounty hunters how to build Burp customizations that surface valuable signals and eliminate repetitive work.

SpeakerBio:  Hannah L, Burp Suite Extensibility Specialist at PortSwigger

Hannah is an Extensibility Specialist at PortSwigger, where she helps shape how Burp Suite can be adapted to real-world testing workflows. She works hands-on with submissions to the BApp Store, as well as the Bambdas and BChecks community repositories, helping refine extensions and community contributions before they’re shared more widely.

She especially enjoys making extensions better and finding creative workarounds to awkward testing problems. She has also written extensions for customers, internal teams, and her own projects, including the original WebSocket Turbo Intruder extension.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 12:00-12:59 PDT


Title: C(2)YA: Inside the Adversary's Inbox
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

85 findings exploitable from the internet with zero prior access. 28 takedown chains. Crypto failures that let you decrypt all C2 traffic with one recovered key.

Here's how I got there. I'd been using coding agents to find bugs in software. Then I thought: what if I did this from the defender's side, against the tools that threat actors actually use? I pointed LLM-assisted research at five C2 frameworks: Havoc, Mythic, Sliver, Covenant, AdaptixC2. Six months later, 251 design flaws, behavioral weaknesses, and vulnerabilities. Validated every finding in realistic lab environments. Then passively tapped 35 live servers via Shodan and Censys, and found operators running campaigns against victims in education, manufacturing, legal, and biotech across eight countries.

Eight bug classes recur across all five codebases. Findings rated on a defender-weighted scale, because CVSS doesn't tell you which bug finds the server. Havoc, the most-deployed framework in the dataset, was archived on February 21, 2026. No patches coming. Defenders carry the load now.

AI isn't just for protecting systems. Defenders can point it at the attackers' own tools and find real ways to fight back. All findings for maintained projects disclosed through proper channels. Every demo against realistic lab environments I control.

SpeakerBio:  Vitaly Simonovich, Cato Networks

Vitaly Simonovich is a Senior Security Researcher at Cato Networks on the CTRL threat research team, following over ten years in cybersecurity across Cato CTRL and Imperva, where he focused on DDoS and botnet research from 2019 to 2023.

He coined HashJack, the first indirect prompt injection weaponizing URL fragments against AI browser assistants, and LAMEHUG, the first LLM-powered malware publicly linked to APT28. He documented the Immersive World jailbreak against Microsoft Copilot and introduced the Zero-Knowledge Threat Actor concept. His research has driven ten coordinated security disclosures across Open WebUI, MongoDB, Jenkins, BIND, Moodle, TYPO3, Perplexity, Microsoft, and others.

His work has been covered by Forbes, The Economist, Business Insider, VentureBeat, The Register, The Hacker News, and CyberScoop.

Conference talks: RSA Conference 2026, Botconf 2022, BSidesTLV 2025 AI Hacking Village, Qubit 2025 Prague, RootedCon 2026.

vitalysim.com


Return to Index    -    Add to Google    -    ics Calendar file

Call Center Village - Saturday - 10:00-17:59 PDT


Title: Call Center Village - Open
Tags: Call Center Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist's desk remains almost completely unmonitored. Nobody's deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open.

And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels.

Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak.

On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you're ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34.

We've also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for.

No prior experience required. If you know how to make a phone call or type a message, you're already qualified. Equipment is provided, including laptops and ANC headsets - but you're more than welcome to bring your own devices.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-16:59 PDT


Title: Car Hacking Village CTF
Tags: Car Hacking Village | Car Hacking Village Capture the Flag (CTF) | Contest
When: Saturday, Aug 8, 10:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Participate in CHV's CTF to learn and play with automotive technology. This year's contest features problems on smart chargers, automotive ECU harnesses, our own badge, and more! Don't worry about bringing your own automotive specific gear, we've got you covered. Stop by the village to register, get started, and get hacking.


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Saturday - 10:00-17:59 PDT


Title: Car Hacking Village Open
Tags: Car Hacking Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Welcome to the Car Hacking Village - a place where you can learn all about the cool technology that powers modern connected transportation. The CHV at DEF CON 34 will feature a whole race track of activities including Creator Stage presentations, a competitive CTF (with awesome prizes!), an amazing badge for sale that doubles as a fully functional car hacking tool, a scavenger hunt, and more!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:00-11:59 PDT


Title: Car Hacking Village Scavenger Hunt Contest
Tags: DEF CON Official Talk | Car Hacking Village
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Go out and find some goofy stuff!!

The DEF CON 34 CHV Scavenger Hunt rules and treasure list can be found at the attached link.

Start Time: Friday, August 7 10:00

End Time: Sunday, August 9: 12:00

One Car Hacking Village 2026 Badge will be awarded to the first player to complete the Scavenger Hunt!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 11:00-12:59 PDT


Title: Cards Against Vulnerabilities
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map

Description:

Join us for "Cards Against Security: Trust Me, It's Secure," a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: Cat-astrophic Hacking: Breaking Into Smart Litter Boxes
Tags: IoT Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

What happens when your cat’s litter box joins the Internet of Things? Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover security risks.


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 14:00-14:59 PDT


Title: Catching Cheaters in Super Smash Bros Melee
Tags: Game Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

Super Smash Bros Melee for the Nintendo GameCube is one of the oldest active fighting game communities, with a storied 25 year history.

Would you believe that people try to cheat at it?!

I am the maintainer of the SLP Enforcer tool, and help with cheating investigations for the community. I'm going to share some stories of people trying to cheat and getting caught! Along the way I'll describe all the ways one could try to cheat at Melee, and how our detection tools work.

SpeakerBio:  AltF4

Dan "AltF4" Petro is a Principal Security Engineer at Bishop Fox R&D. As a longtime pentester at Bishop Fox, Dan's presented public research on everything from hacking into smart safes, compromising the power grid, breaking into secure facilities, and cheating at online video games. There was even that time he found a vulnerability in (nearly) every IoT device. But Dan's favorite research project is always whichever is next.


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 11:30-11:59 PDT


Title: Catching Cheaters in Super Smash Bros Melee
Tags: Game Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Super Smash Bros Melee for the Nintendo GameCube is one of the oldest active fighting game communities, with a storied 25 year history.

Would you believe that people try to cheat at it?!

I am the maintainer of the SLP Enforcer tool, and help with cheating investigations for the community. I'm going to share some stories of people trying to cheat and getting caught! Along the way I'll describe all the ways one could try to cheat at Melee, and how our detection tools work.

SpeakerBio:  AltF4

Dan "AltF4" Petro is a Principal Security Engineer at Bishop Fox R&D. As a longtime pentester at Bishop Fox, Dan's presented public research on everything from hacking into smart safes, compromising the power grid, breaking into secure facilities, and cheating at online video games. There was even that time he found a vulnerability in (nearly) every IoT device. But Dan's favorite research project is always whichever is next.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 14:00-14:59 PDT


Title: Chaining Credentials Through the AI Infrastructure Nobody Secured
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

AI/ML services are proliferating across enterprise networks without security review. Developers deploy Ollama instances locally, data science teams stand up Jupyter notebooks and MLflow registries without authentication, platform engineers run Ray clusters and LiteLLM API gateways on default configurations, and MCP tool servers expose file system access and code execution to the network. These services rarely appear in traditional vulnerability scans and are seldom included in asset inventories.

To measure the scope of this problem, I built a 5-VM benchmark lab simulating four independent teams deploying 19 AI/ML endpoints with 122 planted findings. The lab includes a manifest-driven scoring harness that enables objective detection measurement across three validation modes: standard (substring matching), strict (host attribution and source module accuracy), and contract (workflow metadata and evidence chain verification).

The tool is aipostex, an open-source single-binary Go framework designed for the full AI infrastructure attack lifecycle. It performs network discovery across 20+ AI service families, executes 123 vulnerability templates, and provides 17 dedicated exploit modules covering Ollama, Jupyter, MCP servers, LiteLLM gateways, MLflow, Ray, vector databases, and inference endpoints. MCP coverage includes schema poisoning, environment variable extraction, and CVE-specific checks for DNS rebinding and remote code execution through tool servers. A separate model-scan capability identifies deserialization risk in pickle, PyTorch, TensorFlow, and ONNX model files.

The live demonstration walks through a credential chain attack against the benchmark lab. The attack begins with Ray cluster enumeration to harvest API keys from job environment variables, pivots into MLflow where experiment run parameters and tags contain embedded secrets and cloud credentials, then chains those tokens to authenticate against a HuggingFace TGI inference endpoint. Each hop crosses a different team's infrastructure, discovered and linked by the tool's credential chain-loading engine.

The session also covers the safety and operational controls that make this suitable for production engagements: explicit --force-exploit gating on mutating actions, --mode full requirement for exploit templates, proof-strength classification on every finding (reachable, read-confirmed, execution-confirmed), and OPSEC features including User-Agent rotation, TLS fingerprint randomization, and timing jitter.

Open-source release coinciding with presentation.

Does your workshop come with a tactic?

Yes. The tactic is "Hands-On: Credential Chain Exploitation Across Shadow AI Infrastructure."

Each group of about five attendees gets their own isolated cloud-hosted lab instance, a full 5-VM environment spun up on AWS and accessible only through a VPN tunnel. You SSH into your group's attack box and work through a guided attack chain against the lab's 19 AI/ML endpoints.

First, you scan the /24 and discover what's running across four target hosts. The tool fingerprints each endpoint and gives you structured next steps, so even if you've never touched MLflow or Ray before, you know what to run next.

Then you follow the credential chain. Enumerate a Ray cluster and pull API keys from job environment variables. Take those into MLflow and extract secrets from experiment run parameters and tags. Chain the tokens forward to authenticate against a HuggingFace TGI inference endpoint. Three hops, three teams' infrastructure, all connected.

At the end, you run the scoring harness against your results and see how you did. Detection rate, missed findings, proof-strength breakdown, all compared against the 122-finding answer key.

Groups that finish the guided chain early can explore additional attack surfaces across the lab's remaining endpoints, including MCP schema poisoning, Jupyter cell secret mining, and vector database injection. The scoring harness covers all 122 findings, not just the guided path, so there is plenty of room to improve your score.

Each wave runs about 50 minutes with a 10-minute reset between waves. I'll run two waves. All you need is a laptop with an SSH client and a WireGuard client. No prior AI/ML experience required. Everything you use during the tactic, the tool binary, lab docs, and scoring harness, is yours to take home and run on your own infrastructure.

https://professor-moody.github.io/aipostex/

https://professor-moody.github.io/aipostex-lab/

SpeakerBio:  Nathan Keys

Nathan is a security researcher focused on ML supply-chain security. Their research spans information hiding in model artifacts, data poisoning of retrieval pipelines, and post-exploitation of AI infrastructure. Nathan is currently a principal penetration tester in the financial sector. This is their first DEF CON talk. Outside of his passion for research, Nathan loves to touch grass, read all manner of scientific study or journal, and listen to old school southern rap (think UGK). Nathan has changed careers more than once, from winemaking to restaurants to professional hacking now for the last seven years, and he loves a good story and a good conversation.


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 10:00-15:59 PDT


Title: Chill Zone: Casual Games & TASBot Smash Demo
Tags: Game Hacking Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

DEF CON got you overwhelmed? Come relax and play Project Plus, a modded version of Super Smash Bros Brawl. Or compete against a frame perfect Smash Bot!


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 16:00-16:59 PDT


Title: Chill Zone: Smash (Project Plus) Tournament with Prizes
Tags: Game Hacking Village | Creator Event/Activity
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

Compete against other attendees in a modded version of Super Smash Bros Brawl! This is a low stakes tourney that is beginner friendly and open to all.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 15:00-15:55 PDT


Title: ChronoRoot: Time-Traveling Through Kernel Trust Boundaries
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Join B.I.C. Village for ChronoRoot: Time-Traveling Through Kernel Trust Boundaries, a welcoming session focused on kernel trust boundaries, system internals, and how attackers challenge low-level security assumptions. Come ready to learn, ask questions, and connect with the community.

Speakers:Ahmeen Muhammad,Sydney Johns

SpeakerBio:  Ahmeen Muhammad, Cybersecurity Professional / Community Speaker

Ahmeen C. Muhammad is a Senior Penetration Testing Consultant and Army cyber veteran with experience conducting offensive security operations across enterprise and government environments. His interests include red teaming, reverse engineering, Malware Development, endpoint security evasion, and AI security testing. When he's not on an engagement, Ahmeen spends his time researching emerging attack techniques, developing offensive tooling, and sharing knowledge with the cybersecurity community. He is passionate about helping organizations better understand their security posture through realistic adversary emulation and hands-on offensive security research.

SpeakerBio:  Sydney Johns, AI/ML Engineer, Virginia Tech Researcher

Sydney Johns is an Artificial Intelligence Researcher at GitHub and a Ph.D. student in Computer Science at Virginia Tech. Her research interests include artificial intelligence, machine learning, reverse engineering, and ethical hacking. She holds a Bachelor’s degree in Electrical Engineering and a Master’s degree in Cybersecurity, along with CompTIA Security+ and EC-Council Certified Ethical Hacker certifications. Sydney is passionate about STEM outreach, mentorship, and creating pathways for more people to enter technology and cybersecurity. In her spare time, she enjoys playing Overcooked and Animal Crossing, painting, and shopping.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 15:30-15:59 PDT


Title: Cl0p ^_- Til You Drop - 6 years, 9 Campaigns, 7 0-Days
Tags: Recon Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Cl0p has executed at least nine major exploitation campaigns since 2020, targeting file transfer and edge devices from Accellion to MOVEit to Centrestack. Each campaign looks different on the surface, different CVEs, different victims, different tooling. But their infrastructure tells a different story.

This talk presents the results of a multi-year infrastructure reconnaissance effort tracking Cl0p's hosting, ASN usage, and operational patterns across all known campaigns. By mining passive DNS data, network telemetry, and hosting records, I mapped the infrastructure behind each campaign and identified patterns the group can't seem to shake — including a favorite bulletproof hosting provider used across four separate campaigns, a finding that roughly one-third of their ASNs get recycled, and pre-attack reconnaissance probing observed as far as two years before exploitation.

SpeakerBio:  Eli Woodward, Senior Threat Intelligence Advisor with Team Cymru

Eli Woodward is a cyber threat intelligence advisor with Team Cymru. He's worked in a variety of industries including financial services and government, and has seen the range of organizations from extremely well-resourced and capable to the shoestring budget. This has given him unique insights into CTI at all levels of complexity, maturity, and resources. He holds a master's degree in Intelligence and Security Studies and also plays bagpipes competitively.


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Saturday - 11:00-11:30 PDT


Title: Classic US High Sec: how to pick a Medeco
Tags: Lockpick Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

With pins that both slide up and down and rotate, Medeco locks have been one of the most common high security locks in the US for over 50 years. Come learn exactly how they work, and how to open them with standard picks.

SpeakerBio:  Max A
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 11:00-11:45 PDT


Title: Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | DEF CON Demo Labs
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Clew is an automated fuzzing-candidate extraction pipeline for environment-sensitive malware analysis. Evasive malware routinely queries its execution environment via Windows API calls to hide functionality until specific environmental conditions are met. By hooking these API calls, a fuzzer can reveal such execution paths that are typically hidden during standard analysis. No seed corpus of environmental fuzzing candidates currently exists for this application. As a result, current API-hooking fuzzers rely on hand-written, sample-agnostic starting values and blind mutations that cannot scale to the diverse evasion techniques seen in sophisticated samples. Clew addresses this by analyzing each PE32 binary and producing a per-sample seed corpus of candidate API return values that downstream environmental fuzzers use to systematically uncover hidden execution paths.

Speakers:Kyler McElroy,Anita Ding,Daniel Koranek

SpeakerBio:  Kyler McElroy

McElroy, a second lieutenant and developmental engineer in the United States Air Force, is pursuing a master's in computer science with an AI focus at the Air Force Institute of Technology. His research focuses on using machine learning and automated analysis to uncover hidden behaviors in evasive malware. He is an alumnus of the ACE Cyber Leadership Development program, where he authored S.A.N.D (Synthetic Adversarial and Natural Data Generation) under the Air Force Research Laboratory.

SpeakerBio:  Anita Ding

Anita Ding is a second lieutenant and cyber operations officer in the United States Air Force, is pursuing a master's in cyber operations with an AI focus at the Air Force Institute of Technology. Her research focuses on LLM-orchestrated red team automation and graph neural networks for attack-path scoring in Active Directory environments. She earned a B.A. in Computer Science from UC Berkeley, where she conducted research at the Berkeley AI Research Lab and the Berkeley Risk and Security Lab. She is also an alumna of the ACE Cyber Leadership Development program, where she designed a CTF challenge for the British Army's Defence Cyber Marvel exercise.

SpeakerBio:  Daniel Koranek

Dr. Daniel Koranek is an Assistant Professor of Computer Science at the Air Force Institute of Technology (AFIT) and a two-time graduate of AFIT in cyber operations (2010, M.S.) and computer science (2022, Ph.D.), where his research interests focus on the intersection of artificial intelligence/machine learning and cybersecurity. This includes using AI/ML to enhance cybersecurity and using vulnerability assessment and secure design techniques to improve AI deployments. He has spent most of his career on reverse engineering and vulnerability assessment of embedded systems, and overlapping AI and cybersecurity drove Dr. Koranek's dissertation research on using the reverse engineering tool Binary Ninja to visualize explanations of malware classifications.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Saturday - 14:00-14:59 PDT


Title: Clone to Pwn: Remote Badge Cloning with the Flipper Zero
Tags: Physical Security Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Traditional RFID badge cloning methods require you to be within 3 feet of your target. So how can you conduct a physical penetration test and clone a badge without interacting with a person? Companies have increasingly adopted a hybrid work environment, allowing employees to work remotely, which has decreased the amount of foot traffic in and out of a building at any given time. This session discusses two accessible, entry-level hardware designs you can build in a day and deploy in the field, along with the tried-and-true social engineering techniques that can increase your chances of remotely cloning an RFID badge.

Langston and Dan discuss their Red Team adventures using implant devices and their Flipper Zero workflow. As a bonus the two will present a new python script to help you decode your badge data faster. This presentation is supplemented with files and instructions that are available for download in order to build your own standalone gooseneck reader, wall implant and clipboard cloning devices!

Speakers:Langston Clement,Dan Goga

SpeakerBio:  Langston Clement, Security Risk Advisors (SRA)

Langston grew up reading stories about the 90’s hacker escapades, and after years of observing the scene, he jumped into the offensive security field and never looked back. He is currently a Senior Purple Team Advisor for Security Risk Advisors (SRA). With over fifteen (15) years of public and private sector experience in cybersecurity and ethical hacking, he aims to provide organizations with valuable and actionable information to help improve their security posture. Langston’s specializations focus on modern-day social engineering techniques, wireless and RFID attacks, red teaming, physical penetration testing and purple team engagements.

SpeakerBio:  Dan Goga, Principal Consultant at NRI North America

Dan Goga serves as a Principal Consultant with NRI focused on conducting penetration testing and red team assessments. Dan Goga has nine years of information security experience in the public, private, and academic sectors. Dan has extensive knowledge and experience with RFID hacking, phishing techniques, social engineering techniques, and penetration testing.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Saturday - 12:00-12:59 PDT


Title: Cloud Forensics 101 : Ghost in the logs
Tags: Blue Team Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

Cloud breaches don't look like Hollywood hacking; they look like a leaked API key and a bot finding it before you've finished your coffee. This introduction to cloud forensics talk walks through a real AWS attack path end-to-end: recon, initial access, privilege escalation, exfiltration, and impact. We'll cover the misconfigurations that actually get exploited in the wild, how to contain them, and close with a demo: a deliberately compromised AWS account, investigated using AI to turn raw CloudTrail logs into a clean incident timeline in minutes.

Speakers:Cassandra (muteki) Young,Dimple Gajra

SpeakerBio:  Cassandra (muteki) Young

As a Principal Consultant on [REDACTED]'s Cloud Technical Advisory team, muteki analyzes the organizational security posture of Azure, GCP and Oracle Cloud environments, and leads the development of data collection and analysis tooling. Additionally, she assists the Incident Response team as a technical GCP and OCI SME, and supports strategic advisory and technical tabletop exercises across multiple cloud platforms. In addition to her decade of IT and then cloud security consulting experience, muteki also holds a Master’s in Computer Science and is a director of Blue Team Village, a nonprofit organization bringing free Blue Team content to the community.

SpeakerBio:  Dimple Gajra

Specializing in Digital Forensics, Incident Response (DFIR), and privacy engineering, Dimple Gajra (aka LocalHost) brings technical expertise to enterprise defense and data protection. Her professional journey includes engineering and response roles at major technology enterprises like IBM and Amazon's Security Incident Response Team (SIRT), where she has actively defended critical infrastructure, mitigated high-severity ransomware incidents, and engineered solutions to safeguard data privacy and automate secure detection pipelines. Driven by a hands-on, analytical approach to uncovering adversary tradecraft, she focuses on building architectural resilience, protecting sensitive user data, and translating complex system artifacts into actionable defensive strategies.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 14:50-15:20 PDT


Title: cloud-auth: a provider-agnostic CLI for cross-cloud workload identity
Tags: Demo 💻 | Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:50 - 15:20 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Modern engineering teams don't live in one cloud. A workload in Google Kubernetes Engine needs to read from an S3 bucket. An EC2 instance needs to fetch a secret from Azure Key Vault. A single GitHub Actions job has to deploy to AWS, log telemetry to GCP, and trigger a workflow in Azure — all in the same run. The default way teams make this work is the same way they have for a decade: paste a long-lived credential into a secret and hope nobody finds it.

This is the credential sprawl problem at the heart of every multi-cloud breach. Static AWS access keys, GCP service account JSON files, Azure client secrets — the most reliably exploited foothold in cloud environments, sitting in env vars, secret managers, and committed git history across every blue team's environment.

Why this was hard before cloud-auth? In theory, every major cloud already supports a way to skip the static credential entirely. A GKE pod can assume an AWS IAM role directly — no AWS keys anywhere. An EC2 instance can call Azure with no service principal on it. A Kubernetes workload can hit GCP APIs with no service account JSON file. In practice, each cloud has its own model, API, and failure modes. Setting up just one of these connections means learning a new mental model, authoring trust documents with provider-specific subject formats, and validating it all by hand. Doing it across clouds means doing that work three or four times over, with no consistent way to set it up, validate it, or clean it up. That friction is why cloud-auth exists. The secure path is already supported by the clouds — defenders just need tooling that makes it as easy as pasting an access key, or easier. So most teams stay on static keys.

cloud-auth: cross-cloud workload identity for defenders cloud-auth is an open-source CLI and library that gives blue teams one consistent way to set up, validate, and safely retire cross-cloud workload identity. One command stands up the trust between any two of: AWS, GCP, Azure, HashiCorp Vault, Cloudflare, GitHub Actions, and Kubernetes. The same command validates it, previews changes before applying, and tears it down without touching anything it didn't create.

Live demo GKE pod → AWS S3, no AWS keys. A GKE pod reads from S3 using a short-lived AWS role. EC2 → Azure Key Vault, no service principal. An EC2 instance fetches a secret with no Azure client secret on it. GitHub Actions → AWS, GCP, and Azure in one workflow. A single CI job deploys across three clouds. Catching a misconfigured trust. The validator flags an overly permissive trust before it ships. Safe teardown. Dry-run a multi-cloud cleanup, then execute. cloud-auth only deletes what it created.

What attendees leave with? A working open-source tool, a concrete pattern for cross-cloud workload identity, and a validation framework to drop into existing CI/CD. Repository: https://github.com/anirudhbiyani/cloud-auth (LGPL-3.0)

SpeakerBio:  Aniruddha Biyani

Aniruddha "AB" Biyani leads the Security and Compliance program at Prophecy, where he focuses on building security as a business enabler for high-growth cloud and AI platforms. His work centers on scaling information security programs, strengthening cloud and identity security, enabling secure product development, and aligning security strategy with customer trust, compliance, and engineering velocity. He has previously held security roles at Mandiant, Securonix, CRED, and Khoros.

AB's career spans cloud security leadership across startups and cybersecurity vendors, with deep experience in defensive cloud engineering, identity and access management, secure developer enablement, and operationalising secure-by-default practices in fast-moving organizations. He is known for translating complex security challenges into practical programs, tools, and frameworks that help engineering teams move quickly while reducing risk.

AB has presented at global security conferences including Black Hat Arsenal, SANS CloudSecNext, and MCPDev BLR, on workload identity, multi-cloud attack surface discovery, credential lifecycle management, and secure cloud adoption at scale. He is also an active open-source contributor and community builder, maintaining cloud security tools and secure developer training resources. He previously served for three years as a core DEF CON Cloud Village CTF volunteer, leading contest design and build efforts.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: CMD+CTRL Cyber Range: DarkMoney
Tags: CMD+CTRL Cyber Range | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range) - Map

Description:

CMD+CTRL is back for our 10th year and bringing something new to show. Drop by our cyber range for hands-on web application security challenges designed for all skill levels. Come to learn, come to compete, come to break things. All are welcome, whether it's your 1st CTF or your 101st.

There is no pre-qualification, and the only participant prerequisite is "Computer with internet access."


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Code Cadaver: Break Every System. Save Your Friend.
Tags: Biohacking Village | Code Cadaver (Biohacking Village CTF) | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver) - Map

Description:
Biohacking Village Capture the Flag: Test your skills against healthcare-themed capture the flag challenges. From beginner to expert levels, there's something for everyone.

Code Cadaver: Break Every System. Save Your Friend.

Your best friend entered St. Dismas Hospital with flu-like symptoms.

He never came back.

Now his hotel room has been torn apart, his phone is still beaconing somewhere in the wreckage, and every clue points toward a hospital that seems less interested in healing people than hiding what happens to them.

Code Cadaver is Biohacking Village’s immersive healthcare cybersecurity CTF—a dark, story-driven challenge that pulls players through the connected systems of a compromised hospital and the criminal network surrounding it.

Follow wireless signals. Pivot from guest networks into production systems. Hunt through patient intake records, webcams, HL7 traffic, payment systems, RFID credentials, pager networks, infusion devices, DICOM archives, and secured medical cabinets. Every system holds another piece of the truth. Every solved challenge brings you closer to Ethan—and deeper into St. Dismas.

This is more than a collection of puzzles. It is a full-chain medical cyber-thriller built around the technologies, mistakes, dependencies, and trust relationships that keep modern healthcare running.

You will need technical skill, persistence, curiosity, and a willingness to question everything.

The hospital is closing in.

The machines are still working.

Ethan is running out of time.

Break every system. Save your friend before St. Dismas finishes what it started.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 11:00-12:59 PDT


Title: Code Invaders: Stop The Insecure Code
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map

Description:
Recruit: help stop the Vibe Invasion. AI-generated code is flooding the frontier with insecure logic, and it’s your job to intercept it before it hits production. Vulnerable snippets (SQL injections, hardcoded secrets, broken crypto, and risky error handling) are falling toward the pipeline. Eliminate the threats, but stay sharp: secure code is mixed in. One wrong move could cause damage. Defend production and stop the Vibe Coding Invasion.
SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 13:00-14:59 PDT


Title: Code Invaders: Stop The Insecure Code
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map

Description:
Recruit: help stop the Vibe Invasion. AI-generated code is flooding the frontier with insecure logic, and it’s your job to intercept it before it hits production. Vulnerable snippets (SQL injections, hardcoded secrets, broken crypto, and risky error handling) are falling toward the pipeline. Eliminate the threats, but stay sharp: secure code is mixed in. One wrong move could cause damage. Defend production and stop the Vibe Coding Invasion.
SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 16:15-17:59 PDT


Title: Code to Cloud: Secure Modern Applications Using Open-Source Tools
Tags: Intermediate | AppSec Village | Creator Workshop
When: Saturday, Aug 8, 16:15 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map

Description:

Want to build secure applications without co-sponsoring a Formula 1 team? The modern threat landscape is a mess of AI-generated vulnerabilities, supply chain poisoning, and cloud misconfigurations. You don't need a seven-figure vendor budget to fight it.

In this 2-hour hands-on workshop, we will build a complete, automated AppSec pipeline using entirely open-source tools. We will wire up Opengrep for SAST, Trivy for containers, Checkov for infrastructure, and ZAP for DAST - piping the chaos into DefectDojo for centralized vulnerability management. We will also explore how to use local AI models to triage the inevitable mountain of false positives. You will walk away with a functional pipeline and a realistic understanding of where open-source excels, and where it falls apart.

SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 16:30-17:59 PDT


Title: Cold Calls
Tags: Social Engineering Community Village | Creator Event/Activity
When: Saturday, Aug 8, 16:30 - 17:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Ready for the hot seat? Step into the soundproof booth, grab a mystery target and three escalating objectives, and we'll place the call. Run by rekdt, Arty Boy, and Shadow Fox. First come, first served, so get your name on the Cold Call list!


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Saturday - 10:00-10:59 PDT


Title: Coloring Reset
Tags: Women in Security and Privacy (WISP) | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you're decompressing or collaborating on a shared poster, it's the perfect low-pressure space to connect, reflect, and color outside the lines.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 12:00-13:59 PDT


Title: Command & Conquer: Hands-on C2 Primer with Mythic
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

This hands-on workshop provides a unified view of C2 fundamentals for both offensive and defensive practitioners. Using the open-source Mythic framework, participants will deploy agents, handle callbacks, execute tasking with commentary on opsec and payload design considerations.

The session will also cover basic C2 infrastructure design including redirectors/domain fronting and an overview of Mythic feature sets. Students should leave armed with practical introductory experience operating Mythic for Red Team engagements.

The requested 2.5 hour timeslot should allow for at least two complete runs through the presentation and hands-on workshops as well as time for Q&A and subsequent "turnover" on the room for a new wave of attendees.

Participants must have the following equipment:

SpeakerBio:  Logan MacLaren

Logan is the lead Offensive Security engineer at Huntress where he is responsible for planning and executing red team operations as well as bolstering incident response capability through purple team exercises. He has been a long time enthusiast in the security space, building a career spanning big data analytics, bug bounty, and offensive security.

Outside of his day job, Logan can often be found building and participating in CTF challenges, bug hunting in open source software, or learning new skills at conferences across the continent. He has had the honour of speaking at several DEFCON villages, NorthSec conferences, as well as multiple BSides and OWASP Ottawa events.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 11:30-11:59 PDT


Title: Compiling the World: A Binary Dataset Built from nixpkgs
Tags: Nix Vegas Community | Creator Talk/Panel
When: Saturday, Aug 8, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Reverse engineering binaries is slow, detailed work, but it's one of the few ways we have to verify what some software actually does. Machine learning might help improve some of those challenges, but only if you have high-quality, real-world ground truth to train and evaluate on. At MIT Lincoln Laboratory, we have built a large dataset for machine learning on x86_64 binaries using nixpkgs, taking advantage of Nix's reproducibility, package coverage, and instrumentable build environments. We compiled tens of thousands of C, C++, Rust, and Go packages, often multiple versions of each, with consistent compiler flags, captured source files, and debug information. From these, we extracted roughly 50 million functions and aligned with their source code and short descriptions. Possible applications include fine-tuning large language models for various binary tasks or training custom, highly efficient models for binary code understanding. I'll walk through what it takes to wrangle nixpkgs in an HPC environment at this scale and show how open build tooling like Nix can help us to better understand and analyze the software that we all depend on.

SpeakerBio:  Chris Connelly, MIT Lincoln Laboratory

Chris Connelly is a Senior Technical Staff member at MIT Lincoln Laboratory in the Cyber Security and Information Sciences Division. Since joining the Laboratory in 2002, he has contributed to or led research, development, and evaluation programs in several areas, including malware analysis, vulnerability discovery, systems analysis, test automation technologies, large-scale distributed systems, and software architecture.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Saturday - 16:00-16:45 PDT


Title: Compounding Interest: Exploiting the ATM Supply Chain
Tags: Payment Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

ATMs are the ultimate high-stakes target, often holding upwards of $400,000 in a single enclosure. While the global financial industry relies on a narrow pool of manufacturers, the software supply chain securing these "vaults" remains an under-examined attack surface. Following my disclosure of 6 code execution vulnerabilities affecting Diebold Nixdorf at DEF CON 32, this research dives deeper into the foundational security layer: CryptWare CryptoPro Secure Disk for BitLocker.

CryptoPro acts as a proprietary security wrapper, adding pre-boot authorization, custom TPM protections, and an obfuscated encryption layer to the standard BitLocker architecture. In this session, I will highlight the nuances of the CryptoPro architecture, including, secret storage through unallocated disk space, TPM sealing logic, and the layered crypto architecture used to secure system secrets. I will demonstrate how these deficiencies provide a path for code execution and full compromise of the Windows BitLocker encryption keys.

In addition to the technical walk through, I will release ragavan, a custom exploitation toolkit designed to automate secret extraction, decryption, TPM unsealing, and compromise of a CryptoPro-protected platform.

SpeakerBio:  Matt Burch, Principal Security Researcher at Atredis Partners

Matt Burch is a Principal Security Researcher at Atredis Partners with 20 years of experience breaking things that aren't supposed to break. From the embedded components of ATM platforms to complex SCADA/OT environments, Matt specializes in identifying critical flaws in hardened, enterprise-class systems. He is best known for his research into ATM disk encryption and Mobile Device Management (MDM) security, some of which has been highlighted in Wired Magazine and presented at DEF CON 32.

Matt is a reverse engineer and tool developer who has authored and contributed to various public projects. His career spans roles as an offensive security lead, expert witness, and technical advisor. Matt’s current research is a deep-dive into the ATM software supply chain, specifically targeting the subversion of TPM-backed roots of trust and the analysis of custom cryptographic primitives.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 12:30-13:30 PDT


Title: Compounding Interest: Exploiting the ATM Supply Chain
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

ATMs are the ultimate high-stakes target, often holding upwards of $400,000 in a single enclosure. While the global financial industry relies on a narrow pool of manufacturers, the software supply chain securing these "vaults" remains an underexamined attack surface. Following my disclosure of 6 code execution vulnerabilities affecting Diebold Nixdorf's Vynamic Security Suite (VSS) at DefCon32, this research dives deeper into the foundational security layer: CryptWare CryptoPro Secure Disk for BitLocker.

CryptoPro acts as a proprietary security wrapper, adding pre-boot authorization, custom TPM protections, and an obfuscated encryption layer to the standard BitLocker architecture. I will be disclosing 9 new CVEs that allow an unauthenticated adversary to dismantle the CryptoPro stack. Join me as I share my journey of locating secrets buried in unallocated disk space, abusing TPM sealing logic, and deconstruct CryptoPro's custom AES256 logic to recover the BitLocker keys. This presentation will highlight how a trusted security component became a critical backdoor.

In addition to the technical walk through, I will be releasing ragavan, a custom exploitation toolkit designed to automate secret extraction, decryption, TPM unsealing, and compromise of a CryptoPro-protected platform.

SpeakerBio:  Matt Burch, Principal Security Researcher at Atredis Partners

Matt Burch is a Principal Security Researcher at Atredis Partners with 20 years of experience breaking things that aren't supposed to break. From the embedded components of ATM platforms to complex SCADA/OT environments, Matt specializes in identifying critical flaws in hardened, enterprise-class systems. He is best known for his research into ATM disk encryption and Mobile Device Management (MDM) security, some of which has been highlighted in Wired Magazine and presented at DEF CON 32.

Matt is a reverse engineer and tool developer who has authored and contributed to various public projects. His career spans roles as an offensive security lead, expert witness, and technical advisor. Matt’s current research is a deep-dive into the ATM software supply chain, specifically targeting the subversion of TPM-backed roots of trust and the analysis of custom cryptographic primitives.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Saturday - 14:30-14:59 PDT


Title: Condense Volumes, Connect Dots, Enrich Contexts: Scaling Root Cause Analysis and Automated Troubleshooting with ML
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Learn to use ML to condense volumes by 80% without data loss by grouping related records and deduping their redundant field values. Learn how to use ML to to auto-normalize records to a unified schema and enrich them with their most relevant tags and labels across objects, assets, entities, frameworks and controls. Use ML to correlate situationally relevant records, similar root causes and link causal sequences and behavior. Use AI to further troubleshoot, detect and remediate with rich-context.

SpeakerBio:  Ezz Tahoun

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada's CSE.

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 16:00-16:59 PDT


Title: Control + C = Control Me
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Demos (Desktop Only at the moment): https://doctoreww.github.io/EvilFontTool/

Tool: https://github.com/DoctorEww/EvilFontTool

General: Workshop goes into evil fonts and how to use them in a red team to get free shells, also hints at a tool to make it easier (saving most of the tool stuff for the tactic)

Tactic will go into using the tool to create malicious word docs for social engineering / popping a shell.

Description: For decades, cybersecurity has taught us to validate what we click, what we download, and what we run. Analysts learn to inspect URLs carefully, read every line, and challenge every prompt or popup that doesn't look quite right. But in all this vigilance, we’ve ignored a foundational assumption. We trust our eyes. We trust that what we see is what the system sees. This talk demonstrates why that assumption puts us at risk.

In the modern computing stack, very little sits closer to human perception than fonts. They are in browsers, PDFs, document editors, terminals, IDEs, chat apps, and nearly every interface in between. Yet despite their ubiquity, fonts are almost never treated as part of the security boundary. They’re handled as passive design elements, harmless vessels used solely to shape text. Users trust them implicitly. This session introduces a new class of “evil font” attacks. With evil font attacks, red teamers can create situations where a user believes they are copying, clicking, or executing one thing… while the machine processes something entirely different.

Evil font attacks don’t depend on JavaScript, macros, or browser exploits. Evil fonts work because there is no reason that a specific letter needs to look the way it does. In other words, the letter “A” only looks like an “A” because that’s how my font drew it. With clever font manipulation a red teamer can make the letter “A” look like any other letter. For example, while a user might see the letter “B” the computer would still see the letter “A” represented by the underlying ASCII hex value. By manipulating fonts, files no longer have a single meaning… They mean one thing to a human reader, and another thing to a computer.

Once you realize this trust boundary is broken, there are so many ways to abuse this.

During the session, we walk through three attack scenarios usable by red teams; each scenario highlights a different security boundary where fonts exert control.

Clipboard deception in modern browsers Clipboard attacks typically require JavaScript, event hijacking, or social engineering. With evil fonts you can poison a clipboard on webpages without any JavaScript. With evil fonts an attacker can make on-screen text appear safe (e.g., “echo hello world” or “https://google.com”) while the underlying copied text is entirely different. Users believe they are copying the text they verified with their eyes, but instead the clipboard receives text the attacker controls.

Document poisoning: Like browsers, documents like docx and pdf files can by poisoned by evil fonts. In this portion of the talk, we explore how to poison word and pdf files with malicious links and commands. These documents can be emailed for deception based social engineering. More insidious, evil fonts can be used to poison existing documents within a target such as how to’s and infrastructure guides. By poisoning documents, red teamers can turn simple shared drive access into credentials and shells.

AI‑era submission manipulation: The rise of AI‑powered document processing introduces a new frontier for deception. Modern systems summarize text, extract entities, detect sentiment, identify anomalies, and evaluate authenticity. Evil fonts can exploit this by making the text look safe to the computer… but when read by a user, it displays malicious content. This manipulation can skew automated summaries, risk scoring, keyword extraction, plagiarism detection, and content filtering.

Please let me know if you have any questions! Thanks, Andrew

SpeakerBio:  Andrew Griess

Andrew Griess is a Red Teamer at Centene who gets paid to break things and calls it a career. With 3 years of professional red team experience, he’s made it their mission to think like an attacker while not succumbing to the dark side. When not poking holes in things for money, Andrew is deep in security research — chasing the next interesting bug, developing new techniques or going down rabbit holes that started as "just a quick look."


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Crack Me If You Can 2026
Tags: Crack Me If You Can 2026 | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 106 (Crack me if you can) - Map

Description:

Time is of the essence! You will have 48 hours to crack as many hashes and files as possible.

Pamama, a US-based data broker had a massive data breach. Profiles on over a billion people, containing all the information amassed about them. It is alleged that the company siphoned records from different government agencies around the world, as well. The dump was encrypted, and regulators are downplaying the breach claiming no damage was done. A bill has been fast-tracked in Congress to exempt Pamama from any investigations, including illegally shield them from GDPR violations. This led to accusations that Pamama has bought or blackmailed members of congress.

Crack the staff's accounts and encrypted files to demonstrate the extent of the exposure and the need for individuals to get restitution and compensation, and to find smoking gun evidence of collusion so that the corruption can be fully exposed before the legislation goes forward.

Participant Prerequisites

Open to all, but pre-registration is recommended. Compete in the Street class for individuals or small teams, or in Pro if you do not want to sleep all weekend. Check out past years' contests at https://contest.korelogic.com/ , or the Password Village site for an introduction to password cracking and links to other resources: https://passwordvillage.org/

Pre-Qualifications

None.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Crack the Core
Tags: Crack the Core | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 214 (Crack the Core) - Map

Description:

Welcome to Crack the Core–a true test of lockpicking skills. Competitors will work through a variety of locks ranging in different difficulties, technologies, and configurations. From standard off-the-shelf locks to evil creations from the community. Locks will be presented in a variety of ways, ranging from your traditional deadbolt to much, much more. Just wait until you see what we have in store for you…

Challenges will not only test traditional lockpicking skills but force competitors to interact with different “environments,” work through various challenges, and adapt to what's presented. Collect the most points, you go home the winner–it’s that simple…

Bring your tools. Bring your focus. The locks will be waiting.

Participant Prerequisites

Basic tools will be available for use but it is highly recommended to bring your own tools. This may include lockpicks, bypass tools, vices, etc. Destructive entry is not allowed and associated tools will not be needed.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 14:00-14:59 PDT


Title: Cracking North Korea's Information Control: How Smugglers, Defectors, and Technologists are Breaking Open the World's Most Locked-Down Information System
Tags: DEF CON Official Talk | Demo 💻
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

North Korea operates the world’s most extreme digital environment. Its custom Android OS enforces an "allowlist" ecosystem where media and apps require state-issued cryptographic signatures to run, while background daemons capture secret screenshots to log "illegal" activity. In this restrictive environment, the stakes for accessing outside information are measured in prison sentences and public executions.

Yet, the hackers are active. This talk deconstructs the regime's information control systems—from signature-verification logic to TraceViewer forensics—and reveals how a network of defectors and technologists is fighting back. We will demo Pigeon, a working SELFSIGN spoof that bypasses handset verification, and discuss eMMC chip-off techniques used to study device internals, and look at Windows data concealment methods used by defectors.

This isn't just a technology briefing; it’s an offensive security call for support. I will map out a unique and intriguing engineering backlog which includes media obfuscation tools, Android internals research, binary analysis, anti-forensics, and hardware hacking. I will show how these skills directly translate into freedom-of-information tool development. Built and validated through iterative testing with defectors, some of these technologies are operational already today.

SpeakerBio:  JDT, Liberty in North Korea

JDT brings over a decade of cybersecurity expertise to his role as Chief Technology Officer at LiNK. Before joining the organization, he served as the lead specialist for the U.S. Department of Homeland Security’s HQ Threat Hunt team, following ten years spent in incident response and red-teaming across the banking, retail, and tech sectors.

After volunteering for the North Korean human rights movement in 2019, JDT stepped into the CTO role in 2025 to spearhead the development of tools designed to pierce the world’s most restrictive information environment. By repurposing his deep understanding of adversary tradecraft, he develops unconventional technologies that empower North Koreans to access outside information safely and bypass state surveillance.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 10:00-10:35 PDT


Title: Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:35 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:
Abstract:
What happens when a leaked malware builder suddenly opens the door for anyone — from low-tier criminals to advanced operators — to deploy a backdoor armed with a kernel-capable rootkit? What happens when that rootkit still carries valid signatures, and Windows 11 willingly loads it?

In this talk, Check Point Research unveils a comprehensive reverse engineering of ValleyRAT, a modular backdoor family also known as Winos/Winos4.0. By dissecting the publicly leaked builder and its development artifacts, we reconstruct the malware’s architecture from the ground up, uncovering a highly organized plugin ecosystem and coding style that reveals a small, specialized team with deep knowledge of the Windows kernel.

The standout finding: ValleyRAT’s Driver Plugin, containing a stealthy and surprisingly robust kernel-mode rootkit. Despite being abused by multiple operators, several variants remain validly signed, bypassing Microsoft’s driver protections and loading successfully on the latest Windows builds. The rootkit’s functionality — including coercive AV/EDR driver deletion, silent installation methods, and APC-based shellcode injection — demonstrates a level of sophistication rarely seen in malware distributed through public builders.

Our telemetry and detection work further expose a dramatic rise in ValleyRAT’s presence in the wild. Roughly 85% of detected plugin samples surfaced within the past six months, directly following the builder leak. This surge marks a turning point: ValleyRAT is no longer a tool reliably associated with specific Chinese-speaking threat actors, but rather an accessible platform fueling opportunistic and un-attributable campaigns.

This research pulls back the curtain on ValleyRAT’s internals, its kernel rootkit mechanics, and the implications of a powerful multi-module malware ecosystem becoming available to the masses. When sophisticated tooling escapes into the wild, who gets to wield it — and who pays the price?

SpeakerBio:  Jiří Vinopal, Threat Researcher at Check Point Research

Jiří Vinopal is a security researcher, malware researcher, and reverse engineer at Check Point Research, focused on advanced cyber threats, kernel internals, and the hidden mechanics of undocumented system components. His work spans uncovering novel attack primitives, reconstructing proprietary protocols from binary analysis alone, and deep-diving into both sophisticated malware families and trusted platform components. When he's not buried in disassembly, he actively shares his knowledge and passion for reverse engineering across his X account, YouTube channel, and blog — delivering tips, tricks, and technical insights to fellow enthusiasts and the broader security community.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Saturday - 13:00-13:59 PDT


Title: Crafting the Future: DEF CON 34 Light-Up Bow Workshop
Tags: Maker's Village | Hack3r Runw@y v8.0 | Creator Event/Activity
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Level up your wearable tech skills and celebrate DEF CON 34 by making your own interactive, light-up accessory! In this hands-on e-textile workshop, proudly presented by Hack3r Runway, you will learn the basics of wearable electronics and sewing circuits to create a custom glowing bow. Whether you want to rock it in your hair or wear it as a sleek cyberpunk bow tie, you'll walk away with a unique, handmade piece of hacker fashion. What you'll learn *Intro to E-Textiles: Learn how to design a basic circuit using a LilyPad battery holder and wearable LEDs. * Conductive Thread Basics: Master the art of hand-sewing with conductive thread to power your creation without bulky wires. * Exclusive Swag: Assemble your circuit onto a custom 3D-printed bow featuring a special glow-in-the-dark DEF CON 34 logo.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 13:00-14:59 PDT


Title: Crash and Compile - Stage Competition
Tags: Crash and Compile | Contest
When: Saturday, Aug 8, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

What happens when you take an ACM style programming contest, smash it head long into a drinking game, throw in a mix of our most distracting helpers, then shove the resulting chaos on stage in front of an audience? You get the contest known as Crash and Compile.

Teams are given programming challenges and have to solve them with code. If your code fails to compile? Take a drink. Segfault? Take a drink. Did your code fail to produce the correct answer when you ran it? Take a drink. ChatGPT wrote your code? First of all shame. Secondly take a drink.

We set you against the clock and the other teams. And because our "Team Distraction" think watching people simply code is boring, they have taken it upon themselves to be creative in hindering you from programming, much to the enjoyment of the audience. At the end of the night, one team will have proven their ability, and walk away with the coveted Crash and Compile trophy.

Crash and Compile is looking for the top programmers to test their skills in our contest. Can you complete our challenges? Can you do so with style that sets your team ahead of the others? To play our game you must first complete our qualifying round. Gather your team and see if you have the coding chops to secure your place as one of the top teams to move on to the main contest.

Qualifications for Crash and Compile will take place Friday starting at 10:00 and run till 18:00, both in the contest area and online at https://crashandcompile.org

You may have up to two people per team. Individuals can compete, but having two people on a team is highly suggested.

Of the qualifiers, ten teams will move on to compete head to head on the contest stage on Saturday.

Participant Prerequisites

As this contest involves the drinking of alcohol (beer), all contestants must be 21 years of age or older. Yes we will check. While we don't limit what development environment or programming language you chose to use, as we used a PDP11/23 when we competed, the team must have at least one computer that can connect to our contest network via wired ethernet for the main contest.

Pre-Qualification

Qualifiers run on Friday from 10:00 to 18:00. We will be located in the contest area, and the problems can be accessed via our site at https://crashandcompile.org


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 14:00-15:59 PDT


Title: Crawlee - Improving crawling with an LLM
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

Traditional web crawlers are great at finding links but terrible at understanding websites. The interesting challenge is not replacing crawlers with AI. It's using the minimum amount of AI required to dramatically improve coverage.

Every automated tool I've tried hit a brick wall the moment it encounters MFA, multi-step workflows, onboarding wizards, or application states where a wrong click deletes data. As a result, large portions of authenticated attack surface require manually using the application.

I built a crawler that combines deterministic tooling such as Katana with a minimal AI agent. The AI is only used where traditional crawlers consistently fail: authentication, workflow navigation, and generation of safety controls. Once authenticated session state is established, the system hands control back to fast deterministic tooling.

I'll cover the basics of how it's built and we'll try it together on a variety of applications.

SpeakerBio:  Daniel Goldberg

Daniel is a security researcher who spent the last 20 years crawling his way up the stack from hacking operating systems to attacking client-side applications to attacking browsers, network protocols, and today web applications. After dabbling with everything in security, he's realized what he really enjoys is how to take something that works and make it really good


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Saturday - 15:30-16:59 PDT


Title: Creator Drop-In
Tags: Scambait Village | Creator Event/Activity
When: Saturday, Aug 8, 15:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

We know a handful of names you would recognize are wandering this conference. We have invited them to swing by the village during this block and say hi. No stage, no line, no format. Just a shot at an actual conversation with the people behind the calls, so ask what you have always wanted to ask and swap a few stories of your own.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Saturday - 14:00-15:30 PDT


Title: Creator Talk with RinoaPoison & VanHelen
Tags: Scambait Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Join popular scambait content creators RinoaPoison and VanHelen for an open, behind-the-scenes conversation about live scambaiting, character work, community building, and the realities of turning the tables on scammers on Twitch and YouTube. Expect stories from the calls, tips for aspiring creators, and insights into keeping the work sustainable and entertaining while still disrupting scam operations.

Speakers:RinoaPoison,VanHelen

SpeakerBio:  RinoaPoison, Twitch Streamer / Content Creator
No BIO available
SpeakerBio:  VanHelen, Twitch Streamer / Content Creator
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 17:00-17:59 PDT


Title: CRLF-Powered Desync Attacks: Beheading HTTP streams
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Have you ever discovered a header injection vulnerability and settled for little more than an open redirect or XSS? In this session, we introduce a battle-tested “header injection” powered desync methodology, enabling you to perform HTTP request smuggling attacks against even strictly RFC-compliant proxy chains.

We will begin by explaining a well-known but overlooked CRLF injection primitive that produced HTTP Request Splitting inside the core infrastructure of a major CDN, resulting in the capture of live users’ credentials across thousands of compromised applications.

Building upon this, we’ll demonstrate how header injections can be used to exploit more traditional smuggling attack classes, even when no parser discrepancy exists. Finally we’ll reveal how you can shift previously non-compliant desync attacks into the browser, unlocking a plethora of novel exploitation opportunities even when keep-alive connections are not shared between users. The result is a slew of real-word case studies with impacts ranging from account takeovers via desync-enabled XSS gadgets to cache poisoning, response queue poisoning, access control bypasses, and in several cases the possibility of creating the ever-terrifying desync worm.

Finally, we’ll release two open source tools that introduce robust detection of header injection.

Speakers:Tom "t0xodile" Stacey,Tobia "mastersplinter" Righi

SpeakerBio:  Tom "t0xodile" Stacey, Independent

Tom 't0xodile' Stacey is a security researcher at PortSwigger with a passion for automating the ideas that "will never work" to find gaps in the industry's current understanding of web security. He is best known for his work in discovering and exploiting underappreciated forms of desync attacks.

At PortSwigger he spends most of his time experimenting with the HTTP protocol and the vulnerabilities that arise due to the disagreements between web servers and components with the goal of finding novel techniques to improve Burp Suite's capabilities. When he's not at work, he's usually playing some form of video / board game or building Lego.

SpeakerBio:  Tobia "mastersplinter" Righi, TurtleSec

I am a security research and bug bounty hunter, recently I have started TurtleSec with other talented hackers, focusing on research driven projects. I spend most of my time tinkering with applications to try and figure out how to break them in the weirdest of ways.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Cryptid Hunt
Tags: Cryptid Hunt | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 203 (Cryptid Hunt) - Map

Description:

Something is already watching you.

The Cryptid Hunt is a task-oriented challenge that moves agents across the conference floor toward a truth most attendees will never find. This is not a passive experience — each clue demands action, and the path forward is never obvious.

Look carefully at what surrounds you. The next layer of any good mystery is always hiding beneath the surface. Patterns emerge for those paying attention. Signals exist for those who know how to listen.

Is this a puzzle? A test? A hunt? At its core, this is a community experience that rewards curiosity, persistence, and the willingness to go further than most people will.

The conference is your map. Maritime exploration, ancient communication, and the village of knowledge surrounding you are all part of the journey. Nothing here is coincidental.

Finishers are recognized. What awaits those who complete the hunt will not be found anywhere else at this conference. Supplies are finite. So is your time.

Your first clue is already in your hands.

— The Cryptid Hunt Team

Bureau of Unverified Phenomena · DC34

Participant Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:20-10:30 PDT


Title: Crypto And Privacy Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 10:20 - 10:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Crypto And Privacy Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Crypto And Privacy Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Saturday - 11:15-11:45 PDT


Title: CTF Intro, Quick Guides, and Rule Review
Tags: OSINT For Good Community | Creator Talk/Panel
When: Saturday, Aug 8, 11:15 - 11:45 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

Participating in today's Global OSINT Search Party CTF? This session, offered by our most senior Coach, the Legendary KennyJ, will do a quick overview of what to expect, how to get organized, and how to make sure you're following the rules.

SpeakerBio:  Kenny J, Trace Labs

Senior Infrastructure Engineer by day. Osint for Good by night. His is the only Trace Labs coach to have coached 20+ CTFs, earning him the singular rank of Legendary Coach.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Cyber Deck Competition
Tags: Maker's Village | Contest | Cyber Deck Makers’ Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

The cyber deck contest at DEF CON 34 encourages makers of all types to create their own cyber deck. Winners will be judged on form, function, creativity, does it work, general, awesomeness, and complexity.

Stop by Makers' Village for more info!

Judging Criteria

Rules

  1. Must be present to enter.
  2. Winners are determined by points awarded by the judges.
  3. Rules are subject to change.

Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 11:00-11:55 PDT


Title: Cyber Gamechangers: Women Who Lead, Secure, and Inspire
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Join B.I.C. Village for Cyber Gamechangers: Women Who Lead, Secure, and Inspire, a welcoming session focused on leadership, career growth, and the impact of women shaping cybersecurity. Come ready to learn, ask questions, and connect with the community.

Speakers:Nikkia Henderson,Arielle Baine,Jess Hoffman

SpeakerBio:  Nikkia Henderson, Senior Advisor, Cybersecurity Infrastructure Security Agency (CISA) / President, Women in Cybersecurity Mid Atlantic Affiliate

Nikkia Henderson is a Senior Advisor at the Cybersecurity Infrastructure Security Agency (CISA), where they lead the Cyber Supply Chain Risk Management (C-SCRM) Strategy and Governance Program. They also serve as President of the Women in Cybersecurity Mid Atlantic Affiliate, helping professionals define their vision and career paths in federal cybersecurity. With over 14 years in federal government, Nikkia holds a Master's degree in Cyber Policy.

SpeakerBio:  Arielle Baine, Chief of Cybersecurity at Cybersecurity and Infrastructure Security Agency (CISA)

Arielle Baine is the Chief of Cybersecurity for Region 3 within the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA). They lead the Cybersecurity Advisor Program, enhancing the security and resilience of critical infrastructure. With over 9 years of experience in cybersecurity across federal civilian and DoD communities, Arielle holds multiple certifications including CISSP, CCSP, GCWN, CEH, and Security+, and a Master of Science degree in Cybersecurity.

SpeakerBio:  Jess Hoffman, Deputy CISO, City of Philadelphia / Professor, Harrisburg University and The Pennsylvania State University

Jess Hoffman is a Certified Information System Security Professional (CISSP) with nearly 20 years of IT and cybersecurity experience in government and private sectors, focusing on Audit and Compliance. They currently serve as Deputy CISO for the City of Philadelphia and are a Professor at Harrisburg University and The Pennsylvania State University. Jess is a national speaker and advocates for mentorship and DEI within cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 10:00-17:59 PDT


Title: Cyber Mirage: Realtime Deepfake Demos
Tags: AI Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become.

SpeakerBio:  Brandon Kovacs

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at offensive cybersecurity firm Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets. Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on the intersection of offensive cybersecurity and artificial intelligence.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Saturday - 15:00-16:59 PDT


Title: Cyberdeck Build
Tags: Maker's Village | Creator Event/Activity | Cyber Deck Makers’ Contest
When: Saturday, Aug 8, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Learn some in's and out's of building your own cyberdeck... by building one with us! Customizable with radio add on, this deck is a great introduction level or intermediate refresher.

SpeakerBio:  Sk!tz0
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 17:00-17:30 PDT


Title: CyberKB: When Your AI Copilot Runs the Recon, Crawls the Dark Web, and Maps the Kill Chain
Tags: Recon Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

What if your recon tool could understand "find leaked credentials for this company on the dark web, cross-reference with their exposed infrastructure, and show me the attack path" — and then actually do it, autonomously, with zero manual commands? CyberKB is a 214,000-line open platform that puts an AI copilot (Keke) in command of 131 offensive tools spanning reconnaissance, dark web OSINT, Shodan intelligence, breach databases, and a full Kali Linux shell — all orchestrated through natural language conversation. The Dark Web Intelligence Pipeline (DarkMonitor): CyberKB's DarkMonitor module queries .onion search engines concurrently through Tor, uses LLM-powered query refinement to generate optimal dark web search terms, applies AI relevance filtering to surface the most critical results.

The AI Copilot (Keke): Keke isn't a wrapper around ChatGPT. It's a function-calling agent with direct execution access to: a privileged Kali container (nmap, curl, nikto, sqlmap, gobuster, hydra — the full toolkit), 16 dark web search engines via Tor, breach and paste database aggregators, a RAG-powered knowledge base with semantic search over ingested recon data, Shodan lookups and CVE correlation, MITRE ATT&CK technique mapping, attack graph generation and path prioritization, and engagement management (targets, credentials, findings, reports).

Scale Proof — 2,250-Domain Assessment: We demonstrate CyberKB against a real-world external attack surface assessment: 2,250 domains belonging to a single organization, producing 11,968 unique IPs, 8,494 hostnames, 2,444 CVEs, 80,238 open ports, and a knowledge graph of 6,390 nodes with 51,990 infrastructure relationship edges. The entire dataset was parsed, correlated, and ingested into the AI-queryable knowledge base in 25 seconds. Keke can now answer questions like "which x domains share infrastructure with known-vulnerable IPs" by searching the graph, not by re-scanning.

What This Means for Defenders: Every autonomous recon step Keke performs leaves detectable artifacts. We discuss what blue teams should monitor: DNS burst patterns from multi-engine enumeration, Tor exit node correlation with target infrastructure, behavioral signatures of AI-driven sequential probing, and how to distinguish human recon from autonomous agent recon. The same platform that empowers red teams reveals the detection surface that defenders can leverage.

Key Takeaways: 1. AI copilots with direct tool execution compress hours of reconnaissance into minutes of conversation — fundamentally changing the operator's role from command executor to strategic decision-maker. 2. Dark web OSINT can be systematically automated with LLM-driven search refinement and relevance filtering, making it accessible beyond specialized analysts. 3. Infrastructure-scale attack surface mapping (2,250+ domains) becomes practical when AI handles correlation instead of humans. 4. Autonomous recon creates detectable patterns that blue teams should be actively hunting for. Tool Stack: Python, Flask, ChromaDB (RAG), Docker (Kali + Tor + Browser Agent), OpenAI-compatible LLM API, SQLite, Playwright, BeautifulSoup. 105 Python modules. Fully self-hosted — no cloud dependencies for core functionality.

Speakers:Suriya Prasath S,Chandru J,Muthu Kumar

SpeakerBio:  Suriya Prasath S, zoho, red teamer, manager

A Red Teamer and Security Manager at Zoho CRM–Red Team, with 6+ years of experience driving adversarial simulations and real-world attack emulation at scale. He focuses on uncovering critical security gaps by thinking like an attacker—blending deep technical expertise with practical red team operations to challenge assumptions and strengthen defences.

SpeakerBio:  Chandru J, Zoho, Product Security Manager

Product Security Manager with over 12 years of experience in driving cybersecurity initiatives, enhancing organizational security posture, and ensuring compliance with international standards such as ISO 27001, SOC 2, and GDPR. Adept at leading and mentoring teams, managing enterprise-wide security programs, and developing in-house security tools to address vulnerabilities effectively. Proven expertise in vulnerability management, incident response, security governance, and implementing secure development lifecycle (SDLC) practices. Recognized for fostering a security-first culture and collaborating with cross-functional teams to mitigate risks, protect assets, and improve processes in rapidly evolving environments.

SpeakerBio:  Muthu Kumar, Security Engineer

I am a Security Engineer with 10 years of experience specializing in web application security and security tool development. I have extensive experience identifying security vulnerabilities, improving secure development practices, and building tools that help organizations detect and prevent security risks at scale.

My expertise includes application security testing, secure code reviews, threat modeling, vulnerability assessment, and developing security automation solutions that reduce manual effort and improve detection accuracy. I have worked on enhancing security tools by reducing false positives and helping engineering teams address vulnerabilities more efficiently.

I am passionate about building secure systems and solving complex security challenges through automation, innovation, and practical security engineering approaches. My focus is on strengthening application security while enabling development teams to build and ship secure products faster.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Darknet-NG
Tags: Darknet-NG | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 105 (Darknet-NG) - Map

Description:

Darknet-NG is an Alternate Reality Game (ARG), where the players take on the Persona of an Agent who is sent on Quests to learn real skills and gain in-game points. If this is your first time at DEF CON, this is a great place to start, because we assume no prior knowledge. Building from basic concepts, we teach agents about a range of topics from Lock-picking, to using and decoding ciphers, to Electronics 101, just to name a few, all while also helping to connect them to the larger DEF CON Community. The "Learning Quests" help the agent gather knowledge from all across the other villages at the conference, while the "Challenge Quests" help hone their skills! Sunday Morning there is a BOSS FIGHT where the Agents must use their combined skills as a community and take on that year's final challenge! There is a whole skill tree of personal knowledge to obtain, community to connect with and memories to make! To get started, check out our site https://darknet-ng.network and join our growing Community!

Participant Prerequisites

Prerequisites for competing in the contest would require a device with access to a web browser like a Phone, Tablet, Laptop.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Saturday - 15:30-15:59 PDT


Title: DarkSyringe: Automated poisoning of Clinical AI Assistants Through PDFs (a physician's point of view)
Tags: Biohacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Doctors are burned out and turning to LLMs — uploading discharge letters, lab reports and papers into ChatGPT, Claude and clinical AI tools. Every PDF is an unvalidated input to a system that cannot tell real facts from injected lies. We introduce Divergent Prompt Injection: unlike classic attacks (""ignore previous instructions""), divergent payloads are clinically plausible false statements — a wrong drug, a fabricated contraindication, a phantom diagnosis — embedded in medical content. They create no semantic conflict, trigger no detection system, and sit indistinguishable from real medicine until an LLM summarizes them into a treatment plan.

We release DarkSyringe, an open-source tool automating the full attack chain: PDF ingestion, de-identification, LLM-driven payload generation, injection and multi-model scoring. In testing, a single poisoned discharge letter caused multiple commercial LLMs to recommend wrong drugs, fabricate contraindications and invent diagnoses — errors that would directly harm patients.

This talk brings a physician's perspective: understanding why even a low-complexity attack becomes critical when it lands in a clinical environment built on time pressure, trust, and information overload.

SpeakerBio:  Francesco Costa

Hand surgeon trainee and cybersecurity researcher focused on LLM security. Creator of DarkSyringe, combining real clinical experience with offensive research to expose the limits of current defenses.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:30-10:40 PDT


Title: Data Duplication Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 10:30 - 10:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Data Duplication Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Data Duplication Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: DC's Next Top Threat Model
Tags: DC's Next Top Threat Model | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 102 (DC's Next Top Threat Model) - Map

Description:

Threat Modeling is arguably the single most important activity in an application security program and if performed early can identify a wide range of potential flaws before a single line of code has been written. While being so critically important there is no single correct way to perform Threat Modeling, many techniques, methodologies and/or tools exist.

As part of our challenge we will present contestants with the exact same design and compare the outputs they produce against a number of categories in order to identify a winner and crown DEF CON’s Next Top Threat Model(er).

Participant Prerequisites

A laptop is recommended, a smartphone could be used but will be less than idea. Internet access to retrieve the design materials and to submit findings and access to the email used during registration.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 15:00-16:59 PDT


Title: DCG New England Meetup
Tags: Meetup
When: Saturday, Aug 8, 15:00 - 16:59 PDT
Where: LVCCW Level 3 W327 (Misc Meeting Room) - Map

Description:

New England's hackers are spread across six smaller states and rarely in the same room. This is the room. DCG New England pulls the region's groups and unaffiliated folks together to hang out, meet other hackers in the region, talk shop, show off half-finished projects, and meet the people who keep the local scene ticking.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: DCNextGen - Bricks in the Air
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft's control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required - all target devices, materials, and interfaces are provided!

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

RIC-1, tail number N3VR-G0N, has gone down! You need to use radio direction-finding (RDF) techniques to locate Emergency Locator Transmitter (ELT), report its position, and help rescue our missing pilot!

Participants will use the provided handheld DF equipment provided by the Village, or bring your own, to triangulate the hidden transmitter location within the village area. Your handheld radio must be capable of receiving on the designated frequency with a directional antenna or attenuator. Once you've located RIC-1, listen closely... you may recognize the beacon's "distress tone." It appears to be broadcasting an audio payload that responders have described as "oddly catchy" and "impossible to stop once you start listening." Bring your comfortable shoes and strong will to ensure you never give up until you find our missing pilot!

No prior RDF experience required - volunteers can walk you through basic triangulation techniques before you start this 15-30 minute event.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

The MOUSE-1 satellite is currently in Safe Mode, and its attitude and heading systems are behaving unexpectedly. Ground control needs answers NOW!

You are a newly assigned Mission Specialist, and it's your job to figure out what's going on. Work through five sequential challenge missions aboard a simulated HUD - complete with live orbital tracking, optical camera feeds, and attitude telemetry - to triage MOUSE-1, uncover what happened, and make it operational again.

Participants will learn how satellites operate, how they stay secure in orbit, and what happens when they don't - using a fully browser-based, gamified interface developed by California Polytechnic State University students.

Just grab a seat in front of the provided station, no prior cybersecurity or aerospace experience required! Each mission is self-guided with built-in instructions, and volunteers are available to assist. Both beginner and experienced participants will find this 30-minute event challenging and fun.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 19:00-20:59 PDT


Title: DCNextGen Party!
Tags: Party | DCNextGen | | Youth
When: Saturday, Aug 8, 19:00 - 20:59 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Are you ready to rock? If so, come to the DCNextGen party where the theme is UV cyberpunk! What is there to do you might ask? We have games, music, create your own raccoon mask, glow in the dark tattoos, and so much more! There is no better place to make new friends and hang out with your fellow DCNextGen cyber warriors.


Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Saturday - 10:00-17:59 PDT


Title: DDV open and accepting drives for duplication
Tags: Data Duplication Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:
We start taking drives at 4: 00pm local time on Thursday - possibly a little earlier. We'll keep accepting drives until we reach capacity (usually late Friday or early Saturday).  Then we copy and copy all the things until we just can't copy any more - first come, first served. Note that some sources require 8TB drives now.  We run around the clock until we run out of time on Sunday morning with the last possible pickup being before 11:00am on Sunday.

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 16:30-17:30 PDT


Title: De la Explotación de Buffer Overflows al C2 Industrial: Infectando y Controlando RTUs con Malware
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

En esta charla práctica y directa al punto, se demostrará cómo una vulnerabilidad de buffer overflow puede ser explotada para comprometer entornos SCADA, evolucionando desde la ejecución de shellcode multietapa hasta el establecimiento de canales de comunicación C2 y el control remoto de sistemas industriales críticos. A través de demostraciones técnicas, se analizará cómo una vulnerabilidad aparentemente aislada puede convertirse en una cadena de ataque capaz de afectar procesos industriales, provocar interrupciones operativas e incluso derivar en escenarios de blackout.

SpeakerBio:  Fernando Mengali, Information Security Specialist

Cybersecurity researcher focused on Pentesting and AppSec, also serving as a Practical / Hands-on Speaker. He also dedicates part of his research to critical infrastructure security (ICS/SCADA), exploring the intersection between classic vulnerabilities and industrial environments. He has over 18 years of experience in offensive security and practical application exploitation.

He has participated in research and development projects focused on vulnerability exploitation and offensive security.

Specialized in 0day discovery and exploit development, he has over 135 published CVEs and is ranked in the Top 10 contributors on VulDB https://vuldb.com/users.top.

Additionally, he has published multiple exploits and technical papers publicly available https://www.exploit-db.com/?author=12136 and https://packetstorm.news/files/author/8470/1.

His work focuses on real-world vulnerability exploitation, including advanced scenarios such as memory corruption, buffer overflows, and complex environments.

He is the creator of https://yrprey.com, an educational framework that brings together more than 20 vulnerable applications based on the OWASP Top 10, used for practical training in Application Security and Offensive Security https://owasp.org/www-project-vulnerable-web-application-directory.

He is also the driving force behind https://speakfy.io, a project focused on promoting Information Security events globally.

Furthermore, he develops application security-oriented tools, such as https://leapfix.co (static code analysis) and https://fitoxs.com, a dynamic application analysis platform powered by artificial intelligence.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 11:30-12:30 PDT


Title: De-Sloppify: Your AI Needs a Proxy
Tags: Bug Bounty Village | Creator Workshop
When: Saturday, Aug 8, 11:30 - 12:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

In the workshop we will explore how to setup yourself for success with AI agents by using a tight integration with your proxy of choice. We will start with why you would want to use a proxy with AI agents (Scoping, Guardrails, Human-in-the-loop, Tool provider) and then showcase multiple ways to achieve the integration (MCP, Skills, Plugins). It will use Caido for the workshop but the concepts will be applicable to all proxies.

Speakers:Emile "TheSytten" Fugulin,Vitor "busf4ctor" Falcao Habibe Costa

SpeakerBio:  Emile "TheSytten" Fugulin, Caido Labs

Emile was a freelance devops & backend developer for many years prior to starting Caido. He always had a passion for security and working on Caido is the perfect combinaison of both!

SpeakerBio:  Vitor "busf4ctor" Falcao Habibe Costa, Frontier AI Red Team Operator, BT6

Vitor is an AI security researcher, Community Manager at Critical Thinking, and a Google VRP hunter, named Best AI Researcher at Google bugSWAT. He's part of the BT6 team and hunts bugs full time.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Saturday - 14:30-15:15 PDT


Title: Deepfake Detection Through Adversarial Research
Tags: Payment Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 15:15 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Deepfake defense is no longer just a matter of classifying media as real or fake. As attackers adopt new generators, optimize them for specific targets, and automate feedback-driven attack loops, the threat is evolving into agentic fraud. This talk presents an adversarial research approach to defending live identity-verification systems: continuously simulating realistic attacks, generating and evaluating domain-specific synthetic media, turning detector failures into new evaluation data, monitoring emerging tools, and rapidly adapting to unseen generators without overfitting to the latest attack. Ultimately, effective defense requires treating deepfake detection not as a static model-building task, but as a continuously evolving adversarial process in which success is measured by resilience against the next attack, not performance on the last one. We'll extend these concepts in the village through a hands-on challenge, inviting participants to evaluate a blind synthetic-data discrimination task, which illustrates the practical challenges of evaluating increasingly capable adversarials.

SpeakerBio:  Efim Boieru, Senior Manager of ML Engineering, Incode Technologies

10+ years in applied AI, computer vision and biometric security, focused on face liveness and deepfake detection; previously in ML research/engineering roles at Huawei and Bosch.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: DEF CON CTF: Benevolent Bureau of Birds
Tags: DEF CON CTF: Benevolent Bureau of Birds | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds) - Map

Description:

We are the Benevolent Bureau of Birds (BBB), formulated from previous victors of past DEF CON CTF contests. We are dedicated to the ethos at the core of CTF: community, skill-building, and showing off insane new hacking talent.

Participant Prerequisites

Players will have to be qualified by an online qualifer to take place in May. Chosen players are then required to have a laptop to participate in the in-person contest, to interact with the scoreboard and challenges hosted on network.

Pre-Qualification

Yes - online pre-qualifier in May 22-24, 2026.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 17:30-20:30 PDT


Title: DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers
Tags: DEF CON Official Talk
When: Saturday, Aug 8, 17:30 - 20:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

How did DEF CON Franklin's cyber volunteers helped American water systems become more secure as they rise to the top of adversaries’ target lists? This talk by Franklin co-founder Jake Braun will outline the program, share success stories from volunteer engagements, and discuss lessons learned from the past year of deployments. The session will also cover Franklin’s expansion into new states, highlight findings from the DEF CON Hackers’ Almanack, and examine why leading security tools struggle to meet the needs of resource-constrained water systems. Finally, the talk will lay out a path to scaling cybersecurity for water systems nationwide through a centrally managed network of regional MSSPs, and how the DEF CON community can help build it from the ground up.

SpeakerBio:  Jake Braun, DEF CON Franklin

Jake Braun is the co-founder of DEF CON Franklin and the Executive Director of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. He most recently served in the White House as acting Principal Deputy National Cyber Director. While at the White House, he oversaw the implementation of the National Cybersecurity Strategy, including efforts to secure our water systems, modernize the federal cyber workforce, enhance cyber cooperation with allied nations, and develop AI cybersecurity policy.

In addition to his role at the University of Chicago, Mr. Braun co-founded the DEF CON Voting Machine Hacking Village. In that capacity, he co-authored two award-winning reports on the cyber security of our election infrastructure: the DEF CON 25 and 26 Voting Village Reports. Most recently, he partnered with DEF CON, the world's largest and longest running hacker conference, to launch “DEF CON Franklin,” a program to memorialize the most innovative and impactful findings from DEF CON in the annual “Hackers’ Almanack.” “DEF CON Franklin” also recruits cyber volunteers to support underresourced critical infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Saturday - 10:00-17:59 PDT


Title: DEF CON Groups (DCG)
Tags: DEF CON Groups | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

DEF CON Groups are the year round, local communities that bring the DEF CON spirit home. Run by volunteers around the world, DCGs create spaces where hackers meet, learn, collaborate, and build community outside of conference season.

The DEF CON Groups community space brings together Points of Contact, members, and prospective members to collaborate, share ideas, and learn from one another. Through informal workshops and hands on interaction, participants exchange practical lessons on building, sustaining, and evolving local hacker communities.

The space also serves as a social anchor. A relaxed place to reconnect with old friends, meet new ones, and participate in light interactive activities that reflect the collaborative nature of hacking culture.

DEF CON has always been the island of misfit toys we all return to once a year. DEF CON Groups are how that ethos survives the other fifty one weeks.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: DEF CON Groups Backdoors & Breaches
Tags: DEF CON Groups | DEF CON Groups Backdoor & Breaches | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

Tournament-Style Backdoors & Breaches Competitive – Live Incident Response Showdowns The DEF CON Groups Community is bringing live, bracket-style Backdoors & Breaches Competitive Games to DEF CON 34. Backdoors & Breaches is an incident response card game built around realistic breach scenarios. In our tournament format, teams step into the roles of adversaries, where they will take turns attacking or defending against each other. They must analyze scenarios, identify adversarial tactics, make technical and business decisions, and mitigate damage before attackers wipe them out of the game. This isn’t passive content. This is live, projected, real-time decision-making. Matches will be bracketed and displayed on screen so attendees can watch strategies unfold, debate choices, and learn from both brilliant plays and catastrophic missteps. Spectators become students of the game — observing how attacks progress, how defenders prioritize, and how communication and leadership shape outcomes. Participants can: • Join the tournament on the spot — no pre-qualifiers required • Compete in structured brackets • Win donated swag • Learn incident response by doing, not just listening What will you learn? You’ll see how modern attacks move from initial access to impact. You’ll experience the tension of limited funding. You’ll learn how small decisions compound during an incident. You’ll understand how legal, executive, and technical perspectives collide in a breach scenario. Most importantly, you’ll build intuition for thinking like both attackers and defenders. This is hacking culture through simulation: adversary thinking, defensive strategy, rapid analysis, and creative problem solving — all wrapped in competition. Located inside the DCG Community space, the tournament creates visible energy and draws attendees into a broader ecosystem of DEF CON Groups, workshops, sticker contests, and community collaboration. If you’ve ever wanted to see incident response as a spectator sport — or test your instincts under pressure — pull up a chair.

Speakers:Tim Doerges,Seth Benning

SpeakerBio:  Tim Doerges, Lead Developer | Backdoors & Breaches at Black Hills Information Security

Tim Doerges is the Lead Developer for Backdoors & Breaches at Black Hills Information Security and will facilitate the live tournament-style matches at DEF CON 34.

SpeakerBio:  Seth Benning, Product Developer at Black Hills Information Security

Seth Benning is an Assistant Conference Coordinator and Product Developer with Wild West Hackin' Fest and Black Hills Information Security. He will help facilitate the Backdoors & Breaches tournament at DEF CON 34.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: DEF CON Groups Sticker Contest
Tags: DEF CON Groups | DEF CON Groups Sticker Contest | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

The DCG Sticker Contest is a sticker design contest withwinner by popular vote and voting happening during DEF CON 34.

Anyone can submit original, human-created sticker designs prior to DEF CON 34. During DC34 attendees view all entries on site, and vote in person for their favorites. Designs will be displayed in the DEF CON Groups Community space throughout the conference, with voting open on Thursday to Saturday and the winning design announced on Sunday.

Stickers are hacker currency. This contest is about celebrating that culture through creativity, participation, and community choice. The top designs go through to the voting round. What wins is what the DEF CON community votes for.

Whether you want to support fellow hackers, or help decide the winning design, this is your chance to participate directly.

Participant Prerequisites

For designers / contributors: - Original sticker artwork created by a human (no AI-generated art) - You may design it yourself or work with a human graphic designer - Ability to submit artwork digitally prior to DEF CON - No specialized technical knowledge required

For voters: - Attendance at DEF CON - Ability to view entries in person and cast a vote - Voting is honor-based: one human, one vote - Participants may vote

No special hardware, software, or prior experience is required to participate or vote.

Pre-Qualification

A call for sticker designs will open prior to DEF CON with the contest and voting happening on-site.

Activity schedule: Thursday setup and preview; Friday and Saturday active voting; contest winner announced Sunday on the Contest Stage. See the Hacker Tracker Contest Stage entry for announcement details.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: DEF CON Scavenger Hunt
Tags: DEF CON Scavenger Hunt | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt) - Map

Description:

Whether you're a seasoned DEF CON veteran or a curious newcomer, the DEF CON Scavenger Hunt promises to challenge your skills, tickle your wits, and ignite your hacker spirit. Our list is a portal to mystery, mischief, and mayhem. Assemble your team of up to 5 members, interpret the items, and submit your efforts at the booth to our esteemed judges. Go beyond the basics for bonus points. Legends are born here.

The DEF CON Scavenger Hunt is open to everyone, regardless of skill level or experience, no pre-qualifying necessary. We strive to maintain the balance of a low barrier to entry while providing a challenge that many are eager to take on. Casual players should not be overwhelmed by the list, find a handful of items and have fun. If you are looking to win however, you will need to fully immerse yourself in the DEF CON Scavenger Hunt. Let's make some memories together.

Remember that it's not just about fame, glory, or boxes of swag; the true allure is the camaraderie of fellow hackers, the knowledge that you've etched your mark on DEF CON history, and the ultimate badge of honor: bragging rights. Nothing says "I'm a hacker" quite like being triumphant at the DEF CON Scavenger Hunt.

Participant Prerequisites

No, we work very hard to maintain a very low barrier to entry. If anything is required for an item, they should be able to find a fellow hacker with it that would be willing to assist them with their item.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 06:00-07:59 PDT


Title: Defcon.run
Tags: Event
When: Saturday, Aug 8, 06:00 - 07:59 PDT
Where: LVCCW Level 1 North Entrance - Map

Description:

Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances.

For DEF CON 34, meet at "The Spot" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype.

Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 10:45-11:25 PDT


Title: Demystifying the Playboy RaaS
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:45 - 11:25 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

In recent years, ransomware has become one of the most prolific forms of cybercrime with financial gain as primary motive. The problem keeps getting bigger, with a new operation seeing the light almost every month. The Dutch National Police is often a key player in large-scale ransomware investigations. Operation Cronos is a prime example, where law enforcement took down infrastructure of the infamous LockBit group in 2024.

Today, many ransomware groups operate RaaS (ransomware-as-a-service) models. They provide the ransomware and a platform to extort victims as a service, and affiliated hacker groups carry out the actual attacks. The platform is often run from a VPS (virtual private server), and sometimes, this server is in the Netherlands. Dutch law enforcement seizes those servers and extracts their content for investigation. This happened to the Playboy ransomware in late 2024.

A chain of various tools is used to provide a ready-to-use ransomware package to affiliates of a RaaS program. Several modern ransomware operations even support CPU architectures and operating systems other than x86-64 and Windows. New cryptographic keys are generated for every victim, ransomware parameters are configured, and a builder creates the final package to be used by the affiliate. In this talk, we will reveal how we seized the Playboy ransomware servers, dive into its toolchain, and look at how executables were prepared to breach victims.

SpeakerBio:  Gijs Rijnders, Malware & CTI Specialist

Gijs is a cyber threat intelligence analyst and malware reverse engineer at the Dutch National Police where he defends the Police organization from cyber attacks. He previously worked at the CERT of Tesorion, a Dutch cybersecurity company, where he reverse engineered various ransomware families and published decryption tools to the NoMoreRansom initiative to help victims recover from attacks.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 12:30-13:30 PDT


Title: Descubrimiento Industrializado de CVEs con Agentes de IA
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

¿De verdad puede la IA encontrar vulnerabilidades reales y nuevas a gran escala? La seguridad de aplicaciones es nuestra disciplina, y somos una CNA de tipo investigador, entre las primeras del CNA Scorecard. Montamos una cadena de producción y la soltamos sobre 36 proyectos de código abierto. Hasta ahora, y contando: 539 hallazgos revisados, depurados hasta 8 CVEs públicos y 30 candidatos a CVE.

La charla recorre la cadena completa: cómo entrenamos agentes que recorren el código, cómo un modelo de machine learning detecta los fragmentos sospechosos, cómo los hackers y researchers validan cada candidato y qué números deja cada etapa del filtrado.

Nuestra meta: acortar el tiempo de detección a escala sin sacrificar exactitud, para que la ventana de exposición (detección + remediación) sea menor que el tiempo de explotación. Te llevas un método replicable para convertir LLMs impredecibles en una fábrica seria de CVEs, con las métricas de precisión que la sostienen.

Speakers:Simon Correa,Michael Rivera

SpeakerBio:  Simon Correa, Fluid Attacks, Head of Research

Simón Correa, Head of Research en Fluid Attacks, es responsable de coordinar el CNA de la compañía, realizar investigaciones técnicas de ciberseguridad y liderar la detección de vulnerabilidades en software open source de terceros, gestionando todo el ciclo de vida de los CVEs desde su descubrimiento hasta su publicación. Además, coordina y participa en el equipo interno de CTFs, analizando el rendimiento y diseñando estrategias de mejora para futuras competencias. En su rol, mantiene la interlocución con MITRE y NIST, prepara publicaciones académicas y ponencias para conferencias especializadas, y organiza meetups técnicos que fortalecen el posicionamiento de Fluid Attacks en la comunidad de seguridad.

SpeakerBio:  Michael Rivera, Chief Data & AI Officer | M.Sc. in Analytics

Michael Rivera is the Chief Data & AI Officer at Fluid Attacks, where he leads initiatives that combine advanced data analytics and artificial intelligence to strengthen software quality and security. His work in recent years has focused on developing methods that reduce the time required to detect vulnerabilities and on ensuring that AI-driven systems are built under the security-by-design approach.

Michael combines an academic background in economics with his Master of Science in Analytics at the Georgia Institute of Technology, enabling him to bring an uncommon interdisciplinary perspective to the field of cybersecurity. With years of experience bridging data science and AppSec practice, he offers both technical depth and strategic insight, making him uniquely positioned to help organizations adopt rigorous frameworks for evaluating security solutions.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 10:00-10:45 PDT


Title: DFMI: Weaponizing MSI Installers for Fileless Code Execution
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

DFMI is a cross-platform, open-source offensive toolkit that hijacks & abuses the Windows Installer's own execution engine to detonate arbitrary payloads during software installation, with zero files written to disk and zero evidence left behind. And this can be achieved without corrupting the Authenticode of the binary. --Which means, ANY signed legitimate installer file can leveraged as an attack vector.

Right now, DFMI provides 3 different methods for abusing MSI files:

GitHub: https://github.com/ccelikanil/DFMI

SpeakerBio:  Anil Celik

Computer Engineer & been working as a Red Teamer for the past ~7 years. Previously did presentations at DEFCON 33 Demo Labs, DEFCON 33 Red Team Village & Black Hat USA Arsenal 2025. Currently holding 6 CVEs, OSCP & OSWP.

Interests: Windows Internals & AD Security


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Saturday - 11:00-11:30 PDT


Title: Digital Modes 101: The Weird, Wonderful World of Computer Radio
Tags: Ham Radio Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:30 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

Digital communication has become one of the fastest-growing areas of amateur radio. By combining traditional radio equipment with computers and software, operators can send text messages, telemetry, position data, and even digitally encoded voice across the airwaves.

This presentation introduces the fundamentals of amateur radio digital modes and how they work. We’ll begin by explaining the difference between analog and digital signals and how computers convert data into audio that radios can transmit.

The talk then explores several widely used digital modes, including FT8 and WSPR for weak-signal communication, JS8Call for keyboard-to-keyboard messaging, and APRS for real-time position tracking and messaging. We’ll also look at newer developments such as LoRa-based APRS experimentation and open-source digital voice technologies like FreeDV and M17.

Finally, we’ll discuss practical ways to get started with digital radio using affordable hardware, including simple USB radio interfaces, beginner-friendly radios, and lightweight portable setups.

Attendees will leave with a clear understanding of how digital radio works and several easy paths to begin experimenting with digital modes themselves.

Modern amateur radio is no longer just voice communication. Today, radios routinely exchange digital data, text messages, telemetry, and even machine-learning encoded voice signals.

This talk introduces the world of amateur radio digital modes and explains how computers and radios work together to communicate using sound. We’ll explore some of the most popular digital modes used by operators today, including FT8, JS8Call, WSPR, APRS, and several emerging digital voice technologies.

Attendees will learn what digital modes are, how they differ from traditional analog radio, and why they have become so popular. The session will also highlight new developments in the digital radio ecosystem, including open-source digital voice systems and long-range LoRa APRS experimentation.

If you've ever wondered what those strange buzzing sounds coming from a radio actually mean—or how to start experimenting with digital radio yourself—this talk will show you how to get started.

SpeakerBio:  Jon Marler (K4CHN)

Jon Marler is a cybersecurity product director, hacker, and RF experimenter who enjoys building strange things that connect computers, radios, and networks together. By day he leads security products at VikingCloud focused on protecting global payment infrastructure. By night he experiments with mesh radio networks, hardware hacking, and unconventional communication systems. Jon is particularly interested in how radio and decentralized networks can complement modern security and resilience strategies.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: Discover GE Appliances!
Tags: IoT Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances!


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 14:30-14:59 PDT


Title: Dissecting the ICX Frog
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 14:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

In 2022, a Dominion Voting Systems ImageCast X ballot marking device (ICX BMD) appeared for sale on eBay and was purchased by security researcher Harri Hursti. Originating in Colfax Township, MI and after being "donated by accident" to Goodwill, it debuted at Voting Village 2023 and has since been the subject of great interest and used for proof-of-concept demonstrations (PoCs) within the village. As the only known instance of a legally-obtained ICX being available for study without burdensome secrecy/pre-publication review agreements, it represents a unique opportunity for improving and updating our understanding of certified, adopted, and deployed voting systems from an engineering and security perspective (among others).

In this talk, we will discuss the hardware, software, architecture, and capabilities of the ICX BMD from a technical perspective. Significant reverse-engineering of its Democracy Suite 5.5 software has revealed much regarding its design, construction, and internal operation along with a few surprises along the way. While one part of one version of one system from one vendor is far from sufficient to draw conclusions about currently-used voting systems in-general, this talk hopes to shed light on what a currently EAC-approved voting system could be.

SpeakerBio:  Drew Springall

Drew Springall is a hacker, security researcher, and frequent Voting Village contributor with a specific interest in the technical/concrete aspects of voting system security. Since 2013, Drew has worked to understand the challenges encountered by and demonstrate the capabilities of realistic attackers should they attempt to interfere with such systems as commonly deployed. In those years, Drew has built and demonstrated many proof-of-concept attacks across various areas of voting system security including Internet Voting, voter-facing software/hardware, ballot de-anonymization, and physical protections.


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Saturday - 12:30-12:59 PDT


Title: Donating Bone Marrow: A Donor's First-Hand Experience
Tags: National Marrow Donor Program (Be the Match) | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Donating bone marrow can save lives, but many don't understand what it really involves. Find out the experience and how you can help participate in one of the coolest bio-hacks ever.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 12:00-14:59 PDT


Title: Dozier Drill Tournament
Tags: Lockpick Village | Dozier Drill Lockpicking Challenge | Contest
When: Saturday, Aug 8, 12:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

Have you ever wanted to break out of handcuffs, pick open a closed bag and shoot your buddy in the chest with a nerf gun? So have we, that's why TOOOL presents the Dozer Drill. A fast paced skill based game where you have to free yourself from handcuffs, open a closed bag, and retrieve the nerf gun to be the first to hit the target. Join us on Friday for qualifiers, through the con for unofficial games, and on Saturday for an official bracket tournament.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 11:00-11:59 PDT


Title: DPAPI Is Not a Boundary: A Full Infostealer Kill Chain Operators Can Replicate
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Complete infostealer kill chain hands-on, executed against Windows 11 21H2 on default UAC using only open-source tooling. No zero-days, no commercial C2. Participants run every command live: HTA delivery, Meterpreter in-memory session, Chrome and Edge credential extraction via DPAPI-locked SQLite, keylogging in explorer.exe memory, UAC bypass via fodhelper, SYSTEM via Named Pipe Impersonation, and LSASS dump via Kiwi. The DPAPI_SYSTEM key recovered from LSA secrets decrypts the browser credentials captured earlier, closing the loop.

OUTLINE

Stage 1: generate HTA payload, deliver via Python HTTP server, open Meterpreter session Stage 2: extract Chrome and Edge credentials via post module, inspect DPAPI-encrypted loot Stage 3: migrate to explorer.exe, start keyscan, capture live keystrokes Stage 4: UAC bypass via fodhelper registry hijack, elevate to SYSTEM via Named Pipe Impersonation Stage 5: load Kiwi, dump NTLM hashes, SAM, LSA secrets, extract DPAPI_SYSTEM key, decrypt browser loot Detection debrief: Sysmon Event ID 1 process tree and PowerShell Script Block log review per stage

TAKEAWAYS

  1. A complete credential theft playbook from HTA delivery to LSASS dump, validated against Windows 11 21H2 with Chrome 147 and Edge 147 on default UAC, ready to adapt for engagements.
  2. The DPAPI close-loop: how DPAPI_SYSTEM from LSA secrets decrypts browser credentials collected earlier, giving operators a concrete credential pivot from a single user-context session.
  3. A detection gap map calibrated against real Sysmon telemetry showing which events fire on default Windows 11 and which require EDR behavioral rules most organizations do not have deployed.
SpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I'm Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0 Black Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires DEF CON 33 / 32 - https://sessionize.com/filipi-pires/ DEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 16:00-16:59 PDT


Title: Dreamcast Ex Inferis — RCE on the Sega Dreamcast PlanetWeb Internet Browser v3.0
Tags: Game Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:



SpeakerBio:  Piffd0s
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 10:45-11:30 PDT


Title: Dreamcast Ex Inferis: RCE on the Sega Dreamcast PlanetWeb Browser
Tags: Game Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:45 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

The PlanetWeb Internet Browser v3.0 (2000–2001) is the official disc that let you browse the web and read email on a Dreamcast. Its online features depend on a backend server that no longer exists. The dreamcast is now a networked, code-downloading appliance whose trust model rests on a domain anyone can now point wherever they want.

What We Did

This is a full unauthenticated, network-only attack. By answering DNS for the dead backend domain, we get the browser to download and run our code. From there we chain through the mail client to reach the console's bare metal, and end by running DOOM natively.

No physical access, no modchip, no user trickery beyond opening one email. The console was built to download and trust code from a server that's gone — so we just become that server.

The talk walks through the chain at a high level, the obstacles of debugging a 24-year-old black box, and what it takes to get a modern game engine running in the few megabytes of RAM the Dreamcast has — ending with a live demo of DOOM running on the browser.

Why It Matters / Why It's Fun

It's a clean case study in why abandoned online infrastructure is a security problem that outlives the product, and it's a nostalgic hardware-hacking story with the most satisfying possible payoff: DOOM, on a Dreamcast, over the internet.

SpeakerBio:  Christopher Hernandez, Binary Enthusiast

Chris Hernandez is a security researcher specializing in vulnerability discovery, exploitation, and large scale reverse engineering using IDA Pro. A Pwn2Own competitor in the ICS/SCADA and embedded systems categories, he actively collaborates with the reverse engineering community to solve binary analysis challenges.

--

Chris Hernandez is the founder of Adversary Consulting Group and an offensive security researcher with more than a decade of experience in vulnerability research, reverse engineering, and exploit development. He holds the OSEE certification and has competed at Pwn2Own in the IoT and ICS/SCADA categories.


Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Saturday - 13:00-13:59 PDT


Title: Drive Stats: 14 years of hard drive failure rates
Tags: Data Duplication Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:

For over 14 years, Backblaze has been collecting the failure rates of hard drives in our data centers. But, what does that even mean? How do you define a failure, and how does that definition define or obscure the realities of drive performance?

SpeakerBio:  Stephanie Doyle, Sr. Manager and Keeper of Stats at Backblaze

Stephanie Doyle is a Sr. Manager at Backblaze and known as the Keeper of Stats. She oversees the various first party data reports including Drive Stats, which reports on the failure rates of hard drives in Backblaze data centers; Network Stats, which reports on network traffic into and out of Backblaze's network; and Performance Stats, which publishes quarterly testing on cloud storage benchmarks. She specializes in taking complex topics and writing relatable, engaging, and user-friendly content. You can most often find her reading in public places, and can connect with her on LinkedIn.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Drone Hacking Choose your Own Adventure
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Dive into our interactive choose-your-own-adventure web interface and learn how to hack a drone in a fun, storyboard-based game. This graphical user interface simulates the process we use when hacking drones for the Air Force, allowing participants to make decisions and see the outcomes.

It's a beginner-friendly, 15-30 minute activity offering insights into the steps involved in drone penetration testing.

Participants can access it from their own computers or mobile phones.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Drone Hacking Workshop
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Join our Drone Hacking Workshop for hands-on experience hacking drone components. This three-step in-depth activity is designed to teach you about the vulnerabilities and security of autonomous systems. Using sample drones, participants will learn techniques used in government pen tests.

This 2-3 hour workshop suits all skill levels, from beginners to advanced hackers. Come and test your skills in a real-world scenario and understand the intricacies of drone security.

Participants need to bring a laptop capable of running a Linux distribution.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 15:00-15:55 PDT


Title: Drone ID on the Wire: RF Detection, Spoofing, and the Limits of Compliance-Based Airspace Awareness
Tags: Radio Frequency Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

The low-altitude airspace has an RF problem. The FAA mandated Remote ID as the foundational identification standard for drone operations across the United States - a broadcast protocol running on Bluetooth and WiFi that any phone is supposed to receive. The problem is that it was designed for individual accountability, not area surveillance, has a practical detection range measured in hundreds of meters, is completely unencrypted and unauthenticated, and is trivially spoofable with an ESP8266 and three dollars in hardware. Meanwhile the proprietary protocol it largely replaced - DJI's OcuSync Drone ID - was detectable at tens of kilometers, is now encrypted on newer hardware, and its primary detection product was discontinued. The gap between what practitioners think Remote ID provides and what it actually provides is a fundamental RF problem with direct public safety consequences.

This talk lives in the RF layer. We will cover what drone broadcasts actually look like on a receiver - Remote ID over BLE advertising channels 37/38/39 and WiFi beacon frames on channels 6 and 149, DJI Drone ID embedded in OcuSync, and what non-broadcasting drones look like (nothing). We will walk through the full detection stack from a $50 COTS build (Ubiquiti Bullet M2, OpenWRT, tcpdump, Wireshark, OpenDroneID dissector) through man-portable dedicated receivers (DroneTag Rider), distributed mobile detection via ATAK plugins (Drone Hone), and enterprise fixed-site systems - and we will show real sensor performance data from multi-sensor deployments at major federal security operations. Key finding: 95.5% of unique drones detected across a SEAR 1 National Special Security Event were seen by only a single sensor. The multi-sensor fusion problem is unsolved at urban scale, and the urban RF environment - path loss, noise floor, building shadows — is why. We will then walk through the spoofing ecosystem in depth. Ghost swarm attacks (jjshoots/RemoteIDSpoofer - 16 fake drones, web UI, $3 ESP8266), pilot location spoofing (brinuk/Remote-ID-Drone-and-Pilot-Spoofer - sends ground teams to empty parking lots), DJI Drone ID spoofing (DJISDKUser/ESP8266_DJI_DroneID_Throwie - Kevin Finisterre, taped to a fence, runs forever), and protocol-level implementations (cyber-defence-campus/droneRemoteIDSpoofer - Python/Scapy, ASTM F3411 plus DJI format, Swiss Cyber Defence Campus provenance). All public, all GitHub, all under $5 hardware. We will cover the attack taxonomy: evasion, flooding, identity spoofing, and operator location spoofing - and what each one means operationally for the detection stack.

The legal layer is real and the audience should know it: 6 USC 124n authorizes four federal agencies to take action against drones. Nobody else can jam, spoof, or kinetically defeat without federal authority. The possession/testing/broadcasting distinction matters and we will be clear about it.

We close with the governance gap: Remote ID's authentication-free design was a deliberate policy choice. The FAA Reauthorization Act of 2024 directed a review of whether cryptographic signing could be added. That review is ongoing. The people in this room build the tools that inform these conversations - this is the right audience to have opinions about what the answer should be.

No policy background required. If you know what a waterfall is you are the target audience.

SpeakerBio:  Greg Albrecht
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 13:00-13:59 PDT


Title: Dylib Hijacking on macOS: Dead or Alive?
Tags: DEF CON Official Talk | Demo 💻
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Over a decade ago, a much younger Patrick showed that macOS (then OS X) was vulnerable to what had long been considered a Windows-only attack: dynamic library hijacking. By planting malicious libraries in the right place, attackers could achieve stealthy persistence, inject code into trusted processes, and even bypass core Apple security mechanisms.

Today, an older (and hopefully wiser) Patrick revisits that work to answer a simple question: is dylib hijacking truly dead on modern macOS, or has Apple’s decade of defenses, including Gatekeeper, App Translocation, Notarization, and the Hardened Runtime, simply made it harder?

This talk revisits the technique in 2026, analyzing these mitigations and evaluating their real-world effectiveness. While the attack surface has been significantly reduced, we show dylib hijacking remains possible under the right conditions. Through real-world examples and live demos, we explore how modern applications can still be coerced into loading attacker-controlled libraries, enabling code execution within trusted processes and bypassing controls such as TCC.

Finally, we present practical detection and defense strategies, including novel approaches leveraging Endpoint Security to detect (and block!) malicious library loads at runtime.

"Dylib hijacking on OS X" 
www.virusbulletin.com/virusbulletin/2015/03/dylib-hijacking-os-x

"Tweaking macOS security controls to thwart application bundle manipulation" 
redcanary.com/blog/threat-detection/mac-application-bundles/

"What's New in Security" (WWDC 2016)
 devstreaming-cdn.apple.com/videos/wwdc/2016/706sgjvzkvg6rrg9icw/706/706_whats_new_in_security.pdf

SpeakerBio:  Patrick Wardle, CEO and Co-Founder at DoubleYou

Patrick Wardle is the cofounder of the Objective-See Foundation, CEO and cofounder of DoubleYou, and author of The Art of Mac Malware series. He previously worked at NASA and the NSA, and has presented at countless security conferences, making him intimately familiar with aliens, spies, and talking nerdy.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 12:30-12:59 PDT


Title: Eating Our Own Dogfood: Running a Bug Bounty Program on a Bug Bounty Platform
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

At HackerOne, the same community that submits vulnerability reports also tests the platform they use to report them. Every report becomes a live stress test of our product, workflows, assumptions, and newly shipped features. In this talk, a Senior Triage Lead and a Product Security Engineer share what we learned from running HackerOne’s own bug bounty program while shipping GraphQL features, AI-assisted tooling, disclosure workflows, and platform-scale infrastructure changes. Using three real disclosed reports, we walk through how seemingly small bugs escalated into platform-wide security lessons: 1. An Elasticsearch query parameter that enabled metadata enumeration through raw script execution. 2. A PDF export feature that unintentionally exposed internal triage activity. 3. An AI agent that exposed non-public report metadata because a researcher asked the right question. We will show how reports move from submission to validation, severity debates, engineering response, remediation, retesting, and disclosure. We will also discuss how we use our own program as a testing ground for AI-assisted triage, automated validation workflows, and disclosure policies before rolling changes out more broadly. This is not a “how to run a bug bounty program” talk. It is a behind-the-scenes look at what happens when hackers continuously attack the bug bounty platform itself and how that pressure forces rapid security evolution. Attendees will leave with practical lessons on: 1. building tighter triage-to-engineering feedback loops, 2. handling modern attack surfaces like GraphQL and AI agents, 3. scaling remediation without losing researcher trust, 4. and turning bug bounty programs into product improvement engines instead of passive inboxes. All case studies are based on disclosed HackerOne reports. No customer data was accessed or exposed.

Speakers:Shrimant Subhash More,Martzen Haagsma

SpeakerBio:  Shrimant Subhash More, Senior Security Analyst, HackerOne

Shrimant Subhash More is a Senior Product Security Analyst at HackerOne with over 8 years of experience in offensive security, penetration testing, and vulnerability management. His expertise spans web, API, mobile (Android and iOS), and AI/LLM security, with more than 300 security assessments conducted across diverse industry sectors. At HackerOne, Shrimant leads and supports vulnerability triage operations, validates security reports submitted by researchers, handles escalations, mentors analysts, and collaborates with global teams to improve security outcomes and triage efficiency. He is passionate about offensive security, product security operations, security automation, and helping organizations build resilient products. Beyond his professional role, Shrimant actively contributes to the cybersecurity community as a HackerOne Community Brand Ambassador for India West (Pune), where he organizes meetups, conducts workshops, mentors aspiring researchers, and promotes responsible disclosure and bug bounty programs. He is the assignee of CVE-2020-35296 and holds multiple industry certifications across security, cloud, and AI domains.

SpeakerBio:  Martzen Haagsma, Security Engineer, HackerOne

Martzen Haagsma is a Product Security Engineer at HackerOne with a passion for building secure systems through collaboration, automation, and continuous learning. With experience spanning security testing, DevOps engineering, and technical leadership, Martzen focuses on helping organizations identify vulnerabilities, improve security processes, and strengthen their overall security posture. Known for a solution-oriented mindset and a strong belief in the power of teamwork, Martzen enjoys connecting people, sharing knowledge, and turning complex security challenges into practical outcomes. Prior to joining HackerOne, Martzen worked across both public and private sectors in roles involving security testing, agile quality engineering, and engineering leadership. Outside of work, Martzen is an active technologist with interests ranging from security and software development to automation, IoT, and 3D printing. Through writing, mentoring, and community engagement, Martzen advocates for curiosity, collaboration, and making technology more secure and accessible for everyone.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 18:00-20:59 PDT


Title: EFF Tech Trivia
Tags: EFF Tech Trivia | Contest
When: Saturday, Aug 8, 18:00 - 20:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

EFF's privacy and security experts have crafted a new trivia challenge for DEF CON 34! Compete as a team in our no-holds-barred showdown to prove mastery over the obscure facts of digital security, online rights, and internet culture.

The First Place team wins a set of custom Cybertiger Champion Badges and EFF swag. Second and third place teams will also win Badges and EFF gear.

Invite your friends OR show up and make new friends! Did someone say BRIBES?The world is unfair! You too could influence the judges to add a point or two to your team's tally. Overall Bribe winner also wins a custom badge! Test your knowledge of all things tech and support EFF, too.

Participant Prerequisites

No phones, laptops, or other digital knowledge allowed! Just you, your friends, and a friendly game of trivia.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 17:00-17:30 PDT


Title: Election Observation: Watching is not Enough
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

As Dan Wallach once said, an election must convince the losers that they lost fair and square. To do this, election administrators need to do more than merely allowing observers from all parties to watch, we must ensure that observers can understand what they are seeing. Watching the back of an election administrator doing something with a computer or even a with a stack of papers is not useful. Anecdotal reports by observers can give a feel for how an election was conducted, but systematic and well documented reporting is far more powerful. Election observation is difficult with simple in-person vote-for one contests; vote by mail, Internet voting and instant runoff voting all pose serious problems for election observers. We must demand electoral procedures that are easy to understand, and we must demand public documentation of those procedures. This talk will focus on successes and failures in election observation and suggest directions for future improvement.

SpeakerBio:  Douglas W. Jones

Douglas W. Jones has been involved with election technology since he was appointed to the Iowa Board of Examiners for Voting Machines and Electronic Voting Systems in 1994. Since then, contributed to the 2002 FEC Voting System Standards, served on the Election Assistance Commission's Technical Guidelines Development Committee, tested voting equipment in Miami and Phoenix, and observed elections in Kazakhstan and the Netherlands. He has testified about voting technology before the House Science Committee, the Federal Election Commission, and in numerous court cases. He was a principal investigator in the NSF funded ACCURATE project, and with Barbara Simons, co-authored the book Broken (CSLI Press, 2012).

He got his PhD in Computer Science from the University of Illinois in 1980, and was on the CS University of Iowa CS faculty until 2021. These days, when he is not answering questions about elections, he is working with a small group of students to restore a 1965-vintage PDP-8 computer.


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Saturday - 10:00-17:59 PDT


Title: Embedded - 101 Labs
Tags: Embedded Systems Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

We have a lab platform that brings everyone from every skill level to the same playing field with step by step instructions that aim to teach individuals specific techniques and skills in a hands-on manner on embedded hacking techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Saturday - 10:00-17:59 PDT


Title: Embedded & Shredded: Advanced Embedded System Hacking
Tags: Biohacking Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map

Description:

This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities:


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 11:30-11:40 PDT


Title: Embedded System Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 11:30 - 11:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Embedded System Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Embedded System Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Saturday - 10:00-17:59 PDT


Title: Embedded Systems Village CTF
Tags: Embedded Systems Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

Get hands-on with devices you won't find anywhere else — rare, hard-to-source embedded devices staged for live exploitation. Hunt real zero-days, and yes, bring your AI: LLM-assisted tooling is fully allowed, so use it to go as deep as you can.

Come break something that's never been broken.

New to embedded? Just wrapped our 101 Labs? Beginner challenges are available as well to apply your new found knowledge!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 12:00-12:45 PDT


Title: Empire 7: Shipping a C2 at AI Speed
Tags: Intro/Beginner | AI | DEF CON Demo Labs | DevOps | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Empire 7 is a near-total overhaul of the Command and Control (C2) framework, from how agents communicate with the server to how operators move through engagements. This major release continues to expand Empire's supported agents to include PowerShell, Python, IronPython, Go, C#, and now C. New tradecraft includes more than 50 new modules derived from Atomic Red Team, patchless AMSI/ETW bypasses, EarlyBird process hollowing, BOF execution with ILRepack assembly merging, and RDP session hijacking, among others. Empire's new cryptographically secure communications leverage AES-256-GCM and mTLS, with MITRE ATT&CK integration to assist in emulating real-world Advanced Persistent Threat (APT) Tactics, Techniques, and Procedures (TTPs).

One more thing we'll talk about, this release shipped at roughly 10x our prior pace, due to our team’s adoption of agentic coding tools as a core development collaborator. We'll share what worked, what didn't, and what LLM-assisted offensive tooling development looks like.

Speakers:Vincent "Vinnybod" Rose,Jake "Hubbl3" Krasnov,Anthony "Coin" Rose

SpeakerBio:  Vincent "Vinnybod" Rose

Vincent "Vinnybod" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/.

SpeakerBio:  Jake "Hubbl3" Krasnov

Jake "Hubble" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON.

SpeakerBio:  Anthony "Coin" Rose

Dr. Anthony "Coin" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Saturday - 10:30-10:59 PDT


Title: Emulating the “Identity-First” Threat Actor: Automated Playbooks for IdP Hijacking
Tags: Adversary Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Modern intrusions often start with identity, not malware. Adversaries abuse IdP drift, device code flows, stale sessions, weak conditional access, helpdesk processes, SaaS integrations, and cloud role mappings. This talk presents a safe emulation framework for identity-first threat actors across AD, Entra ID, Okta-like workflows, and cloud control planes. The lab provides ATT&CK-aligned playbooks that simulate identity compromise, IdP pivoting, session abuse, and SaaS access without stealing real credentials. The focus is measurable purple-team validation: expected telemetry, detection hypotheses, failure points, and repeatable scoring.

Speakers:Samet Can Tasci,Mehmet Önder Key

SpeakerBio:  Samet Can Tasci, Senior Linux Systems Engineer

Samet Can Tasci is a Senior Linux Systems Engineer and security researcher with experience across enterprise infrastructure, cloud and hybrid environments, automation, and defensive security validation.

His research interests include web defense behavior, WAF normalization gaps, parser inconsistencies, adversary-informed testing, and practical tooling for security teams.

He is the creator of WaffleX, a research prototype selected for Black Hat USA Arsenal, which focuses on semantic consistency analysis, enforcement drift, and family-level request-variant testing across modern web application defense stacks.

SpeakerBio:  Mehmet Önder Key, Cyber Security Consultant

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Escalation Desk CTF
Tags: Call Center Village | Escalation Desk CTF | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

Customer service channels are increasingly saturated with conversational text and voice AI agents. Can you convince, trick, or break enough of them to earn your shot at a live human operator in a real-world call center?

Escalation Desk is Call Center Village's capture-the-flag challenge. Start with low-pressure AI agents and learn how to spot, avoid, and exploit common pitfalls and patterns in system prompts — eventually unlocking live human operators at our partner call centers. A real-time leaderboard tracks solo and team progress, with our not-so-famous Golden Telephone Booth trophy awarded to the top participant.

Hit our minimum point threshold and earn a special Call Center Village 100 Trying black flight tag. The top individual and their team also take home the rare Call Center Village 200 OK gold flight tags. Bring your tags to Party Line, Call Center Village's after-hours telephony-themed party, and enjoy free refreshments for your spoils.

Escalation Desk is beginner (and introvert) friendly — if you can dial a phone number or use a keyboard, you can participate. Bring your own laptop and headset, or use one of our village stations. Active Noise-canceling headphones with a microphone are highly recommended.

The CTF will run during village hours, pausing when the village closes each night, and ends on Sunday at 12:00.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 12:00-12:59 PDT


Title: Europe’s Expanding Role in Global Vulnerability Management
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

The Common Vulnerabilities and Exposures (CVE) Program has become foundational to global cybersecurity operations. However, as vulnerability discovery accelerates and regulatory frameworks emerge, CVE is no longer just a technical reference system — it is evolving into critical infrastructure at the intersection of security and public policy. This talk presents ENISA’s operational and policy role in strengthening the global CVE ecosystem, including its designation as a CVE Numbering Authority and Root CNA, its development of the EU Vulnerability Database (EUVD), and its mandate under the Cyber Resilience Act to build a Single Reporting Platform for vulnerability coordination across Europe. Moreover, the talk will explain how ENISA plans to operationalize the collected data to strengthen the overall security ecosystem. The session will explore how policy decision at EU level impact vulnerability disclosure, coordination, and data quality — and how Europe is scaling its role without fragmenting the global system. The goal is to provide a practical, but both strategic and operational perspective on how the EU’s increased role in this area will ensure a more resilient and interoperable vulnerability ecosystem. (This talk will develop both talks held by ENISA at VulCon 2026)

Speakers:Nuno Rodrigues Carvalho,Razvan Gavrila

SpeakerBio:  Nuno Rodrigues Carvalho, ENISA - The European Union Agency for Cybersecurity

Nuno Rodrigues Carvalho currently serves as Head of Sector of the Incident & Vulnerabilities Services within the Operations and Situational Awareness Unit (OSA) of the European Union Agency for Cybersecurity (ENISA). He leads the department in ENISA dealing with the development of Vulnerability Services (including the European Union Vulnerability Database), of the Single Reporting Platform of the Cyber Resilience Act and the Cybersecurity Incident Reporting and Analysis System (CIRAS) and the reports stemming from the NIS 2 legislation related to that system. Before joining ENISA as a Senior Threat and Vulnerability Analyst, he developed more than 15 years of experience in strategic, tactical, and operational analysis and situational awareness through roles at both national and international levels. Previously, he also worked at the European Parliament and in the banking sector.

SpeakerBio:  Razvan Gavrila, ENISA - The European Union Agency for Cybersecurity

Razvan Gavrila is a seasoned cybersecurity professional with over 15 years of experience across national and EU institutions. In his current role, he oversees ENISA’s work on the implementation of the EU Cyber Resilience Act and leads initiatives in product and security engineering, including the cybersecurity of AI systems. Prior to his appointment as Head of Sector for Market, Technology, and Product Security in January 2025, he served as ENISA’s lead Cyber Threat Intelligence (CTI) analyst. He holds several industry-recognized certifications and a Master of Science in Computer and Information Security


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 16:00-17:59 PDT


Title: Evading EDR in ATM
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

ATMs in the end are a computer with windows

I will talk about EDRs and how parent-child process inheritance works

The Windows boot process, known as the boot process, is divided into several phases as we have already seen: PreBoot (initialization of BIOS/UEFI firmware and POST), Boot Manager (loading of bootmgr or bootmgfw.efi), OS Loader (execution of winload.exe to load the kernel), and Kernel Initialization (loading of ntoskrnl.exe and hal.dll, initialization of drivers and services). Finally, winlogon.exe is started to present the user interface. This process enables the transition from a powered-off state to a functional operating system through a hierarchical and verified sequence.

Regarding kernel-based EDRs (Endpoint Detection and Response), they operate in kernel mode, the most privileged level of the system (some also operate at the UEFI level), which allows them to monitor low-level activities such as system calls, memory manipulation, driver loading, and file access. By running in this mode, EDRs can detect and block advanced threats such as rootkits or persistent malware that attempt to evade user-mode protections. Their deep integration with the kernel enables real-time monitoring, behavioral analysis, and immediate response to suspicious activities during and after the boot process. EDRs are typically located in the kernel, but as mentioned, some also operate at the UEFI level. If we recall how Windows works, beneath UEFI lies SMM (System Management Mode), making this an even more complex layer to analyze and operate within.

This talk is intended for individuals interested not only in ATMs and simple cash dispensing, but in going beyond that—focusing on deeper analysis and the full experience gained when confronting these systems.

More information about the attack and the theory behind it: https://h0km4.com/posts/DMA-Introduction/ https://h0km4.com/posts/telemetria-bypass/

SpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master's in AI and Cybersecurity.

--

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK


Return to Index    -    Add to Google    -    ics Calendar file

Cryptocurrency Village - Saturday - 13:00-13:59 PDT


Title: Evading LLM Detection
Tags: Cryptocurrency Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Software supply chain attacks are no longer a distant threat — they are happening at scale and extremely dangerous from a crypto exchange's POV.

As build pipelines grow more complex and dependencies multiply across npm, PyPI, SBOM, and internal registries, a single scanning layer is no longer enough to detect malicious code.

This talk focuses on an AI journey — from deploying a single AI agent to gate code merges, to architecting a full multi-agent system hardened through structured simulated exercises — along the way catching real-world attacks, including the coordinated compromise of a highly popular npm package spanning over 2 billion weekly downloads.

Speakers:Hanley Shun,Cong Zhang,⁨Oscar Skjerven

SpeakerBio:  Hanley Shun, OKX

Hanley has been working in information security for 10 years, with a background in penetration testing and vulnerability management. Now at OKX, channeling that offensive mindset into building secure CI/CD pipelines with AI, every day keeping customers' funds safe.

SpeakerBio:  Cong Zhang, OKX

Cong has spent 5 years building SAST from the inside out — engines, rules, and the thinking behind them. From AST-level detection logic to full scanning pipelines, he knows where static analysis hits its limits. Now at OKX, he's pushing past them with AI, teaching tools to reason about supply chain risks and logic flaws that pattern matching will never catch.

SpeakerBio:  ⁨Oscar Skjerven, OKX
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 14:10-14:40 PDT


Title: Every ride you take - Hacking a City’s Public Transportation
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Saturday, Aug 8, 14:10 - 14:40 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Let's talk about some critical infrastructure that millions of people use every day: Public transportation. In this talk, I’ll present some findings that I discovered in the public transportation ecosystem of one of the largest cities in Argentina, impacting more than 1.5 million people daily. Reading code, chaining vulnerabilities, weak access controls, and flawed internal designs, I got full access to core mobility systems, from buses to taxis, including DVRs, transport cards, user data, real-time tracking and administrative panels. We’ll walk through the technical exploitation path, the real-world impact and the lessons learned.

SpeakerBio:  Ignacio Navarro

Ignacio Navarro, an Ethical Hacker and Security Researcher from Cordoba, Argentina. With around 6 years in the cybersecurity game, he's currently working as an Application Security. Their interests include code analysis, web application security, and cloud security. Speaker at DEFCON, H2HC, Troopers, LeHACK, NorthSec, TyphoonCon, Security Fest, 8.8, among others. @Ignavarro1


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 13:00-13:59 PDT


Title: Everything I Need to Know About Security, I Learned from Mr. Rogers
Tags: The Diana Initiative | Creator Event/Activity
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

The same lessons we learned from children’s programs growing up can help keep organizations safe. Kindness builds trust, and trust gets team buy-in to security processes. Diversity increases the vantage points and perspectives able to spot gaps or loopholes in technology and process. Empathy that puts us in the shoes of our users helps refine workflows, and a company that takes care of its employees reduces the likelihood of internal bad actors. Security is more about effective cooperation than a digital dogfight.

SpeakerBio:  Zoe
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 14:00-15:59 PDT


Title: Execution of modern techniques to start/improve your career in Incident Response
Tags: La Villa Community | Creator Workshop
When: Saturday, Aug 8, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map

Description:

Practicaremos algunas técnicas modernas que utilizamos en equipos globales de Respuesta a Incidentes para procesar y analizar evidencias digitales durante ataques cibernéticos, y responder con conclusiones acertadas en un lapso muy corto.

Este taller está dirigido para quienes desconocen cómo empezar su carrera en DFIR o buscan afinar sus técnicas de investigación.

Habrá un pequeño CTF de un incidente de Ransomware con regalos para los ganadores.

SpeakerBio:  Ashley Hiram Muñoz, Kaspersky - Incident Response Specialist

I currently work as an Incident Response Specialist on Kaspersky's Global Emergency Response Team (GERT). I live in Mexico and have over seven years of experience in Incident Response, Digital Forensics, Malware Analysis, and Reverse Engineering. Before joining DFIR, I worked for two years as a Penetration Tester.

I have collaborated on various Threat Hunting and Threat Intelligence projects.

Additionally, I have been a speaker at international events such as DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, HackGDL, BugCON, Pwnterrey, and others. I currently teach the Digital Forensics, Malware Analysis, and Incident Response modules in an information security diploma program at UNAM (Universidad Nacional Autónoma de México).

Certifications: GREM, GCFA, GCFR, eCTHP, CHFI.

--

Actualmente me desempeño como Incident Response Specialist en el Global Emergency Response Team (GERT) de Kaspersky, cuento con +6 años de experiencia realizando Respuesta a Incidentes, Análisis Forense Digital, Análisis de Malware y Reversing; previo a dedicarme a DFIR laboré 2 años como Penetration Tester.

He colaborado en distintos proyectos de Threat Hunting y Threat Intelligence.

Adicionalmente, he sido ponente en eventos internacionales como DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, BugCON, etc.

Actualmente soy profesor de los módulos de Análisis Forense, Análisis de Malware y Respuesta a Incidentes en un diplomado de seguridad de la información de la UNAM.

Certificaciones: GREM, GCFA, eCTHP, CHFI.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 14:00-14:30 PDT


Title: Exfil Everything: A Year of Stealing Data from AI Agents
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

For two decades, XSS was the king of data theft — exploiting trust boundaries in a victim's browser to exfiltrate sensitive data and perform malicious actions. AI-powered interfaces have introduced new ways to deliver XSS to victims alongside an entirely new bug class that has emerged as the most impactful vulnerability pattern in modern AI applications. The parallels between XSS and AI data exfiltration are striking — both exploit trust boundaries to force a system into performing unintended actions on behalf of a victim but the attack surface in AI is broader, spanning web interfaces, mobile apps, wearables, and any client consuming agent output. The exfiltration channels are diverse: markdown image rendering, iframe and HTML tag injection, sandbox escapes, native platform connectors, network connectivity tools, javascript: URI schemes, link unfurling side channels, MCP server poisoning, and multi-step agent tool-abuse chains. In this talk, two bug hunters who've spent the past year exploiting these vulnerabilities across production applications break it down and walk through real attack chains, demonstrate how we bypass common mitigations and share the bypass techniques we've developed. We'll cover how to threat model AI applications, identify viable attack paths, and select delivery mechanisms to weaponize end-to-end exploits. Beyond offense, we'll discuss the mitigations we've encountered, what actually works, what doesn't, and emerging trends in agentic AI and autonomous tool use mean for the next wave of vulnerabilities hunters should be watching for. Leave with: (1) a clear mental model of AI data exfiltration as a bug class and how it relates to familiar web primitives, (2) concrete attack techniques and bypass methods, (3) practical threat modeling for identifying exfil paths in AI agents and applications, and (4) visibility into upcoming trends and bug classes they should be hunting as AI systems gain more autonomy and connectivity.

Speakers:Ads Dawson,Mike "TakSec" Takahashi

SpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta's MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting "Exfil Everything: A Year of Stealing Data from AI Agents" at Bug Bounty Village DC34 (schedule pending publication).

SpeakerBio:  Mike "TakSec" Takahashi, AI Red Team Researcher, Zenity

Mike Takahashi, aka TakSec, is an AI Red Team Researcher at Zenity; member of BT6; and Bug Bounty Hunter focused on breaking AI systems. He has submitted 400+ vulnerabilities across major bug bounty programs and top ranking on both Anthropic’s Safety Bug Bounty Program on HackerOne and Mozilla’s 0din GenAI Bug Bounty Program. His work targets prompt injection, data exfiltration, and AI agent security.


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Saturday - 10:00-17:59 PDT


Title: Exploit Bluetooth Low Energy with BLESPloit and optional ESP32
Tags: Embedded Systems Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

Discover how easy it is to fingerprint and control nearby BLE devices with a tap on your phone - yes, including iPhone that gets BLE superpowers with with an external ESP32. Scan remotely, clone and simulate BLE devices, test a popular headset for known vulnerabilities (or perhaps uncover a new one?) and take control of a robotic dog. Already know some BLE? Crack open our smart safe and claim the BLESPloit hardware reward inside!

SpeakerBio:  Slawomir Jasek, BLESPlo.it

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups. Currently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks. Beyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them. Loves sharing his knowledge via trainings, workshops, talks and open source hackme's (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 14:00-14:55 PDT


Title: Exploring Security Features in the Armv8-M Architecture
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Join us for an in-depth session exploring the critical security features embedded within the Armv8-M architecture. We'll dive into TrustZone for Cortex-M, the PACBTI Extension, and the Debug Authentication/Unprivileged Debug Extension, providing clear explanations of their functionalities and the motivations behind their development. Discover how these advanced features contribute to robust embedded system security.

Speakers:Ian Harris,Jacob Gutierrez

SpeakerBio:  Ian Harris, University of California, Irvine

Ian Harris is a Professor at the University of California, Irvine, specializing in computer science with a strong focus on embedded systems and security. They bring a rich background in hardware design verification and security, and their research encompasses secure hardware/software systems. Ian also teaches courses related to embedded systems and has presented at cybersecurity conferences.

SpeakerBio:  Jacob Gutierrez, Cybersecurity Professional / Community Speaker

Jacob Gutierrez is a recent Computer Science graduate with a keen interest in embedded systems and their security. They are passionate about contributing to the cybersecurity community and sharing their knowledge.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: Expose Hidden Surveillance in Everyday Tech
Tags: IoT Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Join the Ludlow Institute Surveillance Mission. Dump firmware, capture packets, probe APIs, or tear devices apart however you like. Prizes up for grabs.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Saturday - 10:00-17:59 PDT


Title: F1NDX OSINT Educational Series
Tags: OSINT For Good Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

The OSINT Educational Series is a 3-level series that introduces Open-Source Intelligence (OSINT). It covers data collection, social media analysis, and investigative techniques, showing how publicly available information is used in cybersecurity and intelligence. Volunteers will be on hand to help you get started and answer questions if you get stuck! Complete all 3 levels and earn a digital badge!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 13:00-14:59 PDT


Title: Factory Floor MVP Incident Response Challenge
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 13:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map

Description:

Defend the Factory. Beat the Attack. The Factory Floor MVP Incident Response Challenge is a fast-paced, interactive card-and-dice game where teams investigate cyberattacks against a modern manufacturing environment. Use strategy, collaboration, and a little luck to uncover attacker activity before production or safety is impacted. Players will walk away with practical insights into OT security, firmware and SBOM analysis, incident response, and the challenges of protecting connected industrial systems.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 22:00-23:59 PDT


Title: Feet Feud (Hacker Family Feud)
Tags: Feet Feud (Hacker Family Feud) | Contest
When: Saturday, Aug 8, 22:00 - 23:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

Feet Feud (Hacker Family Feud) is a Cybersecurity-themed Family Feud style game arranged by members of the OnlyFeet CTF team and hosted by Toeb3rius (aka Tib3rius). Both survey questions and their answers are crowd-sourced from the Cybersecurity community. Two teams (Left Foot and Right Foot) captained by Ali Diamond and John Hammond and comprised of audience members go head to head, trying to figure out the top answers to the survey questions.

Attendees can either watch the game or volunteer to play on one of the two teams. Audience participation is also encouraged if either of the two teams fails to get every answer of a survey question.

Ultimately Feet Feud is about having a laugh, watching people in the industry attempt to figure out what randomly surveyed people from the Cybersecurity community put as answers to a number of security / tech related questions.

Participant Prerequisites

Participants are chosen by team captains from the audience at the start of the show. In order to be fair, we try to select participants from all seating areas, so folks who show up later than others still have a chance to volunteer.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Saturday - 13:30-13:59 PDT


Title: Field Notes on Offensive Agents: Reusability, Reliability, and What Breaks
Tags: Adversary Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Offensive agents are easy to demo, but much harder to make useful across real adversary emulation work. Key challenges lie in making agents reusable and reliable across different assessment types, tech stacks and doing so, as models, tools, and environments change.

This talk shares lessons from designing, deploying, and refining a suite of modular offensive agents used in real client engagements. We will cover what made the agents reusable, where they broke against real-world complexity, and how we evaluated their effectiveness over time as prompts degraded, models drifted, and underlying tools evolved. The session is framework-agnostic and vendor-neutral.

Attendees will leave with a practical model for building composable offensive agents that remain useful and reliable across attack types.

Speakers:Dominika Pietrzak,Ibai Castells

SpeakerBio:  Dominika Pietrzak, Offensive AI Engineer

Building AI-led tooling to scale offensive security operations.

SpeakerBio:  Ibai Castells, Senior Red Team Hive Member

Senior Red Teamer and Red Team Capability Lead at CovertSwarm. Passionate about Windows, AD, malware dev and offensive tool engineering. Currently exploring how AI can be integrated in Red Team workflows. I drop my latest research, malware dev, and how-tos on my blog and GitHub.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 13:30-14:30 PDT


Title: Fix It, Snooze It, or Ignore It? Cloud Security Decisions Under Pressure
Tags: Cloud Village | Creator Event/Activity | Strategic Defense
When: Saturday, Aug 8, 13:30 - 14:30 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) B - Map

Description:

Cloud security teams rarely struggle to find issues. They struggle to decide what actually matters—and how to fix them with limited resources.

In this interactive CloudSec Village lab hosted by Aikido Security, attendees step into the role of a cloud security lead. Navigating a custom simulation dashboard, you'll manage a realistic environment spanning containers, Kubernetes, serverless, and virtual machines.

The catch? Your engineering teams have a strict cap on available hours, and every fix comes with an estimated time cost. You must evaluate a live queue of vulnerabilities, assign remediation to the right teams, and decide what to fix, defer, or ignore to find the most optimal defense strategy before your resources run out.

This drop-in lab focuses on real-world decision-making under pressure rather than theory. Join at any time, manage your clock, and see how your prioritization strategy compares.

SpeakerBio:  Mackenzie Jackson

Mackenzie is the Field CTO for Aikido Security, helping tech leaders understand application security through an attacker’s lens. As the co-founder and former CTO health tech company Conpago, he understands the challenges of building secure applications. He has spoken in over 30 countries, hosts the popular Podcast The Secure Disclosure, and contributes to multiple publications including Dark Reading, Financial Times, and Fast Company.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Flight Simulator/EFB
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Experience the effects of tampered engine performance data as you take the controls on a departing flight. Feel for yourself how vulnerabilities in electronic flight bags can have a physical impact inside the cockpit.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 14:00-14:30 PDT


Title: For Prompt Injection, Press 1: Hacking AI Voice Agents
Tags: Social Engineering Community Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

What happens when you social engineer an AI agent that was trained to be helpful over the phone? Can you get it to reveal its system prompt out loud? Will it disclose information about other callers? How far can you push it before its guardrails kick in? AI voice agents sit behind telephony layers like speech-to-text, text-to-speech, and call routing that introduce new attack surfaces and opportunities. They're replacing human operators everywhere: answering phones at doctors' offices, handling IT help desks, triaging customer support, and booking appointments. They sound human, but underneath, they're the same LLMs we've been prompt injecting. I built an open-source tool that tackles this by placing real phone calls to voice AI agents, speaking attack scenarios using text-to-speech, capturing responses via speech recognition, and analyzing transcripts for signs of successful exploitation. It maps 20 attack scenarios across five categories from the OWASP Top 10 for LLM Applications: prompt injection, sensitive information disclosure, system prompt leakage, excessive agency, and misinformation. Detection uses pattern matching and an LLM judge to catch both obvious and subtle failures.

SpeakerBio:  Willie Zhang, Offensive Security Consultant

Willie Zhang is an Offensive Security Consultant with experience protecting companies by thinking like an attacker. What started as a $1 online course on ethical hacking in college turned into a career built on finding the gaps in systems that aren't supposed to have any. Willie has a growing passion for understanding and attacking AI systems, building on a foundation of testing everything from corporate networks to the humans that run them. When he's not learning something new, Willie is in a League of Legends lobby, because apparently cybersecurity isn't chaotic enough.


Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Saturday - 12:15-12:45 PDT


Title: Forcing Physical Interlocks into Data Transit and Storage Replication
Tags: Data Duplication Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:15 - 12:45 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:

Traditional software-based security cannot prevent data destruction or unauthorized cloning when authorized credentials are compromised. This presentation introduces a hardware-level physical intervention approach with a zero-OS FPGA architecture to overcome vulnerabilities at the L3/L4 layer. This invisible Layer-2 transparent bridge, lacking IP or MAC addresses, performs sub-nanosecond-level gate-level Deep Packet Inspection (DPI) on the pipeline. When high-risk storage commands (deletion, unauthorized data transfer, etc.) are detected at the silicon level, the data flow is hardware-intercepted and held in a "Catch-and-Release" buffer until a physical human confirmation is received.

Speakers:Mehmet Önder Key,Temel Demir

SpeakerBio:  Mehmet Önder Key, Cyber Security Consultant

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

SpeakerBio:  Temel Demir

Temel Demir is a cybersecurity researcher and hardware architect specializing in hardware defense, offensive security, and the protection of critical infrastructure. With a core focus on embedded system vulnerabilities and Layer-1/Layer-2 network manipulation, his research involves developing deterministic, hardware-enforced frameworks that bypass traditional software-defined security flaws. Having previously shared security research on global stages, his work bridges the gap between sophisticated threat actor methodologies and immutable physical security barriers.


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Saturday - 14:00-14:59 PDT


Title: Forget FIPS: An Analysis of Russian and Chinese Cryptographic Standards
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Despite securing the connections of over a billion people, Russian and Chinese state cryptography often remains unfamiliar to western practitioners. We survey the GOST, ShangMi, and ZUC standards, their respective histories, designs, and the current academic understandings of their security. We additionally cover implementation conveniences, such as the use of AES-NI instructions with SM4 as a method of side channel hardening, and algorithmic peculiarities, such as the hidden substructure of the Kuznyechik and Streebog S-box. We conclude with considerations about why specific algorithms were standardized, and how they reflect the priorities of the respective nations that standardized them.

SpeakerBio:  1nfocalypse

1nfocalypse is a GCC developer and cryptography enthusiast, with a particular focus on applied cryptography and implementation security. He has contributed to libstdc++-v3 and GCC's OpenMP implementation, authored cryptographic CTF challenges for C2 Society and the "?Cube" CTF, and has conducted security research leading to CVEs involving cryptographic aspects of Apache Druid and mbedTLS.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 11:00-11:59 PDT


Title: Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

The cybersecurity community chases the greatest risks in the latest tech, while components with outdated security principles gather dust. Companies rush to secure their latest AI product, while their network remains the same. Do attackers really need more than legacy services to take you down?

We asked this question as we analyzed an unauthenticated RCE in GNU-TelnetD that was discovered in January. We were amazed a simple shell injection existed for so long in the most popular telnet daemon. We further investigated Telnet and discovered it runs a root-privileged process with environment variables supplied by an unauthenticated client! Leading us to a privilege escalation vulnerability.

We then looked into Samba, the Linux service for sharing files and printers over SMB. Focused on shell injections, we searched for command execution using format strings - and we couldn't believe it! Two more shell injection RCEs waited for us! In this talk, you'll ask yourself, “How come it was only found in 2026?!” We will analyze the unauthenticated RCE in TelnetD and reveal three severe vulnerabilities: 2 unauthenticated RCEs in Samba (CVE-2026-4480 & CVE-2026-4408) and a privilege escalation in TelnetD (CVE-2026-28372). The routers or printers you forget to update might run those services, and they put you at risk

https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/

SpeakerBio:  Ron Ben Yizhak, SafeBreach

Ron (@RonB_Y) is a security researcher at SafeBreach with 11 years of experience. He works in vulnerability research and has knowledge in forensic investigations, malware analysis and reverse engineering. Ron previously worked in the development of security products and spoke several times at DEF CON


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Saturday - 13:30-13:59 PDT


Title: FORTRESS Framework
Tags: Physical Security Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

As physical security threats increase in sophistication and frequency, organizations face a critical gap in their physical security, the lack of a structured framework for physical security assessments and tests. FORTRESS was designed to fill this need by providing a categorized model of physical Tactics, Techniques, and Procedures (TTPs), each aligned to industry-standard compliance controls such as NIST, HIPAA, FedRAMP, ISO 27001, and PCI DSS. Designed for both red and blue teams, FORTRESS enables coordinated, repeatable physical security testing by consolidating adversarial behaviors into mapped TTPs. Each TTP is supported by detailed guidance for the execution, validation, and reporting of physical security gaps making assessments more consistent across multiple teams, business units, and future engagements. This paper presents the overall breakdown of FORTRESS, highlighting its application, structure, and flow. I believe this framework fills that critical void in operational and physical security and can be viewed as the foundation for enhancing and maturing physical security risk programs with real threat models as the base.

SpeakerBio:  Brad "Sno0ose" Ammerman

Brad Ammerman, a leading figure in security testing, currently serves as the Senior Director at Prescient Security. His background includes influential roles at companies like Foresite, Optiv, Lockheed Martin, DIA, DoD, and Supreme Court of Nevada, where he developed his expertise in offensive security and team management. A skilled hacker himself, Brad is also a recognized speaker, educator, mentor, and disabled veteran, dedicated to teaching and protecting others.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 11:00-16:59 PDT


Title: Free Ham Radio License Exams
Tags: Event | Ham Radio Village
When: Saturday, Aug 8, 11:00 - 16:59 PDT
Where: LVCCW Level 3 W314 (Ham Radio Meeting) - Map

Description:

Free ham radio exams return to DEF CON 34! Partake in this hacker “rite of passage” by getting your license at DEF CON, presented by the Ham Radio Village.

While anyone is able to listen in to amateur/ham radio transmissions, only those who have an amateur radio license are able to fully partake in the “oldest hacker hobby”. With your license, you’ll be authorized by the FCC to transmit up to 1,500W on designated frequencies, build/modify radios & antennas, and even administer your own exams! Additionally, having your ham radio license can improve your resume as it is a well-recognized proof of technical and regulatory knowledge when it comes to all things radio.

About The Exam

In the US there are 3 current levels of amateur radio license - Technician, General, and Amateur Extra. You can progress through the levels by taking a series of multiple-choice exams showing increasing breadth of knowledge. Most folks at DEF CON looking to become a ham take just the technician exam.

The technician exam is a 35 question, multiple choice exam. Questions come from from a public question pool of 400 questions. Because of that, the most popular way folks at DEF CON prepare is by reading through all 400 questions before the exam, and learning hands on once you get licensed. Many study resources exist - most people recommend ham.study.

Signing Up

Who may register for this testing session:

Fees

Questions

If you have any questions leading up to DEF CON, come visit us on the Ham Radio Village Discord server (discord.gg/hrv) and let us know what questions you have. During the conference, come visit the Ham Radio Village to learn all things ham radio, including the studying, testing, and licensing process.


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Saturday - 16:00-16:30 PDT


Title: Free IP, Free Chaos: DHCP-Assisted Flooding Against Automotive Ethernet
Tags: Car Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Modern vehicles are increasingly adopting Automotive Ethernet for UDS-based diagnostics instead of CAN. While Gateway ECUs are designed to restrict communication to specific IPs, some support DHCP to facilitate communication with diagnostic tools. This DHCP support allows an attacker to deploy a rogue DHCP server via the OBD Ethernet interface, assigning a controlled IP to the Gateway ECU and enabling network-level attacks without any prior knowledge of the vehicle's internal network. In this talk, we demonstrate that high-rate Layer 2/3 flooding — regardless of protocol (ARP, ICMP, UDP, TCP) — disrupts safety-critical systems including AVN, wipers, headlights, and causes abrupt stopping when shifted into Drive or Reverse, and that at higher packet rates the infotainment display blacks out and does not recover until fully powered down. We discovered these findings on a production vehicle and have prepared a demo.

SpeakerBio:  Yehyeong Lee, Autocrypt Inc.

Yehyeong Lee is a cybersecurity engineer specializing in automotive security and embedded systems. He focuses on vulnerability analysis and penetration testing of vehicle ECUs and in-vehicle networks. His work includes real-world vehicle security testing and automotive network attacks. His research interests include automotive security, firmware analysis, and embedded system security.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 12:00-12:59 PDT


Title: Friends of Bill W
Tags: Meetup
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W301 (Misc Meeting Room) - Map

Description:

We know DEF CON and Vegas can be a lot. If you're a friend of Bill W who's looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 17:00-17:59 PDT


Title: Friends of Bill W
Tags: Meetup
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 3 W301 (Misc Meeting Room) - Map

Description:

We know DEF CON and Vegas can be a lot. If you're a friend of Bill W who's looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Saturday - 12:00-12:59 PDT


Title: Friendship Bracelets
Tags: Women in Security and Privacy (WISP) | Creator Event/Activity
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Saturday - 10:00-10:59 PDT


Title: From al-Kindi to DEF CON: The Middle Eastern and African Roots of Cybersecurity
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

The word algorithm comes from a mathematician in ninth-century Baghdad. The first person to write down how to break a cipher was working in the Arab world more than a thousand years before modern computing. The foundations of the field we now call cybersecurity were laid by scholars from the Middle East and Africa, and that lineage runs straight through to the practitioners in this room. This session opens the MEACS Community Space with a look at those roots, from the origins of cryptanalysis and algebra to the engineers, defenders, and founders carrying the work forward today. We will talk about where we come from, why representation in this field is not a side conversation, and what this community is here to build over the next few days. Whether you trace your roots to the region or you just want the history the industry skipped, you are welcome here. Come meet the people who make this space what it is.

Speakers:Amber Bennoui,Ezz Tahoun

SpeakerBio:  Amber Bennoui
No BIO available
SpeakerBio:  Ezz Tahoun

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada's CSE.

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 14:30-15:30 PDT


Title: From Disclosure to Defense: Rebuilding Vulnerability Management for the AI Era
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 15:30 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

AI has upended vulnerability discovery. What used to be scarce is now abundant: vulnerabilities can be found faster, at greater scale, and across more systems than ever before. Systems that uplevel vuln hunters are becoming widely available, to both defenders and malicious actors. Finding vulnerabilities used to be the hard part - but it’s not anymore, and we need to adapt the vulnerability ecosystem to reflect that. But vulnerability management - thoughtful and methodical disclosure, triage, patching, and policy - still operates on assumptions of scarcity. That mismatch is becoming dangerous. If AI makes vulnerability discovery effectively infinite, what does a safe, scalable system for handling them actually look like? This panel will discuss how the vulnerability needs to evolve to match the moment. Current policy approaches - especially those mandating rapid reporting or broad sharing of unmitigated vulnerabilities - risk making systems less secure in an AI-driven environment. At the same time, rapid response by defenders is critical, and resources are scarce. Disclosure models need to evolve, governments need to support defenders, and incentives must align to ensure that AI-driven discovery strengthens security.

Speakers:Lindsey Cerkovnik,John Banghart,Ben Flatgard,Elizabeth Eigner

SpeakerBio:  Lindsey Cerkovnik, CISA

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.

SpeakerBio:  John Banghart, Center for Cybersecurity Policy & Law

John Banghart leverages his significant federal government and private sector experience in cybersecurity to navigate issues related to risk management, government policy, standards and regulatory compliance, and incident management. He has successfully led efforts to address significant and high-profile cybersecurity issues within major government programs and institutions while facing complex legal, technical, and political circumstances. From 2013 to 2015, John played a key role in developing the Obama administration's cybersecurity and technology policy as the National Security Council's director for federal cybersecurity. He led policy, technical, and process efforts to reduce cybersecurity risk and improve metrics and measurement for all civilian, military, and intelligence community agencies. He served as a primary advisor on cybersecurity incidents and preparedness and led the National Security Council’s efforts to address significant cybersecurity incidents, including those at OPM and the White House, among others. He also spent several years at the National Institute of Standards and Technology (NIST), both as a cybersecurity researcher and in the Office of the Undersecretary of Commerce for Standards and Technology. John also worked as a senior cybersecurity advisor for the Centers for Medicare and Medicaid Services, providing leadership to the cybersecurity preparations for the Healthcare.gov website.

SpeakerBio:  Ben Flatgard, JPMorgan Chase

Ben Flatgard is an Executive Director with JPMorgan Chase Co. He leads public policy development and advocacy, as well as partnership initiatives, to improve the cybersecurity of the firm, its customers and clients, and the broader digital ecosystem. Ben previously served in the Obama Administration from 2009-2017. In his most recent post as Director for Cybersecurity Policy on the National Security Council, Ben was responsible for leading cybersecurity policy development related to protection of critical infrastructure and emerging technologies. Before joining the National Security Council, Ben served as Senior Advisor to the Assistant Secretary of the Treasury for Financial Institutions. Prior to his time at Treasury, Ben held positions at the Department of Commerce and the White House. Ben graduated from the University of Edinburgh. He holds fellowships at the Atlantic Council in Washington, DC, and at the University of Sydney.

SpeakerBio:  Elizabeth Eigner, Microsoft

Elizabeth Eigner is a Senior Manager on Microsoft’s Global Cybersecurity Policy team, where she leads Microsoft's vulnerability policy portfolio, overseeing efforts to develop and implement strategies that address vulnerability management both in the United States and globally. She represents Microsoft on the Hacking Policy Council, where she works collaboratively with industry leaders and policymakers to advance responsible cybersecurity and strengthen the frameworks that underpin software security worldwide. Elizabeth also leads initiatives aimed at creating and enhancing national cyber strategies in countries around the world. She works closely with governments and stakeholders to strengthen policy frameworks and promote resilient cybersecurity practices globally. Elizabeth also leads Microsoft's Advancing Regional Cybersecurity (ARC) initiative, focusing on improving incident response capabilities and cyber capacity building in the Global South. Previously, she served as Microsoft’s representative on the Cloud Service Provider Advisory Board (CSP-AB), contributing to FedRAMP public policy discussions and best practices for cloud security. Before joining Microsoft, Elizabeth worked at The Washington Technology Industry Association to enhance Washington State's innovation ecosystem. At MIT Solve, she collaborated with tech-based social entrepreneurs on solutions fostering digital inclusion and equitable economic opportunity. She holds a B.S. in Political Science from Northeastern University, with concentrations in Law and International Security.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 11:00-12:59 PDT


Title: From Findings to Remediations: Open Source Cloud Security at AI Speed with Prowler
Tags: Cloud Village | Creator Event/Activity | Strategic Defense
When: Saturday, Aug 8, 11:00 - 12:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) B - Map

Description:

Cloud security teams are drowning in findings, but isolated misconfigurations rarely tell the full story. This hands-on workshop shows how to use Prowler, the open-source cloud security platform, to detect vulnerabilities and misconfigurations, prioritize risks, and remediate with AI- driven workflows. Participants will learn how to run Prowler from the CLI and import findings into Prowler Cloud using the new Import Findings workflow. From there, the workshop will go beyond traditional compliance reporting and demonstrate Prowler's newer capabilities: Attack Paths for graph- based analysis of cloud resources, permissions, findings, and privilege-escalation chains; Lighthouse AI for natural-language investigation, environment-aware prioritization, and direct guided remediation grounded in Prowler Hub's deterministic database; and the Prowler Claude Code plugin/MCP workflow for bringing security triage, remediation guidance, automated pull- request generation from IaC scanner findings as well as live cloud scans, and re-scanning into the developer workflow. By the end, attendees will understand how to use Prowler not only to assess compliance against frameworks such as CIS, GDPR, HIPAA, and cloud security best practices, but also to identify which findings matter most, explain their blast radius, and accelerate remediation with open source tooling and controlled AI assistance.

Speakers:Toni de la Fuente,Amit Sharma

SpeakerBio:  Toni de la Fuente

Toni de la Fuente, Prowler’s open-source creator and CEO, has profoundly impacted cybersecurity. His AWS background and passion for FLOSS, cloud computing, and information security have fueled contributions to projects such as phpRADmin and Alfresco BART. An esteemed speaker at Black Hat and DEF CON, de la Fuente champions open-source solutions and advancements in cloud security.

SpeakerBio:  Amit Sharma

Amit Sharma has over a decade of experience as a cloud architect and built cybersecurity and observability products at Splunk, Cisco, and SentinelOne before joining Prowler as Head of Product.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 15:30-16:30 PDT


Title: From Live Malware to Red Team Tradecraft: Process Hollowing in msbuild.exe
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

The best hiding place is often a binary Microsoft already signed. This talk presents a complete red team operation reconstructed from a real multi-stage JScript dropper captured in April 2026 targeting Energy, Government, and Aerospace organizations. Using custom tooling and malware analysis, we transformed the adversary’s workflow into a repeatable offensive playbook focused on trusted binary abuse, fileless execution, and stealthy process injection.

The session demonstrates how attackers delivered a .NET payload through steganographic C2 hosted on trusted paste services, loaded assemblies directly in memory with Reflection.Assembly::Load(), and performed Process Hollowing into msbuild.exe using native Windows APIs including ZwUnmapViewOfSection, VirtualAllocEx, and SetThreadContext.

We also explore operational evasion techniques such as WMI hidden process spawning, obfuscated Base64 transformations, and Sysmon telemetry analysis from the perspective of a red team operator. Every technique shown was extracted from a live adversary sample and operationalized for realistic adversary emulation.

SpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I'm Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0 Black Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires DEF CON 33 / 32 - https://sessionize.com/filipi-pires/ DEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 11:45-12:30 PDT


Title: From ONT to STB: Detecting IPTV Attack Chains in the Telecom SOC
Tags: Telecom Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:45 - 12:30 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. IPTV Architecture – How IPTV is delivered over FTTH/GPON and the security implications of ONTs and STBs.
  2. Weak Links – Common vulnerabilities in ISP-managed ONTs.
  3. ONT to STB Attack Chain – A real-world red team attack demonstrating remote compromise and IPTV manipulation.
  4. Telecom SOC Detection – Detecting ONT compromises through management, authentication, configuration, and IPTV traffic monitoring.
SpeakerBio:  Zibran Sayyed
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 10:00-11:59 PDT


Title: From Path Traversal to Domain Credentials in 90 Seconds
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

In this hands-on tactic, attendees will exploit a realistic document management portal to chain path traversal into something far more dangerous. We'll demonstrate a complete attack path from initial discovery to domain credentials, then discuss why this works, where you'll find it, and how defenders should be looking for it.

What You'll Do: You'll get hands-on access to a vulnerable Windows IIS application and work through the complete exploitation chain. By the end of the session, you'll have captured real domain credentials and understand exactly how the attack works at each step.

Basic familiarity with web vulnerabilities helpful but not required. We'll explain the concepts as we exploit them.

SpeakerBio:  Mike Lisi

Mike helps organizations identify, prioritize, and eliminate real-world security risks before attackers exploit them. As Founder & CEO of Maltek Solutions, he brings over 15 years of hands-on experience across penetration testing, risk assessments, and cyber capability development.In addition to his consulting leadership, Mike serves as President of Red Team Village, a 501(c)(3) nonprofit delivering free offensive security training to a global community. Mike also leads CTF design for NCAE CyberGames, engaging 1,000+ collegiate participants annually.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 11:00-11:59 PDT


Title: From Policy to Prod: How a Frontier AI Lab Enforces its Cyber Rules
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

Every frontier AI lab publishes policies, but far less is known about what happens between a line in that policy and a blocked request in production. On Anthropic’s safeguards team, we operate in that gap. In this talk, we’ll walk through the full enforcement lifecycle at Anthropic: how policy gets written, how we translate it into evals that actually measure the behavior we care about, how we build precision-tuned classifiers to detect misuse traffic at scale, and how those classifiers feed a layered enforcement stack. We'll share what's worked, what hasn't, and the open problems we think the policy community should be paying attention to.

Speakers:Grant Versfeld,David "0xdf" Forsythe

SpeakerBio:  Grant Versfeld, Anthropic

Grant Versfeld co-leads cyber enforcement on Anthropic's Safeguards team, where he bridges the Policy and Threat Intelligence teams to disrupt cyber threat actors. Before Anthropic, he was a security engineer for Google Cloud Threat Intelligence, investigating nation-state campaigns against Cloud customers, contributing to Google Cloud's Threat Horizons report, and supporting Mandiant's cyber espionage research. He is a former Cybersecurity Policy Fellow at the Center for Democracy & Technology, a Hackers on the Hill ambassador, and a judge for Atlantic Council's Cyber 9/12 competition. He returns to DEF CON having previously played the FBI agent in DC 31's Hacker Court.

SpeakerBio:  David "0xdf" Forsythe, Anthropic

David Forsythe (0xdf) is a member of technical staff at Anthropic working on cybersecurity strategy and safeguards for frontier AI. Before that, 20+ years across the US public and private sectors in SOC/CIRT, threat intelligence, red teaming, threat research, and education, most recently as Principal Lab Architect at HackTheBox.

He is also a long-running security content creator, publishing CTF walkthroughs and technical breakdowns of exploits and other security topics at 0xdf.gitlab.io and on YouTube. As a player, he has reached as high as 4th on the HackTheBox global leaderboard, is a two-time Best Overall winner of the SANS Holiday Hack Challenge, and a three-time SANS Netwars Tournament of Champions team winner.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 17:30-17:59 PDT


Title: From Prompts to Production: Discovering Exposed PII & IDORs in AI-Generated Apps
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Users building apps with vibe coding platforms like Lovable or Base44 often overlook critical security vulnerabilities. As these platforms gain rapid adoption, thousands of apps are being created without sufficient attention to security, leaving significant flaws in plain sight. Our research, conducted across thousands of apps, revealed widespread issues, including 175 instances of sensitive PII leakage (such as medical records and personal contact information), SSRF, 0-click account takeovers, and IDORs.

In this talk, we’ll share our field experience in developing discovery and security testing techniques that uncover exploitable web app and API behaviors at scale. We’ll walk through concrete examples, showing how critical vulnerabilities hide in plain sight and how even minor misconfigurations can lead to catastrophic breaches. Attendees will learn to identify these security risks and secure their no-code apps, including best practices for handling sensitive data and securing APIs.

SpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:00-10:59 PDT


Title: From Wind Farm to CHP Plant: The Untold Story of Lateral Movement in a Polish Energy Sector Attack
Tags: DEF CON Official Talk
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

On December 29, 2025, Poland’s energy sector was hit by what we believe was the first destructive cyber sabotage attack against energy infrastructure in NATO. Our public report described attacks against 30 renewable energy sites and a large combined heat and power plant. But one piece of the incident was still missing - and it led to an attack path we had never seen in the wild before.

This talk goes behind the scenes of the investigation into a second, smaller CHP plant affected during the same campaign. What first looked like human error turned into a three-month hunt through false leads, forgotten remote access devices, wiped industrial hardware, cellular connectivity, and infrastructure that was assumed to be isolated.

The talk ends with lessons on private APN security, OT incident response, and handling large-scale cyber incidents involving critical infrastructure.

SpeakerBio:  Marcin Dudek, CERT.PL

Marcin Dudek leads CERT Polska, Poland’s national CERT. Before taking on this role, he spent more than a decade in hands-on technical work across OT security, incident response, and APT investigations. His background includes industrial control systems security in critical infrastructure environments, including Poland’s only research nuclear reactor, as well as analysis of APT activity targeting Poland. He regularly speaks at local and international cybersecurity conferences and was deeply involved in the response to the incident described in this talk.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 14:15-14:45 PDT


Title: From Zero-Day to Zero-Hour: Rethinking Telecom Defense for the Frontier AI Era
Tags: Telecom Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:15 - 14:45 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
Details:

Frontier AI is changing the economics and speed of cyberattacks—compressing vulnerability discovery, exploitation, and attack automation from days to potentially hours or minutes. For telecom networks and their complex OEM and supply-chain ecosystem, traditional vulnerability management and defense models may no longer be fast enough.

This session explores how telecom operators, OEMs, security teams, and regulators must adapt for the frontier AI era—from AI-driven vulnerability discovery and autonomous attacks to faster remediation, AI-powered defense, supply-chain resilience, and coordinated industry response. The key question: when attackers operate at machine speed, can telecom defense keep up?

SpeakerBio:  Arvind Singh
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 21:00-00:59 PDT


Title: Front Man's Fête: An Octopus Game Party (including Octopus Game winners and prizes)
Tags: Party | Octopus Game
When: Saturday, Aug 8, 21:00 - 00:59 PDT
Where: LVCCW Level 2 W212 (Misc Meeting Room) - Map

Description:

Front Man’s Fête: An Octopus Game Party is a curated respite from the chaos of the city, offering a sophisticated and low-key lounge experience centered on strategy and soul. Instead of high-stakes elimination, we offer the timeless rhythm of old school hip-hop and the analog competition of classic board games. This event is designed for those who seek a chill atmosphere where the vibes are smooth and the conversation is clear. Come for the nostalgia of golden-era beats and stay for a relaxed evening where the only goal is to unwind and outsmart your opponents in a sanctuary of cool.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 13:00-13:59 PDT


Title: FTS Build it Yourself: cDc X OWASP X Veilid
Tags: OWASP Foundation | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Join us for a state of Veilid update, where we'll explore the latest progress, milestones, and what's next for the project as it continues to build a decentralized, privacy-first communications and networking platform.

After the presentation, stick around for an open discussion about what it really takes to escape today's digital walled gardens. We'll talk about the challenges of reducing dependence on centralized services, the practical realities of building and adopting self-hosted and decentralized alternatives, and how open source communities can create tools that preserve privacy, autonomy, and user ownership.

Speakers:Gibson,medus4,cdC & Veilid crew

SpeakerBio:  Gibson
No BIO available
SpeakerBio:  medus4
No BIO available
SpeakerBio:  cdC & Veilid crew
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Saturday - 08:30-17:30 PDT


Title: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Saturday, Aug 8, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W224 (Training) - Map

Description:
SpeakerBio:  Dawid Czagan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Saturday - 14:00-14:59 PDT


Title: Fun with alternative smartphones with The Tech Reclaimers!
Tags: Hackers.town | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  Janet Vertesi, Officer at Tech Reclaimers
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Game Hacking Village CTF
Tags: Game Hacking Village | Game Hacking Village CTF | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

Compete againt other teams to be the first to hack all of our games on our custom Mist Store platform


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 12:00-12:59 PDT


Title: Game Hacking with AI
Tags: Game Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

This informal talk is intended to cover expert usage of AI agents using Claude/Codex and how you can apply them to be effective in areas like game hacking. How do you keep an agent on track, how do you make it more accurate, more efficient, and how do you get it to go around guiderails. If you're using AI in a web browser or copy+pasting code (in game hacking or otherwise) this talk is for you.

SpeakerBio:  Juno, Game Hacking Village
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 15:00-15:59 PDT


Title: Game Time: Input, Output, and Variables
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Input, output, and variables are the building blocks behind every single program you've ever used, and once you understand them, you're well on your way to writing your own code! In this session, we'll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 12:00-12:59 PDT


Title: Game Time: Input, Output, and Variables
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Input, output, and variables are the building blocks behind every single program you've ever used, and once you understand them, you're well on your way to writing your own code! In this session, we'll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 10:00-10:59 PDT


Title: Game Time: Loops
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Have you ever had to do the same thing over and over and thought, there has to be an easier way? Good news, there is, and it's called a loop! Come play some classic schoolyard games with us and discover that you've been using loops in real life all along. Then we'll show you how programmers use for loops and while loops to make computers repeat tasks automatically, whether that's counting to 100 or spawning enemies in your favorite video game. No experience needed, just come ready to play! If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 11:40-11:50 PDT


Title: Gamer Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 11:40 - 11:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Gamer Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Gamer Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 11:45-12:45 PDT


Title: Gamifying the Matrix: a MITRE ATT&CK Video Game
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 11:45 - 12:45 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

This session introduces attendees to the MITRE ATT&CK Defense Game, a technical capstone project designed to bridge high-level gaming logic with real-world cybersecurity infrastructure. We will explore how gamification can be used to visualize adversary tactics and techniques in a controlled, interactive environment. The presentation covers the development of frontend interfaces and backend logic used to simulate defensive responses to various attack vectors, making complex security frameworks accessible to those just starting their journey in the field.

Speakers:Annie Meaney,Anne Drago

SpeakerBio:  Annie Meaney
No BIO available
SpeakerBio:  Anne Drago
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 11:00-16:59 PDT


Title: GE(O)SINT Contest
Tags: Recon Village | Creator Event/Activity
When: Saturday, Aug 8, 11:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Test your geospatial intelligence skills in this unique contest. Identify locations, analyze imagery, and demonstrate your GeoINT expertise.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 15:00-15:59 PDT


Title: Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Python is widely used in LLM applications and agent frameworks. Its ease of use comes from two core features: a uniform object model and dynamic reflection, which unfortunately also enable an emerging vulnerability class: Python class pollution. To date, with only one CVE and a handful of synthetic examples since its first disclosure in 2023, what is known is merely the tip of the iceberg, the real threat runs far deeper into the Python ecosystem.

In this talk, we introduce the first complete taxonomy of this vulnerability class, built from two object-resolution primitives and three object-assignment primitives, which together yield six types. Only one was previously known.

Building on this taxonomy, we design and implement Pyrl, the first automated framework for detecting Python class pollution via a novel static analysis technique named operational taint analysis. Applying Pyrl to over 600,000 GitHub and PyPI packages, we found 47 exploitable zero-days in Azure CLI, Taipy, ComfyUI, Google Mesop, HuggingFace Smolagents, and others. Through live case studies, we show how class pollution can be weaponized into token exfiltration, authentication bypass, stored XSS, sandbox escape, and RCE. Most importantly,we demonstrate that even the weakest type—one previously unknown—can still lead to critical impact in practice.

Speakers:Gavin Zhong,Zhengyu Liu,Jianjia Yu

SpeakerBio:  Gavin Zhong, Johns Hopkins University

Jiacheng (Gavin) Zhong is a security researcher, focusing on AI system security, program analysis, and identity security. He recently completed his M.S. in Security Informatics at Johns Hopkins University, where his work was accepted to IEEE S&P 2026. Gavin has reported over 30 CVEs in widely used open-source projects. He is also an active CTF player with r3kapig, an international team ranked top 3 worldwide.

SpeakerBio:  Zhengyu Liu, Johns Hopkins University

Zhengyu Liu is a third-year PhD student in Computer Science at Johns Hopkins University. His research focuses on web and software security via program analysis. His work received Distinguished Paper (S&P ’25), Honorable Mention (USENIX ’25), and Best Student Paper (ICICS ’22). He is a DEF CON speaker and is a member of CTF team TheHackersCrew.

SpeakerBio:  Jianjia Yu, Johns Hopkins University

Jianjia Yu is a PhD student at Johns Hopkins University, advised by Prof. Yinzhi Cao. Her research focuses on security and privacy in web and mobile ecosystems using program analysis techniques. Her work has received Distinguished Paper Awards at CCS '23 and S&P '25, and an Honorable Mention at USENIX Security '25. She has discovered over 40 zero-day vulnerabilities and uncovered privacy leaks affecting millions of users across browser extensions and mobile applications.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 13:00-13:59 PDT


Title: Getting Started in OT/ICS Cybersecurity
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Industrial Control Systems (ICS) and Operational Technology (OT) run the world around us. Power plants, offshore oil rigs, trains, and other transportation systems, manufacturing plants – these are just a few examples of the critical infrastructure that society depends on. Each ICS/OT environment is unique and has specialized security requirements.

Protecting critical infrastructure becomes increasingly important each day as the frequency of cyberattacks and the number of attackers continue to grow. State adversaries are no longer the only ones targeting these specialized environments. Today’s attackers include ransomware groups, hacktivists, cyber mercenaries, and more.

ICS/OT cybersecurity can seem complicated and even daunting at first, but it does not have to be. This session will help participants understand the fundamentals of how these environments operate and how to secure them with a practical, simple approach.

SpeakerBio:  Mike Holcomb
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Packet Hacking Village - Saturday - 17:00-17:59 PDT


Title: Ghost Followers: Using AI to Unmask Fake LinkedIn Profiles at Scale
Tags: Packet Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

LinkedIn hosts over 1 billion profiles and a growing number are fake. From AI-generated profile photos to synthetic work histories, adversaries use fake identities for spear-phishing, social engineering, and influence operations. This talk breaks down the anatomy of a fake LinkedIn profile and demonstrates an AI-powered detection framework using behavioral signals, image forensics, and network graph analysis. Attendees will leave with a hands-on methodology and open-source toolset to identify synthetic identities before they become insider threats. Prior knowledge of networking fundamentals is helpful; no machine learning background is required.

SpeakerBio:  Aiswarya Venkitesh, Principal Cloud Solution Architect, Microsoft

Aiswarya Venkitesh is a Principal Cloud Solution Architect at Microsoft Canada with 13+ years in Data & AI, specializing in agentic AI architecture, multi-agent orchestration, and enterprise Azure deployments. Ranked #4 globally in IT & Tech by Favikon with 55,000+ LinkedIn followers, she studies identity authenticity and influence operations on professional networks as both a practitioner and creator. She is a confirmed keynote speaker at Futura AI Conference 2026 and author of the forthcoming book The Agentic AI Playbook.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 15:00-15:45 PDT


Title: Ghost in the IDE
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:
Hook: The Blind Spot
Your EDR sees the server compromise. Your SIEM catches the phishing campaign. Your firewall blocks the C2 traffic. But what happens when the attacker doesn't target your infrastructure—they target your developers?

28 million developers worldwide rely on three IDE platforms: JetBrains IntelliJ, Microsoft VS Code, and Eclipse. These aren't just text editors—they're command-and-control platforms disguised as productivity tools. Developers trust them with AWS credentials, database passwords, SSH keys, source code, and network access to production systems. And here's the kicker: IDE plugins run with full user privileges, no sandboxing, no permission dialogs, no questions asked.

We built GHOST IN THE IDE, a production-ready C2 framework that weaponizes IDE plugins across all three major platforms. Not a proof-of-concept. Not a research prototype. A functional red team tool with keystroke logging, clipboard monitoring, file exfiltration, and remote command execution—working silently inside IntelliJ, VS Code, and Eclipse on Windows, macOS, and Linux.

The Attack: Multi-IDE C2 That Actually Works Most IDE plugin research stops at "look, I can pop calc.exe from VS Code." We went further. Way further.

Speakers:Venkata Jayaram Yalla,Pardhiv Reddy

SpeakerBio:  Venkata Jayaram Yalla

Yalla, Jayaram is Director – Application Security at S&P Global, leading enterprise-wide initiatives in secure application development, vulnerability management, and security architecture. He has transformed the Application Security function from a primarily tactical penetration-testing team into a strategic security engineering organization, emphasizing automation, governance, and advanced threat modeling.

Jayaram combines deep hands-on experience in offensive security and research (including multiple CVEs) with ownership of large-scale AppSec programs across SAST, SCA, DAST, CI/CD security, and emerging AI security initiatives.

SpeakerBio:  Pardhiv Reddy

Pardhiv is a security specialist with vast experience in the field of information security ranging from health care,hospitality, banking and government sectors throughout the world. He also earned many industry standard certifications in the security, some of them are SANS GPEN, OSCP, OSWP, CISSP, Security+, ISO 27001 LA and many others.

Pardhiv's interest areas includes cloud security and IOT security and his research has been presented at EuropeanSec 2016 in Portugal. His expertise helped teams to build secure products and applications by providing security guidelines and best practices.

Pardhiv has performed various iOT security assessments which includes both embedded hardware security, firmware analysis, mobile applications, network security including wireless communications and backend cloud server assessments.

Pardhiv is also an active bug bounty hunter and helped many companies around the world by pointing their security vulnerabilities to make their application and products secure. He spares his free time to build prototypes and security research by learning new techniques and methodologies.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 10:40-11:20 PDT


Title: Ghost Records: Automating Dangling DNS & Subdomain Takeover Detection at Enterprise Scale
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:40 - 11:20 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

This is not another subdomain takeover 101 talk. It's about what dangling DNS actually looks like at enterprise scale - in large, multi-account AWS environments with sprawling DNS footprints - and the automation and hard-won triage lessons the problem demands.

Let's be honest: ~95% of subdomain takeover findings are noise - 3rd- and 4th-level subdomains on dead non-prod environments no customer ever visits. They generate alert fatigue and little else. The other 5% - cookie theft via a *.domain.com scope, OAuth token hijack, phishing from a legitimate domain carrying a valid TLS cert - are catastrophic. Telling the 5% from the 95% is the entire game.

Then there's the bug bounty dynamic. Researchers find these in bulk and report them in bulk. They're frustrated that fixes take weeks; program owners are frustrated that most reports are low-impact but can't simply be closed. The relationship erodes on both sides - a cost nobody puts on a dashboard.

From what We've seen, the time sinks are predictable: manually triaging hundreds of researcher reports, chasing low-impact findings, writing one-off fix scripts instead of systemic solutions, and reconstructing record ownership after the fact. The structural causes are just as consistent: multi-account sprawl with no central DNS ownership, rapid dev cycles where IaC teardowns never touch Route53, and researchers reporting faster than teams can remediate.

The core of the talk is architecture: automatically cross-referencing every Route53 A record and CNAME against Elastic IPs allocated across all AWS regions, wired into ownership routing and shift-left pipeline hooks. Done right, this shifts detection from reactive to proactive, can take MTTR from weeks to hours, and eliminates entire classes of records at the source.

We'll release Ghost Records, an open-source tool aimed at the one of the highest impact vector: dangling A records and CNAMEs pointing to released or unallocated AWS Elastic IPs. It inventories every EIP across all enabled regions, cross-references them against Route53, and flags any DNS record pointing to an IP the account doesn't own. Read-only, multi-account, parallel scanning, risk-scored output. Live demo included.

Speakers:Jai Kumar Sharma,Tom McCarthy

SpeakerBio:  Jai Kumar Sharma, Principal Offensive Security Engineer at GoDaddy

Jai Sharma is a Principal Offensive Security Engineer at GoDaddy, where he leads cloud penetration testing, red team operations, AI red teaming, and security research across one of the world's largest domain registrars and hosting platforms. A self-taught offensive security researcher from New Delhi, India, he built his career with a hacker's mindset, breaking code logic, chasing vulnerabilities, and proving real-world business impact from technical exploits. He also leads TTP research, drives threat emulation efforts, and works closely with blue teams to sharpen detection through an adversary-focused lens.

At GoDaddy, Jai tests the same infrastructure and enterprise environments that millions of customers rely on. His work spans cloud and on-premises penetration testing, IAM privilege escalation research, and building automated offensive tooling that helps turn point-in-time assessments into continuous detection. Before GoDaddy, Jai held offensive security roles at Housing.com, FIS, and EY, giving him firsthand experience with how security weaknesses and misconfigurations surface across different industries, architectures, and maturity levels.

Jai volunteers with the DEF CON community as CTF Ops for the Cloud Village and on-site Coordinator for the Bug Bounty Village.

SpeakerBio:  Tom McCarthy

Tom McCarthy is the Director of Offensive Security and Business Information Security Officer at GoDaddy, where he oversees penetration testing, red team operations, and security strategy across multiple lines of business. With over 15 years in offensive security — spanning consulting, penetration testing, research, and training — Tom has built multiple penetration testing teams from the ground up and led or managed hundreds of penetration tests and red team engagements throughout his career. Tom is a returning DEF CON speaker, having previously presented research, tooling, and training at both DEF CON and DerbyCon. He has contributed to open-source offensive security projects including smbexec and Metasploit, and served as a trainer in hacking and incident response for local, federal, and military organizations across multiple countries.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 11:00-11:45 PDT


Title: GhostCatcher (endpoint detection agent)
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Purple Team | DEF CON Demo Labs
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

GhostCatcher is an open-source Linux endpoint detection agent written in Go. It runs as a single binary or a systemd service and looks for host-visible adversary tradecraft on Linux: web shells, LD_PRELOAD abuse, SSH, cron, and systemd persistence, PAM/sudoers tampering, SUID and capability drift, reverse shells and unexpected network behavior, reflective / memory-map signals, and related patterns aligned with MITRE ATT&CK-style coverage. Detections are driven by a versioned, optionally signed rule pack, baselines and learning mode, multi-signal scoring, time-windowed correlation, CEL-style boolean expressions, optional Sigma-lite rules, optional YARA (disk and memory) and eBPF (with auditd/proc fallbacks), and JSONL output to stdout plus optional syslog, Splunk HEC, Elasticsearch _bulk, or Grafana Loki. The goal is to give blue teams a transparent, self-hosted way to turn Linux host telemetry into actionable events in the SIEM—without a vendor cloud control plane.

SpeakerBio:  Sercan Okur

Sercan Okur is the Founder and CEO of NextRay AI Detection & Response, Inc., a San Jose–based cybersecurity company building AI-driven Network Detection and Response technology. A cybersecurity practitioner with more than fifteen years of experience across critical-infrastructure, defense, and enterprise environments,


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Saturday - 14:45-15:30 PDT


Title: Give an AI Industrial Protocol Tools and Watch What It Destroys
Tags: ICS Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:45 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Every major ICS attack of the last decade succeeded not because of software vulnerabilities, but because industrial protocols were built to trust any packet on the wire. The village has read the incident reports. What it doesn't have is a way to replay them against its own infrastructure to learn what its detections actually catch and what they miss.

We present mrhOTshOT, an open-source framework that emulates history's most destructive ICS attacks across the complete kill chain, reconstructed from publicly available incident analyses. Not just the OT payload the full chain: Windows initial access with real CVEs, lateral movement to engineering workstations, protocol-native process manipulation, and persistent physical impact. Every emulation generates wire traffic consistent with publicly documented behavior on the correct industrial protocol for that attack family.

The framework spans a wide range of industrial protocols across ten distributed PLCs, each simulating the real-world process that protocol actually controls: a heating district controller for Modbus, a safety instrumented system for TriStation, a centrifuge cascade for S7comm. Nothing runs on a generic simulated tank with ten protocols bolted on.

We also introduce the Agentic Attack Emulation Framework: every protocol action is exposed as a callable tool, orchestrated by an LLM agent that reads live process state and composes attack sequences on the fly. No hardcoded playbook, you decide. This is what AI-assisted ICS attack composition looks like, and defenders need to understand it before they meet it in the wild.

The talk closes with a live demo: three centrifuges destroyed in real time while the operator HMI, deceived by an S7 rootkit, shows normal operation throughout, until it doesn't.

Speakers:Malav Vyas,Asher Davila

SpeakerBio:  Malav Vyas, Palo Alto Networks

OT and IoT security researcher. I spend my time hunting vulnerabilities, crafting exploits, and pushing the boundaries of ecosystem security. When I’m not breaking things, I’m helping run the show with the Null, BSides, and OWASP communities. Catch me at the villages.

SpeakerBio:  Asher Davila, Vulnerability Researcher at Palo Alto Networks

Passionate about binary analysis, binary exploitation, reverse engineering, hardware hacking, retro computing, and music.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 12:00-15:59 PDT


Title: Global OSINT Search Party CTF – DEF CON 34 Edition
Tags: OSINT For Good Community | Contest
When: Saturday, Aug 8, 12:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

The Trace Labs Global OSINT Search Party CTF is a non-theoretical CTF where teams of up to 4 people use their OSINT skills to look for actual missing people. For DEF CON 34, we will be working directly with Las Vegas Metro PD to source local missing person cases they have requested the public’s assistance with. This is a hybrid event, open to participants of all skill levels, from anywhere in the world. Prizes will be awarded for 1st, 2nd, and 3rd places, as well as for Most Valuable OSINT. Participants at DEF CON can pickup their free event ticket by stopping by the OSINT4Good Community anytime prior to the event start. Global participants can get a ticket by going to https://www.tracelabs.org/tickets. Bring a laptop and some snacks and get ready to use OSINT4Good!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 16:00-16:45 PDT


Title: GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

GnawLab is a community-driven, open-source offensive cloud security training platform that recreates real-world AWS attack chains. Each scenario is modeled after documented breaches—Capital One's SSRF-to-IMDS pivot, Uber's leaked credential exploitation, SolarWinds-style CI/CD pipeline hijacking—deployed via Terraform in your own AWS account. Attendees will see live demonstrations of multi-hop attack chains: from SSRF and command injection entry points, through IMDS credential theft and Secrets Manager extraction, to full CI/CD pipeline compromise with Blue/Green deployment backdoors. GnawLab bridges the gap between theoretical cloud security knowledge and hands-on exploitation skills.

Speakers:ialleejy,Kyul,HyunJun "Beaver King" Kwon

SpeakerBio:  ialleejy

I am ialleejy, a Security Researcher at ENKI focusing on web security and cloud security. I have created WEB challenges for CODEGATE and HACKTHEON SEJONG CTF, and I am interested in designing CTF challenges that connect real-world service architectures with practical vulnerability research.

Recently, I have been exploring Offensive Cloud Security, especially how traditional web vulnerabilities can lead to privilege escalation, credential exposure, and abuse of trust relationships in cloud environments. I am currently diving deeper into AWS Bedrock AI Agents, RAG-based knowledge poisoning, OIDC authentication flows, and IAM trust policies.

Through this talk, I aim to show how a small vulnerability on the web can evolve into a broader cloud security issue, crossing trust boundaries between applications, identities, and cloud services.

SpeakerBio:  Kyul

I am a college student relentlessly exploring cloud vulnerabilities. I possess an exceptionally high threshold for hunting, gathering, and deeply analyzing whatever piques my interest.

My mindset is clear: effective defense demands an attacker's lens. Only by understanding actual infiltration paths and how they trigger critical risks can defenders accurately prioritize assets and build robust controls.

Driven by this, I’ve operated at the intersection of Red and Blue. In incident response projects, I analyzed real-world TTPs to build attack scenarios while collaborating to engineer detection rules and automated responses. I’ve also researched and presented how AWS misconfigurations can be weaponized to cause cascading breaches.

Currently, alongside the BeaverDam community, I am developing GnawLab for the DEF CON Demo Lab. GnawLab is an open-source, community-driven cloud security training platform. It provides high-fidelity sandbox environments reflecting real-world flaws, enabling players to execute realistic scenarios and vividly master cloud exploitation and analysis.

At DEFCON, my goal isn't just to show what I've built. I want to share this sandbox, break it alongside you, and absorb the brilliant, diverse approaches of world-class hackers. I am here to hack, learn, and grow together.

SpeakerBio:  HyunJun "Beaver King" Kwon

HyunJun Kwon is an Application and Cloud Security Engineer with 12 years of offensive security experience. Currently at Rapport Labs in Korea, he previously led vulnerability assessments, DevSecOps, and cloud security initiatives at Woowa Brothers, the company behind Baemin, South Korea's largest food delivery platform.

He serves as an AWS Community Builder for security and leads the Beaver Dam Community, an offensive cloud security research group. He also contributes to AWS Bedrock Agent Samples and mentors junior security professionals through programs like Baby Beavers, K-Shield Junior, and Whitehat School.

His cloud security research focuses on scaling security in dynamic environments. He built automated CCE assessment systems using AWS VPC Endpoints and Systems Manager. Recently he explored AI and security intersections, building LangChain and LangGraph agents for infrastructure assessment automation and MCP security checkers to detect supply chain risks.

He won the 2021 HDCON Grand Prize for cloud security architecture and authored two books on web hacking. He spoke at .HACK 2025 on Offensive Cloud Security and at .HACK 2026 on whether CloudTrail and GuardDuty are really enough.


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Saturday - 11:00-11:59 PDT


Title: Gold Bug: Puzzle Panel with Friends
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:
Speakers:CPV Gold Bug Team 2026,TBD

SpeakerBio:  CPV Gold Bug Team 2026
No BIO available
SpeakerBio:  TBD
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 10:00-10:45 PDT


Title: Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Malware | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Modern GPUs have become foundational to computing infrastructure for gaming, machine learning, and AI workloads at scale, yet GPU memory remains a largely unmonitored attack surface. No mainstream antivirus or endpoint-detection solution currently inspects it, creating a significant blind spot that sophisticated adversaries can exploit. This Demo Lab presents a novel technique that uses NVIDIA RTX 5090 CUDA APIs to stage payload data, such as DLLs, directly in GPU memory, entirely outside the visibility of host-based security tools, including Windows Defender. A benign executable, with no malicious code of its own, uses CUDA's native memory transfer capabilities to move binary payload data onto the GPU immediately upon execution. No CUDA Toolkit installation is required on the target host. When triggered, the same executable retrieves the payload from GPU memory, manually maps it into process space, and executes it. A working proof of concept has been validated as an Empire C2 module, confirming practical operational viability. The technique is particularly impactful for high-uptime environments such as AI inference servers, rendering farms, and enterprise GPU clusters, where small executables interacting with the GPU blend naturally into background workloads.

Speakers:Gannon "Dorf" Gebauer,Anthony "Coin" Rose,Hana Christensen

SpeakerBio:  Gannon "Dorf" Gebauer

Gannon "Dorf" Gebauer is a second lieutenant in the United States Air Force pursuing a master's in computer science at the Air Force Institute of Technology. He earned a Bachelor of Science in Computer Science from Arizona State University. His expertise spans red team operations, reverse engineering, and offensive tool development, and his current research focuses on novel persistence techniques that abuse GPU memory as an unmonitored attack surface.

SpeakerBio:  Anthony "Coin" Rose

Dr. Anthony "Coin" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

SpeakerBio:  Hana Christensen

Hana Christensen is a second lieutenant and developmental engineer (electrical) in the United States Air Force. She is currently pursuing a master's in electrical engineering, with a focus on signal processing and machine learning. Her research investigates security vulnerabilities in AI hardware, examining whether side-channel analysis can be used to extract information about machine learning algorithms. She holds a B.S. in Electrical and Computer Engineering from the United States Air Force Academy (class of 2025).


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 21:00-00:59 PDT


Title: GOTHCON
Tags: Party
When: Saturday, Aug 8, 21:00 - 00:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Returning for their 9th year, Gothcon invites you to come dance the night away with a line-up of some of the community's best dark dance music DJ's from across the US! Dress however you would like in whatever makes you feel comfortable and happy, and all are welcome.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 13:00-13:59 PDT


Title: gpwn: Wiretapping fiber (GPON) ISP deployments from the comfort of your home
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Have you ever wanted to know what your neighbor does on their network and what sites they're browsing? How about all the people around you on their mobile phones, on cellular data?

GPON is the fiber-to-home protocol that carries traffic for hundreds of millions of subscribers worldwide (and climbing). It operates on a threat model that makes several assumptions that break in the real world.

We'll chat about how it's possible to become a modern day fiber optic voyeur with hardware that costs about $100 and watch your neighbor's DNS, SIP calls and most excitingly, GTP-tunneled 4G/5G traffic from the cellular towers that you share a fiber line with.

Additionally, we show some fun, new techniques to retain your access even if your ISP wisens up and enables downstream AES encryption, by hacking the Optical Line Terminal itself over the fiber line, and how to build your own botnet army out of all the members of your ISP.

Finally, we'll also explore how we built custom hardware to read and write onto a fiber line despite the rules of the network (and land).

Speakers:Rithwik "thel3l" Jayasimha,Rithvik Vibhu

SpeakerBio:  Rithwik "thel3l" Jayasimha, Lagrange Point

Rithwik is a hacker who's been breaking into systems since the impressionable age of 10.

SpeakerBio:  Rithvik Vibhu, Lagrange Point

Rithvik has always been fascinated by network systems and in the past was a core contributor to the HNS ecosystem. In the past, he reverse engineered an implementation of UPI in India, and built distributed proxy infra.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Hac-Man
Tags: Hac-Man | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal)) - Map

Description:

Rogue Signal builds bespoke, technically driven interactive experiences rooted in hacker culture, game design, and immersive storytelling. Drawing from backgrounds in immersive theater, live events production, community building, and deep game design practice, Rogue Signal creates systems that transform participation into exploration.

Rather than relying on superficial gamification, Rogue Signal focuses on meaningful challenge design. Their experiences reward curiosity, experimentation, collaboration, and strategic thinking. From scavenger hunts to technical skill challenges to digital easter eggs, each activation is designed around the specific audience and environment it lives in.

At DEF CON, Rogue Signal brings that philosophy to Hac-Man. A Pac-Man–themed security challenge platform that blends retro inspiration with layered technical depth. Participants will engage directly with structured challenges that test logic, pattern recognition, foundational security and hacker knowledge, and progressively more advanced technical skills.

Hac-Man reflects the hacker mindset: iterate, experiment, fail, refine, break assumptions, and try again. It encourages collaboration where helpful, competition where motivating, and discovery at every level.

Attendees can expect: - Hands-on security challenges - Multiple subject-matter tracks - Layered difficulty levels - Scavenger style discovery elements - Competitive scoring and mission style progression - A welcoming but technically rich environment

Whether you’re new to security or already deep in the field, Rogue Signal’s space offers a place to test your thinking, sharpen your skills, and experience hacking concepts through play.

Participant Prerequisites

Participants will need access to a smartphone, tablet, or laptop in order to access gameplay content and view leaderboards. The experience is web-accessible and designed to function on standard modern devices.

No specialized hardware (e.g., Flipper Zero, SDR, etc.) is required. Foundational familiarity with basic computer use and logical problem-solving will be helpful, but no advanced security knowledge is required to begin. The game features layered difficulty tracks to accommodate both beginners and more advanced participants.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: Hack The Box DC Junior Ranger Program Challenge
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:
Hack The Box brings its Junior Ranger Program to DEF CON: a beginner-friendly challenge guide built by the Hack The Box team specifically for the Noob Village, modeled after the U.S. National Park Service's Junior Ranger booklets. Work through the challenges in the guide and earn custom Junior Ranger badges as you complete them. Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-11:59 PDT


Title: Hack3r Runw@y v8.0
Tags: Hack3r Runw@y v8.0 | Contest
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map

Description:

Hack3r Runw@y v8.0

Where Code Meets Catwalk @ DEF CON 34

The Hack3r Runw@y returns for its 8th evolution! After nearly a decade of bridging the gap between hardware and haberdashery, we’re back at DEF CON 34 to prove once again that hackers are the most creative engineers on the planet.

Whether you’re a glamorous geek, a crafty coder, or a fashionably functional phantom, it’s time to weaponize your wardrobe. We’re challenging you to dismantle the boundary between "security" and "style." If you can hack it, you can wear it.

The Mission Categories - Smart-Wear (Active Tech): The high-voltage category. Integrate microcontrollers, sensors, and live telemetry into your designs. We want to see hardware that reacts to the environment—or the wearer—in real-time. - Digital Dazzle (Passive Tech): Bling with a brain. Focus on LEDs, fiber optics, and glow-tech that remains passive but high-impact. Light up the room without needing a CLI. - Functional Fashion (Tactical): Gear for the field. Think "Cyber-Chic Pentester": lockpick jewelry, shim-integrated accessories, signal-blocking fabrics, or high-fashion physical security tools. - Extraordinary Style (Creative Ops): The "Kitbash" category. Elevate the everyday with 3D textures, optical illusions, security-inspired patterns, and deep-cut cosplay.

THE PEOPLE'S CHOICE Trophy: One coveted trophy is up for grabs where ANYONE can win. But be warned: in true DEF CON fashion, there will be a twist. Follow the social media for updates.

The Judging Criteria

Our panel will be scoring builds based on: - Technical Mastery: Execution of hardware/software. - Couture Craftsmanship: Quality of the "fit" and finish. - Relevance: How it speaks to hacker culture or security. - Originality: Creative use of materials and "kitbashing."

Participant Prerequisites

Originality: Items must be handmade by the entrant.

Verification: Documentation (photos/video) of the build process is required to verify authenticity.

Modification vs. Acquisition: We celebrate the "kitbash." Using pre-made components to create something new is allowed, but "off-the-shelf" or "plug-and-play" retail items are not permitted.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 14:00-15:59 PDT


Title: Hacker Book Club meet up
Tags: The Diana Initiative | Creator Event/Activity
When: Saturday, Aug 8, 14:00 - 15:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

Community is essential and so is continual learning. Reading books and discussing books can greatly impact an individual’s access and sense of community and knowledge. This Hacker Book Club book discussion will be an accessible group aiming to build community and share out learnings, all in a quieter setting. Come join us and discuss what you’ve been reading. We also run a year round Discord to discuss books throughout the year, hackerbookclub.com. This Hacker Book Club is not locked to a region and is for those who love books and escaping to the cyberpunk and scifi worlds that inspire DEF CON and modern literature. The DEF CON 34 theme is agency and our DEF CON themed book is The Dispossessed by Ursula Le Guin.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Saturday - 13:00-14:15 PDT


Title: Hacker Culture 101
Tags: DCNextGen | Creator Event/Activity | Youth
When: Saturday, Aug 8, 13:00 - 14:15 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Learn about the K-Rad side of hacking, from media representations in movies and tv shows, to hacker fashion throughout the years (we wear more than black hoodies!). In this session, we will also cover two iconic pieces of hacker culture- Handles and stickers, with an opportunity to make your own stickers and choose your unique handle! If you wanna jam with the console cowboys in cyberspace, this is the event for you!

SpeakerBio:  medus4
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Hacker Games
Tags: Hacker Games | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 207 (Hacker Games) - Map

Description:

The Hacker Games is a series of hacker skills tests meant to challenge the hacker's knowledge of computer systems such as Binary -> Hex -> X conversion, Adapter -> Adapter knowledge, Keyboard Layout, and many more arbitrarily useless skills. Hackers will go head-to-head in a series of several skill-based games. BinHexAscii, Chopstick Challenge (a.k.a. Will it Flow), Keyboard Layout, Adapt or Die, ToS, and more! Can you hack it?

Participant Prerequisites

A box of computer-style adapters of no particular order would be very helpful.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 20:00-21:59 PDT


Title: Hacker Jeopardy
Tags: Event | Hacker Jeopardy!
When: Saturday, Aug 8, 20:00 - 21:59 PDT
Where: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 20:00-00:59 PDT


Title: Hacker Karaoke
Tags: Party
When: Saturday, Aug 8, 20:00 - 00:59 PDT
Where: LVCCW Level 2 W229, W232 - Map

Description:

Two great things that go great together! Join the fun as your fellow hackers make their way through songs from every era and style. Everyone has a voice and this is your opportunity to show it off! Everyone is encourage to participate in a DEF CON tradition from all folks and skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 13:20-13:30 PDT


Title: Hackers with Disabilities Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 13:20 - 13:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Hackers with Disabilities but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Hackers with Disabilities and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: HackFortress
Tags: HackFortress | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 108 (HackFortress) - Map

Description:

HackFortress is back! Returning to DEF CON with a twist on our standard format. Two teams of players, 6 gamers and 4 hackers each, compete in a mashup of a jeopardy style CTF and a first person shooter. New this year, we're replacing our previous FPS of Team Fortress 2 with a web based version of the 2000's classic Quake 3!

While gamers are rocket jumping and sniping each other in Quake, hackers will be solving challenges in a variety of areas: web security, network security, cryptography, lock picking, social engineering, and more! Challenges range from beginner to advanced, from serious to absurd. During the competition, as both sides of the team star scoring points, the teams also earn points in the HackFortess HackConomy Store, in the store hackers can buy in game effects, both offensive and defensive, and much like the challenges, these effects range from serious to absurd.

With all of the contest being web based, both hacking and Quake, players MUST bring their own laptop (or whatever device they want to use) and a wired network adapter.

Grab your friends!

Ask that random stranger standing next to you in Linecon if they want to join your team!

Come play HACKFORTRESS!

Participant Prerequisites

All players will need to bring a laptop and wired network adapter. Since we are now using web based version of Quake 3 (which can run on players phones), we are no longer providing any gaming laptops.

Gamers: bring any gaming accessory of your choice, its your hardware, go for it

Hackers: bring lockpicks


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 14:30-14:59 PDT


Title: Hacking AFDX or Not; A Primer for Flight Control Systems Security
Tags: Aerospace Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

One of the challenges of independent airplane cyber research is the lack of availability of recent hardware; avionics, LRUs and anything from the aircraft control domain is insanely expensive, even when used. Access to retired airframes therefore represents the state of the art from 20+ years ago. We have been stuck with researching older ACD protocols such as ARINC 429 and 629. However, through a fortuitous stroke of luck, we were given access to an ARINC 664 or ‘AFDX’ environment on a test bench recently. The protocol was developed by Airbus for the A380, but is also found on the B787, A350 and is increasingly being implemented on new designs. Avionics Full-Duplex Switched Ethernet / ADFX will be much more familiar to IT folks than the earlier protocols, having much more in common with the OSI reference model. But, it has crucial differences which requires a steep learning curve. This talk is a primer for interfacing with AFDX and the various security and safety features that it offers.

Speakers:Andrew Tierney,Adam Bromiley

SpeakerBio:  Andrew Tierney
No BIO available
SpeakerBio:  Adam Bromiley, Pen Test Partners

Adam is a security consultant at Pen Test Partners who specialises in industrial control systems and embedded hardware security. He's worked on everything safety-critical: from high-speed rail to aircraft, power stations, and gas distribution. His embedded work has seen him break driverless cars, slot machines, and drones and has led to the responsible

disclosure of numerous vulnerabilities in industrial controllers. Adam enjoys hands-on and boots-on-the-ground testing, reverse engineering, and providing practical security advice for complex real-world systems.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Hacking GRC Contest
Tags: Hacking GRC | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: Online

Description:

Hacking CMMC is a hands-on cybersecurity competition designed to immerse participants in the practical aspects of the Cybersecurity Maturity Model Certification (CMMC). Through realistic, challenge-based scenarios, players explore common compliance gaps, security controls, and threats faced by defense contractors.

The CTF blends technical problem-solving with compliance-driven thinking, helping participants understand how security requirements translate into real-world incidents. It offers an engaging way to learn, test skills, and strengthen readiness for CMMC-aligned environments.

The CTF will be a Jeopardy-style CTF where every player will have a list of challenges in different categories. For every challenge solved, the player will get a certain number of points depending on the difficulty of the challenge.

Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 13:15-14:45 PDT


Title: Hacking iOS Apps in a Structured Way
Tags: Mobile Hacking Community | Creator Event/Activity
When: Saturday, Aug 8, 13:15 - 14:45 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

Mobile app testing has many pitfalls and a structured approach is needed to get a holistic picture of the attack surface. The OWASP Mobile Application Security (MAS) project is able to support you with that. In this workshop, you'll get a practical introduction to the MAS ecosystem which consists of the standard, mobile weaknesses and how to test them. You will experience test cases and demos for iOS in action for static and dynamic analysis, and learn how to perform a mobile penetration test on a non-jailbroken iOS device.

By the end of the workshop, attendees will be able to: - Navigate the OWASP Mobile Application Security (MAS) project (MASVS, MASWE, MASTG) and locate relevant test cases for their own engagements. - Apply a mix of static and dynamic analysis techniques against real iOS apps. - Use the right tooling (e.g. frida, radare2, AI-assisted reverse engineering) in their pentest workflow.

Instructions: https://github.com/sushi2k/defcon34-ios-workshop

Prerequisites: a laptop with 10 GB free disk space; GitHub account and git installed.

SpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

--

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 16:00-16:59 PDT


Title: Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

AI orchestration platforms promise to automate your life. They deliver, just not always for you. Kestra, Langflow, Nocobase, Flowise, Activepieces, Dify, and Apache Airflow have quietly become critical infrastructure, and they all share the same dangerous assumption: anyone who can touch a workflow is trusted to run code on the host. I went hunting across seven major platforms and walked out with multiple CVEs and critical-severity findings. I'll share an arsenal of RCE primitives: shell injection through template rendering, exec() on user-supplied "validation" code, eval() on raw LLM output, and unauthenticated API endpoints that hand you a shell. Then I'll demonstrate the kill shot: an unauthenticated attacker achieving full RCE through a single prompt injection into an LLM module. When I reported these, some vendors told me code execution is intended behavior and security is the deployer's problem. I'll show you why that argument falls apart in real deployments, and walk through the trust boundary failures that keep producing the same bugs across the ecosystem. You'll leave with a methodology for tearing these platforms apart, a catalog of recurring vulnerability patterns, and a framework for evaluating whether a platform's threat model survives contact with reality.

SpeakerBio:  Peyton "p80n-sec" Kennedy, Endor Labs

Peyton 'p80n-sec' Kennedy is a Senior Security Researcher at Endor Labs, where he focuses on offensive security research, vulnerability discovery, and exploit development against the open source projects shaping modern software. His research has produced CVE disclosures across widely deployed frameworks and platforms, including koa.js and openclaw, with a consistent focus on the gap between what platforms claim about their threat models and what they actually enforce.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 11:35-12:15 PDT


Title: Haetae: An Agent to Takedown North Korean C2 Servers
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:35 - 12:15 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.

Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.

In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.

We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.

This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters.

SpeakerBio:  Nelson Colon, Offensive Security Specialist at Bitso Quetzal Team

Dominican Offensive Security Specialist. I spoke at DEF CON Data Duplication Village about creating immortal C2 servers using modern data duplication platforms.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Saturday - 14:30-14:59 PDT


Title: Ham Radio - Licensed to Experiment
Tags: Ham Radio Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 14:59 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

The most common question we hear in the village is, "What can I do now that I'm licensed?" N0OPS and W0BDP attempt the guide new hams into incorporating ham radio into their current hobbies or pursuing new interests.

N0OPS and W0BDP will walk the audience through the diversity of ham radio operations such as portable activations such as POTA/SOTA, satellite contacts, digital weak-signal modes, direction-finding competitions, emergency communications, and drone telemetry.

The takeaway: no matter how long you've held a call sign whether it's 5-minutes or 5 years, there's almost certainly a corner of this hobby you haven't touched yet. This speech is an invitation to go find it.

SpeakerBio:  Dan W0BDP Norte

Dan "darkestofdans" Norte (W0BDP) is a penetration tester, currently with NetSPI. Dan has been a ham radio operator for 9 years, currently Amateur Extra class. Dan enjoys popping shells and chasing DX.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 10:00-11:59 PDT


Title: Hands-On Autonomous Pentesting with Pentest Copilot
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

Pentest Copilot is an MIT licensed open-source agentic penetration testing workspace designed to assist security professionals with web/network application assessments.

This hands-on tactic introduces participants to operating autonomous web pentesting workflows against intentionally vulnerable applications. Attendees will deploy Pentest Copilot, configure the environment, and use it to perform attack-surface discovery, authenticated testing, vulnerability investigation, and workflow-driven analysis.

Rather than focusing on theory, the session is designed around practical offensive workflows. Participants will observe how autonomous agents navigate modern web applications, identify interesting attack paths, investigate findings, and assist with security testing tasks that traditionally require significant manual effort.

The goal is to provide attendees with a realistic understanding of how autonomous systems can augment offensive security work today, where they are effective, and where human operators remain essential.

Pentest Copilot is fully open source and available at: https://github.com/bugbasesecurity/pentest-copilot, Wiki is at: https://github.com/bugbasesecurity/pentest-copilot/wiki over 800+ stars.

Speakers:Dhruva Goyal,Sitaraman Subramanian

SpeakerBio:  Dhruva Goyal

Dhruva has been hacking since middle school and enjoys offensive security research and red teaming. Dhruva is certified with OSCE3(ie. OSWE, OSEP & OSED) and OSCP. He leads the cybersecurity engagements and triage team at BugBase. He also loves playing AOE4 and working out.

SpeakerBio:  Sitaraman Subramanian

Sitaraman Subramanian is the CTO at BugBase. He has spent over five years working in offensive security and over a decade building products. His work spans full stack development, DevSecOps, cloud security, and offensive security. He built BugBase from the ground up, and now leads engineering on Pentest Copilot, an autonomous AI driven pentesting platform. He presented at Black Hat USA Arsenal in 2025 and Microsoft BlueHat in 2024. He is an active open source contributor. Pentest Copilot is open sourced at https://github.com/bugbasesecurity/pentest-copilot, with 850+ stars and growing. He writes about hacking and AI evals at https://blog.ssitaraman.com.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access
Tags: IoT Village | Creator Workshop
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Using tools like OpenOCD and Segger J-Link Mini, we’ll guide you through modifying the boot 'init=' process in memory via JTAG, forcing the device into a single user mode shell via UART.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:30-11:30 PDT


Title: Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Saturday, Aug 8, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Post-quantum cryptography is being deployed to defeat a computer that doesn't exist yet - and the rush is opening a wide, purely classical attack surface today. This talk walks three implementation attack vectors against NIST's lattice standards (ML-KEM / FIPS 203, ML-DSA / FIPS 204): (1) memory corruption at the deserialization boundary, culminating in remote code execution through a hybrid TLS 1.3 key exchange; (2) compiler-induced timing side channels, where "constant-time" source becomes variable-time binary and yields a chosen-ciphertext key-recovery oracle; and (3) fault injection against ML-DSA's signing state machine on a low-cost ChipWhisperer. No quantum computer is required for any of them. The talk closes with the limits of hybrid cryptography as a defense and the live release of LatticeScope, an open-source timing-leak detector and lattice-aware fuzzer for auditing compiled PQC binaries.

SpeakerBio:  Aleksandr Krasnov

Aleksandr has been an industry expert in DevSecOps, has worked in companies like Dropbox, Palo Alto Networks, and Meta/Facebook. He has spent his time doing security research and holds several patents in the area of application security. In the free time, Aleksandr spends time exploring the great outdoors in British Columbia, climbing new boulders, or free diving in the ocean.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 17:00-17:59 PDT


Title: High Voltage Heist: Turning Your EV into my Power Bank
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Ever found yourself with a dead phone battery in a Walmart parking lot? What if we told you that you could walk up to a parked EV and charge your phone directly from its traction battery - no authorization, no keys, and no official V2L features required.

As the EV market expands, the complexity of its charging infrastructure scales with it. The push for Vehicle-to-Grid (V2G) communication capabilities introduces a significant attack surface with destructive potential for high-voltage systems. In this talk, we explore the security risks within current V2G communication. We break down exactly how this data is processed internally, map out the high-voltage charging architecture, and expose logic weaknesses hiding within the vehicle's Battery Management System (BMS) ECUs.

Based on this research, we introduce ChargeSploit, a custom hardware and software toolkit designed for cybersecurity testing of the EV charging ecosystem. Capable of simulating both vehicles and chargers, or acting as a physical Man-in-the-Middle, ChargeSploit allows researchers to intercept, manipulate, and inject payloads into live communication flows. We conclude with a live demonstration exploiting V2G protocols and the BMS to force an unauthorized discharge, successfully powering an iPhone directly from a locked EV's traction battery.

Speakers:Fabien Guillebot,Stepan Konicek

SpeakerBio:  Fabien Guillebot, Accenture

Fabien Guillebot is a Hardware Security Researcher at Accenture based in Prague, Czech Republic. He specializes in hardware-level security testing with a primary focus on the automotive sector. Fabien's core expertise lies in designing custom hardware for specialized penetration testing and conducting advanced research in microcontroller glitching and fault injection.

SpeakerBio:  Stepan Konicek, Accenture

Stepan Konicek, MSc. is an Embedded Systems Penetration Tester at Accenture based in Prague, Czech Republic. Specializing in automotive cybersecurity, Stepan focuses on testing and securing ECUs and full-vehicle architectures. His primary research focus lies in EV charging security, where he investigates the physical and protocol-level vulnerabilities that exist between modern vehicles and grid infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 13:00-13:45 PDT


Title: Hook Crook - Extracting More From Discord Webhooks
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

A webhook URL is often thought to be write-only — post a message, nothing more. So when one leaks through a misconfigured repo, a paste site, or breached infrastructure, it's written off as a spam-or-phishing nuisance and left to rot. Hook Crook shows that assumption is the vulnerability — and that "write-only" was never really the case.

By abusing how Discord resolves references, what it returns when you query users and messages, and how its error and rate-limit responses differ, the write-only token quietly becomes a read primitive — leaking by design, not by bug. With nothing but the URL — no account, no additional authentication, no interaction from anyone on the target server — Hook Crook fingerprints the host guild, enumerates and confirms members, pulls profile data on known users (including their home-server tag), and in some cases recovers message content. The same behaviors let it bypass the server's posting restrictions, stage convincing impersonation and phishing, quietly edit or delete messages to scrub the evidence, and — on the way out — delete the webhook itself. None of it breaks Discord — it just reads Discord more carefully than its designers intended.

Speakers:Jeremy Banker - K0JLB,Arity0

SpeakerBio:  Jeremy Banker - K0JLB
Bio: Jeremy Banker is a Senior Security Software Engineer at Horizon3.ai, focused on the reliability and resiliency of Horizon3's automated penetration testing platform. He previously spent nearly a decade at VMware, where he co-founded the Security Product Engineering group and led efforts to secure VMware's software supply chain. His open source security tooling, including Build Inspector for CI/CD pipeline anomaly detection and Tommyknocker for automated security control validation, has been featured at Black Hat Arsenal and DEF CON Demo Labs. A licensed amateur radio operator since 2010, he built open-packet, an MIT licensed Python client for packet messaging, after becoming frustrated with the existing closed-source options.
SpeakerBio:  Arity0

Arity0 is an independent security researcher specializing in the Discord platform. A self-taught hacker, he focuses on uncovering undocumented behaviors, edge cases, and design-level privacy implications in Discord's API and rendering pipeline. His long-running exploration of Discord's rendering quirks led to the discovery of the webhook rendering oracles that form the foundation of the Hook Crook identity disclosure technique.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 14:00-14:45 PDT


Title: Hook Crook - Extracting More From Discord Webhooks
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

A webhook URL is often thought to be write-only — post a message, nothing more. So when one leaks through a misconfigured repo, a paste site, or breached infrastructure, it's written off as a spam-or-phishing nuisance and left to rot. Hook Crook shows that assumption is the vulnerability — and that "write-only" was never really the case.

By abusing how Discord resolves references, what it returns when you query users and messages, and how its error and rate-limit responses differ, the write-only token quietly becomes a read primitive — leaking by design, not by bug. With nothing but the URL — no account, no additional authentication, no interaction from anyone on the target server — Hook Crook fingerprints the host guild, enumerates and confirms members, pulls profile data on known users (including their home-server tag), and in some cases recovers message content. The same behaviors let it bypass the server's posting restrictions, stage convincing impersonation and phishing, quietly edit or delete messages to scrub the evidence, and — on the way out — delete the webhook itself. None of it breaks Discord — it just reads Discord more carefully than its designers intended.

Speakers:Jeremy Banker - K0JLB,Arity0

SpeakerBio:  Jeremy Banker - K0JLB
Bio: Jeremy Banker is a Senior Security Software Engineer at Horizon3.ai, focused on the reliability and resiliency of Horizon3's automated penetration testing platform. He previously spent nearly a decade at VMware, where he co-founded the Security Product Engineering group and led efforts to secure VMware's software supply chain. His open source security tooling, including Build Inspector for CI/CD pipeline anomaly detection and Tommyknocker for automated security control validation, has been featured at Black Hat Arsenal and DEF CON Demo Labs. A licensed amateur radio operator since 2010, he built open-packet, an MIT licensed Python client for packet messaging, after becoming frustrated with the existing closed-source options.
SpeakerBio:  Arity0

Arity0 is an independent security researcher specializing in the Discord platform. A self-taught hacker, he focuses on uncovering undocumented behaviors, edge cases, and design-level privacy implications in Discord's API and rendering pipeline. His long-running exploration of Discord's rendering quirks led to the discovery of the webhook rendering oracles that form the foundation of the Hook Crook identity disclosure technique.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 13:30-14:59 PDT


Title: Hook, Line & Pretext Workshop: Crafting Effective Phish
Tags: Social Engineering Community Village | Creator Event/Activity
When: Saturday, Aug 8, 13:30 - 14:59 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

Every effective phishing email is really a marketing email with a hostile goal. It wins attention, builds desire, and drives a single click. This hands-on introductory workshop pulls back the curtain on that craft. In 90 minutes you'll learn the persuasion techniques that make a lure irresistible, borrowed straight from the sales and marketing playbook: the handful of influence levers that actually move people, the copywriting structure behind a high-converting message, and the emotional triggers that turn a glance into a click. Then you'll add the ingredient that separates a generic blast from a believable one, which is context, using open-source intelligence (OSINT) to tie a lure to a real department, location, or current event so it feels timely and true. You won't just watch. After we run the full method end to end against a familiar fictional target, the Scranton branch of Dunder Mifflin, you'll roll up your sleeves and build your own department or location wide pretext against a real organization you know. You'll walk out able to reason about why people click, not just that they do, with a repeatable process and a finished lure you can take straight back to your own awareness program. This is a content-creation and analysis workshop. No live phishing is conducted and no email is ever sent. Who it's for: Aspiring and early-career security practitioners, security-awareness and blue-team staff who want to think like an attacker, IT professionals moving toward security, and students or career-changers exploring offensive security. Anyone who builds or improves a phishing-awareness program will get direct, practical value. Level and prerequisites: Introductory. No prior phishing, red-team, or OSINT experience required. You should be comfortable using a web browser and reading professional email. Nothing to install, no coding, no command line. What to bring � A laptop with a web browser, for light open-source research during the lab � A real organization you know: your employer, your school or university, a nonprofit or club you belong to, or a former workplace, etc. � Something to write with. All worksheets are provided � Curiosity and a willingness to share your draft for friendly peer feedback What you'll leave with � The three-gates test (legality, then ethics, then morality) for vetting any campaign before it runs � A working command of the four influence levers that drive clicks and the "one hook, one ask, one button" rule for writing them � A repeatable OSINT-to-pretext method for making lures timely and relevant to a department or location � A completed Pretext Canvas and a draft, awareness-grade phishing email you can optionally submit to your own organization's security-awareness program Format and duration: A hands-on 90 minutes: about 30 minutes of instruction, a 10-minute guided case study against Dunder Mifflin, and roughly 50 minutes of lab with peer review and debrief. What this workshop is not: It's not a tooling or infrastructure course. There are no phishing frameworks, payloads, landing pages, or email spoofing. It's not spear-phishing of named individuals; the focus is wide-net, department and location-level pretexts. And nothing is ever sent.

Speakers:Jenn,JC

SpeakerBio:  Jenn

Jenn (@_nextjenn) is a Senior Offensive Security Consultant and a DEF CON Black Badge holder, earned by winning the vishing competition. With over a decade of cybersecurity experience, she specializes in social engineering, physical security testing, and network penetration testing. Leveraging her background in psychology and experience as a licensed Private Investigator and Locksmith, she has led sophisticated red team engagements across physical penetration testing, phishing, vishing, and deepfake-driven operations. An active mentor and coach in the social engineering community, Jenn has judged DEF CON's 2024 "Humans vs AI" and 2025 Vishing competitions and shares insights through podcasts and conference talks, including Wild West Hackin' Fest and San Diego Comic-Con.

SpeakerBio:  JC, President at Snowfensive

JC is a U.S. Marine Corps veteran, President of Snowfensive, and co-founder of the Social Engineering Community Village at DEF CON. With more than a decade of experience spanning information technology, digital forensics, incident response, penetration testing, and social engineering, he specializes in turning complex security concepts into practical skills people can immediately apply.

At Snowfensive, JC oversees the company's offensive security services, including phishing, vishing, physical social engineering, covert entry assessments, and technical penetration testing across networks, wireless environments, and applications. He has designed and led human-focused security engagements for organizations across a wide range of industries, combining technical tradecraft with a practical understanding of how people, processes, and technology intersect.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 10:10-12:10 PDT


Title: Hostile Input: PDF Triage That Survives an Adversarial Document
Tags: Malware Village | Creator Workshop
When: Saturday, Aug 8, 10:10 - 12:10 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map

Description:

Abstract A malicious document is no longer only a payload for the endpoint. It is an input your tooling has to parse and judge, and as SOC teams bolt language models onto triage, that input becomes something an attacker can shape to corrupt the verdict itself. This workshop treats the document as an adversarial surface aimed at the analyst’s tooling, including the analyst’s AI.

It is hands-on, starting from basic command-line tools, participants build the techniques that defeat AI-assisted triage, then build triage that survives them: a prompt injection placed where no human reader sees it, a metadata and ToUnicode parser differential where the renderer and the extractor disagree on the same glyphs, and a staged payload the document never reveals on its own. The two contributions that carry the workshop are treating extractor disagreement as a detection signal, and a triage architecture where a deterministic stage owns the verdict and the model is confined to advisory roles downstream of it.

Participants leave with a working pipeline, the sample set, and a scoring harness, and can state exactly where a language model belongs in triage and why putting it anywhere else is the vulnerability. The pipeline runs locally on modest models, because the detection power is in the tooling, not the model. Clean files never leave the environment.

Outline Deterministic floor. Point an autonomous agent at a file, watch an indirect injection in the document hijack it. That failure is the problem statement. Participants then lay the structural floor with pdfid and pdf-parser: the facts an attacker cannot phrase their way out of.

Demote the model. Analyze a malicious PDF structurally, then watch a hidden render-mode injection talk a naive model pipeline into a clean verdict. Rebuild it so a deterministic stage owns the verdict and the model is fed structural findings, not the attacker’s prose. Rule: extracted content is untrusted input, never instruction.

Add redundancy: the parser differential. Two documents that defeat detection by placement alone: an injection living in metadata a body-text extractor never reads, a ToUnicode trick that makes the rendered page and the extracted text disagree on identical glyphs. Participants build a multi-extractor differential and treat disagreement as the alert.

Resolve, and place the model. A staged payload forces the last lesson: Participants add input validation and type-confusion detection at the floor, extract the hidden artefact as a suspicion finding, decode it in-terminal, and let bounded model roles explain it and assemble competing hypotheses with evidence while the analyst decides. The model advises downstream of a deterministic gate, never holds the verdict.

Capstone CTF and Q&A. A fresh set: technique-carriers, clean decoys, and documents styled as beingenin PDFs Sthat baits the analyst into pasting it straight into the model. Participants show their work: verdict, technique, extraction path, hidden URLs, execution behaviour. Scoring rewards correctness first, then fewest tokens, because the analyst who needed the model least played the strongest game.

Learning objectives Participants will be able to: 1. Build a PDF triage pipeline from command-line tools and explain exactly where its verdict comes from. 2. Analyze a malicious PDF structurally (pdfid, pdf-parser, stream inspection) and decode embedded artefacts in-terminal. 3. Construct and recognize the three adversarial-document techniques that defeat AI-assisted analysis: hidden-layer prompt injection, metadata and ToUnicode parser differentials, and staged payloads. 4. Distinguish an early structural suspicion verdict from a late analytical identification verdict, and treat extractor disagreement as a detection signal. 5. Place a language model in bounded advisory roles downstream of a deterministic gate, never holding the verdict, and select the right model for each task. 6. Run the whole pipeline locally on modest models, understanding why the detection power lives in the tooling and why the architecture is private by construction.

SpeakerBio:  Klaus Wunder, Principal Cyber Defence Analyst at SECUINFRA

With nearly two decades in cybersecurity, Klaus has gone from configuring firewalls to protecting industrial control systems where breaches cost safety, not just data. That journey gives him a full-spectrum perspective on security operations. He guides teams through complex incidents and builds detection engineering capabilities across hybrid environments as a Principal Cyber Defence Analyst, while his role as an Authorized OffSec Instructor, Ambassador keeps him equally focused on developing the next generation of analysts. His current work explores how Large Language Models can revolutionize cyber defence with practical applications, not hype. He recently launched The Analyst Mind on Substack (theanalystmind.io), where he writes about analytical thinking, critical frameworks, and the evolving analyst mindset.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 15:30-15:59 PDT


Title: How Malicious AI Skills Hijack Your Agents
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

When OpenClaw went viral in January 2026, threat actors were in ClawHub within hours. They didn't need to exploit a vulnerability - they just opened a GitHub account and uploaded malicious AI skills. Within weeks, over 700 malicious skills had shipped, all designed to steal crypto and credentials from unsuspecting users. When maintainers added scanning, attackers moved their payloads off the platform entirely. The green badge stayed green. The malware kept spreading.

This talk uses that campaign as a case study to examine how AI skills get weaponized, why the security signals on skill registries create a false sense of safety, and what practitioners and security leaders can do to evaluate skills safely before installing them.

SpeakerBio:  Jenn Gile

Jenn Gile is a community builder and tech educator in the Security and DevOps fields. She's Co-Founder of OpenSourceMalware.com and runs the community program for BSides Seattle. Jenn previously worked at NGINX, F5, Endor Labs, and the U.S. Department of State. Outside of work, she's deeply involved in the cycling community as a board member for 2nd Cycle.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 16:30-17:30 PDT


Title: How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs?
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Saturday, Aug 8, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Last year Xeno manually reverse-engineered Realtek RTL8761B* Bluetooth chips' ROM & firmware, to inject code into them that allows everyone to send custom packets that aren't supposed to be possible on a well-behaved device. Previous to that Veronica manually reverse-engineered multiple firmware to find link layer over-the-air exploitable vulnerabilities. This year we wanted to understand how much time we could have saved on past projects if we had used LLMs to automate the reversing process.

The answer turns out to be "quite a lot!". In this talk we'll discuss how we've created skills for LLMs to almost entirely automate the reverse engineering of Bluetooth Low Energy / Classic chip firmwares' low level packet handling & Host Controller Interface layers. The key is to focus on helping the LLMs find the code that you know must be there in order for a chip to be spec-compliant ("Waypoints").

If you work in another firmware/OS RE domain, with well-defined specification-required interfaces and data structures, we expect you'll be able to follow the same process as us to significantly accelerate your reversing. Especially if you have binaries that you've already reverse-engineered in the past that you can feed into an automation process for grading purposes.

[1] "Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes" - Xeno Kovah - https://darkmentor.com/publication/2025-11-hardweario/
[2] "DarkFirmware_real_i" - Xeno Kovah - https://github.com/darkmentorllc/DarkFirmware_real_i [3]

Speakers:Veronica Kovah,Xeno Kovah

SpeakerBio:  Veronica Kovah, Dark Mentor LLC

Veronica is a researcher who has created and released multiple over-the-air arbitrary code execution exploits which target Bluetooth chip firmware. She presented these attacks at BlackHat USA 2020. In 2018 she founded the security consultancy Dark Mentor LLC. She has previously worked at companies like Tesla on vehicular security and NSA as an adjunct instructor and Capability Development Specialist developing CNE tools for embedded systems. She is currently using her background in reverse engineering and exploitation to specialize in the security analysis of Bluetooth systems.

SpeakerBio:  Xeno Kovah, Dark Mentor LLC

Prior to working full time on OpenSecurityTraining2 (ost2.fyi), Xeno worked at Apple designing architectural support for firmware security; and code auditing firmware security implementations. A lot of what he did revolved around adding secure boot support to the main and peripheral processors (e.g. the Broadcom Bluetooth chip.) He led the efforts to bring secure boot to Macs, first with T2-based Macs, and then with the massive architectural change of Apple Silicon Macs. Once the M1 Macs shipped, he left Apple to pursue the project he felt would be most impactful: creating free deep-technical online training material and growing the newly created OpenSecurityTraining 501(c)(3) nonprofit.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 13:30-13:59 PDT


Title: How Shadow APIs Become an Attacker's Free Pass Into Your Cloud-Native App
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Old endpoints rarely die. They get forgotten. They survive refactors, go-lives, and cloud migrations, quietly drifting outside the visibility of gateway security testing. Many are inherited through third-party SDKs, shared libraries, and open-source middleware that teams never provisioned and never fully tracked. Built from a real security review of a production mobile app, this talk shows how a legacy authentication endpoint quietly bypassed every modern control around it. Through a live demonstration using only open-source tooling, we show how forgotten APIs can become full paths to compromise and why cloud-native visibility models fail by design.

Speakers:Emma Yuan Fang,Krity

SpeakerBio:  Emma Yuan Fang

Emma is a seasoned Security Architect specialising in cloud security and AppSec. As Regional Practice Lead at EPAM, she leads a team of security practitioners across the UK&I, Switzerland, and Germany. Her focus has recently expanded into the intersection of LLMs, MCP, and security, exploring how agentic AI systems reshape the threat landscape. Beyond her day job, Emma is an award-winning conference speaker, a dedicated mentor, and Vice President of WiCyS UK&I, where she champions diversity in the cyber workforce.

SpeakerBio:  Krity

Krity is a dedicated cybersecurity professional with a strong foundation in application security, data analysis, and machine learning. As an Application Security Engineer at ServiceNow, she leverages her diverse experience and research background to enhance security practices. Beyond her technical role, Krity serves as the Community & Development Lead at Breaking Barriers Women in Cybersecurity (BBWIC), a nonprofit dedicated to empowering women in the field. Her work reflects a deep commitment to both advancing cybersecurity and fostering inclusive community growth, making her a passionate advocate for innovation, collaboration, and leadership in the industry.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 13:50-14:30 PDT


Title: How to destroy a country
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:50 - 14:30 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

Some people just want to see the whole world burn. And some cyberwarfare units just want your systems to go pufff.

Wipers are the cyber version of napalm, taking destruction from the kinetic to the cyberspace, and have been the most utilized weapons by cyberwars in the last decade. These wipers are design to destroy everything that they can get their hands on to: files, disks, backups, you name it. And they are purposefully designed this way by a dedicated group with their destabilizing a whole country in times of war.

In this talk we are going to go through the history of wipers, since our discovery of Flame in 2012 to our latest research on a destructive wiper we named Lotus Wiper. We are going to go through the technical details as well as providing a panoramic view to the impact that these types of cyberweapons have on countries, companies and people around the globe.

Speakers:Lisandro Ubiedo,Leandro Cuozzo

SpeakerBio:  Lisandro Ubiedo, Senior Security Researcher at Kaspersky GReAT LATAM

Lisandro is currently a security researcher, part of the GReAT team at Kaspesky. Previously, he was part of the security research team at GoSecure and collaborator at Stratosphere Labs based on Czech Republic. He’s focused on analyzing and tracking threat actors in Latin America, creating profiles and reporting on their doings.

SpeakerBio:  Leandro Cuozzo, Cybersecurity investigator at Kaspersky

Investigador de Seguridad en el equipo GReAT de Kaspersky. Cuento con más de 12 años de experiencia en ciberseguridad. Ex mantenedor principal de la suite Impacket.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Saturday - 11:00-11:59 PDT


Title: How to get RCE on a car
Tags: Hackers.town | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  Ac0rn
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 10:30-10:45 PDT


Title: How to piss off your Nix friends
Tags: Nix Vegas Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 10:45 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Nix is surging in popularity, and with it the community has taken the stance that Nix should be for everyone & their grandparents. I'm here to fight against that idea and share why I think it dilutes the power of Nix itself. By catering to the masses and targeting multiple platforms (MacOS), we weaken the potential of the idea and implementation. When we stop building for the lowest common denominator, we get to push the absolute limits. I will spend this time trying to convince you why Nix should drop support for platforms such as MacOS, diverge even more radically from traditional Linux distros and take on more grand technical solutions to problems at large.

SpeakerBio:  Farid Zakaria

I'm a software engineer, father and wishful amateur surfer. If you've come seeking my political views, you've found the wrong. You can find my writings on Nix, build systems and software engineering in general at https://fzakaria.com


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: HSPACE: AI Battlegrounds
Tags: HSPACE: AI Battlegrounds | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds) - Map

Description:

"Your prompt becomes a character, a machine, or an attack—and every word can change what happens next.

HSPACE: AI Battlegrounds is a collection of three hands-on games that turn natural-language and visual prompts into playable systems:

Wizard of Prompts — Write a short prompt to generate a pixel-art hero with unique stats and skills, then guide that hero through a five-boss, card-based battle campaign. Experiment with wording, build a stronger character, and see how the game's AI responds to prompt-injection attempts.

Prompt Prix — Describe your ideal race car and watch the AI convert your prompt into a validated vehicle build. Race across changing track conditions, study the result, and tune your prompt to improve the car's speed, grip, stability, and final ranking.

Vision Breaker — Face a vision-language-model security guard that decides who may enter. Use signs, screens, clothing, props, and visual prompt-injection techniques to influence its observations, bypass its checks, and progress through three escalating stages—from changing a decision to hijacking a command.

No joystick, coding experience, or prior security knowledge is required. Come experiment, iterate, and discover how small changes in language and visual context can reshape an AI agent's behavior.

Participant Prerequisites

Anyone who has used AI at least once is welcome. A camera-enabled smartphone or laptop with a modern web browser is recommended for Vision Breaker; camera permission is required for live play. Game stations and physical props are provided at the booth.

Participants can also play on their own smartphones or personal laptops. The competitive portion of AI Battlegrounds will be conducted online."


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 09:00-18:59 PDT


Title: Human Registration Open
Tags: Misc
When: Saturday, Aug 8, 09:00 - 18:59 PDT
Where: LVCC West Hall

Description:

Our human registration process this year will be very similar to previous years. Please be patient. All of the times listed here are approximate.

Basics

Who needs a badge?

A badge is required for each human age 8 and older.

Human?

You are a human if you do not know otherwise. People that are not humans include goons, official speaker, village/community/contest/creator staff, press, black badge holders, or similar. If you are not a human, you need to register separately. If you don't know how, see an NFO goon (NFO Node, formerly known as an infobooth, is where you can get help). The remainder of this message applies only to humans.

Lines? Linecon?

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

Ways to buy a badge

Online Purchase

You will be emailed a QR code to the email address provided when you bought your badge. Please guard that QR code as though it is cash -- it can only be redeemed once, and anyone can redeem it if they have it (including a photo of it). Badges are picked-up on-site -- they will not be mailed or shipped.

We can scan the QR code either from your phone's display or from a printed copy. You must have the QR code with you in order to obtain your badge. As you approach the front of the line, if you are going to show your QR code on an electronic device, please ensure that your display is set to maximum brightness.

If you pre-registered, but ultimately are unable to attend DEF CON and want to cancel your purchase, the only way to get a refund is from the original online source. We are unable to provide any refunds on-site at DEF CON. There is a fee to have your badge canceled: $34 before July 18, and $84 on and after July 18.

Online purchases are provided a receipt via email when the purchase is made.

Online purchase -- often referred to as pre-registration -- does not allow you to skip any line/queue to pick up your badge. Once you arrive on-site, you will need to join the existing line for human registration. There may or may not be a dedicated line for pre-registration badge pickup, depending on when you arrive, how long the line is, available staff, etc.

Cash Purchase

Badges will be available for purchase on-site at DEF CON. All badge sales are cash only. No checks, money orders, credit cards, etc., will be accepted. In order to keep the registration line moving as quickly as possible, please have exact change ready as you near the front of the line.

There are no refunds given for cash sales. If you have any doubt about your desire to buy a badge, please refrain from doing so.

We are unable to provide printed receipts at the time of the sale. A generic receipt for the cash sale of a badge will be made available on media.defcon.org after the conference. You are welcome to print your own copy of the receipt on plain paper.

Via BlackHat

If you've purchased a DEF CON badge as part of your Black Hat registration, you're in luck - you will be able to pick up your DEF CON badge at Black Hat on Thursday. Please bring your Black Hat badge and watch for emails from Black Hat about where exactly the badge pickup will be.

Please note that DEF CON is not able to access or verify Black Hat registration or attendee info. DEF CON's preregistration list is not the same as Black Hat's. For help, ask at Black Hat registration or the concierge area.

Misc

Want to buy multiple badges? No problem! We're happy to sell you however many badges you want to pay for.

If you lose your badge, there is unfortunately no way for us to replace it. You'll have to buy a replacement at full price. Please don't lose your badge. :(

If you are being accompanied by a full-time caretaker (such as someone who will push your wheelchair, and will accompany you at all times), please ask to speak to a Registration Goon. Your caretaker will receive a paper badge that will permit them to accompany you everywhere you go.

Still need help?

If you have questions about anything regarding human registration that are not addressed here, please ask to speak to a Registration Goon.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 10:00-12:30 PDT


Title: Hunting the Contagious Trader Delivery Network
Tags: Recon Village | Creator Workshop
When: Saturday, Aug 8, 10:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

North Korean threat actors are running one of the largest software supply chain campaigns ever observed in the npm ecosystem, and the infrastructure hiding it in plain sight is discoverable through open-source reconnaissance alone.

This workshop walks participants through how we mapped a live DPRK delivery network targeting cryptocurrency developers, starting from a single malicious npm package and expanding outward to uncover 50+ malicious packages, 100+ GitHub repositories, 30+ throwaway npm personas, 20+ rotating C2 domains, and a social media promotion layer spanning X and Reddit.

The investigation surfaces three malware families: PromptMink, ClipViper, and OtterCookie, which operate through what initially appeared to be separate campaigns but share overlapping infrastructure, actors, and delivery techniques.

The workshop focuses on the recon methodology behind the mapping through six hands-on modules:

Participants work directly with actionable IoCs (packages, C2 domains, SSH keys, YARA rules, detection queries) and leave with a breakdown of how current Contagious Interview and Contagious Trader toolsets are converging into a unified threat.

Attendees will leave with a repeatable framework for mapping supply chain malware delivery networks using open-source data: package registries, Git metadata, DNS records, social media artifacts, and cross-referencing with community threat feeds.

Speakers:Alessandra Rizzo,Ariel Ropek

SpeakerBio:  Alessandra Rizzo
No BIO available
SpeakerBio:  Ariel Ropek
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 16:30-17:25 PDT


Title: I'm Not Special, and You Can Too! A journey into RF Antenna Design for Dummies.
Tags: Radio Frequency Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 17:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Take a walk with Hamspiced from Midwest Gadgets as he explains, with an appropriate amount of sarcasm and emotional damage, how to make an LC tank circuit from scratch.

This talk will cover the basic theory behind inductance, capacitance, resonance, and why math has a terrible habit of being correct even when your prototype is not. From there, we will move into design, simulation, PCB layout, testing, tuning, and the deeply humbling process of discovering that “close enough” is absolutely not close enough at 13.56 MHz.

Using open-source tools and real-world examples from Midwest Gadgets hardware, this talk follows the full maker journey: theory, design, prototyping, failure, more failure, brief hope, additional failure, and eventually something that works well enough to accidentally become a product.

Attendees do not need to be RF engineers, electrical engineers, or people who enjoy reading datasheets for fun. This talk is meant for makers, hackers, badge builders, hardware weirdos, and anyone who has ever stared at a PCB and thought, “This should work,” immediately before it did not.

By the end, you will understand the basic concepts behind LC tank circuits, how to approach designing one, what tools can help, what mistakes to expect, and why failure is less of a roadblock and more of a mandatory subscription service. Most importantly, you will see how open-source tools, persistence, and a questionable amount of stubbornness can turn a pile of bad revisions into working hardware."

SpeakerBio:  Hamspiced, Owner, Midwest Gadgets

Hamspiced (Nick Gambino) is a maker, technologist, and founder of Midwest Gadgets LLC, where he designs hardware tools for hackers, makers, and security researchers. His work focuses on RF exploration, NFC systems, embedded development, wardriving, and open-source hardware.

With a background in event and exposition technology leadership, Hamspiced combines hands-on engineering with practical product design and community-focused education. His work is driven by curiosity, accessibility, and the belief that understanding technology gives people greater agency.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:00-10:59 PDT


Title: Identity Crisis: Novel Vulnerabilities leading to Kerberos Downgrade, DoS, and Full Domain Takeover
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Active Directory remains a major component of modern enterprise networks, and its security is paramount. Active Directory attack campaigns often aim to achieve Domain Admin privileges, which allow complete control over the domain. But what if we could simply confuse domain controllers, causing them to identify us as someone else? In this talk, we’ll dive into Kerberos and Active Directory and show how curiosity and creative thinking led to the discovery of two new identity confusion vulnerabilities. The first vulnerability, KerberLoss (CVE-2026-25177), bypasses a forest-wide security mechanism to perform a Denial of Service, or even force authentication to downgrade from Kerberos to NTLM. We later discovered ResetNightmare (CVE-2026-27912): a logical flaw in a Kerberos mechanism, allowing low-privileged users to compromise any account in the domain, including domain admins, leading to full domain takeover. The vulnerability is surprisingly easy to exploit and has a single, common prerequisite, making it highly dangerous for unpatched environments. We’ll explain the vulnerabilities, show them in action, and share practical detection opportunities and mitigation strategies to reduce exposure. In addition, we’ll be releasing a tool that automatically runs the entire attack flow for simple experimentation and testing.

SpeakerBio:  Shai Laron, Semperis

Shai Laron is a Security Researcher with 6 years of experience, focusing on Active Directory, Windows, and Identity Security, working at Semperis' Research team. He has a strong passion for researching Kerberos and has discovered multiple vulnerabilities related to it.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 14:00-14:10 PDT


Title: Illumicon Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 14:00 - 14:10 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Illumicon but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Illumicon and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 21:00-00:59 PDT


Title: Illuminati Party
Tags: Party
When: Saturday, Aug 8, 21:00 - 00:59 PDT
Where: LVCCW Level 3 W327 (Misc Meeting Room) - Map

Description:

It's time to get under the hood and rewrite the rules of engagement. If we want a future where explorers aren't outlaws, we have to start by taking over the room—so join us for the Illuminati Party, where our crew gathers to set the parameters for the night. Come share your passion, plot the future, and help us amplify the community.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 16:15-16:45 PDT


Title: Imposter Syndrome Is Distracting You From the Work That Matters
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 16:15 - 16:45 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Cybersecurity has an imposter syndrome problem, and it isn’t just personal — it’s structural. The field is so wide that no single human can cover it, which means even five-year practitioners feel behind. New entrants interpret that feeling as evidence they don’t belong, and the field loses exactly the people it needs most: the pattern-recognizers, the communicators, the artists, the networkers, the non-stereotypical thinkers. This 30-minute talk reframes imposter syndrome as a misread of a real signal. It makes the case that cybersecurity is the defining fight of this era — and argues that now, when AI is shifting the terrain and some people are throwing in the towel thinking they’re already behind, is exactly when we need warriors who understand that every generation has faced unfamiliar ground. We shouldn’t deny ourselves a tradition of fighting simply because the landscape has changed. The next generation of warriors won’t look like the picture in your head — and they need to be you. The talk moves through three acts. First, it names the lie of “being behind” — the field is too big for any one human, and feeling inadequate is evidence you’re perceiving its size correctly, not a verdict on you. Second, it makes the stakes concrete: hospitals diverting ambulances during ransomware events, ICAC task forces doing digital forensics on devices seized from predators, dissidents whose phones are compromised by state actors. The technical failure and the human failure are the same event seen from opposite ends of the same wire. Third, it widens the door: DFIR, GRC, threat intelligence, security awareness, policy, AppSec partnership — the field has roles for thinkers who don’t fit the hoodie-in-a-basement stereotype, and it needs them urgently. If you’re sitting in N00b Village wondering whether you belong here, this talk is for you. The voice telling you everyone else belongs more is wrong about you, and it’s wrong about the field. Stay.

SpeakerBio:  Samantha Schwartz
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 16:00-16:30 PDT


Title: Improving Security Vulnerability Descriptions using LLMs
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:30 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

CVE records are a foundation of modern vulnerability management, but many entries still contain incomplete, vague, or low-context descriptions. This limits their usefulness for security teams, researchers, and automated tools that rely on CVE text to understand and communicate risk. This talk presents research on using large language models to enrich CVE descriptions with additional vulnerability context. By combining information from CWE, CVSS, and proof-of-concept code, the approach generates clearer and more informative vulnerability descriptions. The enriched descriptions are then evaluated through MITRE ATT&CK technique classification to measure whether they improve downstream security analysis. Results show that structured prompting can make vulnerability descriptions more interpretable and improve classification performance, achieving up to a 12.7% F1 score increase over original CVE text. This work highlights how LLMs can support vulnerability analysis, strengthen security communication, and help transform incomplete vulnerability records into more actionable cyber threat intelligence.

SpeakerBio:  Kenechukwu Nwodo, Ph.D. Student, Virginia Tech / Co-founder, WayWave Inc.

Kenechukwu Nwodo is a Ph.D. student in the Bradley Department of Electrical and Computer Engineering at Virginia Tech, where their research interests include software and mobile security. Originally from Lagos, Nigeria, Kene is also the co-founder of WayWave Inc., where they lead the development of advanced localization solutions.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 10:15-11:15 PDT


Title: In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike
Tags: Intermediate | AppSec Village | Creator Event/Activity
When: Saturday, Aug 8, 10:15 - 11:15 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

We keep saying “never trust user input.” Yet our frameworks still do not differentiate between trusted data and attacker-controlled data.

OWASP Untrust is an OWASP umbrella project built around a simple invariant: all data is implicitly untrusted and may cross security boundaries only through deliberate, verifiable trust transitions.

Through projects like VV (Validated Values) and BoxedPath, implemented across Python, Java, C#, C++, and Node.js, Untrust makes unsafe states structurally difficult to represent.

Instead of detecting vulnerabilities after they are written, Untrust enforces trust boundaries by construction for humans and AI alike.

SpeakerBio:  Yariv Tal

Yariv Tal is a senior developer, security researcher, and cofounder of Secure From Scratch, a venture dedicated to teaching developers secure coding from the very first line of code.

A summa cum laude graduate of the Technion, Yariv brings four decades of programming experience and years of university lecturing and bootcamp mentoring to the field of application security.

He lectures on secure coding in academia and the private sector, leads the OWASP-untrust project, and researches the intersection of AI and application security, with a focus on secure code generation, LLM evaluation, and secure-by-construction development.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Saturday - 17:00-17:59 PDT


Title: Incident Response in 2026
Tags: Blue Team Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

Join us at the Blue Team Village for an interactive session on the shifting dynamics of Incident Response. As modern threat vectors evolve, security teams must actively adapt their core competencies and refine their playbooks. Our panel of practitioners will dive into practical strategies for navigating high-pressure environments-balancing technical depth with stakeholder management, and building resilience against burnout. We will discuss critical operational mistakes, the role of automation, and how to foster a collaborative IR community. Whether you are a seasoned responder or just starting your journey, gain actionable insights on advancing your IR career while maintaining your sanity.

Speakers:Chriss Hansen,K Singh,Levone Campbell,Sarthak Taneja

SpeakerBio:  Chriss Hansen

Chriss Hansen is a seasoned Cyber Field Engineer at Pentera, with a background as a Digital Forensic Engineer and extensive experience in DFIR roles for various companies. He serves as an Incident Response Lead for the Wisconsin Cyber Response Team, leveraging his expertise to combat cyber threats. Prior to his cybersecurity career, he worked as a mattress salesman at Mattress Firm. Outside of work, he enjoys water polo, running, riding motorcycles, and playing the drums, showcasing his diverse interests beyond the tech world. He is also on the board for DC608: a non-profit educational group in Madison Wisconsin based on training and educating future cyber security experts.

SpeakerBio:  K Singh

"K" Singh is a Senior Incident Response Consultant at Mandiant, where he helps Fortune 500 companies, leading enterprises, and a wide range of organizations navigate high-stakes cybersecurity incidents. With experience spanning large-scale incident response, tabletop exercises, strategic security planning, and hands-on “dead disk” forensics, K has seen just about everything under the sun—and then some.

Before joining Mandiant, K served as a Senior Incident Response Consultant at CrowdStrike and as an Incident Response Consultant and Forensic Lab Manager with the Global Incident Response Practice at Cylance.

When he’s not untangling cyber crises, K is usually elbows-deep in a car project—grumbling about questionable engineering decisions and breaking things that, by all logic, should never break.

SpeakerBio:  Levone Campbell, Chief Information Security Officer

Levone Campbell, MBA, MPS, CISSP

With more than two decades of experience in cybersecurity operations, Levone Campbell serves as a Cybersecurity Lead and Incident Coordinator, helping safeguard his organization’s digital environment through strategic defense and incident response.

A seasoned information technology professional, Levone has developed deep expertise in cyber threat intelligence and cybercrime analysis, consistently anticipating and responding to emerging threats in an increasingly complex digital landscape. He has also expanded his focus to include the growing intersection of artificial intelligence and cybersecurity, with particular attention to the evolving challenges of AI-driven threats and defensive capabilities.

Levone’s academic background includes dual bachelor’s degrees in Management and Marketing from North Carolina A&T State University, a Master of Business Administration from Walden University, and a Master of Professional Studies in Technology Management with a concentration in Cybersecurity from Georgetown University.

His commitment to professional excellence is further demonstrated by his industry-recognized certifications, including the CISSP, which underscore his standing as a well-rounded cybersecurity leader.

Based in Houston, Texas, Levone values the balance between a demanding career and a strong family life. Married for 20 years and a proud father of two, he brings discipline, perspective, and purpose to his work in protecting critical digital assets and advancing cyber resilience.

SpeakerBio:  Sarthak Taneja

Started from Offensive Security and ended up in Defense. Wearing Purple hat most of the days.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 15:45-16:45 PDT


Title: Industry Challenges & SOC Reality
Tags: Telecom Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:45 - 16:45 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. Telecom SOC challenges and operational realities
  2. Evolving telecom threat landscape (2G–5G & cloud-native)
  3. Telecom-specific attack surfaces and protocol risks
  4. Limitations of traditional SOCs in telecom environments
  5. Detection challenges across SS7, Diameter, GTP, SIP, and 5G
  6. Real-world telecom attacks and fraud scenarios
  7. Threat hunting and protocol-aware monitoring
  8. AI-driven detection, automation, and response
  9. Building a modern Telecom SOC
  10. Future security challenges in 5G and beyond
SpeakerBio:  Vinod Shrimali
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Saturday - 08:30-17:30 PDT


Title: Influence Operations: Tactics, Defense, and Exploitation
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Saturday, Aug 8, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W223 (Training) - Map

Description:
Speakers:Greg Conti,Tom Cross

SpeakerBio:  Greg Conti
No BIO available
SpeakerBio:  Tom Cross
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 10:00-10:59 PDT


Title: Inside the Red Team Cabal: A Decade of Lessons from Enterprise Red Teams
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

The Red Team Cabal is an invite-only community of enterprise red team practitioners dedicated to advancing the craft through trusted collaboration, candid discussion, and the sharing of real-world experiences. While organizations, industries, and technologies may differ, red teams consistently encounter many of the same challenges. The Cabal provides a unique forum where practitioners can learn from one another, exchange lessons learned, and collectively mature the practice of adversary emulation.

This panel brings together Red Team Cabal members from diverse internal red teams spanning multiple industries and organizational environments. Collectively, they represent decades of experience building, operating, and evolving enterprise red team programs. Their perspectives offer a rare opportunity to hear how red teaming has changed over the last ten years, what foundational principles have remained constant, and how organizations at different stages of maturity continue to solve remarkably similar problems.

Panelists will discuss the origins and purpose of the Red Team Cabal, the unique role of internal red teams compared to external consulting engagements, and how internal teams create lasting value through adversary emulation, improving detections, identifying and reducing risk, validating security investments, and driving defensive maturity. The discussion will also cover common challenges faced by enterprise red teams, lessons learned from years of collaboration across the community, and practical guidance for building a successful career in red teaming—from breaking into the field to long-term growth and leadership.

Panelists * Jason Strange * Nat Hirsch * David Martinjak * Niru Ragupathy * Wesley Thurner

Speakers:Jason Strange,Wes Thurner

SpeakerBio:  Jason Strange

Jason is a former fortune 100 red teamer turned startup security leader. While at work, he's passionate about all things security, software, user/developer experience, and infrastructure. While he's not at work, he's passionate about getting back to work. He also enjoys developing software, blogging, self-hosting, and writing rap songs about his interests and hobbies.

SpeakerBio:  Wes Thurner

As a Principal Security Engineer on Intuit's Red Team, Wesley Thurner specializes in offensive security, protecting the global technology platform and its customers from advanced cyber threats. His expertise is built on a distinguished career as an Exploitation Operator within the U.S. Department of Defense's most elite computer network exploitation (CNE) unit. During his service, he led and developed specialized teams for the U.S. Air Force's premier cyberattack squadron and at U.S. Cyber Command (USCYBERCOM).

A recognized thought leader, Wesley co-authored 'Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in an AI-driven World'. He is also deeply involved in the community as a Co-Organizer for the Red Team Village, where he helps bridge the gap between penetration testing and real-world offensive operations.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 16:00-16:59 PDT


Title: Install Me Maybe: Turning Claimable VS Code Extension IDs into Supply-Chain Attacks
Tags: DEF CON Official Talk | Exploit 🪲
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Developer tools trust extension identifiers way more than they should.

A VS Code extension ID like publisher.extension shows up everywhere a dev environment gets set up, and people treat it as the same trusted thing no matter where it's resolved, but it isn't. Extension identity is marketplace-specific. An extension can be trusted and popular in one marketplace while the matching namespace sits unclaimed in another that the main forks actually pull from. Claim that namespace, publish under the same identifier, and a name people already trust now runs your code. It's dependency confusion, but for editor extensions. I've been calling it Extension Confusion.

I'll show where the trust boundary breaks, the IDE quirks that carry these identifiers across the gap, and what happened when I published proof-of-concept extensions to measure it for real.

The scale got out of hand fast: 1M+ callbacks, hundreds of organizations, $200k+ in bounties, all in under 3 months. Code running on laptops, managed corporate machines, remote dev setups, WSL, and containers, across SaaS, fintech, Fortune 500s, healthcare, government, and universities.

A trusted name, a missing namespace, and the marketplace gap no one was watching.

Editor extensions are supply chain. Treat them that way.

My talk from last year around malicious extensions can be a good intro:

SpeakerBio:  Raphael "rcss" Silva

Raphael Silva is a security researcher at Aikido Security, focused on web security, software supply-chain security, and vulnerability research. He has spoken at DEF CON, RootedCON, OWASP Global AppSec, Black Alps and OWASP local chapters, and has also run hands-on activities at DEF CON. His work centers on finding weird trust assumptions in real systems, turning them into clear attack models, and responsibly disclosing the results to vendors and open-source projects.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 14:00-14:45 PDT


Title: Intercept.js: Runtime-Aware Detection for JavaScript Environments
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | DEF CON Demo Labs
When: Saturday, Aug 8, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

Modern attacks increasingly execute inside JavaScript runtimes (browsers, email clients, and embedded app environments) where traditional file-scanning and OS-level controls lack visibility into application-layer behavior. In these contexts, payloads often exist only as in-memory buffers, fetch responses, or dynamically constructed objects. Detection therefore depends not just on inspecting bytes, but on understanding their origin, transformation, and use at runtime.

We present Intercept.js, an open-source detection engine that runs natively within JavaScript environments, combining byte-level inspection with execution context in real time. Built for YARA compatibility, it extends rule evaluation beyond static artifacts by incorporating signals such as origin provenance, user gesture state, MIME inconsistencies, and object construction paths.

This unified model enables detection of threats as they are assembled and executed — including identifying executable buffers built in memory, anomalous data flows, or content whose structure diverges from its declared type.

As a concrete demonstration, we show how HTML smuggling attacks can be intercepted at the moment of payload construction, preventing delivery before artifacts ever reach disk and exposing a class of threats that evade both network and endpoint controls.

SpeakerBio:  Rishi Kant

A builder at heart, Rishi has spent his career turning deep technical ideas into real-world impact. He holds a PhD in Electrical Engineering from Stanford, and earned his B.S. in EECS from UC Berkeley. After 4.5 years of advising global high-tech firms at McKinsey & Company, he followed his passion for building and moved into product management. Rishi led product teams at several cybersecurity companies—including Tanium, Authentic8, and Uptycs. Now, as founder of Sekant Security, he’s embedding runtime intelligence directly into web browsers to protect users from phishing, ClickFix, unsafe downloads, shadow AI and other emerging online threats.


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Saturday - 10:15-10:45 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Saturday, Aug 8, 10:15 - 10:45 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Saturday - 15:00-15:30 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Saturday, Aug 8, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Saturday - 10:00-10:30 PDT


Title: Intro to Scratch
Tags: DCNextGen | Creator Event/Activity | Youth
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Are you interested in learning to code but don’t know where to begin? This class introduces Scratch, a free visual programming language developed by MIT, and is intended for youth ages 8-16. Use real coding concepts and blocks to develop interactive stories, games, and animations. Come learn how to begin coding in a fun and engaging way and join in with millions of your new global peers. You will need a laptop with Chrome or Edge.

SpeakerBio:  N3rd H3Rder
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Saturday - 11:30-11:50 PDT


Title: Introduction to Vulnerable ATM Badge
Tags: Payment Village | Creator Workshop
When: Saturday, Aug 8, 11:30 - 11:50 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

The Payment Village set out to design a badge that represents a purposefully vulnerable ATM for educational use. Providing conference attendees with access to a real ATM is impractical due to its size, weight, and limited accessibility. Instead, the badge offers a portable ATM-inspired platform, available to all, that simulates real-world attack surfaces through interactive challenges. We have five prototypes available to try!

To extend its value beyond DEF CON, the badge will be supported by an online platform featuring learning resources, firmware updates, and community support via a website and Discord. We also have a life-size version of the badge as a fully interactive ATM demonstration for attendees to interact with in the village

SpeakerBio:  Vincent Sloan, Software Engineer, GoFundMe

20+ years of experience in payments, spanning e-commerce and crowdfunding; currently leads payments engineering at GoFundMe.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 10:00-10:59 PDT


Title: Journey to Create an All-state Cybersecurity Plan for Oklahoma
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

This talk will go over the challenges and successes that the State of Oklahoma had in creating an all-of-state cybersecurity plan. It will also offer insights into how we leveraged the State Local Cybersecurity Grants to help shore up defenses in state and local agencies. Finally, I will share personal insights as a grant recipient and what it looks like from the end-user perspective.

SpeakerBio:  Craig "jafo" Buchanan, City of Stillwater Oklahoma

Craig Buchanan has worked in government at the city, state, and federal levels. In addition, he worked for over a decade at computer multimedia innovator Creative Labs Inc. He currently works for the city of Stillwater Oklahoma as the security administrator, where his duties include installing and maintaining the city's ever-growing fleet of security cameras, servers, and monitoring devices as well as serving as a professor at Northern Oklahoma College. In his spare time, he volunteers for the American Red Cross doing fraud reviews and serves on the state of Oklahoma’s State Local Cybersecurity Grant committee.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: Just Hacking Training
Tags: IoT Village | Creator Workshop
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

2 Mini-Workshops, Only 15 Minutes Each: QEMU: Emulate Your 'Things' – Hack a Drug Lord’s Smart Toilet; Encryption! What Encryption? – Decrypt TLS Traffic with mitmproxy. No Schedule.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 22:00-00:59 PDT


Title: Kayos Klub
Tags: Party
When: Saturday, Aug 8, 22:00 - 00:59 PDT
Where: LVCCW Level 1 North Lobby - Map

Description:

The Kayos Klub will be a night of music and magic for all ages. To celebrate the life of a lost loved one, we are going all out on a party that will make even the most socially awkward computer nerd want to dance <3.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 14:00-14:30 PDT


Title: Keep the Model on Course: Agentic LLM Workflows for Reversing
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Malware analysts are wiring LLMs into their reversing workflows today. The MCP integrations for IDA Pro, Ghidra, radare2, and Binary Ninja are public, and analysts use them to rename functions, triage samples, and hunt vulnerabilities. Adoption has outpaced any measured account of where these tools hold up and where they mislead, and running an agent against one sample can burn an enormous number of tokens on work the model repeats for every binary.

We built an agentic malware analysis framework on ADK (Agent Development Kit) that connects LLMs to disassemblers through MCP, wrapped in per-language skills for C/C++, C#, Go, Android, etc. The ADK agent loop drives the analysis: pulling functions, following xrefs, reading decompiled output, making notes, and issuing disassembler commands on its own. Each skill supplies the runtime context once, so the model spends its budget on the sample. Everything runs in Docker containers for isolation and reproducibility.

We tested it across multiple models on real samples and scored every result against ground truth. Triage and function renaming on stripped binaries work well when the agent is steered. Crypto identification and CVE matching fail in ways that read as authoritative. The analyst is the captain, the model the crew. We ship the containers, skills, and prompt templates so attendees can reproduce similar workflows efortlessly.

Speakers:Asher Davila,Lenin Alevski

SpeakerBio:  Asher Davila, Vulnerability Researcher at Palo Alto Networks

Passionate about binary analysis, binary exploitation, reverse engineering, hardware hacking, retro computing, and music.

SpeakerBio:  Lenin Alevski, Security Engineer at Google

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Saturday - 16:00-16:45 PDT


Title: Keeping the Angry Pixies Happy: the Care and Feeding of your Batteries
Tags: Ham Radio Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

The talk will cover various battery types. For each type, we will cover such items as why you might want to use it, what the cost is, and most importantly, how do you charge/discharge it safely?

While most of the batteries will be of the chemical variety, some mention will be made of mechanical batteries.

Lead acid, nickel metal, lipo, lithium iron, silicon carbon? With all the different battery types out there now, how can you be sure you're keeping it functioning at its best, and not creating a ticking time bomb?

This talk will cover the plethora of energy sources for off-grid radio operations and give tips for what works best and how to get the most out of it.

SpeakerBio:  hamster

Passionate about electronics and energy storage


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 16:40-17:20 PDT


Title: Key Rotation Won't Save You: Hunting Workload Identity Backdoors in AWS and GCP
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:40 - 17:20 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Cloud incident response runbooks end with "rotate all keys and credentials." AWS IAM Roles Anywhere and GCP Workload Identity Federation were designed to remove keys from the trust chain, and that design is what lets an attacker survive standard containment.

This talk shows how an attacker registers their own certificate authority as an AWS Roles Anywhere trust anchor, or modifies a GCP Workload Identity Federation provider to trust an attacker-controlled identity, and mints fresh credentials indefinitely. Defender content has not caught up to the attack research: Roles Anywhere trust anchor and session events land in CloudTrail by default, but no published hunting query traces the CreateSession back to the issuing certificate authority via the hex serial recorded in roleSessionName. GCP pool and provider creation lands in Admin Activity logs for free, but the federated token exchange only lands in Data Access logs when explicitly enabled and paid for.

The session closes with the cross-cloud fingerprint: when the same attacker-controlled OIDC provider is registered in both clouds (as an AWS OIDC identity provider and as a GCP Workload Identity Federation pool provider), the same OIDC sub claim surfaces in both audit trails. Extracting and joining on it ties one attacker to two cloud incidents.

Attendees will gain the WIF Hunting Pack: a working playbook for keyless persistence in AWS and GCP, two prevention policy templates that block the attack at organization scope, and a cross-cloud correlation pattern for OIDC-based incident response. Live demo across speaker-controlled AWS and GCP environments. This talk is for blue teamers and platform security engineers who secure infrastructure across AWS and GCP.

SpeakerBio:  Jie Wu

Jie is a Senior Security Engineer at Shopify based in New York City, working on cloud security, Kubernetes, and detection engineering to secure cloud infrastructure. She has spoken at KubeCon EU, fwd:cloudsec, and BSides (Chicago, Ottawa, Montréal), covering topics from Kubernetes security at scale to non-human identity accountability in the cloud. Before Shopify, she worked on cyber defense and vulnerability management at Bank of America.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 13:00-13:45 PDT


Title: Keychecker : SSH Key based attack tool for DVCS Systems
Tags: Intro/Beginner | DEF CON Demo Labs | Defense/Blue Team | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
When: Saturday, Aug 8, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

KeyChecker is a CLI tool to fingerprint SSH private keys and identify which Git hosting accounts they unlock. In incident response and red team work, finding a private key is common, but scoping impact is slow and manual. KeyChecker automates the two primitives defenders and attackers both use: safe SSH handshakes that can reveal the mapped username, and read only git ls-remote probes that confirm whether a key can access a target repo.

The tool performs local key intelligence first, supporting OpenSSH, PEM, and DER formats, detecting key type (ed25519, rsa, ecdsa, dsa), key size, passphrase protection, fingerprints (SHA256 and MD5), and useful metadata from key comments. It then validates the key across multiple providers including GitHub, GitLab, Bitbucket, Codeberg, Gitea, and Hugging Face, extracting usernames where possible, and optionally using a GitHub token for organization discovery.

KeyChecker also supports repository discovery with a wordlist and configurable concurrency, giving a clear blast radius report like “this key unlocks these private repositories.” It is designed for authorized assessments, runs locally, and avoids write operations.

SpeakerBio:  Anant Shrivastava

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 12:00-12:45 PDT


Title: Keychecker : SSH Key based attack tool for DVCS Systems
Tags: Intro/Beginner | DEF CON Demo Labs | Defense/Blue Team | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

KeyChecker is a CLI tool to fingerprint SSH private keys and identify which Git hosting accounts they unlock. In incident response and red team work, finding a private key is common, but scoping impact is slow and manual. KeyChecker automates the two primitives defenders and attackers both use: safe SSH handshakes that can reveal the mapped username, and read only git ls-remote probes that confirm whether a key can access a target repo.

The tool performs local key intelligence first, supporting OpenSSH, PEM, and DER formats, detecting key type (ed25519, rsa, ecdsa, dsa), key size, passphrase protection, fingerprints (SHA256 and MD5), and useful metadata from key comments. It then validates the key across multiple providers including GitHub, GitLab, Bitbucket, Codeberg, Gitea, and Hugging Face, extracting usernames where possible, and optionally using a GitHub token for organization discovery.

KeyChecker also supports repository discovery with a wordlist and configurable concurrency, giving a clear blast radius report like “this key unlocks these private repositories.” It is designed for authorized assessments, runs locally, and avoids write operations.

SpeakerBio:  Anant Shrivastava

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 12:00-12:45 PDT


Title: Keynote: Colorado's Creation of RLAs
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

As Colorado’s 38th Secretary of State, Mr. Williams oversaw the creation of the nation's first full forensic risk limiting audit (“RLA”) in 2017.

Colorado’s legislature ordered the use of RLA’s in 2009 -- long before widespread media coverage of fears about hacking election equipment and interference by foreigners or other bad actors. Three Secretaries of State later, Colorado implemented the nation’s first full RLA in 2017.

An RLA is a procedure that provides strong statistical evidence that the election outcome is right and has a high probability of correcting a wrong outcome. Risk-limiting audits require human beings to examine and verify more ballots in close races (exactly when you want to examine more ballots), and fewer ballots in races with wide margins.

Colorado’s process attracted attention nationwide. The Washington Post pronounced Colorado “the safest state to cast a vote.” Matt Masterson, then chairman of the U.S. Election Assistance Commission, attended the implementation and stated that "Colorado is a national leader in exploring innovative solutions for accessible, secure and auditable elections.”

Secretary Williams will discuss the benefits of RLAs, the processes used, and some of the hurdles Colorado overcame during its implementation.

SpeakerBio:  Wayne Williams

Wayne Williams served as Colorado's 38th Secretary of State from 2015 to 2019 and now serves as Colorado Springs Chief of Staff for Mayor Yemi Mobolade. Secretary Williams' 20 years of elected service includes four years as Clerk and Recorder for Colorado's most populous county. He continues to serve as a designated election official and on the Board of Advisors for Verified Voting.

As Secretary of State, Wayne Williams adopted rules requiring voter-verifiable paper ballots, created the nation's first full risk limiting audit, and defended Colorado voters against attempts by rogue electors to deprive them of their vote in the 2016 presidential election. Secretary Williams' actions were upheld by a unanimous U.S. Supreme Court.

His work in these positions earned regional and national recognition, including the National Association of Secretaries of State Medallion Award, the Colorado League of Women Voters' Leader of Democracy, Defender of Democracy, and the Truman Foundation's Stevens Award for attorneys in public service. He has been appointed to state boards by Colorado Governors from both political parties.

Secretary Williams received his B.A. in Political Science from BYU (1986), and his J.D. from the University of Virginia Law School (1989).


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 12:00-12:30 PDT


Title: Killing AI Slop: A Multi-Model Orchestration Framework That Only Reports Findings It Can Prove
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

AI-assisted bug hunting has a reliability problem. Modern models can generate convincing vulnerability reports, but many fail under validation. They reference non-existent endpoints, unreachable exploit paths, or attack chains that break when tested against the target. As a result, triage teams spend increasing time reviewing low-quality submissions, while researchers struggle to separate genuine vulnerabilities from model-generated noise. This talk presents a multi-agent bug hunting framework built around a simple principle: a finding is not considered valid until it has been reproduced against the target. The goal is to improve the quality and reliability of reported findings. The process begins with understanding the target. Before testing starts, the framework analyzes JavaScript, API specifications, documentation, authentication flows, endpoints, parameters, and technologies to build a structured model of the application. This enables agents to reason about the actual attack surface rather than relying on assumptions. An orchestrator coordinates specialized agents operating from a shared understanding of the target. Candidate findings are routed through a central coordination layer that manages context sharing and eliminates duplicate results. To improve decision-making and reduce hallucinations, the agents leverage a RAG engine backed by publicly disclosed vulnerability reports and security research. Every candidate finding passes through a verification stage that evaluates application-specific context, observed behavior, and supporting evidence. Findings that pass validation are further tested to determine their maximum practical impact before being reported, while non-actionable and expected behavior is discarded. The presentation covers the architecture, orchestration model, and verification workflow, providing practical guidance for building AI-assisted security tooling that prioritizes evidence over assumptions.

SpeakerBio:  Armaan Pathan

Armaan Pathan is a Senior Security Engineer at KATIM with more than 10 years of experience in offensive security, application security, and vulnerability research, helping organizations identify and remediate critical security risks.Throughout his career, he has discovered and responsibly disclosed vulnerabilities impacting major companies, including Google, Meta, and Apple, through bug bounty and coordinated vulnerability disclosure programs. His interests include web and API security, security engineering, and exploring how AI can be used to enhance offensive security and vulnerability research. Armaan actively contributes to the security community-publishing technical blogs, presenting at conferences, and raising awareness of emerging threats and practical defenses.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: Kryptsec Labs
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Kryptsec started as a Discord server for people who wanted to learn cybersecurity together and has grown into a company focused on making security training engaging rather than monotonous, including hands-on, AI-assisted CTF labs and OASIS, its open-source tool for benchmarking AI agent vulnerabilities. Stop by the Kryptsec Labs table during village hours to work through their hands-on challenges.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Saturday - 10:00-17:59 PDT


Title: KSCM Scambait Radio
Tags: Scambait Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 12:00-12:10 PDT


Title: Kubernetes CTF at DEF CON Contest Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 12:00 - 12:10 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Kubernetes CTF at DEF CON Contest but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Kubernetes CTF at DEF CON Contest and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Kubernetes CTF
Tags: Kubernetes CTF | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 212 (Kubernetes CTF) - Map

Description:

Want to learn more about Kubernetes hacking or compete against other people in a Capture the Flag contest? Sign up on-line and come see us in person/on Discord at the Kubernetes Capture the Flag (CTF) contest .

We have two events - you can play in both if you like.

From Friday to Sunday, we have a non-competitive Learning CTF, where you can go through last year's Kubernetes CTF scenario, referring to a cheat sheet whenever you want. This runs from Friday 12:00 to Sunday 12:00. We'll be in the contest area to support you during:

Friday: 12:00-17:00 Saturday: 10:00-17:00 Sunday: 10:00-12:00

On Saturday only, you can play in the competitive Kubernetes CTF challenge, where teams (of one or more) can build and test their skills. Each team is given access to a single Kubernetes cluster that contains a set of challenges. This runs from 10:30am to 5:30pm on Saturday.

Find out more and sign up at: https://containersecurityctf.com/


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Saturday - 12:00-12:30 PDT


Title: KYC and XMR… FOR HACKERS!
Tags: Hackers.town | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

An overview of handy usecases for specific crypto currencies for technologists.

SpeakerBio:  AltKey
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 13:00-13:45 PDT


Title: L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security
Tags: DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

Browser Extensions is one of the overlooked attack surface in the modern era. Most browser extension have permissions to allow direct access to cookies, browsing history, network requests and a poorly written extension can help attackers with stuff like silently steal credentials, log keystrokes, fingerprint users etc.

L.A.Y.E.R.S. (Logical Analyst for Your Extension Risk Surface) is a fully client-side chrome browser extension security engine that performs multi-layered security analysis on extensions. The tool performs analysis on various levels like JS analysis, permissions analysis, manifest analysis, secret scanning, URL extractions etc. simultaneously to uncover potential risks. The tool comes with its own scoring system guiding the team if the extension is safe to use or not.

L.A.Y.E.R.S. is designed for security researchers auditing in-house extensions, third-party extensions, red teams assessing browser attack surfaces, enterprises enforcing extension policies, and developers seeking to harden their own extensions before publication.

What sets L.A.Y.E.R.S. apart begins with its privacy-first architecture - the entire analysis runs in-browser via the File System API and JSZip, with very little setup required. On the detection side, it incorporates Shannon entropy analysis. To keep results actionable rat

Speakers:Abhinav Khanna,Krishna Chaganti

SpeakerBio:  Abhinav Khanna

Abhinav is an Information Security Professional with 7+ years of experience and currently works at S&P Global. His area of expertise include Web App Security, API Security, Mobile App Security, Secure Architecture. He has spoken at conferences like BlackHat USA, DefCon 33, BlackHat Europe, BlackHat Asia etc.

SpeakerBio:  Krishna Chaganti

Krishna Chaganti works as Associate Director Application Security at S&P Global, based in the USA, with over a decade of experience in Information Security. As a Certified Information Security Manager (CISM), he leads a team of more than 10 pentesters and specializes in Application Security along with Security Architecture.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 17:30-18:30 PDT


Title: latinas.exe has entered the chat (ESP - POR)
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 18:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 10:00-10:30 PDT


Title: Learning Deception by Doing: Attacking and Defending
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Cyber deception is one of the most powerful and least understood defensive disciplines — most practitioners have read about honeypots, but few have ever deployed a breadcrumb, watched an attacker chase a fake credential, or felt the confusion deception causes from the attacker's side.

This session shares the fundamentals of deception by doing and experiencing: what deceptive artifacts exist (honey-credentials, deceptive configs, honey-services, synthetic activity), where they belong in a real environment, what telemetry they generate, and how they change an adversary's behavior. Everything is practiced in an open-source, Docker-based playground that recreates a realistic multi-tier company — with an attacker toolkit on one side and a defender SIEM on the other — so attendees can safely play both roles.

The 25-minute format is a guided demo; the 50-minute format is a hands-on lab.

Speakers:Diego Staino,Fede Pacheco

SpeakerBio:  Diego Staino, R&D+i Manager

Cybersecurity professional with 15+ years of experience as Security and IT consultant. Certified Incident Handler (ECIH) with a degree in Information Security and Communications. Currently works as R&D+i Manager at BASE4 Security, where he leads the company's research and development initiatives.

SpeakerBio:  Fede Pacheco, Cybersecurity Services Director, BASE4 Security

Especialista en ciberseguridad con formación en ingeniería electrónica, y destacadas certificaciones profesionales en seguridad de la información. Cuenta con 20 años de experiencia docente, principalmente en la Universidad Tecnológica Nacional. Lleva publicados cuatro libros y diversos trabajos de investigación en temáticas de ciberseguridad y de educación, algunos de los cuales han sido presentados en congresos y conferencias globales. Además, se desempeñó en roles de liderazgo de alcance regional en distintas empresas multinacionales. Actualmente tiene a cargo el área de Cybersecurity Services de BASE4 Security.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 15:20-16:05 PDT


Title: Leigh Trinity OTW
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:20 - 16:05 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

Discussion on the current state of cellphone and network hacking.

SpeakerBio:  Leigh Gilbert, Malware village

Leigh Trinity is a Canadian exploit developer, red team hacker, and instructor known for her work in binary exploitation and reverse engineering. Now branching out into malware development.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 10:00-10:59 PDT


Title: Let's Play! OWASP Cornucopia for Mobile Application Security Threat Modeling
Tags: OWASP Foundation | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Think threat modeling can't be fun? Think again! Join us for an interactive OWASP Cornucopia for Mobile Application Security game session, with OWASP MAS/MASTG core team member, Sven Schleier, where you'll team up to uncover security risks, challenge assumptions, and sharpen your secure design skills through friendly competition. Whether you're a developer, security professional, or just curious about mobile application security, come play, collaborate, and experience one of the most engaging ways to learn threat modeling.

SpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

--

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 11:00-11:30 PDT


Title: Liberty and Justice for All
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

Just weeks after Arizona's 2026 Primary Election, this presentation will provide a candid look at what went right, what challenged election officials, and what we learned from operating one of the nation's most scrutinized election environments.

Election security is often discussed through the lens of cybersecurity, but the reality facing election officials today is far broader. Modern election security requires defending against physical threats to election workers, cyber threats targeting systems and infrastructure, reputational attacks that seek to undermine public confidence, logistical challenges that can disrupt operations, and an increasingly complex legal landscape. Success depends on addressing all of these simultaneously while still delivering a free, fair, secure, accurate, and transparent election.

Drawing on Arizona's experiences during the 2026 election cycle, this session will examine how election officials prepare for and respond to these challenges, the partnerships that make election security possible, and the difficult balance between transparency, security, and public trust.

The presentation will also explore emerging efforts to responsibly integrate artificial intelligence into election administration. Through work with Arizona State University's Mechanics of Democracy Laboratory, election officials are learning how AI can enhance productivity and improve public service while maintaining appropriate safeguards, accountability, and human oversight.

Most importantly, this session is not simply about what government is doing. It is about how the security, research, and civic communities can contribute. Whether you are a security researcher, election official, journalist, technologist, or concerned voter, you have a role in strengthening democratic resilience.

Attendees will leave with a clearer understanding of today's election threat landscape, practical ways to support election security efforts, and greater confidence in the professionals working every day to defend the democratic process.

SpeakerBio:  Michael Moore

Michael Moore is the CISO at Arizona Secretary of State's Office. He leads efforts to strengthen election security through coordinated partnerships across federal, state, and local governments, alongside trusted private-sector partners. His work is grounded in protecting democratic processes and maintaining public confidence in elections. He focuses on the most pressing risks to election integrity: mis-, dis-, and malinformation (MDM), and the insider threats that can emerge from an increasingly polarized and misinformed environment. His approach centers on countering false narratives with verifiable truth while advancing a defense-in-depth strategy. This includes preventing attacks wherever possible, rapidly detecting anomalies, and ensuring resilient, transparent recovery when incidents occur.

Through organizational leadership and national collaboration, Michael has driven initiatives that enhance the security, resilience, and credibility of election systems. His work helps safeguard the voter experience and uphold trust in democratic institutions.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 17:00-17:30 PDT


Title: Lightning Talks and Unconference
Tags: Nix Vegas Community | Creator Event/Activity
When: Saturday, Aug 8, 17:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Give a talk about whatever you want, as long as it's less than 10 minutes! Or just come and chill in the Nix Vegas space for the Unconference.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 14:00-14:59 PDT


Title: Lights Out: Out-of-Band, Out of Mind, Out of Control
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Every enterprise server has a second computer you probably forgot about. The baseboard management controller runs its own OS, has its own network stack, and stays on even when the server is off. It speaks IPMI, a protocol from the 1990s that Dan Farmer thoroughly dismantled in 2013. Thirteen years later, nobody went back to check. We did.

We scanned 15,000 internet-facing BMCs and 125,000 across corporate networks, extracted RAKP password hashes from three out of four targets without credentials, and cracked thousands offline. We show how to fingerprint vendors from unauthenticated GUID responses, extract Dell service tags and HPE serial numbers before logging in, and brute-force the "random" passwords that California's SB-327 law was supposed to fix.

Then we show what comes next: pivoting from a compromised host to its BMC over the internal bus without touching the network, jumping to the out-of-band management VLAN, reusing shared credentials across the fleet, and landing on production hosts via Serial-over-LAN and virtual media. The host and BMC are the same physical machine; network segmentation means nothing when the bridge is a PCIe bus.

We release OOBscan, an open-source IPMI exploitation tool, and demonstrate the full attack chain.

========================================

FOUNDATIONAL IPMI RESEARCH (2013-2014)

Dan Farmer - IPMI Security Research Hub http://fish2.com/ipmi/

Dan Farmer - "IPMI: Freight Train to Hell" (January 2013) http://fish2.com/ipmi/itrain.html

Dan Farmer - "Sold Down the River" (June 2014) http://fish2.com/ipmi/river.pdf

Dan Farmer - IPMI Security Best Practices http://fish2.com/ipmi/bp.pdf

Dan Farmer - Cracking IPMI Passwords Remotely http://fish2.com/ipmi/remote-pw-cracking.html

Dan Farmer - IPMI Tools (GitHub) https://github.com/zenfish/ipmi

HD Moore - "A Penetration Tester's Guide to IPMI and BMCs" (July 2013) https://www.rapid7.com/blog/post/2013/07/02/a-penetration-testers-guide-to-ipmi/

Bonkoski, Bielber, Halderman - "Illuminating the Security Issues Surrounding Lights-Out Server Management" (WOOT '13, August 2013) https://jhalderm.com/pub/papers/ipmi-woot13.pdf

US-CERT Alert TA13-207A - Risks of Using the Intelligent Platform Management Interface (IPMI) https://www.cisa.gov/uscert/ncas/alerts/TA13-207A

CVE-2013-4786 - IPMI 2.0 RAKP Authentication Remote Password Hash Retrieval https://nvd.nist.gov/vuln/detail/CVE-2013-4786

Metasploit IPMI Modules (ipmi_dumphashes, ipmi_cipher_zero, ipmi_version) https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/auxiliary/scanner/ipmi/ipmi_dumphashes.md

========================================

INTEL ME / AMT VULNERABILITIES

CVE-2017-5689 "Silent Bob is Silent" - Intel AMT Remote Privilege Escalation (CVSS 9.8) https://nvd.nist.gov/vuln/detail/CVE-2017-5689

Intel SA-00075 - Intel Active Management Technology Elevation of Privilege (May 2017) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00075.html

Intel SA-00086 - Intel ME/SPS/TXE Multiple Vulnerabilities (November 2017) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00086.html

EFF - "Intel's Management Engine is a Security Hazard" (May 2017) https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it

Wikipedia - Intel Management Engine (comprehensive history) https://en.wikipedia.org/wiki/Intel_Management_Engine

Evdokimov - "Intel AMT Stealth Breakthrough" (Black Hat USA 2017) https://blackhat.com/docs/us-17/thursday/us-17-Evdokimov-Intel-AMT-Stealth-Breakthrough-wp.pdf

========================================

PLATINUM APT - WEAPONIZED OOB MANAGEMENT

Microsoft - "PLATINUM Activity Group Using Intel AMT for C2" (June 2017) https://www.microsoft.com/en-us/security/blog/2017/06/07/platinum-continues-to-evolve-find-ways-to-maintain-invisibility/

========================================

ASPEED BMC HARDWARE VULNERABILITIES

CVE-2019-6260 "Pantsdown" - ASPEED AST2400/AST2500 AHB Bridge Arbitrary R/W (CVSS 9.8) https://nvd.nist.gov/vuln/detail/cve-2019-6260

Stewart Smith - "CVE-2019-6260: Gaining Control of BMC from the Host Processor" (January 2019) https://www.flamingspork.com/blog/2019/01/23/cve-2019-6260-gaining-control-of-bmc-from-the-host-processor/

OpenBMC Security Advisory for CVE-2019-6260 https://github.com/openbmc/openbmc/issues/3475

Pantsdown Exploit Tool https://github.com/amboar/cve-2019-6260

========================================

ECLYPSIUM BMC RESEARCH (2019-2025)

Eclypsium - "CloudBorne: Bare-Metal Cloud Server Vulnerabilities" (2019) https://eclypsium.com/blog/the-ilobleed-implant-lights-out-management-like-you-wouldnt-believe/

Eclypsium - "Vulnerable Firmware in the Supply Chain" (2019) - Lenovo/Vertiv MergePoint EMS https://eclypsium.com/wp-content/uploads/Vulnerable-Firmware-in-the-Supply-Chain.pdf

Eclypsium - BMC&C Part 1: "Supply Chain Vulnerabilities Put Server Ecosystem At Risk" (December 2022) CVE-2022-40259 (RCE via Redfish API), CVE-2022-40242, CVE-2022-2827 https://eclypsium.com/blog/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/

Eclypsium - BMC&C Part 2: "Lights Out Forever" (July 2023) CVE-2023-34329 (CVSS 9.1, auth bypass via HTTP header spoofing), CVE-2023-34330 https://eclypsium.com/research/bmcc-lights-out-forever/

Eclypsium - BMC&C Part 3: AMI MegaRAC Vulnerabilities (March 2025) CVE-2024-54085 (CVSS 10.0, remote auth bypass via Redfish Host Interface) https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/

Eclypsium - "CVE-2024-54085 Joins CISA's KEV" (July 2025) https://eclypsium.com/blog/bmc-vulnerability-cve-2024-05485-cisa-known-exploited-vulnerabilities/

Eclypsium - Nuclei Templates for AMI MegaRAC Detection (July 2025) https://eclypsium.com/blog/eclypsium-releases-tools-for-detecting-ami-megarac-bmc-vulnerabilities/

Eclypsium - "The iLOBleed Implant" (analysis/commentary) https://eclypsium.com/blog/the-ilobleed-implant-lights-out-management-like-you-wouldnt-believe/

========================================

NVIDIA BMC RESEARCH

NVIDIA OSR - "Breaking BMC: The Forgotten Key to the Kingdom" (DEF CON 31, 2023) 18 vulnerabilities, 9 exploits, full chain to persistent firmware implant https://developer.nvidia.com/blog/analyzing-baseboard-management-controllers-to-secure-data-center-infrastructure/

DEF CON 31 Talk Description (Tereshkin & Zabrocki) https://forum.defcon.org/node/245714

========================================

iLOBLEED ROOTKIT (2020-2021)

Amnpardaz - "Implant.ARM.iLOBleed.a" Technical Report (December 2021) First known in-the-wild BMC firmware implant https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/

Amnpardaz - Full Technical Analysis PDF https://threats.amnpardaz.com/en/wp-content/uploads/sites/5/2021/12/Implant.ARM_.iLOBleed.a-en.pdf

========================================

HPE iLO SECURITY RESEARCH & TOOLS

CVE-2017-12542 - HPE iLO4 Authentication Bypass (CVSS 9.8) https://nvd.nist.gov/vuln/detail/CVE-2017-12542

Airbus Security Lab - "Subverting Your Server Through Its BMC: The HPE iLO4 Case" (SSTIC 2018) Périgaud, Gazet, Czarny - firmware analysis, backdooring, persistence https://airbus-seclab.github.io/ilo/SSTIC2018-Article-subverting_your_server_through_its_bmc_the_hpe_ilo4_case-gazet_perigaud_czarny.pdf

Airbus Security Lab - Presentation Slides (SSTIC 2018) https://airbus-seclab.github.io/ilo/SSTIC2018-Slides-EN-Backdooring_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf

Airbus Security Lab - iLO4/iLO5 Toolbox (firmware analysis, extraction, exploitation) https://github.com/airbus-seclab/ilo4_toolbox

iLO4 Unlock - Custom firmware patching for HPE iLO4 (fan control, diagnostics) https://github.com/kendallgoto/ilo4_unlock

========================================

SUPERMICRO IPMI FIRMWARE TOOLS

Supermicro IPMI Firmware Source Code (GPL release) https://github.com/devicenull/supermicro_ipmi_firmware

IPMI Firmware Tools - Extract, modify, and rebuild Supermicro firmware images https://github.com/devicenull/ipmi_firmware_tools

smcbmc - Decrypt Supermicro BMC firmware images https://github.com/c0d3z3r0/smcbmc

super-bmc-fw-tools - Decrypt Supermicro BMC firmware (alternative implementation) https://github.com/zt-chen/super-bmc-fw-tools

Supermicro IPMI License Key Generation (reverse engineered) https://github.com/manfromafar/supermicro-ipmi-keygen

========================================

JUNGLESEC RANSOMWARE (2018)

BleepingComputer - "JungleSec Ransomware Infects Victims Through IPMI Remote Consoles" (December 2018) https://www.bleepingcomputer.com/news/security/junglesec-ransomware-infects-victims-through-ipmi-remote-consoles/

========================================

GOVERNMENT ADVISORIES

CISA/NSA - "Harden Baseboard Management Controllers" Joint CSI (June 2023) https://media.defense.gov/2023/Jun/14/2003241405/-1/-1/0/CSI_HARDEN_BMCS.PDF

CISA Alert - "CISA and NSA Release Joint Guidance on Hardening BMCs" (June 2023) https://www.cisa.gov/news-events/alerts/2023/06/14/cisa-and-nsa-release-joint-guidance-hardening-baseboard-management-controllers-bmcs

NSA Press Release - "NSA and CISA Release Guide to Protect BMCs" (June 2023) https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3426648/nsa-and-cisa-release-guide-to-protect-baseboard-management-controllers/

CISA Binding Operational Directive 23-02 - Mitigating the Risk from Internet-Exposed Management Interfaces (June 2023) https://www.cisa.gov/news-events/directives/bod-23-02-mitigating-risk-internet-exposed-management-interfaces

CVE-2024-54085 - Added to CISA Known Exploited Vulnerabilities Catalog (June 2025) https://nvd.nist.gov/vuln/detail/CVE-2024-54085

========================================

CALIFORNIA SB-327 IoT SECURITY LAW

SB-327 Bill Text - California Legislative Information https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB327

========================================

IPMI SPECIFICATION

IPMI v2.0 Specification (Intel, maintained by DMTF) https://www.intel.com/content/www/us/en/products/docs/servers/ipmi/ipmi-second-gen-interface-spec-v2-rev1-1.html

========================================

CRACKING TOOLS

Hashcat - Mode 7300: IPMI2 RAKP HMAC-SHA1 https://hashcat.net/wiki/doku.php?id=example_hashes

John the Ripper (bleeding-jumbo branch) - IPMI RAKP support https://github.com/openwall/john

========================================

ADDITIONAL BMC VULNERABILITY REFERENCES

CVE-2022-40259 - AMI MegaRAC Arbitrary Code Execution via Redfish API https://nvd.nist.gov/vuln/detail/CVE-2022-40259

CVE-2023-34329 - AMI MegaRAC Auth Bypass via HTTP Header Spoofing (CVSS 9.1) https://nvd.nist.gov/vuln/detail/CVE-2023-34329

CVE-2018-7078 - HPE iLO4/iLO5 Remote Code Execution https://nvd.nist.gov/vuln/detail/CVE-2018-7078

CVE-2018-7113 - HPE iLO5 Secure Boot Bypass https://nvd.nist.gov/vuln/detail/CVE-2018-7113

CVE-2021-29202 - HPE iLO Host-to-iLO Arbitrary Code Execution https://nvd.nist.gov/vuln/detail/CVE-2021-29202

========================================

RELATED TOOLS

ipmitool - Standard open-source IPMI management utility https://github.com/ipmitool/ipmitool

PCILeech - Direct Memory Access (DMA) attack toolkit (relevant to BMC-host trust) https://github.com/ufrisk/pcileech

Shadowserver Foundation - Open IPMI Report (ongoing internet scanning) https://www.shadowserver.org/what-we-do/network-reporting/open-ipmi-report/

SpeakerBio:  HD "hdm" Moore

HD Moore is a pioneer of the cybersecurity industry who has dedicated his career to vulnerability research, network discovery, and software development since the 1990s. He is most recognized for creating Metasploit and is a passionate advocate for open-source software and vulnerability disclosure. HD serves as the CEO and founder of runZero, a provider of cutting-edge exposure management software and cloud services that helps organizations minimize risk across their total attack surface. Prior to founding runZero, he held leadership positions at Atredis Partners, Rapid7, and BreakingPoint. HD's professional journey began with exploring telephone networks, developing exploits for the Department of Defense, and hacking into financial institution networks. When he's not working, he enjoys hacking on weird Go projects, building janky electronics, running in circles, and playing single-player RPGs.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Wednesday - 17:00-07:59 PDT


Title: Linecon
Tags: Misc
When: Wednesday, Aug 5, 17:00 - 07:59 PDT
Where: LVCC West Hall

Description:

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

Please also review the "Human Registration Open" event, and familiarize yourself with the important notes therein.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 16:00-16:59 PDT


Title: Live Recon Contest — Final Presentations
Tags: Recon Village | Creator Event/Activity
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Final presentations for the Live Recon Contest. Participants present their findings in front of a jury.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 12:00-13:59 PDT


Title: Live Recon Contest
Tags: Recon Village | Creator Event/Activity
When: Saturday, Aug 8, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Do you fancy doing live recon on Real Organizations? Activate Yourself. And compete in a unique HACKER challenge. Participants will perform live reconnaissance on a specified list of companies. Your mission is to unearth as much critical information as possible. Contest continues from Friday and ends Saturday at 2:00 PM.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 14:00-15:59 PDT


Title: Living Off Someone Else's Inference
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 14:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

LLM-powered tooling is becoming a force multiplier for attackers, from reconnaissance automation to post-exploitation enumeration. Using their own API keys creates attribution and cost, so they look for alternatives.

Thousands of inference endpoints sit exposed on the internet: misconfigured Ollama instances, open vLLM deployments, leaked API keys in directory listings, and expired OAuth tokens from AI coding assistants that can be silently refreshed. Attackers can discover these resources and use them as free compute for their operations, without spending a dollar or registering an account.

Attendees will learn how to:

•⁠ ⁠Discover exposed inference endpoints and leaked API keys using Infreerence •⁠ ⁠Validate that discovered resources provide usable inference access •⁠ ⁠Operate Echidna, powered entirely by discovered inference •⁠ ⁠Chain LLM skill agents together to execute a guided campaign against a target network

Current LLMs are effective force multipliers when directed, and significantly more so when the compute bill goes to someone else. This is resource hijacking applied to the AI era: living off someone else's inference. Understanding this threat is essential for any organization deploying or exposing AI infrastructure.

Two tools will be released as open source during the session:

•⁠ ⁠Infreerence: A multi-phase scanner and dashboard that discovers exposed inference endpoints and leaked API keys through Shodan and Censys, validates them against live provider APIs, and catalogs usable inference resources across 10+ providers. •⁠ ⁠Echidna: A Mythic C2 agent type that consumes discovered inference endpoints and turns them into operator-directed skill agents for reconnaissance, exploitation planning, post-exploitation, and lateral movement.

Speakers:Armend Gashi,Redon Gashi

SpeakerBio:  Armend Gashi, Managing Security Consultant at Sentry Cybersecurity

Armend Gashi is Managing Security Consultant at Sentry. With over 5 years in the industry, he specializes in application security and AWS cloud assessments. Armend has conducted AI red teaming engagements, developed multi-agent systems to perform security-focused tasks such as code auditing and exploit development, and was part of Anthropic’s external AI red team capability through HackerOne.

Armend has led security research initiatives resulting in the discovery of multiple vulnerabilities, including:

CVE-2023-26482 - Critical-risk vulnerability enabling remote code execution CVE-2023-48239 - High-risk vulnerability allowing arbitrary user storage updates CVE-2023-35928 - High-risk vulnerability enabling user account hijacking CVE-2023-45660 - Medium-risk application-level denial of service vulnerability CVE-2023-48301 - Medium-risk arbitrary browser code injection vulnerability CVE-2023-48307 - Low-risk server-side request forgery vulnerability

SpeakerBio:  Redon Gashi, Managing Security Consultant at Sentry Cybersecurity

Redon Gashi is a Managing Security Consultant and offensive team lead at Sentry, where he has spent close to a decade leading and executing penetration tests and red team operations for Fortune 500 clients across banking, telecom, insurance, and fintech. He holds the OSEP, CRTL, and CRTO certifications, and has personally performed over 200 engagements spanning web applications, internal infrastructure, and mobile platforms, while leading many more across his team. A former lecturer at Cyber Academy, speaker at multiple BSides conferences, and multiple-time CTF champion, Redon combines deep hands-on technical expertise with a proven ability to build and scale offensive security teams.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 10:00-11:59 PDT


Title: Living Off the Vault
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map

Description:

Sablefort is a fintech startup that ships an in-house password manager, Sablefort Keyvault. Rather than use a vetted encryption library, its engineering team rolled their own cipher. Starting from nothing but a public support chatbot, the player attempts to work through the attack chain.

Speakers:Alexandru Uifalv,Jennifer Slaybaugh,Morton Schenk

SpeakerBio:  Alexandru Uifalv

Alexandru Uifalvi (sickness) has been a part of the Advanced Windows Exploitation class over the past 7 years. His passion for vulnerability research and exploit writing comes through in his teaching and course content creation. Alex is well versed in Windows Internals, Windows Kernel Exploitation, and Reverse Engineering.

SpeakerBio:  Jennifer Slaybaugh

n/a

SpeakerBio:  Morton Schenk

Morten Schenk (morten) is a Content Technical Manager and trainer at Offensive Security with a focus on exploit development and mitigation bypasses on Windows. His recent work includes bypasses of exploit mitigations and exploitation vectors against the Windows 10 kernel. He presented on this topic at Black Hat USA 2017 and DEF CON 25. Morten was also the main content developer and designer for PEN300 and EXP-301.


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Saturday - 12:00-12:30 PDT


Title: Local Language Models in OT - Basics and Considerations
Tags: ICS Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

AI models are everywhere but most are talking about Frontier models that might not be deployable in OT environments. Either due to regulations or data sensitivity, local models might be the answer to extract more value out of various OT datasets. How do you get started? This presentation lays out the basics - from the HW options to various models available (e.g, Qwen, Gemma) - we cover what can be achieved by a bit of investment and a not a lot of elbow grease!

SpeakerBio:  Vivek Ponnada

Vivek Ponnada is an Operational Technology (OT) Security practitioner with global experience and currently serves as SVP of Growth & Strategy at Frenos, the world's first Simulated OT Pentesting Platform. Having started his career in Industrial Control Systems (ICS) as a Technician, Vivek became a Controls Engineer and commissioned Gas Turbines in Europe, Middle-East, Africa and South-East Asia. Post MBA, Vivek held multiple roles in Sales, Marketing & Business Development and Services covering ICS and OT Security solutions for Critical Infrastructure industries (Power, Oil & Gas, Water, Mining etc.) at GE, XenonCyber Dynamics and Nozomi Networks. He was a co-lead for the Top 20 Secure PLC Coding Practices Project and regularly speaks at Information Security Conferences. Vivek has a C.Eng. from IEI, MBA from McCombs (UT Austin) and holds the ISA/IEC 62443 Cybersecurity Expert & GICSP certifications. He is a member of the ISA, ISACA, Public Safety Canada ICS Security Symposium Advisory Committee and is a CS2AI Fellow.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 15:00-15:59 PDT


Title: Locktopus - Final Championship
Tags: Lockpick Village | Locktopus Competition | Contest
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

How do your lockpicking skills compare to the rest of the class? Enter the TOOOL US Locktopus Competition and find out! Eight legs, eight locks, eight lockpickers, one red table. Four locks of a similar difficulty must be picked, only five minutes per lock is given, thus 20 minutes per attempt/round. The 32 pickers with the fastest combined time will move on to a semi-final championship. The fastest of each round will move on to the final round, with the eight fastest pickers at the table. Open qualifying starts on Friday from 1:00pm and runs until village close. Semi-finals on Saturday at 1:00pm. Final championship on Saturday at 3:00pm.

Participant Prerequisites

Participants should be familiar with the very basics of picking locks. This can be learned at the lockpick village, where the locktopus challenge will be taking place.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 13:00-13:59 PDT


Title: Locktopus - Semi Finals
Tags: Lockpick Village | Locktopus Competition | Contest
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

How do your lockpicking skills compare to the rest of the class? Enter the TOOOL US Locktopus Competition and find out! Eight legs, eight locks, eight lockpickers, one red table. Four locks of a similar difficulty must be picked, only five minutes per lock is given, thus 20 minutes per attempt/round. The 32 pickers with the fastest combined time will move on to a semi-final championship. The fastest of each round will move on to the final round, with the eight fastest pickers at the table. Open qualifying starts on Friday from 1:00pm and runs until village close. Semi-finals on Saturday at 1:00pm. Final championship on Saturday at 3:00pm.

Participant Prerequisites

Participants should be familiar with the very basics of picking locks. This can be learned at the lockpick village, where the locktopus challenge will be taking place.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 15:30-17:30 PDT


Title: Locktopus Challenge Finals
Tags: Lockpick Village | Locktopus Competition | Contest
When: Saturday, Aug 8, 15:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

The biggest speed picking event in North America debuts at DEFCON 33 this year! Join us to see the top competitors from Friday and Saturday's qualifying brackets hash it out and be crowned champion of TOOOL's Locktopus Speed Picking Challenge!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 14:00-14:45 PDT


Title: LoKi: A LoRa/Meshtastic based implant for Red Teaming
Tags: Intro/Beginner | DEF CON Demo Labs | Hardware/IoT | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
When: Saturday, Aug 8, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

LoKi is a covert USB HID implant for Red Teaming that builds on the work of tools like the O.MG cable by replacing Wi-Fi with LoRa, extending the operational range of physical layer attacks from meters to kilometers. The implant integrates a Heltec LoRa module with custom Meshtastic firmware into an off-the-shelf wired USB mouse, retaining full mouse functionality. When LoKi receives a direct Meshtastic message, it translates the payload into DuckyScript™-compatible USB HID keystrokes and executes them on the host machine. No Wi-Fi, no Bluetooth, and no network traffic — the mouse simply begins typing. LoKi requires no line of sight and produces no detectable wireless LAN or Bluetooth signatures, making it effectively invisible to standard wireless monitoring. The live demo will walk through a payload from a handheld Meshtastic device to acquire a remote admin shell and bypass UAC on a target machine. Bring your own Meshtastic device and you can send commands to the implant during the demo. The presentation covers the hardware build, the customized open-source Meshtastic firmware, reliability considerations for keystroke delivery over a mesh network, and actionable blue team detection strategies, including monitoring for rogue HID device enumeration and LoRa RF activity.

SpeakerBio:  Venky Raju

Venky Raju is a lifelong maker and hacker who firmly believes that if you haven't voided the warranty, you don't truly own it. While he holds a Master’s in Comp. Sci. and an EE degree, his most prized "certifications" were earned at the business end of a soldering iron, a 3D printer, and an array of metal and wood-working tools.

By day, he navigates the complex worlds of Zero Trust, IoT, and OT security. To keep the corporate world happy, he maintains his CISSP and CCSP credentials—validating that he knows the academic rules well enough to know exactly how to safely bend them. His professional expertise isn't just theoretical. By night, he’s a renewable energy vigilante who built an off-grid solar shed and a custom PowerWall clone, mostly because he refuses to sell his electrons back to the grid for pennies. An early contributor to the LIRC and LCDproc projects, Venky’s code has been riding along in Linux distros for years.  He loves C, Python and PLC Ladder Logic.

Beyond the lab, Venky is dedicated to "pay-it-forward" hacking. Whether he’s teaching the next generation how to solder at Maker Faire or volunteering with the Pacific Hackers Association, he is committed to building the community as much as the tech. He is happiest when he’s elbow-deep in a project that requires both a compiler and a multimeter.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 15:00-15:45 PDT


Title: LoKi: A LoRa/Meshtastic based implant for Red Teaming
Tags: Intro/Beginner | DEF CON Demo Labs | Hardware/IoT | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
When: Saturday, Aug 8, 15:00 - 15:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

LoKi is a covert USB HID implant for Red Teaming that builds on the work of tools like the O.MG cable by replacing Wi-Fi with LoRa, extending the operational range of physical layer attacks from meters to kilometers. The implant integrates a Heltec LoRa module with custom Meshtastic firmware into an off-the-shelf wired USB mouse, retaining full mouse functionality. When LoKi receives a direct Meshtastic message, it translates the payload into DuckyScript™-compatible USB HID keystrokes and executes them on the host machine. No Wi-Fi, no Bluetooth, and no network traffic — the mouse simply begins typing. LoKi requires no line of sight and produces no detectable wireless LAN or Bluetooth signatures, making it effectively invisible to standard wireless monitoring. The live demo will walk through a payload from a handheld Meshtastic device to acquire a remote admin shell and bypass UAC on a target machine. Bring your own Meshtastic device and you can send commands to the implant during the demo. The presentation covers the hardware build, the customized open-source Meshtastic firmware, reliability considerations for keystroke delivery over a mesh network, and actionable blue team detection strategies, including monitoring for rogue HID device enumeration and LoRa RF activity.

SpeakerBio:  Venky Raju

Venky Raju is a lifelong maker and hacker who firmly believes that if you haven't voided the warranty, you don't truly own it. While he holds a Master’s in Comp. Sci. and an EE degree, his most prized "certifications" were earned at the business end of a soldering iron, a 3D printer, and an array of metal and wood-working tools.

By day, he navigates the complex worlds of Zero Trust, IoT, and OT security. To keep the corporate world happy, he maintains his CISSP and CCSP credentials—validating that he knows the academic rules well enough to know exactly how to safely bend them. His professional expertise isn't just theoretical. By night, he’s a renewable energy vigilante who built an off-grid solar shed and a custom PowerWall clone, mostly because he refuses to sell his electrons back to the grid for pennies. An early contributor to the LIRC and LCDproc projects, Venky’s code has been riding along in Linux distros for years.  He loves C, Python and PLC Ladder Logic.

Beyond the lab, Venky is dedicated to "pay-it-forward" hacking. Whether he’s teaching the next generation how to solder at Maker Faire or volunteering with the Pacific Hackers Association, he is committed to building the community as much as the tech. He is happiest when he’s elbow-deep in a project that requires both a compiler and a multimeter.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Saturday - 10:00-17:59 PDT


Title: Lonely Hackers Club - Lockpicking Table
Tags: Lonely Hackers Club | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

Learn new skills and find new friends at our lockpicking table. We provide you with beginner friendly locks, picks, and experienced volunteers to guide you through the process. Bring your own equipment to talk shop and get some new perspectives.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Saturday - 10:00-17:59 PDT


Title: Lonely Hackers Club - Sticker Swap Table
Tags: Lonely Hackers Club | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

DEF CON and stickers can't be separated. Visit our sticker swap table to get your hands on the latest sticky art and exchange the ones you made yourself. Check in regularly to get a chance to find rare gems.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Saturday - 10:00-17:59 PDT


Title: Lonely Hackers Club CTF
Tags: Lonely Hackers Club | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

We welcome all skill levels, from first-time DEF CON attendees to experienced CTF competitors. The challenges are layered, so newcomers can get meaningful wins while veterans still find plenty to chew on. Participants often team up spontaneously on location, making it as much a social experience as a technical one. Participate for a chance to get awesome prizes!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 14:30-15:30 PDT


Title: Looking and Peering: Attacking from beyond BGP Adjacency
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 14:30 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

The internet is fragile. A single misconfiguration in BGP can cause worldwide outages. There have been various efforts to harden BGP, like BGPsec, RPKI, and MANRS, but those mostly address route validation. The session-level boundary that everything else rests on is adjacency trust. If your router only connects to trusted peers, the router should be safe. That assumption shaped a lot of the security design around BGP: peer whitelisting, MD5 / TCP-AO authentication, GTSM (RFC 5082) using TTL to enforce that a peer is one hop away.

In this talk, we look beyond that boundary. Building on Route to Bugs (dos Santos & Guiot, DC31) and From Spoofing to Tunneling (123ojp, DC33), we demonstrate three vectors that undermine the assumption. We hijack a trusted peer through pre-auth command injection in BGP monitoring tools. We abuse tunnel injection to establish adjacency from off-path, and chain into a heap UAF for unauthenticated RCE. We turn implementation disagreement between FRR, BIRD, and other daemons into a weapon: we craft UPDATEs that one router type happily re-emits while causing denial of service in a different implementation.

BGP: - Route to Bugs: https://i.blackhat.com/BH-US-23/Presentations/US-23-dosSantos-Route-to-Bugs-Analyzing-the-Security-of-BGP.pdf

Tunnel injection: - From spoofing to tunneling: https://i.blackhat.com/BH-USA-25/Presentations/USA-25-Tung-From-Spoofing-To-Tunneling-New.pdf?_ga=2.41373794.1394109082.1756795982-2018511848.1751622634 - Free VPNs everywhere — tunnel injection: https://blog.chummydns.com/blogs/tunnel-injection-english/ - Hunted by legacy: discovering and exploiting vulnerable tunneling hosts: https://www.usenix.org/system/files/usenixsecurity25-beitis.pdf

Looking glasses: - Through the looking-glass and what eve found there: https://www.usenix.org/system/files/conference/woot14/woot14-bruno.pdf - Looking glass research WOOT2014 / DEFCON 22: https://blog.talosintelligence.com/looking-glasses-with-bacon/

SpeakerBio:  Bo-Shiun "bronson113" Yen, Calif.io

Bronson Yen (@bronson113) is a security researcher working at Calif.io. He has experience in researching networking equipment and hardware attacks, with a focus on binary exploitation and cryptography. He previously presented at HITCON for his work in router exploitation.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 16:00-16:30 PDT


Title: Low Skill, High Impact Attacks on Internet Voting
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

Debates over internet voting frequently focus on sophisticated technical threats, including malware, server intrusions, insider attacks, and cryptographic vulnerabilities. While these concerns remain significant, they may obscure a broader class of low-cost, "cheap" attacks that target voters and public confidence rather than election infrastructure itself. This presentation explores how internet voting systems may expand opportunities for inexpensive, highly scalable disruption, information operations, and psychological attacks against election legitimacy. Examples include phishing campaigns aimed at vote-by-phone users, fraudulent voting applications distributed through app stores, compromised browser extensions, automated social-media campaigns or website defacements that manufacture the appearance of widespread system failures, and targeted messages to early voters falsely informing them that their ballots or personal information have been compromised. Traditional vote-suppression techniques such as robocalls may likewise be adapted to digital platforms and enhanced through AI-generated content and voice cloning. In some cases, no actual compromise need occur; the perception of a successful attack - a form of psychological operation (psyop) - may itself achieve an adversary's objectives. The central argument is that the most consequential threats to internet voting may not always involve defeating election technology itself but rather exploiting expanded opportunities to attack voters and erode confidence in the electoral process.

SpeakerBio:  John Odum

John Odum is the elected City Clerk of Montpelier, Vermont, where he serves as Election Administrator. He holds the Certified Municipal Clerk (CMC) designation from the International Institute of Municipal Clerks, a Certificate in Election Administration from the University of Minnesota Humphrey School of Public Affairs, and Certified Ethical Hacker (CEH) and Certified Network Defense Architect (CNDA) certifications from EC-Council. Prior to becoming an election administrator, he worked in information technology and electoral politics, including as the Technology Director for the Vermont Democratic Party, Statewide Field Director for the Clavelle for Governor campaign, Clinic Management System Administrator for Planned Parenthood of Northern New England, and as a political organizer for Oregon’s “No On 13” campaign, Maryland Citizen Action, and the 2018 Bernie Sanders for Congress campaign. He currently writes on elections and democracy at his substack, electionmatters.net.


Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Saturday - 16:30-16:59 PDT


Title: LSTM Autoencoder Ensemble for NMEA 2000 Intrusion Detection on Vessel Networks
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Maritime vessels increasingly depend on NMEA 2000 (CAN bus) networks to interconnect navigation, propulsion, and safety-critical systems, yet the underlying protocol provides no authentication, any device can transmit any message ID. As maritime cyber incidents such as GPS spoofing, engine manipulation, and AIS attacks become more frequent, existing automotive CAN intrusion detection systems fall short because they fail to model maritime-specific traffic behavior, including variable RPM, long duty cycles, and sensor drift. We present a multi-modal LSTM autoencoder ensemble in which four specialized models independently monitor message timing, payload content, frequency, and device-level behavior. Each autoencoder learns normal operating patterns and flags anomalies via reconstruction error, with a majority-voting aggregator raising an alert when at least two of four components agree. Detection thresholds are set automatically at the 99th percentile of validation error, requiring no labeled attack data. The system was evaluated on a 24-hour continuous capture from an operating vessel comprising 9.16 million messages across 24 PGNs and three source devices, spanning a full operational cycle and six simulated attack types. Using 5-fold temporal cross-validation, the ensemble achieved an F1 score of 0.964 (95% CI: 0.952–0.976) and ROC-AUC of 0.991, while reducing variance 28× relative to a single-model baseline. The unsupervised threshold matched supervised tuning (F1=0.965 vs. 0.971) without attack labels, and a novel network drift detection module identified unauthorized hardware changes with perfect accuracy (F1=1.000) across 120 trials. With 38.76 ms inference latency, the approach is suitable for real-time onboard monitoring. Future work includes voltage fingerprinting, live deployment, and transfer learning.

Speakers:Anissa Elias,James Campbell

SpeakerBio:  Anissa Elias, University of Rhode Island

Anissa Elias is a Research Engineer and Ph.D. researcher specializing in maritime cyber-physical system security, autonomous monitoring, and on-edge AI. Her work focuses on securing underwater and maritime systems through real-time anomaly detection, embedded intelligence, and resilient network architectures. She has deep experience with maritime network analysis, digital twins, and deployable AI for resource constrained environments. Anissa brings a strong background in defense-focused research, autonomous system security, and AI trust and compliance for naval and maritime operations.

SpeakerBio:  James Campbell, Independent Researcher

James (Soups) Campbell is a Red Team Operator for the US Coast Guard, specializing in malware research, offensive tool development, and OT cybersecurity. In his free time, he can be found building autonomous vessels, hacking on boats, and playing with his very energetic puppy.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 14:00-14:45 PDT


Title: MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

When TSA scans your luggage, they see what's inside without opening the bag. MailX-Ray brings that pattern to email triage.

Phishing reports hit analysts as small crises: open carefully, don't trigger anything, extract IOCs, hand off to detection. Tooling lives at two extremes: cloud sandboxes that ship customer data offsite, or lightweight CLIs that run malicious parsers directly on the analyst's host. Neither produces a portable safe artifact, on-prem and hardware-isolated, in roughly 30 seconds.

MailX-Ray does. Every email is processed inside an ephemeral hardware-virtualized microVM with no network device. Network egress is prevented by design. Output includes a single-file portable HTML safe-read report, structured JSON with 45+ offline signal categories, and optional STIX and MISP exports for SOC integration. Original attachment binaries are never re-distributed.

It's not a malware sandbox. No decompilation, no execution, no verdicts. It's a non-invasive structural scan: the first 30 seconds of email triage, with zero network egress, on the analyst's own laptop.

Demo Labs attendees will see the live pipeline across real phishing scenarios, including encrypted nested archives. Open source on the day of the talk.

SpeakerBio:  Uğur "uJohn" Can ATASOY

Uğur Can Atasoy is a Senior Security Engineer at Udemy, working primarily on blue and purple team operations.

A believer in hybrid approaches that combine technical fieldwork with academic rigor, he has spent the past decade across higher education, media, defense, and automotive sectors in roles spanning security architect, specialist, trainer, and consultant. His work spans both offense and defense — from security operations, threat hunting, intrusion detection, purple teaming, and adversary simulation to penetration testing and secure architecture. He has served as a Senior Content Engineer at TryHackMe and as an Information Security Architect at Mercedes-Benz. He has delivered security training for NATO personnel, law enforcement investigators, and military leadership, spoken at DeepSec (Vienna), holds CCSP, GCIA, OSCP, and OSWP, and served as an ISC2 SME for exam and training item development. He has been recognized by Oracle and IBM for responsible disclosure.

MailX-Ray is his answer to a recurring annoyance: every tool in the email triage stack is either a cloud SaaS that ships customer data offsite, a heavyweight VM-based sandbox that takes minutes per sample, or an unprotected CLI that runs malicious parser input directly on the analyst's host. It produces a safe artifact analysts can read and forward.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Saturday - 10:00-17:59 PDT


Title: Makers' Village - Hacker Arts and Crafts
Tags: Maker's Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 13:00-13:45 PDT


Title: MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

Your AI agent trusts every skill in its directory. What if one of them is lying? In this Demo Lab, I walk you through MalSkills, natural language malware planted inside AI agent skill systems. No binaries, no shellcode, no signatures. Just English sentences with OS-level access. Using ORPHEUS, my open-source multi-skill orchestration framework, I demonstrate three escalating attacks live: 1. BURIED INSTRUCTION: A malicious sentence hidden in a legitimate skill exfiltrates .env files on first execution. I show you 12 skills and challenge you to spot it. 2. CHAIN ATTACK: Five individually benign skills that, when orchestrated together, create an emergent data exfiltration path. No single skill is malicious. The composition is the weapon. 3. PERSISTENT GHOST: A skill that writes itself into agent memory, surviving file deletion and session restarts. Remove the skill, restart the agent, exfiltration continues. After offense, I flip to defense. I demo the MalSkill Detection Toolkit: skill integrity verification, capability-based sandboxing, orchestration graph analysis, and runtime behavioral monitoring. Attendees leave with: the ORPHEUS framework, a MalSkill sample pack, and a detection toolkit, all open source! Every AI agent with a plugin system is vulnerable today. Come see why.

SpeakerBio:  Nur "BurritoTheNurrito" Gucu

Offensive security professional and AI security researcher with 10+ years across financial services, startups, and Amazon. Currently on the foundational model red team at Amazon AGI Labs, where I break AI systems and build the tooling to detect what I find. Core focus: LLM security, agentic system exploitation, and the gaps between how AI frameworks are designed and how they actually behave under adversarial pressure. 6 patent applications. Published author (AWS Security Blog, internal science papers). Invited speaker on MCP security and LLM training APT attack surfaces. I turn research into shipped products and open-source tools, not empty slide decks.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 16:00-17:59 PDT


Title: MalSkill: Weaponizing AI Agent Skills for Persistence, Exfiltration, and Lateral Movement
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

Every red teamer's dream: a persistence mechanism that's a plain text file, invisible to EDR, survives reboots, self-propagates, and gives you full OS access through a trusted process. Welcome to MalSkills.

AI coding agents (Claude Code, Cursor, Codex, Copilot) execute shell commands, read/write files, and make network requests, and all orchestrated by natural language "skills" stored as plain text. These skills are never scanned, never signed, and fully trusted by the agent runtime. I built ORPHEUS, a multi-skill orchestration framework, and weaponized it to demonstrate a new tradecraft category.

WHAT I'LL DEMONSTRATE:

Initial Access: Skill injection via poisoned repos, malicious PRs, or "helpful skill packs." The agent IS your execution environment, no binary needed.

Persistence: Skills survive reboots (they're config files). Self-propagation: skills rewrite other skills to include dormant copies. Memory persistence: skills write instructions into agent memory that survive file deletion. No registry, no cron, no scheduled tasks.

Exfiltration: Conditional triggers that activate only on credential patterns. Chain attacks: 5 benign skills that compose into a C2 channel. Agent makes the request; it's a trusted process.

Evasion: No binary = no signature = no EDR. No process injection, no shellcode. The "malware" is grammatically correct English.

LIVE DEMOS:

Plant a MalSkill via malicious PR → credential exfiltration on next agent invocation 5-skill orchestration chain where no individual skill is malicious but composition creates C2 Persistence that survives skill deletion via agent memory poisoning

TOOL RELEASE (open source, day-of):

TACTIC (hands-on companion):

"Plant, Chain, Persist — Hands-On MalSkill Tradecraft"

Attendees (10-15) work through three exercises at a table:

Exercise 1 - Craft Your First MalSkill (10 min): Write a malicious instruction in plain English, hide it in a legitimate skill, execute the workflow, verify exfiltration to local C2.

Exercise 2 - Build a Chain Attack (15 min): Modify orchestration wiring (not skills) to create an emergent exfiltration path. No individual skill looks malicious — the data path is the weapon.

Exercise 3 - Achieve Persistence After Remediation (10 min): Before your skill gets deleted, write persistence into agent memory. Delete the skill, restart agent, verify behavior persists.

Bonus - Detection Challenge (5 min): Try to spot your neighbor's MalSkill using the detection toolkit.

All tooling provided. Attendees leave with the full ORPHEUS environment, sample MalSkills, and detection toolkit.

SpeakerBio:  Nur Gucu

AI security researcher and offensive security professional with 10+ years of experience across financial services, startups, and big tech (Amazon). Currently a member of the foundational model red teaming and AI security tool development at Amazon AGI Labs. Deep expertise in LLM security, agentic system security, breach and attack simulation, penetration testing, and secure architecture design. Proven track record of translating research into shipped products: 6 patent applications filed, published author on the AWS Security Blog, internal science research papers, and invited conference speaker on MCP security and LLM training APT attack surfaces. Passionate about securing AI systems at scale through research, tooling, and cross-functional collaboration.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 12:00-12:30 PDT


Title: Malware Inc.: Cybercrime-as-a-Service y la economía del cibercrimen moderno
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

El cibercrimen moderno dejó atrás el modelo del atacante aislado. Hoy existe un ecosistema modular y altamente especializado donde servicios como Malware-as-a-Service (MaaS), Ransomware-as-a-Service (RaaS), Pay-Per-Install (PPI), Initial Access Brokers (IAB) o Phishing-as-a-Service (PhaaS) permiten que distintos actores colaboren dentro de una cadena de suministro criminal distribuida.

En esta charla exploraremos cómo el malware adoptó principios de industrialización similares a los de la industria tecnológica legítima: afiliados, automatización, revenue sharing, soporte técnico y servicios bajo demanda. A través de casos reales revisaremos cómo funciona esta economía clandestina, cómo se monetizan distintas etapas de un ataque y por qué entender el modelo de negocio detrás del malware es clave para comprender las amenazas actuales.

SpeakerBio:  Isabel Manjarrez, Threat Researcher

[EN] María Isabel Manjarrez is a security researcher with Kaspersky's Global Research and Analysis Team (GReAT). She specializes in investigating threat actors in Latin America, tracking their movements, and analyzing the new techniques they deploy. She holds a degree in telecommunications and electronic systems engineering and her interests include threat intelligence, malware analysis, satellite communications, electronics, and music.

She has shared her knowledge as a speaker at local and international conferences such as Defcon, Security Analyst Summit (SAS), and EkoParty.


[ES] María Isabel Manjarrez es investigadora de seguridad en el Equipo Global de Investigación y Análisis (GReAT) de Kaspersky. Se especializa en la investigación de actores amenaza en Latinoamérica, rastrea sus movimientos y analiza las nuevas técnicas que implementan. Es Ingeniera en telecomunicaciones y sistemas electrónicos, sus intereses incluyen la inteligencia de amenazas, análisis de malware, comunicaciones satelitales, electrónica y música.

Ha compartido su conocimiento como ponente en conferencias locales e internacionales como Defcon, Security Analyst Summit (SAS) y EkoParty.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 12:10-12:20 PDT


Title: Malware Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 12:10 - 12:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Malware Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Malware Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Saturday - 12:30-12:59 PDT


Title: Maritime Threat Hunting: What We Actually Find When We Look
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

You cannot secure what you cannot see. As maritime organizations work to improve cyber resilience, many are discovering that the biggest challenge is not detecting threats. It's understanding their networks in the first place. Drawing from real-world maritime environments, MAD Security and GuROO Networks will demonstrate how Network Operations Centers (NOCs) and Security Operations Centers (SOCs) work together to identify assets, establish operational baselines, uncover hidden risks, and investigate suspicious activity across maritime IT and OT environments. This presentation examines actual findings from vessel operators, ports, terminals, and maritime infrastructure organizations, including:

Attendees will see how network visibility, asset intelligence, operational monitoring, and cybersecurity analytics combine to provide a more complete picture of maritime risk. Rather than focusing on theory or compliance, this session highlights what maritime operators actually discover when they begin looking deeper into their environments and why visibility remains the foundation of both network reliability and cybersecurity.

Speakers:Cliff Neve,Philip Acosta,Dean Macris

SpeakerBio:  Cliff Neve, MAD Security

Cliff Neve is Vice President of Maritime Cybersecurity at MAD Security and a retired U.S. Coast Guard Commander with more than 30 years of experience in cybersecurity, operational technology (OT), and critical infrastructure protection. As a founding leader of Coast Guard Cyber Command, he helped establish the Coast Guard's cyber defense mission and contributed to national cybersecurity policy development.

Today, Cliff leads maritime cybersecurity initiatives supporting ports, terminals, shipping companies, and government agencies. His experience includes terminal cybersecurity risk assessments, threat hunting, incident response, and Security Operations Center (SOC) services for maritime organizations, including projects supporting the U.S. Maritime Administration (MARAD) and commercial shipping operators.

Cliff specializes in the intersection of maritime operations, OT security, and cyber resilience, and is a frequent speaker on maritime cybersecurity, threat detection, and critical infrastructure protection.

SpeakerBio:  Philip Acosta, GuROO
No BIO available
SpeakerBio:  Dean Macris, University of Rhode Island
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 10:00-11:59 PDT


Title: MCP Servers: The Next Enterprise Attack Surface
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

Everyone's building MCP servers. Nobody's attacking them yet. AI agents are now wired directly into developer workflows via the Model Context Protocol (MCP). This session dissects the hidden security risks in MCP ecosystems, from malicious tool servers to over‑privileged integrations. You’ll walk away with actionable defenses and a fresh lens on AI‑augmented attack surfaces. This talk covering five distinct attack surfaces mentioned in the outline. Two live demos make the risk visceral: 1)A malicious MCP server masquerading as a calendar tool silently exfiltrates conversation context, secrets, and API keys with zero user-visible indicators of compromise. 2)A prompt injection payload planted in a GitHub repository triggers lateral movement across three connected MCP servers (filesystem, GitHub, cloud APIs), demonstrating how MCP multiplies blast radius without any direct server exploitation.

Speakers:Apoorwa Joshi,Justin Dray

SpeakerBio:  Apoorwa Joshi

Meet Apoorwa Joshi – Security Engineer, Code Whisperer & Threat Tamer at Amazon. With over 6 years in the trenches of application and cloud security at scale, she currently brings her talents to helping teams think like attackers before the attackers do. Armed with a Master’s degree, a knack for demystifying technical complexity, Apoorwa specializes in "shifting left" Based in Austin, Texas, Apoorwa is part of a new wave of security professionals. Though this is her first time on the conference stage, she’s no stranger to leading conversations that matter from mentoring junior engineers to influencing cross-team architecture decisions. When she’s not taming threats or refactoring risk, she enjoys playing ping pong and spending time with her cat.

Ask her about: threat modeling, secure architecture, DevSecOps, or how to sneak security into sprint planning without getting side-eyes.

SpeakerBio:  Justin Dray

Meet Justin Dray – Senior Security Engineer & AI Automation Lead at AWS.

With over 10 years in cloud and application security at Amazon-scale, Justin is the lead engineer on the team responsible for application security across AWS Database services, and has made a career out of finding the risks nobody else knew to look for — then building the AI-powered tooling to catch them before they ever reach production. He's architected AI investigation frameworks and automated code review systems now running across tens of thousands of packages organization-wide.

Based in Seattle, Justin specializes in turning security from a bottleneck into a force multiplier, recovering thousands of engineering hours a year by embedding automation directly into the SDLC. He's built a reputation as a trusted bar raiser, able to align even the most historically high-friction teams around shared security outcomes.

When he's not building security tooling, Justin can be found out on a hiking trail, behind a camera, or deep in a book.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Saturday - 10:00-10:30 PDT


Title: MCPwned: How Exposed AI Agents Became the Internet’s New Recon Toy
Tags: Adversary Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

This talk examines how exposed AI infrastructure is becoming a new adversary playground, as attackers and internet-scale scanners and bruteforcing target LLM gateways, MCP servers, local inference APIs, and AI developer tooling faster than defenders have built threat models for them.

I ran a purpose-built AI honeypot that simulated 16 LLM and AI infrastructure personas across 16 ports, returning framework-authentic responses, headers, errors, and protocol behaviors. In one 48 hour window, the system captured 3,993 requests from 327 unique source IPs, including 155 MCP probes and 344 AI API key probes. What emerged was not generic internet noise, but a repeatable playbook against the emerging AI stack: LiteLLM model-registration abuse, MCP resource enumeration, framework-aware credential brute forcing, and coordinated scanning for exposed local inference services.

SpeakerBio:  Eli Woodward, Senior Threat Intelligence Advisor with Team Cymru

Eli Woodward is a cyber threat intelligence advisor with Team Cymru. He's worked in a variety of industries including financial services and government, and has seen the range of organizations from extremely well-resourced and capable to the shoestring budget. This has given him unique insights into CTI at all levels of complexity, maturity, and resources. He holds a master's degree in Intelligence and Security Studies and also plays bagpipes competitively.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Saturday - 17:00-17:59 PDT


Title: MEACS Trivia, Games and Networking
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Event/Activity
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

Test what you know and meet the people who know the rest. Bring your team or find one when you get there for a few rounds of security trivia, from the history this community is built on to the attacks making headlines right now. Expect a friendly, competitive crowd, bragging rights on the line, and plenty of time to connect with other Middle Eastern and African practitioners and friends of the community between rounds. Whether you came to win or just to find your people, pull up a chair.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:10-10:20 PDT


Title: MEACS: Middle Easterns & African in Cyber Security Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 10:10 - 10:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:
Interested in visiting MEACS: Middle Easterns & African in Cyber Security but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to MEACS: Middle Easterns & African in Cyber Security and be introduced to the community and activities inside!

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 11:00-11:59 PDT


Title: Meet XEntry Team: A powerful threat actor abusing Bitlocker for ransomware
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Our GERT team was notified about a company affected by a previously unknown threat actor identified as "XEntry Team". Initially, the customer identified this threat as a hijacked LogMeIn session that allowed the attackers to activate BitLocker and encrypt the disks of every system synchronizing to the AD; but our analysis confirmed a 2 months intrusion, using a mix of clever techniques and lack of monitoring, that allowed attacker to configure a bridge to the infrastructure for:

• Recognition

• Critical assets identification

• Exfiltration

• Persistance

• ransomware deployment

• Other not so funny stuff.

During this session we will present to the audience the investigation results, the techniques implemented by the threat actor, the scope of the attack from beginning to the end, and the analysis and attempts to recover affected systems.

SpeakerBio:  Eduardo Chavarro Ovalle, DFIR Group Manager at Kaspersky - GERT

Eduardo Chavarro Ovalle, DFIR Group Manager for Americas, member of Kaspersky GERT Team. Student of DBA in ML and AI and MSc in Cybersecurity with more than 20 years of experience in cybersecurity, DFIR, eDiscovery, and threat analysis. GCIH | GRID | GCFA | CISM | CHFI | CPTE | SFCP | ITIL.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:00-10:30 PDT


Title: Memory Laundering via Metal: What EDR Can't See on Your Mac
Tags: DEF CON Official Talk | Demo 💻
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

DEF CON Abstract

Metal is Apple's GPU framework, it replaced OpenGL and is now the only way to talk to the GPU on macOS. Among its buffer types is StorageModePrivate: memory managed entirely by the GPU. The CPU can't read it, write to it, or map it into virtual address space.

macOS endpoint security scans process memory through mach_vm_region and task_for_pid. Apple's own Endpoint Security framework watches mappings via ES_EVENT_TYPE_NOTIFY_MMAP. None of them see StorageModePrivate buffers. Those pages live in GPU firmware page tables, allocated through IOGPUDevice in the IOAccelerator family, completely outside Mach VM. No API exists to let a security tool inspect them from another process.

I turned this gap into a working evasion technique. Incoming payload gets XOR-encoded to destroy signatures, staged through a shared MTLBuffer, then blitted into private GPU memory via MTLBlitCommandEncoder on AGXCommandQueue. All CPU-side artifacts get wiped, volatile pointers, _syncsynchronize barriers, multi-pass zeroing. At that point the data exists only in pages no process on the box can read. When I need it back, I reverse the blit, decode, execute, and wipe again. Total CPU exposure is milliseconds.

Tested on the latest Apple Silicon hardware. 100% evasion. No entitlements, no kexts, no root. Runs from a sandbox

Apple Metal Framework Documentation:MTLBuffer, MTLResourceStorageModePrivate, MTLBlitCommandEncoder https://developer.apple.com/documentation/metal

Apple Endpoint Security Framework Documentation: ES_EVENT_TYPE_NOTIFY_MMAP https://developer.apple.com/documentation/endpointsecurity

Apple Silicon Unified Memory Architecture: Apple Platform Security Guide https://support.apple.com/guide/security/welcome/web

IOKit IOAccelerator Family: GPU driver interface for macOS kernel subsystem https://developer.apple.com/documentation/iokit

SpeakerBio:  Hxr1

15+ years specializing in Red Teaming, Adversary Emulation, and Application Security. Proven track record executing advanced offensive operations across enterprise environments. Active contributor to the cybersecurity community focused on evolving offensive tradecraft and automating purple team capabilities.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Saturday - 15:00-15:59 PDT


Title: Men Loving Men Meetup
Tags: Queercon Community | Creator Event/Activity
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: Mentoring and Career Advice
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Informal, one-on-one conversations with volunteer mentors and speakers about breaking into cybersecurity, career pivots, resumes, certifications, and next steps. No appointment needed — just come find a mentor in the village during open hours.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 09:00-15:59 PDT


Title: Merch (formerly swag) Area Open -- README
Tags: Misc
When: Saturday, Aug 8, 09:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1500 (MERCH) - Map

Description:

The short version

The slightly longer version:

Similar to the last few years, HackerTracker will have artwork or photos of the merch for you to browse before you join the line -- you can decide ahead of time if you are interested in a product. HackerTracker is also showing stock status – if an item goes out of stock, that’ll be indicated in-app; this is on a best-effort basis, and some products move fast. You're able to make a wish list in Hacker Tracker, which expedites the ordering process at the front of the line (making everything faster and easier for everyone). If you don't want to use Hacker Tracker, you can have a merch goon create the order on your behalf.

Tentative instructions

Here’s the process, from beginning to end:

  1. Browse the products, in-app. The list of products with associated artwork are expected to be published early the morning of August 6.
  2. When you find a product that you want to buy, make sure that you’ve selected the right variant/size, and then tap “Add to List”. Think of your list like a wish list.
  3. To view your list: If you’re using iOS, tap on the QR code at the top right. If you’re using Android, tap the “View List” button at the bottom.
  4. Your list shows everything you’ve added; if an item has gone out of stock since you added it, a warning will appear, and you’ll be required to remove the item from your list.
  5. When you near the front of the merch line, show the QR code at the top of your list to the order taker. They’ll scan it, and print a paper list. The list will have an order number on it, as well as your total amount due. The order taker can help answer any questions and help you modify your order if needed. If any items have sold out since they were added to your list, the order taker can help you find a replacement or remove it from your list.
  6. The paper list will be used to retrieve the merchandise from the warehouse. You will wait in a space that is after order taking but before checkout while your order is being picked. While you are waiting, please get your cash out. Exact change is preferred (it makes everything move faster), but change is available when required. If there are any issues picking your order, someone will help with you find alternatives or update your order.
  7. Once your merch is ready, a cashier will shout your order number, and/or hold up a sign with your order number written on it. Quickly make your way to the cashier, and complete the transaction.
  8. Enjoy!

Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 15:00-16:30 PDT


Title: Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!
Tags: IoT Village | Creator Workshop
When: Saturday, Aug 8, 15:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. Kit Cost: $140. Class Cap: 30.

SpeakerBio:  Kody Kinzie
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 16:00-16:59 PDT


Title: MeshLens: Security Profiling at Scale
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

This is a sit down discussion in a more casual conversational format.

In modern, enterprise-scale microservice architectures, answering the fundamental questions—"What services exist?", "What do they actually do?", and "How are they exposed?"—is a monumentally complex task. While static API definitions exist, the actual runtime paths, authentication gates, and data flows of production services frequently drift from their documented schemas. Traditional security and asset-discovery tooling relies on siloed static code analysis or passive network sniffing, failing to bridge the gap between network-level routing and actual source code behavior.

This talk introduces MeshLens, an automated system designed to achieve semantic understanding of RPC and HTTP endpoints at scale. MeshLens acts as an automated mapping engine, tracing the lifecycle of an API call from the internet edge, through API gateways and proxies, down to the container orchestrator, and ultimately to the exact lines of source code executing in production.

By combining static code analysis, semantic compiler graphs, and runtime metadata, MeshLens builds a unified service-to-source dependency map and extracts security-relevant metadata labels that can be leveraged for downstream security decision-making. We will walk through the design and implementation of MeshLens, demonstrating how it uses graph-based queries to stitch together heterogeneous data sources like semantic code graphs (e.g., Kythe/LSIF), container specs, and network routing configurations. Finally, we will show how MeshLens systematically eliminates configuration drift and access control ambiguities across complex distributed environments.

As security and platform teams struggle to manage sprawl in cloud-native environments, static asset catalogs and simple pattern-matching scanners are no longer sufficient. The security industry must move toward deep semantic understanding of software systems. The AI Village audience is uniquely positioned to explore how machine learning and semantic code analysis can be applied to solve these fundamental engineering visibility problems. MeshLens demonstrates a practical, production-grade approach to using large language models and code representation for automated security profiling. Rather than treating code as plain text, MeshLens leverages LLMs and semantic parsing to extract the actual operational intent of services—determining not just if a service is exposed, but what it does, how it handles data, and why it exists. This talk provides a concrete architectural blueprint for combining deterministic infrastructure mapping with semantic code understanding, providing a path toward automated, high-fidelity application security posture management (ASPM) at scale.

Speakers:Vipul Ujawane,Jigar Bhavsar,Rayden Chia

SpeakerBio:  Vipul Ujawane
No BIO available
SpeakerBio:  Jigar Bhavsar

Jigar is a Security Engineer working on AI infrastructure defense at Google, focusing on hardening unilateral access to user data and sensitive model data within Google from humans and agents. Their work includes developing tools to determine and remediate Google wide unilateral access and creating prompt-driven exploit methodologies for agentic security. Jigar is currently working on MeshLens, a system that aims to bridge the semantic gap between static service definitions and their actual runtime behavior by agentically tracing endpoints from the network edge through various layers of infrastructure down to the specific source code that handles requests.

Additionally, in the past as part of a university research group at the University of Maryland, they helped engineer genetic AI algorithms to bypass state-level censorship via targeted TLS manipulation. By combining deep infrastructure knowledge with offensive methodologies, Jigar effectively bridges the gap between theoretical AI research and practical, large-scale threat mitigation.

SpeakerBio:  Rayden Chia, Staff Security Engineer at Google

Rayden Chia is a Staff Security Engineer at Google with 13 years of industry experience, specializing in hyperscale infrastructure security and Identity and Access Management (IAM). He currently leads the architectural evolution of autonomous security posture management systems designed to protect trillions of resources across Google. Deeply focused on the intersection of AI and infrastructure, Rayden researches actionable security patterns to harden multi-agent workflows against complex threats like prompt injection, credential leaking, and privilege escalation. He holds an M.Eng. and S.B. in Computer Science and Engineering from MIT.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Saturday - 11:00-11:45 PDT


Title: Meshpocalypse: Building Your Own Off-Grid Hacker Network
Tags: DCNextGen | Creator Event/Activity | Youth
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Join Adventures of Illya for Meshpocalypse! The internet goes down. Cell towers die. How do hackers still talk? In Meshpocalypse, we’ll use tiny radios and cheap hardware to build a mini off-grid network right in the room. You’ll learn how mesh networks work, try out Meshtastic, and send messages without Wi-Fi or cell data. Each attendee will help build and keep their own radio node device so they can keep experimenting after DEF CON. No experience needed. Basic tech comfort helps but isn’t required. Defcon and I will provide all radios. Each attendee should bring a small USB-C power source (like a power bank or USB-C wall adapter) to power their device. Only 30 radio units available, first come first served.

SpeakerBio:  Adventures of Illya
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Saturday - 15:00-15:50 PDT


Title: Meshtastic Beasts and Where to Find Them
Tags: Ham Radio Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:50 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

Meshtastic is an open-source LoRa mesh used off-grid by preppers, hikers, event organizers, and amateur radio operators, and increasingly for protest logistics, disaster response, and other high-stakes comms, usually where people assume their traffic is private and their neighbors are who they claim to be. Those two assumptions are the subject of this talk. A shared channel key buys confidentiality for everyone who holds it and nothing else: not message integrity, not sender identity, not header privacy, not availability. The default key ships with every node, so for much of the mesh the wall is not there at all. None of this is a flaw. It is the threat model of a protocol built for simple, low-power text between people who already trust each other, and the talk treats it that way.

To make that concrete, we hunt four beasts, each shown live. The Impersonator forges messages and node identities the mesh accepts as real, through AES-CTR ciphertext forgery and firmware-level source-ID spoofing. The Eavesdropper reads who is talking, when, and the shape of the network from cleartext headers with no key, and their location too on any channel still running the default key. The Saboteur breaks delivery for a chosen target by dropping its packets, rewriting hop limits, or decrypting, modifying, and re-encrypting traffic in transit. The Swarm exhausts the node database, only about a hundred slots on the boards we run, with ghost nodes and poisons the public map through the MQTT bridge. The active attacks run on a custom firmware fork whose features toggle at runtime and default to safe, with an on-device KILL ALL that resets everything to safe, so the live demos stay penned in our own isolated mesh. For the HAMs there is a sharper cut: licensed mode sets your callsign and transmits in the clear, and a callsign maps through public FCC records to a name and often an address, so a by-the-book node beacons your legal identity and rough location to a village full of people who can direction-find it. The point is not the regulation, it is the consequence.

We also tell an honest story about how fast this came together: two developers who do not write firmware for a living built the firmware fork, a Python toolkit, and custom device-UI panels in about 16 working days (well, evenings) with heavy AI assistance. The one part that did not yield was the hardware, a radio regression that took old-fashioned diagnosis and a version pin, not a cleverer prompt. The attacker's effort floor collapsed; the hardware did not care, and that asymmetry applies to every volunteer-run protocol. So we close where it matters, with an opsec playbook drawn straight from the beasts: change the default key, verify identity and content out of band, assume broadcast, do not stake life-safety on availability, and match the tool to the threat (Meshtastic bought simplicity and adoption, Reticulum offers cryptographic identity and authenticated encryption by default, MeshCore sits between). Credit where due: Meshtastic already ships public-key DMs and signed admin messages, with cryptographic node identity in progress, and our hardening is offered as support for that trajectory, not a homework list for volunteers. Come find the beasts, then learn to live alongside them.

Meshtastic does exactly what it says: it carries your text off-grid to whoever shares your channel key. The risk is what people assume it does on top of that. The mesh does not keep your secrets and does not vouch for your neighbors, and a growing number of people are betting real stakes on both, using it for protest logistics, disaster response, and off-grid safety where "trusted friends on a channel" is exactly the wrong threat model. We go looking for the beasts that live in that gap, impersonation, forgery, silent packet-dropping, traffic analysis, and node-database floods, each shown live on a real mesh with a custom firmware fork and a Python toolkit. The uncomfortable part is how little it took: two developers who do not write firmware for a living built the whole offensive stack with AI assistance in about 16 days of evenings. This is not a dunk on Meshtastic. It is a field guide to its actual threat model, and to operating like you know the difference.

SpeakerBio:  Scott Thompson

Scott Thompson, KF5CPY, is a Cloud Architect for a motorsports team by day and a compulsive tinkerer by night, with a home lab full of Raspberry Pis, SBCs, and a backlog of HackerBox projects that will absolutely get soldered eventually. He earned his Technician license in 2019 for the most practical reason possible: surviving a back-country trip into the New Mexico desert without cell service. He has spent most of his career security-adjacent, doing the kind of remediation work that gives you strong opinions about how things break. This is his first conference talk.


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Saturday - 14:00-14:30 PDT


Title: Microsoft and Amazon are my Favorite C2 Providers
Tags: Adversary Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Cloud relay services are the perfect C2 infrastructure, and most organizations cannot block them without breaking legitimate business operations.

This talk presents a comprehensive offensive analysis of three abuse vectors across Microsoft Azure and Amazon Web Services, weaponizing cloud services that enterprises depend on daily for command and control, lateral movement, and persistent access. We target Azure Relay Bridge, AWS IoT Secure Tunneling, and AWS IoT Core MQTT, services whose endpoint domains (*.servicebus.windows.net, *.iot.amazonaws.com) enterprises cannot blocklist without crippling legitimate business operations.

I'll demonstrate that these are not isolated findings but instances of a repeatable pattern: cloud relay weaponization. Any cloud service that brokers connections through trusted infrastructure, requires only outbound HTTPS, and shares domains with business critical services is a candidate for C2 abuse. I'll present the methodology for identifying these services and validated attack chains for each.

For Azure Relay Bridge, the attacker deploys azbridge, a legitimate Microsoft-authored, open-source tool, to tunnel arbitrary TCP traffic through Azure's relay infrastructure, appearing as standard HTTPS to *.servicebus.windows.net. It installs as a persistent system service across Windows, Linux, and macOS. The abuse here is trust in Microsoft's infrastructure and shared service domains, not a pre-existing binary on the host.

For AWS IoT, I'll present two complementary techniques. First, Secure Tunneling: the attacker uses their own AWS account to create encrypted WebSocket tunnels via the officially published localproxy binary, generating no control plane API activity in the target's CloudTrail. I validated this with Sliver C2 across three protocols (mTLS, HTTPS, HTTP), but discovered operational limitations including 12 hour tunnel maximums, token rotation complexity, and IoT optimized bandwidth caps that constrain persistent C2 use. These limitations led to the second technique: weaponizing AWS IoT Core MQTT as a full C2 transport channel using X.509 mutual TLS authentication, which eliminates the tunnel lifetime and bandwidth constraints entirely.

I'll also present custom Mythic C2 agents (Poseidon for Linux/macOS, Apollo for Windows) with transport profiles for both Azure Relay and AWS IoT MQTT, all end to end validated on AMD64 and ARM64. Live demonstrations showcase complete attack chains: Mythic beaconing through Azure Relay, lateral movement via IoT Secure Tunneling, and persistent C2 over IoT Core MQTT, all through traffic indistinguishable from legitimate cloud service usage.

Attendees leave with released Mythic C2 agents and profiles for Azure and AWS, a framework for identifying additional cloud relay services, detection engineering guidance mapped to the Pyramid of Pain, and actionable defensive hardening for both cloud providers.

SpeakerBio:  Robert Pimentel, Hacker Hermanos

Robert is a seasoned offensive security professional with more than a decade of experience in Information Security.

He began his career in the U.S. Marine Corps, where he worked on secure telecommunications. Robert holds a master's degree in Cybersecurity, numerous IT certifications, and a background as an instructor at higher education institutions like the New Jersey Institute of Technology and American University.

Robert is committed to sharing his knowledge and experiences for the benefit of others. He enjoys Brazilian steakhouses and cuddling with his pugs while writing Infrastructure as Code to automate Red Team Infrastructure.

Robert is the Director of Offensive Security at Humana, Inc.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 13:00-13:30 PDT


Title: Minimal by Design: Building Hardened Near-Zero-CVE Container Images
Tags: Demo 💻 | Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:30 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Most production containers ship on base images with dozens of known CVEs — debian:latest currently sits at 127. Patches take weeks. Your compliance team isn't happy. We built "minimal" — an open source project producing 36 hardened (and adding more), distroless container images for the stack most cloud teams actually run: Python, Node, Go, Redis, PostgreSQL, MySQL, Kafka, Nginx, Prometheus, Jenkins, and more. Image runs as non-root, has no shell, ships with a signed SBOM, and is rebuilt daily so CVE patches land in under 48 hours instead of 30 days. This talk is a practical walkthrough of how you build something like this from scratch using entirely open source tools — and what could go wrong. We'll cover the toolchain: Chainguard's melange for sandboxed source builds, apko for declarative image assembly,Wolfi as the package base, Grype for scanning, and cosign for keyless signing. We'll show the CI pipeline — 60 parallel GitHub Actions jobs, native ARM64 runners, ephemeral signing keys for PRs, multi-arch manifest assembly — and the 24 automated update workflows that track upstream releases daily across GitHub tags, RubyGems, php.net, and Wolfi's APKINDEX. We'll close with live Grype scan comparisons against official Docker Hub images. The numbers are dramatic, and they make the case better than we can. Every source build is SHA256-verified, and every assembled image is tested in CI before publishing — tests for no shell, correct entrypoint, expected binaries present, services responding. Everything is open source and running in production today. If you leave this talk and build your own hardened container pipeline the next week, we've done our job.

Speakers:Kyle Quest,Ritvik Arya

SpeakerBio:  Kyle Quest

Kyle is the creator of DockerSlim, a popular tool to secure and optimize containers. His area of focus is autonomous and secure cloud-native infrastructure, sandboxing and agent security. With over two decades in security, Kyle had a chance to wear many different hats as a builder, breaker, and defender. Currently reverse engineering coding agents like Claude Code for fun AND profit ;-)

SpeakerBio:  Ritvik Arya

Ritvik Arya is an Application Security Engineer at Amazon Web Services specializing in cloud security, container security, and offensive security research. His work focuses on securing large-scale cloud-native applications, building hardened container ecosystems, and developing scalable AppSec automation and vulnerability discovery tooling.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Mission: Compromised - Hacking a Satellite from the Ground Up
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Ever wondered what it takes to hack a satellite? At this hands-on station, you'll step into the role of an attacker targeting a CubeSat-class spacecraft and its ground control station — all running in a safe, fully isolated environment.

Working against a live mission control system (OpenC3 COSMOS / Yamcs) and a spacecraft simulator, you'll follow an attacker's kill chain across multiple layers — from reconnaissance and ground station compromise all the way to the spacecraft itself. Where does it end? Let's just say the mission doesn't survive. Come find out how. Every step is paired with the real-world defense that would have stopped it - so you'll leave understanding both how these attacks work and how space systems defend against them. Whether you're new to space security or already deep in the field, come try it out, break a satellite (safely!), and see the attack surface of modern spacecraft up close.

It will take approximately 15-30 minutes to work through this hands-on demo and guided exercises. You can watch attacks demonstrated by our team, then try guided scenarios yourself using real CCSDS space protocols, RF concepts, and industry mission control tooling. A live mission dashboard will reveal the spacecraft's fate as the scenario plays out.

No prior space experience required - all skill levels welcome. We recommend you bring your own laptop the hands-on portions. A laptop with GNU Radio will let you dig into the RF challenge, and a Kali Linux setup or your equivalent pentesting toolkit are recommended for the more advanced challenge.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 10:00-17:59 PDT


Title: Mobile Hacking - Informal CTF
Tags: Mobile Hacking Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 10:00-17:59 PDT


Title: Mobile Hacking Community - Open
Tags: Mobile Hacking Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs.

Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills.

Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain.

Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment.

Prerequisites:


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 10:00-10:45 PDT


Title: Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF
Tags: DEF CON Demo Labs | Advanced | Cloud | Defense/Blue Team | DEF CON Demo Labs
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Container security tools observe behavior (eBPF) and enforce policy (BPF-LSM, AppArmor, Seccomp). But the translation between observation and enforcement is manual and incomplete. We present the first tool that treats this translation as a compilation problem. Built in Rust with the Aya eBPF framework, three monitoring modules serve as compiler frontends feeding a normalized behavioral IR. Optimization passes operate on this IR: pattern classification, rule deduplication, dead rule elimination, conflict detection, and cross-category dependency linking. The backend compiles optimized IR into BPF-LSM enforcement rules across three LSM hooks: security_file_open, security_bprm_check_security, and security_socket_connect. Enforcement is default-deny: any operation not in the compiled profile is blocked. We demo end-to-end: a container is profiled, the profile compiled through the pipeline, and enforcement blocks unauthorized file access, process execution, and network connections at the kernel level. Zero manual policy writing. We document the friction points where monitoring context diverges from enforcement context. No existing tool, including vArmor and KubeArmor, implements this compilation architecture with a true IR, optimization passes, and multi-category LSM enforcement.

SpeakerBio:  Buğrahan Yücel

Buğrahan Yücel is a software engineer at a SaaS company in Turkey, where he works on infrastructure security. He currently builds eBPF-based behavioral profiling and enforcement tooling in Rust using the Aya framework. This is his first DEF CON presentation.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: MOUSE Runner & Flappy Drone
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

How High Can You Make a Satellite Jump? Can You Fly a Drone Around Aliens and Rockets?

Put your action-hero reflexes and hand-eye coordination to the test as you battle fellow DEF CON attendees for the top scores in MOUSE Runner and Flappy Drone. The highest scores on Friday and Saturday will earn a special prize. Stop by our booth to learn more, show off your button-mashing skills, and prove you're the ultimate space cyber pilot.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 20:00-23:59 PDT


Title: Movie Night
Tags: Event
When: Saturday, Aug 8, 20:00 - 23:59 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 12:00-12:45 PDT


Title: MSCodePhish: Redeem Your Coupon. Surrender Your Session
Tags: Intro/Beginner | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

MSCodePhish is a red‑team toolkit that turns Microsoft’s Device Code OAuth flow into an embeddable phishing primitive that works inside any lure (e.g., “grab your coupon,” “unlock access,” etc.). Instead of pre‑generating device codes and racing against the usual 15‑minute timeout, MSCodePhish exposes a simple API endpoint that phishing pages can call via JavaScript (XHR/fetch) at the exact moment a victim opens the page. The tool then generates a fresh device code on demand, returns it to the phishing page (e.g., rendered as a “coupon code”), and instructs the user to complete the login on the legitimate Microsoft device login portal using that code.

Behind the scenes, MSCodePhish continuously polls Microsoft’s token endpoint for that device code and, once the victim finishes authentication, captures the resulting refresh token and related claims (tenant, user, etc.). From its web UI, operators can track active campaigns, monitor which lures are converting, and use captured refresh tokens to request new access tokens for different resources (ARM, Key Vault, Graph, Storage, or custom scopes) in real time. Because the code is generated only when the phishing HTML is actually loaded, MSCodePhish effectively sidesteps device‑code expiration issues and enables more realistic, flexible phishing flows that closely mimic

Speakers:Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla

SpeakerBio:  Raunak "Trouble1" Parmar

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.

SpeakerBio:  Chirag "3xpl01tc0d3r" Savla

Chirag Savla is a Cyber Security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. He prefers to create open-source tools and explore new attack methodologies in his leisure. He has worked extensively on Azure, Active Directory attacks, defense, and bypassing detection mechanisms. He is an author of multiple Open Source tools such as Process Injection, Callidus, etc. He has presented at multiple conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 20:00-20:59 PDT


Title: Music - Genre: Drum & Bass
Tags: Entertainment
When: Saturday, Aug 8, 20:00 - 20:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  RELAY

With over 25 years of experience, RELAY is fluent in the language of electronic music, effortlessly blending genres ranging from house, trance and techno to bass music, electro and drum and bass while also incorporating turntablism. His sets promise to keep the vibe alive.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 22:00-22:59 PDT


Title: Music - Genre: Drum & Bass
Tags: Entertainment
When: Saturday, Aug 8, 22:00 - 22:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  Miss Jackalope

Miss Jackalope is DEF CON's Resident DJ. She's played all sorts of awesome events, parties, and infosec conventions. Her current faves are drum and bass and electro. Usually she is spotted getting abused by her cat while trying to spin on her weekly Twitch show (twitch.tv/missjackalope) and in the DC Vendor room selling her legendary merch. She is the DEF CON Arts and Entertainment evangelist and leader of the Mighty Jackalope Army. She also has a massive pile of claw game fun and Twitch replays on her Youtube channel! (youtube.com/@MissJackalope) Come join the party!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 23:00-23:59 PDT


Title: Music - Genre: Drum & Bass
Tags: Entertainment
When: Saturday, Aug 8, 23:00 - 23:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  Syntax + Luna

Syntax has been DJing almost as long as he’s been hacking, experienced in a variety of genres and currently obsessed with Drum & Bass. Luna started joining Syntax on stage in the last few years by mixing their visuals with the same live intensity. Together they perform at hacker cons across the US—plus other shows in between—always blasting earholes and bouncing eyeballs to the best bass-y beats.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 19:00-19:59 PDT


Title: Music - Genre: Dubstep
Tags: Entertainment
When: Saturday, Aug 8, 19:00 - 19:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  ZipZapZop

Clark ov Saturn, Space Trucking Mogul, aka ZipZapZop has been releasing music off and on since the late 1980's. Notable projects have included pH10 (Terraformat Records, Europe tour with Trumystic Sound System 1999), Socks and Sandals (Microcosm Music, Unfoundsound Records) and resident DJ at Halcyon's weekly Deep Unda Brooklyn Undercity party in NYC in the early 2000's. After a long break focusing on family, an educational technology career and earning a doctorate, Saturn returned to music production with several projects since 2021: ZipZapZop, Pill Hill Deans, Luther VanGross and DubRatz, each featuring a variety of sounds, sub pressure bass-oriented music styles and friends, with the goals of fun, travel and liberation via creativity. More info, videos, links & connections at ZipZapZop.com


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 21:00-21:59 PDT


Title: Music - Genre: Nerdcore
Tags: Entertainment
When: Saturday, Aug 8, 21:00 - 21:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  Dual Core

Dual Core is an international hip hop duo. Drink all the booze; hack all the things!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 00:00-00:59 PDT


Title: Music - Genre: Trance
Tags: Entertainment
When: Saturday, Aug 8, 00:00 - 00:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  𝗔𝗙𝗧Ʃ𝗥↡𝗚𝗟Ф𝗪

AfterGlow is a Los Angeles-based DJ known for his electrifying sets that span across a wide range of EDM genres. Captivating crowds with his high-energy performances and infectious beats. Whether performing at intimate venues, events, or clubs, his sets leave a lasting impression that are sure to make you a fan.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 10:00-18:59 PDT


Title: Music - SomaFM
Tags: Entertainment
When: Saturday, Aug 8, 10:00 - 18:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:

SomaFM is back in the Chillout Lounge– just off the atrium at the south entrance (W107-W109). SomaFM DJs including kampf, Rusty, Merin MC, djddead and special guests will provide the perfect soundtrack for hacking or relaxing. Stop by and say hello, and pick up a 2026 limited edition sticker. We'll also be broadcasting live on https://somafm.com/live/ – And did we mention, we have stickers!?


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Nebula Showdown: Space Systems Security CTF Adventure
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Join the Aurora Alliance in their critical mission to thwart the notorious Nebula Syndicate and save the Earth! The Syndicate threatens to destroy historic monuments around the world with their Space Laser unless their demands are met. Do you have what it takes to dismantle their malevolent plans and deorbit a menacing space threat?

This entry-level CTF kicks off as soon as the village opens - no pre-registration necessary. Just bring your laptop and your go-to cybersecurity tools – Wireshark, NMAP, and any FTP client you prefer. We know the DEF CON wifi can be unpredictable, so this CTF will be local only to the Aerospace village via an isolated local range. The CTF is designed to be completed in under an hour, making it perfect for a quick yet engaging challenge. Team collaboration is encouraged, and if you encounter obstacles, numerous hints are available to guide you. There are no penalties for using hints. Our goal is for you to learn something new and make it all the way through the CTF. Excel in the challenge, and you could walk away with an exclusive CT Cubed SAO prize while supplies last.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 12:30-13:25 PDT


Title: Neotropolis: The Making of the Railgun Trackers
Tags: Radio Frequency Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 13:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Neotropolis is an annual 5-day cyberpunk festival in the California High Desert. In this talk, I'll present the technology behind the "Railgun Runner" game, which used Bluetooth Discovery Beacons and low-cost ESP32 hardware to conduct "good-enough" proximity tracking in an RF-adversarial environment. I'll demonstrate the trackers live in person, and discuss the techniques used, technical challenges and trade-offs, effective distance and calibration techniques, and how this technology can be applied to a broader set of problems.

SpeakerBio:  John O'Connor, Panasonic Avionics Corp

I'm just a hacker that loves building cool stuff and showing people how it works. Aerospace industry software engineer and radio enthusiast.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 14:00-14:30 PDT


Title: Nix Knows When the Agent Is Wrong
Tags: Nix Vegas Community | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

I built a tool to help maintainers patch nixpkgs CVEs faster. But I optimized the wrong thing.

The tool - Vulnpatch, is a dashboard. It pulls together CVE intelligence, triages by what is actually being exploited, gives the maintainer the context they need and gets out of the way. The assumption underneath it was that the maintainer is the bottleneck: speed up the workflow and packages get patched faster.

I no longer believe that assumption. I was already building Vulnpatch to automate the remediation work when Mythos was announced, and it undercut the premise. Building a product to do what a frontier model could now do on its own was the wrong problem to be solving.

The difficult part was never automating the work. It is making an agent's output something a volunteer on the security team can actually trust. The work is the evidence: which package is actually affected, which upstream commit fixes it, what the new hash is, whether it still builds, whether the tests still pass and whether a maintainer has any reason to trust it. And that is before the non-trivial cases: the patches that are not simple version bumps or hash updates.

This is a talk about that shift. I will discuss Vulnpatch and Trace, an agent-owned nixpkgs fork that produces signed, reproducible CVE evidence bundles instead of drive-by pull requests. And I want to make one argument I think is worth taking seriously: Nix is unusually well-suited to AI agents because it provides strong automated feedback. Reproducible builds and passthru.tests give agents an objective verifier for many changes, whereas most repositories offer much weaker validation.

Patches are cheap. Proof is not. I will show what it takes to make an agent's work auditable enough to be worth a maintainer's time and I hope, to persuade maintainers that agents belong in their workflow. The workflows we built for human-only contribution will not survive contact with agents unchanged.

SpeakerBio:  Jason Odoom

"Thing Doer"


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 10:00-10:30 PDT


Title: Nix Vegas Opening Ceremony
Tags: Nix Vegas Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Kickoff and opening of the Nix Vegas space on Saturday.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Saturday - 11:00-11:59 PDT


Title: No Entry: Badge Access Denial on Demand
Tags: Physical Security Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Badged access is one of the most common security controls to enforce 2 factor physical access. In this presentation we will remove this on demand and demonstrate forcing access verification to a lower tier as well as preventing others from utilizing badged access cards. What's even better is you can build this yourself for under $100, and we'll show you how.

SpeakerBio:  Andrew Quill, FD Contractors, LLC

Andrew Quill has done over 18 years of federal and military service, performing roles ranging from signals analysis and waveform planning, to digital forensics and incident response. Andrew is a frequent contributor to the research community and avid dabbler in expanding technical applications across implied boundaries.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 16:50-17:20 PDT


Title: No Jailbreak Required: Pwning AI Agents Through the Tools They Trust
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Saturday, Aug 8, 16:50 - 17:20 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Your AI agent approved the vendor, sent the status email, processed the payment, and BCC'd customer PII to an attacker's dead drop. One turn, no jailbreak, no prompt injection of the user. The MCP tool metadata the agent trusted had been quietly rewritten upstream, and from the model's view it was just doing its job.

A live attack-to-defense demo on OWASP FinBot CTF, a deliberately vulnerable multi-agent platform (Juice Shop for agentic AI) with real MCP agents running onboarding, compliance, and payments.

Act I, Kill Chain: a poisoned tool description with security-framed exfil logic no model refuses. One admin request triggers vendor lookup, PII harvest, BCC exfil, and payment. Output stays clean.

Act II, Guardrail: poison stays. We deploy a ~40-line before_tool webhook that inspects invocations live. Benign calls pass, exfil dies on the wire.

Tool metadata sits inside the agent's trust boundary, and few pin or diff-review it. Clone the CTF and keep pwning.

Speakers:Helen Oakley,saikishu

SpeakerBio:  Helen Oakley

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.

SpeakerBio:  saikishu

Venkata Sai Kishore Modalavalasa is Chief Architect & Engineering Leader at Straiker, building AI security products for AI-native apps at scale. With 15+ years in cybersecurity and distributed systems, he scaled Cyberfend to acquisition by Akamai, where he led bot detection and web security engineering. He’s an OWASP author contributing to AI Exchange, AIBOM, Top 10 for Agentic Applications, OWASP GenAI Security Project, creator and co-lead of OWASP FinBot CTF, and holds multiple security patents.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 11:00-11:30 PDT


Title: No One Makes It Alone - Community as the Ultimate Security Control
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

When systems fail and plans fall apart, survival depends on people. This talk explores why resilience, recovery, and critical infrastructure security ultimately rely on community, agility, shared knowledge, and mutual support.

SpeakerBio:  Kristen Sanders
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:00-10:30 PDT


Title: No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Every day, developers and ML engineers pull containers and models from OCI registries without a second thought. What if that pull, no privileges, no special access, could be turned into host enumeration, credential theft, remote code execution, or even a container escape?

We found a class of vulnerabilities that spans the OCI ecosystem. Not just in registry clients, but in the underlying technologies they feed into, container runtimes, ML inference engines, and more. By standing up malicious registries and abusing how these tools handle registry responses, we turned routine pull operations into attack primitives. The result: multiple critical vulnerabilities across widely used tools and platforms, including SSRFs, arbitrary file reads for credential exfiltration, and a novel path to escaping a Docker container to the underlying host.

What do they all have in common? They all either use or offer OCI services through a client or a registry. This talk walks through the different attack paths we’ve found, how they were discovered, trends we’ve noticed across multiple products, proof-of-concepts, and what it means for the ecosystem moving forward.

Speakers:David "davidrxchester" Rochester,Nicholas "gouldnicholas" Gould

SpeakerBio:  David "davidrxchester" Rochester, Booz Allen Hamilton

David Rochester is a penetration tester by day, where he focuses on web, cloud, network, and Active Directory security. He earned his B.S. in Computer Science from Clemson University and is currently pursuing a master's at the University of Texas at Austin. He holds the OSCP, OSWE, and CRTO, along with several cloud security certifications. As an independent security researcher, his vulnerability research and exploitation work has produced eight CVEs to date, including findings in Docker and Ollama.

SpeakerBio:  Nicholas "gouldnicholas" Gould, Booz Allen Hamilton

Nicholas Gould is a Red Team Operator & Penetration Tester, as well as an independent security researcher specializing in offensive, cloud, application, and container security. He has discovered or co-discovered multiple CVEs across containerization, proxies, IaC tooling, and programming language runtime/interpreter implementations. His recent research focuses on AI / ML infrastructure security, and when not hunting for vulnerabilities, he builds agentic AI tools for offensive and defensive security operations.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: No Stupid Questions
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Ongoing AMA booth with volunteers and speakers answering all your DEF CON and cyber questions


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Saturday - 11:30-11:59 PDT


Title: Nuclear Industrial Control System Simulation (NICSSIM) aka Multi-Agent Cyber Defense Framework for Distributed Nuclear Operational Technology Systems
Tags: ICS Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

In-person live demonstration (talk plus live demo), 30 minutes

Abstract: As small modular reactors (SMRs) are deployed as distributed energy resources, their interconnected digital infrastructure expands the cyber attack surface across nuclear operational technology (OT) in ways that traditional, rule-based security mechanisms were never designed to address. NICSSIM (Nuclear Industrial Control System Simulation) is a modular ICS testbed that models, deploys, monitors, and analyzes an SMR fleet in a fully software-based environment, so security research can be conducted with no live infrastructure at risk.

This demonstration shows NICSSIM end to end: a human-aware multi-agent architecture in which a supervisory agent coordinates a read-only vulnerability-analysis agent and a remediation agent under deterministic safety guardrails and an independent safety auditor, with strict separation between analysis and execution that keeps human operators as the final decision-makers. Attendees watch agents and operators detect, analyze, and respond to live attacks across 1 to 3 reactor fleets, alongside results showing up to a 96 percent response success rate with ISA/IEC 62443 compliance verification, and the latency and cost trade-offs measured across seven models from four providers.

Presentation Outline/Walkthrough:

Why nuclear OT, why now. SMRs are deployed as distributed energy resources rather than large centralized plants, which tightens the coupling between cyber and physical processes and widens the attack surface across an interconnected fleet. Traditional defense-in-depth, built on the Purdue model, firewalls, and intrusion detection, provides rigidity rather than adaptability and cannot reason about a live fleet in real time. 
The gap and the testbed. What is missing is a single environment that combines high-fidelity ICS simulation, coordinated multi-agent reasoning, and human-aware control. Presenters introduce NICSSIM: SMR digital twins built on ICSSIM and Docker, aligned to the Purdue model, generating continuous telemetry, with no live infrastructure at risk.

Architecture walkthrough and Live UI. Live interface, deploys a modular fleet, and shows the digital twins and live operational data. Display of human-aware multi-agent design: a human-in-the-loop gateway, a supervisory agent that serves as the single control point, a read-only vulnerability-analysis agent, a remediation agent, and an independent safety auditor, with deterministic guardrails and enforced separation between the analysis environment and the target ICS environment. 
Live attack and defense. Presenters “deploy” 1-SMR and 3-SMR fleets and run scenarios live: an unauthenticated Modbus write command evaluated for correct risk severity, a safety-threshold violation such as a request to push the primary coolant outlet temperature past its hardcoded limit, which the system must reject, and an ISA/IEC 62443 compliance mapping in which a finding must map to the correct regulatory sub-section rather than offer vague advice. The audience sees the guardrail reject an unsafe command, the safety auditor catch a flawed finding, and the forensic audit trail a human operator would review. 
Results and trade-offs. Response Success Rate by fleet size and model, from 0.96 for a single SMR down to 0.91 for a three-reactor fleet with the highest-reasoning model, alongside the latency, token, and cost trade-offs measured across seven models from four providers. The takeaway is that higher-reasoning models buy accuracy at the cost of latency and dollars, a trade-off that matters for real OT deployment decisions.
 Dual-use and responsible design. The framework establishes defensive elements through isolated, simulation-only boundaries, deterministic guardrails, and required human authorization for any non-read-only action, while gating system access using IEC 62443 security levels. Conversely, its offensive elements reside in the embedded red team capabilities that possess the dual-use potential to identify exploit vectors in nuclear Operational Technology (OT) environments. To ensure a responsible design, this dual-use capability is set for credentialed security researchers operating within sanctioned, simulated training exercises under institutional oversight and strict operational containment.

Speakers:Carmela Gonzales,Brian G. Rodiles Delgado,Marco A. Alanis Komiyama

SpeakerBio:  Carmela Gonzales

Carmela Gonzales, M.Eng., is a Ph.D. candidate in Space Cybersecurity focused on the security and resilience of cyber-physical systems in space and critical infrastructure environments. Her work and research bridge technical and policy perspectives in emerging technologies across academia, government, and industry. She is the founder of Astryx Research Group, a DEF CON Aerospace Village volunteer, a Space Beach Law Lab Fellow, and a Member-at-Large for the American Society of Mechanical Engineers (ASME) Los Angeles Section. She contributes to workforce development as a teaching fellow with the National Cybersecurity Training and Education Center (NCyTE), conducted lab validation for Cyber Security Forum Initiative (CSFI), and co-founded Women in Cybersecurity at George Washington University (WiCyS GW). Recognized through scholarships from The Diana Initiative, Women in Security and Privacy (WISP), Women in Cybersecurity (WiCyS), and Out in STEM (oSTEM), she is committed to advancing women in cybersecurity.

SpeakerBio:  Brian G. Rodiles Delgado

Brian G. Rodiles Delgado is a Cybersecurity Management MBA candidate at the University of West Florida and a cybersecurity professional at Capital One in Dallas, Texas. He has presented research on software-defined networking, federated learning, and cybersecurity for critical infrastructure at ACM and IEEE conferences in Norway, Spain, and the United States, and has contributed to U.S. Department of Energy projects through Dr. Deepak Tosh's TRUstworthy CYBER system (TRUCYBER) laboratory at the University of Texas at El Paso. He is one of UTEP's first Barry Goldwater Scholars and a recipient of the Black Hat and Google Generation scholarships. He is recently selected as a 2026 scholar for The Diana Initiative Hacker Summer Camp.

SpeakerBio:  Marco A. Alanis Komiyama

Marco A. Alanis Komiyama is a researcher at the University of West Florida (Lewis Bear Jr. College of Business) and a co-developer of NICSSIM. He presents the platform's live demonstration, including the deployment of the simulated reactor fleet and the multi-agent attack and defense workflow.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 11:30-12:50 PDT


Title: OASIS: Prompt to Pwn
Tags: Noob Community | Creator Workshop
When: Saturday, Aug 8, 11:30 - 12:50 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

AI went from a tech toy to critical infrastructure overnight, but measurement is lagging behind. This 90-minute session skips the theory to show how AI actually performs using OASIS - a free, independent benchmarking tool you can run right from your phone.

SpeakerBio:  Marshall Livingston
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Saturday - 17:00-17:45 PDT


Title: Objectively Awesome Robots: A Hands-On Introduction to Python Classes and Objects
Tags: DCNextGen | Creator Event/Activity | Youth
When: Saturday, Aug 8, 17:00 - 17:45 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Python has rules and structure like any language, but we’re skipping the boring grammar lesson. You’ll jump straight into building a robot that appears on your screen and comes to life as you code it. As you customize and experiment, you’ll naturally learn classes and objects by using them to define your robot’s appearance and behavior. At the end, we’ll finish with a Kahoot challenge where you’ll test your new skills and compete for prizes.

Requirements/Prerequisites: A laptop with a USB port (for workshop files) Python 3 installed and able to run VS Code or another IDE that supports Jupyter Notebooks Some basic Python experience is helpful, but not required, we’ll provide a cheat sheet to help you along

SpeakerBio:  4ng3lhacker
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 16:00-17:59 PDT


Title: OCIguana - A vulnerable-by-design OCI lab
Tags: Cloud Village | Creator Event/Activity | Attack | Tools
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) A - Map

Description:

This workshop will discuss Oracle Cloud Infrastructure (OCI) and its unique take on IAM in [kcomparison to other major cloud providers. We will explore how OCI's policy language, dynamic groups, and principal types (instance principals, resource principals) create an attack surface that differs from other major cloud providers. Attendees will also get hands-on experience with attacking OCI environments by completing a vulnerable-by-design lab, designed to highlight the unique design decisions of OCI and its IAM system in general.

SpeakerBio:  Eli Shparaga

Eli Shparaga is a Security Researcher in XM Cyber, specializing in cloud and AI security. His work involves identifying attack vectors and adversarial tactics in major cloud providers. Before that, Eli worked as a red teamer, helping secure multiple Fortune 500 companies.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 13:00-13:59 PDT


Title: Octopus Game - Booth Battle #3: The Marbles Match
Tags: Octopus Game | Contest
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Octopus Game - Booth Open
Tags: Octopus Game | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 17:00-17:59 PDT


Title: Octopus Game - The Final Booth Battle
Tags: Octopus Game | Contest
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Come to the final booth battle!

Later, at the Octopus Game Party: ties will be resolved, and winners and prizes will be announced!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 13:00-10:59 PDT


Title: Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed)
Tags: Octopus Game | Contest
When: Saturday, Aug 8, 13:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 17:00-17:59 PDT


Title: OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

LiteLLM is the most popular open-source AI gateway, deployed across a third of cloud environments. Organizations route all their LLM traffic through it, trusting it with API keys for every provider, every prompt and response, and connections to external tools via MCP. We broke every layer of its security model.

We present three independent attack vectors, an authentication bypass in the MCP layer, a root-level RCE through sandbox escape, and an SSRF path to cloud credentials, that chain from zero credentials to full cloud infrastructure compromise. We validated every attack at internet scale across thousands of real-world instances and found that nearly 1 in 10 accepted default credentials or required no authentication at all.

Beyond the individual findings, we examine the broader security patterns emerging across AI infrastructure and what they mean for organizations adopting AI gateways as core infrastructure.

SpeakerBio:  Yaara Shriki, Wiz (Google)

Yaara Shriki is a Threat Researcher at Wiz, specializing in emerging threats in cloud environments and attack surface analysis. She explores novel ways to integrate ML and NLP into security research and investigates new attack vectors in cloud and AI infrastructure. Yaara is currently pursuing an MSc in Computer Science at Tel Aviv University.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 12:00-12:59 PDT


Title: Oh hai! Meet Jason Haddix
Tags: OWASP Foundation | Creator Event/Activity
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Ever spotted someone from InfoSec Twitter in the wild and chickened out on saying hi? Yeah, us too. Come embrace the social awkwardness in a safe space where everyone's just as nervous as you are - but also just as excited to connect. We're gathering the chronically online, the terminally technical, and even the legend himself, @JHaddix. Haddix is dropping by for an hour, come and say hai!

SpeakerBio:  Jason "jhaddix" Haddix, CEO and "Hacker in Charge" at Arcanum Information Security

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 11:00-11:59 PDT


Title: Oh hai! Meet Tanya "SheHacksPurple" Janca
Tags: OWASP Foundation | Creator Event/Activity
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Ever spotted someone from InfoSec Twitter in the wild and chickened out on saying hi? Yeah, us too. Come embrace the social awkwardness in a safe space where everyone's just as nervous as you are - but also just as excited to connect. We're gathering the chronically online, the terminally technical, and even the legend herself, SheHacksPurple (Tanya Janca). Tanya is dropping by for an hour, come and say hai!

SpeakerBio:  Tanya "SheHacksPurple" Janca

Tanya Janca, known online as SheHacksPurple, is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec Station Podcast.

Over 29 years in the industry Tanya has received numerous awards, spoken at events worldwide, and built a reputation as one of the most approachable and influential voices in application security. She has trained thousands of developers and security practitioners through her academies and live programs. Her experience includes counter-terrorism work, leading security for the 42nd Canadian federal election, as well as building and securing a vast range of applications. Today, she is recognized internationally as a leading authority on the security of software.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 16:30-16:59 PDT


Title: On the Weaponization of Voting Channels
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 16:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

The main purpose of any election is to deliver a peaceful resolution to the civic battle between stakeholder groups about power and governance with the goal to guarantee a peaceful transfer of power. A well-working democracy is resilient against false narratives and marked by losing parties to concede and accept the outcome of the election. Election legislation defines how an election should be run, who is eligible to vote, how voter eligibility is verified, which voting channels are offered to voters to cast their vote, what constitutes a valid vote, how votes are tallied, how results are transmitted, how the results are audited and how disputes are resolved.

Different voting channels improve accessibility and comfort, however they can provide grounds for false narratives before and after an election and thus strain public confidence. Examples from the US include in-person voting, early voting, in-person absentee voting, or mail-in voting. Experiences from Estonia offering only two voting channels, in-person voting and Internet voting, have demonstrated a worrying trend of voting channel weaponizations, which has led to a noticeable drop in voter confidence for the first time since Internet voting was introduced in 2005. Politicization driven by political parties, activism, and domestic and foreign influence are to blame. Voting channels supported by election technologies are particularly exposed.

In my talk, I will discuss the anatomy of voting channel weaponization, who are the actors, what techniques are being used, how to recognize it and how to defend against it.

SpeakerBio:  Carsten Schürmann

Carsten Schürmann is a professor of computer science at the IT University of Copenhagen where he leads the Center for Information Security and Trust CISAT. His academic research focuses on cyber- and information security—with a particular interest in making elections secure and trustworthy. He has extensive hands-on experience in the election field, having worked as an election technology expert on observation missions with the Carter Center, NDI, and OSCE/ODIHR, and on assistance and training missions with IFES and OSCE. Through his consultancy, DemTech Group, he advises NGOs and international organizations on election security across the full electoral cycle. Carsten became known in the DefCon hacking community when he demonstrated vulnerabilities in the WinVote DRE voting machine at DEF CON in 2017.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Saturday - 10:00-17:59 PDT


Title: Open Q&A
Tags: Scambait Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Saturday - 14:15-14:45 PDT


Title: Operation Restoration
Tags: Maker's Village | Creator Event/Activity
When: Saturday, Aug 8, 14:15 - 14:45 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Every forgotten machine has a story—and a second chance. This talk explores the multidisciplinary maker ethos through restoration: where machining, woodworking, sewing, CAD, 3D printing, and whatever other skills you have in your toolbox come together to resurrect forgotten machines and breathe new life into once-loved objects.

SpeakerBio:  Cannibal
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 16:00-16:59 PDT


Title: OSINT for Hackers Redux
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

In this Workshop and Tactic, attendees will be exposed to and get hands-on with some of the most impactful strategies, techniques, and tools to increase the value of OSINT to their red-teaming activities. As a guided learning experience, the instructors will immerse attendees in the topic and provide numerous hands-on opportunities within just the Workshop component. In addition, the dedicated Tactic (which will be offered multiple times) will focus on building secure sock puppets (fake identities) for use in the recon and information gathering phases of red team and penetration testing operations.

Speakers:Lee McWhorter,Sandra Stibbards

SpeakerBio:  Lee McWhorter

Lee McWhorter, Owner & Chief Geek at McWhorter Technologies, has been involved in IT since his early days and has over 30 years of experience. He is a highly sought after professional who first learned about identifying weaknesses in computer networks, systems, and software when Internet access was achieved using a modem. Lee holds an MBA and more than 20 industry certifications in such areas as System Admin, Networking, Programming, Linux, IoT, and Cybersecurity. His roles have ranged from the server room to the board room, and he has taught for numerous universities, commercial trainers, and nonprofits. Lee is the SWAG Master and a Core Staff member for the Red Team Village at DEFCON; and works closely with the Pacific Hackers Association, Dark Arts Village at RSAC, Texas Cyber Summit, CompTIA, and the CompTIA Instructor Network as a Speaker, SME, and Instructor.

SpeakerBio:  Sandra Stibbards

Sandra Stibbards opened her investigation agency, Camelot Investigations, in 1996. Currently, she maintains a private investigator license in the state of California. Sandra specializes in financial fraud investigations, competitive intelligence, counterintelligence, business and corporate espionage, physical penetration tests, online vulnerability assessments, brand protection/IP investigations, corporate due diligence, and Internet investigations. Sandra has conducted investigations internationally in five continents and clients include several Fortune 500 and international companies. Sandra has been providing training seminars and presentations on Open Source Intelligence (OSINT) internationally since 2010 to federal governments and corporations.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Saturday - 16:00-16:59 PDT


Title: OSINT Search party CTF Debrief
Tags: OSINT For Good Community | Creator Workshop
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

An opportunity to ask questsions and get clarification on things that happened during the CTF.

SpeakerBio:  Trace Labs Staff
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Saturday - 17:00-17:15 PDT


Title: OSINT Search Party CTF Prize and Award Announcements.
Tags: OSINT For Good Community | Creator Event/Activity
When: Saturday, Aug 8, 17:00 - 17:15 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

Prizes and awards from the Gobal OSINT Search Party CTF will be announced.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Saturday - 10:00-17:59 PDT


Title: OSINT4Good Community - DC NextGen Content
Tags: OSINT For Good Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

Make this a stop on your DC NextGen journey, solve the challenge, and earn a digital badge!


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Saturday - 17:15-17:59 PDT


Title: OSINT4Good Sticker Swap
Tags: OSINT For Good Community | Creator Event/Activity
When: Saturday, Aug 8, 17:15 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

Bring some stickers, take some stickers. There will be some specially themed OSINT4Good stickers available only here!


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Saturday - 14:00-14:45 PDT


Title: OT Round table. Real talk on how to protect your OT spaces
Tags: ICS Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

A hosted open discussion on strategies for protecting OT with Tom Van Norman and Dillon Lee.

Speakers:Aaron Crow,Tom VanNorman,Dillon Lee

SpeakerBio:  Aaron Crow, PrOTect IT All

Aaron is the host of the #2 OT Security Podcast "PrOTect IT All". Aaron has spent the last decade helping asset owners across utilities, manufacturing, food and beverage, and transportation build OT cybersecurity programs that actually hold up in operational reality, not just on a compliance checklist. Today he is the Senior Director at Arcova (formerly MorganFranklin Cyber), leading OT/ICS engagements: assessments, SOC design, NERC CIP, segmentation architecture, and Cyber-Informed Engineering. Before this he was CTO of Industrial Defender, and spent 4+ years at EY running an OT program that included a 3,000-site deployment at a major North American power utility. His podcast, PrOTect IT (100+ episodes, Top Rated by Feedspot in Industrial Security) has featured guests including Mike Holcomb, Sean Tufts, Thomas VanNorman, Jori VanAntwerp, Bryson Bort, Clint Bodungen, and many others. He is a long-time volunteer with ICS Village.

SpeakerBio:  Tom VanNorman

Tom VanNorman is the co-founded ICS Village and leads the CyPhy Product group at GRIMM, where his primary focus is securing Industrial Control Systems and the networking of such systems. Tom brings an unparalleled level of operational knowledge and experience — he has been working in is the Operational Technology (OT) field for almost three decades. He has considerable expertise in constructing Cyber-Physical testing environments for OT systems.

Retired from the Air National Guard after over 20 years of service, where he worked in Cyber Warfare Operations.

SpeakerBio:  Dillon Lee, Dragos, Inc

Dillon volunteers for ICS Village and works at Dragos as a Principal Technical Account Manager. Throughout the year he volunteers for ICS Village to increase public’s awareness of the need OT systems have for cybersecurity with interactive learning like CTF, TTX, and interactive demos. As a Technical Account manager, he is a specialized product expert who works collaboratively with OT/IT organizations to strategically plan for successful deployments and help realize optimizations of their OT processes.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 12:00-13:59 PDT


Title: Ouroboros Attack! Recursive AI-Assisted 0-Day Hunting
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

This session presents a practical workflow for discovering and building real zero-day vulnerabilities using a recursive AI-assisted approach. The first part of the talk examines a logic flaw identified in the rendering mechanism of a large language model environment. Through structured interaction and controlled prompt chaining, inconsistencies in rendering state handling were exposed. By refining responses and feeding outputs back into follow-up prompts, the system revealed weaknesses in its own internal logic. Under specific crafted conditions, this behavior demonstrated a scenario that could lead to sensitive data exposure, including API-related material.

The second part of the session applies the same structured workflow to traditional web applications: SquirrelMail , ISPConfig , DokuWiki. Using recursive hypothesis refinement, attack surface expansion, and manual validation, multiple high and critical impact zero-day vulnerabilities were identified and confirmed with working proof-of-concept exploit chains.

These vulnerabilities have not yet been publicly disclosed. The conference presentation will include their first public technical analysis and exploit breakdown.

The focus of the talk is methodology: How to structure AI interaction for vulnerability research How recursive prompt chaining expands edge-case discovery How model output can be converted into real exploit paths Where manual validation remains necessary

This is a technical session centered on real exploit development and practical offensive research.

Speakers:Mehmet Önder Key,Temel Demir

SpeakerBio:  Mehmet Önder Key, Cyber Security Consultant

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

SpeakerBio:  Temel Demir

Temel Demir is a cybersecurity researcher and hardware architect specializing in hardware defense, offensive security, and the protection of critical infrastructure. With a core focus on embedded system vulnerabilities and Layer-1/Layer-2 network manipulation, his research involves developing deterministic, hardware-enforced frameworks that bypass traditional software-defined security flaws. Having previously shared security research on global stages, his work bridges the gap between sophisticated threat actor methodologies and immutable physical security barriers.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 16:00-16:45 PDT


Title: Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

Conference talks, earnings calls, product demos, training videos. Organizations put hours of footage online every week, full of things they didn't mean to share: hostnames in terminal windows, org charts on slides, infrastructure details dropped during Q&A. Traditional OSINT can't touch video at scale, and manual review falls apart past a handful of recordings.

Overcast is a CLI agent and skill pack for video OSINT that drops into any agentic harness, such as Claude Code, Codex, or Tinycloud, giving it senses plus recon and targeting reach, organized around an investigation case. Point it at 10 videos or 1,000 and it turns footage into cited evidence: speech, video understanding, on-screen text and objects, faces, and named entities, all accumulating in persistent case memory.

Discovery runs on the same case: scan and monitor sweep sources and surface reviewable findings. Ask across the whole corpus and get answers cited to the exact record and timestamp, backed by tiered retrieval. Match a photo against thousands of clips to find a person. Each subcommand is modular and pluggable, so analysts can drop one into other agent flows, author custom skills, or feed Overcast's media analysis into existing recon and security tooling to complete the mission.

SpeakerBio:  Kevin "kdrwins" Dela Rosa

Kevin Dela Rosa is a multimodal AI researcher and engineer with 17+ years in computer vision, NLU, and large-scale retrieval. He led engineering teams at Snapchat building billion-scale visual search and generative AI products, worked on large-scale ML at Amazon, and interned at NIST and SPAWAR on NLP and information retrieval for government applications. He's published at ACM WWW, ACM CAIS, IEEE ICCV, KDD, CVPR, NeurIPS, AAAI, and ISMIR, and has spoken at AWS re:Invent, KubeCon, and CascadiaJS. He's currently CTO of Cloudglue, where he builds video understanding infrastructure.

At DEF CON 33 he presented "Autonomous Video Hunter" at Recon Village, demoing an AI agent that investigated video corpora using face recognition, logo detection, and content analysis to produce structured OSINT reports. Overcast is the evolution of that work: a CLI agent and skill pack that gives any agentic harness senses plus recon and targeting reach, organized around an investigation case with persistent memory, cited evidence, and modular subcommands that plug into other recon and security workflows.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 14:00-14:59 PDT


Title: OWASP AIBOM Generator
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

AI systems increasingly depend on opaque model, dataset, and tooling supply chains, but most teams still lack a practical way to capture what is inside them. This Arsenal session demonstrates the OWASP AIBOM Generator, an open-source tool from the OWASP GenAI Security Project that creates CycloneDX-based AI Bills of Materials (AIBOM) for AI/ML assets. Attendees will see how to generate AIBOMs that can support AI transparency, security review, governance, incident response, and software supply chain risk management without turning the process into a manual documentation review exercise.

Speakers:Dmitry Raidman,Helen Oakley

SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.

SpeakerBio:  Helen Oakley

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: OWASP CTF
Tags: OWASP Foundation | OWASP Foundation CTF | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

This challenge simulates a real-world secure development lifecycle, where security professionals must not only identify vulnerabilities but also collaborate with development teams to implement, validate, and deploy secure fixes.

By completing the challenge, participants gain hands-on experience in:

The ultimate goal is to help practitioners develop the full skill set required to identify vulnerabilities, implement secure fixes, and deploy those fixes safely within their infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 12:45-13:45 PDT


Title: OWASP FinBot CTF: Hands-On Agentic AI Threats
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 12:45 - 13:45 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

OWASP FinBot is an intentionally vulnerable agentic AI application designed to teach real-world security risks in AI agents beyond prompt injection alone. This Arsenal session demonstrates how an AI assistant connected to business tools can be manipulated through indirect prompts, unsafe tool use, broken authorization, and weak runtime controls. Attendees will see and experience first-hand how attacker-controlled inputs can influence agent behavior, trigger unsafe actions, and expose sensitive data.

Speakers:Helen Oakley,saikishu

SpeakerBio:  Helen Oakley

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.

SpeakerBio:  saikishu

Venkata Sai Kishore Modalavalasa is Chief Architect & Engineering Leader at Straiker, building AI security products for AI-native apps at scale. With 15+ years in cybersecurity and distributed systems, he scaled Cyberfend to acquisition by Akamai, where he led bot detection and web security engineering. He’s an OWASP author contributing to AI Exchange, AIBOM, Top 10 for Agentic Applications, OWASP GenAI Security Project, creator and co-lead of OWASP FinBot CTF, and holds multiple security patents.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Saturday - 14:00-14:59 PDT


Title: Own the con
Tags: Queercon Community | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

A talk about Queercon and you


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 21:00-00:59 PDT


Title: Party Line (Call Center Village Party)
Tags: Party | Call Center Village
When: Saturday, Aug 8, 21:00 - 00:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

You've been placed on hold — but for once, you don't mind the music.

Party Line is Call Center Village's telephony-themed party open to all attendees at DEF CON 34.

A full-size telephone booth, retro telephones, dial-pad light shows, and lo-fi hold music grooves mixed with telephony-flavored party tracks.

If you've ever listened to Opus No. 1 on repeat, then this is your extension. No IVR to navigate Just pick up and dial in.

Don't let the phones go unanswered. Join us at Party Line.

Between calls, swing by our unofficial DEF CON TCG trading table — donate your extras, hunt down the ones you're missing, or make a deal for your favorites.

Make sure to bring your Call Center Village flight-tags (100 Trying or 200 OK) earned from the Escalation Desk CTF to claim free drinks!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 11:50-12:20 PDT


Title: Past the Bouncer: The Limits of CSP, Eleven Years In
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:50 - 12:20 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

CSP turned eleven this year. It is the standard the web ultimately adopted to decide which scripts a page is allowed to load and execute, and it now sits at the center of how we think about XSS mitigation, third-party script risk, and client-side supply-chain compromise.

The problem is that CSP was designed as a fetch-time control. It evaluates origins, nonces, hashes, and directives when resources are requested, yet it is often expected to provide guarantees about what trusted code does after execution begins. The bypass literature tells a different story.

This talk examines five representative CSP bypass classes, and uses them to expose the gap between controlling what may be loaded and governing behaviour at runtime. It also raises broader questions of script governance, supply-chain security, and the distinction between fetch-time and runtime security controls.

I conclude by introducing an open learning platform that contains a comprehensive catalogue of CSP bypass techniques.

SpeakerBio:  Pedro Fortuna

Pedro Fortuna is a security researcher, entrepreneur, and CTO of Jscrambler. For more than 15 years, his work has focused on web security, client-side security, reverse engineering, malware analysis, and software supply chain threats. He is the author of multiple security patents, a contributor to OWASP, and a member of the PCI Security Standards Council Board of Advisors.

Pedro regularly presents security research at international conferences and spends much of his time investigating how modern web applications fail in practice, from browser-side attacks and web skimming campaigns to the security implications of emerging technologies.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 11:00-12:59 PDT


Title: Patch Me If You Can: Hands-On Network Threat Defense
Tags: Cloud Village | Creator Event/Activity | Investigation
When: Saturday, Aug 8, 11:00 - 12:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) A - Map

Description:

Join this hands-on workshop to explore an integrated set of network security capabilities designed for real-time threat detection, prevention, and proactive risk management. You’ll see how inline traffic inspection can block threats with virtual patching, helping reduce exposure before vendor patches are available.

The session will also cover how deep network visibility supports detection of command-and-control activity, lateral movement, and advanced malware using behavioral analysis and custom sandboxing. You’ll learn how continuous asset monitoring can uncover misconfigurations, exposure, and other risk factors across the environment, then use that insight to prioritize response and reduce overall risk.

SpeakerBio:  Don Bogert

With more than 25 years of experience in cybersecurity, Don brings a comprehensive approach to organizational defense. Grounded in a strong network security foundation, his expertise spans physical security, compliance auditing, and the deployment of cloud, workload, and endpoint solutions. Throughout his career, Don has secured commercial, federal, and public sector organizations globally; and understands the challenges of a secure air-gapped environment. Currently, he focuses on delivering tailored security solutions to public sector customers in the Northeastern United States.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 14:50-15:20 PDT


Title: Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:50 - 15:20 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:
We ran three fundamentally different security analysis approaches against the same production monorepo at a large tech company: a pattern-based static analysis tool, a code property graph analyzer, and LLM-powered code review. Together they surfaced over 100 confirmed vulnerabilities.
Each approach has real strengths and real limitations. Pattern-based static analysis is fast and deterministic but struggles with complex taint propagation and cannot reason about logic. Graph-based analysis can trace dataflow across the entire codebase but has no concept of developer intent. LLM-powered review can reason about whether a security mechanism actually does what it claims, but it is non-deterministic, expensive, and cannot guarantee exhaustive coverage the way a static tool can.
We present a practical methodology for layering these approaches, share the detection overlap data from our analysis, and provide a framework for deciding which paradigm to apply where.
SpeakerBio:  Mudita Khurana

Mudita Khurana is a Tech Lead at Airbnb, where she builds scalable security tooling and automation across the software development lifecycle. Previously at Meta, she drove key initiatives in product security, including bug bounty strategy, privacy-focused reviews, and automated vulnerability detection through static and hybrid analysis. Her work focuses on advancing security automation through robust workflows, agentic systems, and scalable system design. Mudita also serves on program committees for several top-tier security conferences and regularly contributes to the community through research, talks, and industry collaborations.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Saturday - 10:30-10:45 PDT


Title: Payment Village Intro - What's Happening at the Village
Tags: Payment Village | Creator Workshop
When: Saturday, Aug 8, 10:30 - 10:45 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Join us to discover some of the highlights of the Payment Village at DEF CON


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:40-10:50 PDT


Title: Payment Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 10:40 - 10:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Payment Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Payment Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 10:00-10:45 PDT


Title: Peekaboo: Breaking the Black Box of Threat and Malware Emulation
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:
Standard security testing often forces a choice: use "script-kiddie" tools that get caught instantly, or use high-end frameworks that are too complex for rapid detection testing. Peekaboo bridges this gap. In this Demo Lab, we present Peekaboo - a modular, open-source framework designed for safe threat emulation. Unlike traditional malware, Peekaboo focuses on generating high-fidelity telemetry through legitimate cloud API abuse (GitHub, Bitbucket, Slack, Discord, Azure, VirusTotal, XBOX, AngelCam, etc) and evasive execution techniques (Direct Syscalls, Callback-based execution).

We will demonstrate how to:

Peekaboo isn't just a tool; it's a "sandbox-friendly" adversary in a box, designed to help Blue Teams level up by understanding the nuances of the Offensive Dev Loop. Come see how we turn "hidden" threats into "visible" learning opportunities.

SpeakerBio:  Zhassulan "cocomelonc" Zhussupov

cybersecurity enthusiast, author, speaker and mathematician. Author of popular books: MD MZ Malware Development Book (Github, 2022, 2024) MALWILD: Malware in the Wild Book (Github, 2023) Malware Development for Ethical Hackers Book: (Packt, 2024) AIYA Mobile Malware Development Book (Github, 2025) Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress) Author and tech reviewer at Packt. Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine Malpedia contributor Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Standoff, Positive Hack Talks, etc conferences


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 11:00-12:59 PDT


Title: Pentester vs AI: Race The Machine, In Real Life
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map

Description:

The machine already solved it. Could you? Pentester vs AI brings our race-the-machine CTF off the screen and onto the table. Draw a card, read the challenge, a leaky query, a forged token, a broken access check, and walk us through how you'd break it. No laptop, no flag to submit. Just talk through your approach: what's the flaw, what would you reach for, where's the path in. Then flip the card and see how the AI reasoned through the same target. Where you agreed, where you didn't. The clock is ticking for each challenge; come show us your line.

Speakers:Gwendal Mognier,Samantha Pearlstein

SpeakerBio:  Gwendal Mognier

Gwendal Mognier is a Security Researcher at Escape. He’s passionate about cybersecurity and always eager to learn new ways to break and secure systems. Gwendal is focused on discovering vulnerabilities and helping improve security across the board.

SpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 12:00-12:45 PDT


Title: Phasmid: Deniable Storage for Rubber-Hose Scenarios
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | SecOps | DEF CON Demo Labs
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:
Phasmid is a prototype deniable storage system built for a problem ordinary encryption handles poorly: what happens when the attacker stops attacking the math and starts coercing the human holding the key. It implements the Janus Eidolon System, or Janus System, a coercion-aware storage method that explores how visible disclosure and true protected state can diverge through deniable cryptographic structure, local-only operation, dual-profile storage, camera-based object-image matching, and owner-controlled destructive actions. Framed by the question of Agency, the project asks how a user can retain meaningful control over disclosure when physical pressure breaks normal cryptographic assumptions. This demo presents a practical low-power implementation on Raspberry Pi Zero 2 W for hostile situations where the attacker targets the person rather than the cipher.
SpeakerBio:  Makoto "Mr.Rabbit" Sugita

Makoto Sugita is a security engineer and security toolmaker focused on practical systems for hostile environments, where cryptographic assumptions break down under real-world pressure. His work sits at the intersection of cryptography, hardware, and adversarial human behavior. He has presented tools and research at venues including Black Hat Arsenal and BSides, and is interested in deniable systems, tactical hardware, and building prototypes that expose uncomfortable but real security problems.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: PhreakMe
Tags: PhreakMe | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 210 (PhreakMe) - Map

Description:

Ever wondered what hacking looked like in the golden age of phone phreaking? What about today? What can we learn about the old techniques that still plague our current infrastructure? The PhreakMe Capture the Flag brings you the classic art of telecom exploitation.

The Hacked Existence team is once again hosting a telecom based CTF. The CTF runs on real live VoIP lines routed through a modified asterisk PBX allowing participants to dial in to the CTF from anywhere in the world. This number is live 24/7 throughout DEFCON, allowing you to hunt the PBX for flags any time, day or night. Don't have a phone? Come test your skills at one of our 5 payphones! Also there's a BBS, hope you brought your modem!

All the flags are based around historically accurate tactics, techniques, and procedures to manipulate emulated old school switching systems.

The purpose of our contest is to bring awareness around the still existing weaknesses in our telecom infrastructure and Interactive Voice Response Systems. Ideally visitors to our contest area will participate in the CTF allowing them to get a better understanding of telecom hacking in the year 2026 as well as a respect for the art of phreaking from yesteryear.

Come test your skills, challenge your knowledge, and dive deep into the world of phreaks.

Hints: Read 'The Cyberthief and the Samurai' and 'Masters of Deception: The Gang That Ruled Cyberspace' for a leg up.

Participant Prerequisites

A phone, or access to a phone that can dial an american based phone number. The BBS will be both accessible from a modem and also ssh. Ideally people will read books like 'The Cyberthief and the Samurai' and 'Masters of Deception: The Gang That Ruled Cyberspace' and the Cult of the Dead Cow book.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Pinball High Score Contest
Tags: Pinball High Score Contest | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 304 (Pinball High Score Contest) - Map

Description:
The Pinball High Score contest at DEF CON 34 will run Friday and Saturday: 10:00-18:00, Sunday 10:00-13:00 with games available for daily High Score contests, daily challenges and open qualifying for a main tournament. The daily contests will allow any attendee to play pinball games and attempt to record a qualifying high score on each of the unique games. At 17:00 on Saturday main tournament qualifying will end, tiebreakers will be played (if needed) and the top 8 players with the highest combined scores across all eligible machines will qualify for the Sunday finals event where they could become the next DEF CON Pinball Champion!

Achieving a high score may sound simple but pinball rulesets are very complex and the skill to complete a “Wizard Mode” or achieve a high score requires research, practice, knowledge and execution. Out of the box thinking, analytical skills and pattern recognition are traits that pinball players must exhibit to be successful and some games have rule sets that can be studied and exploited to achieve a high score. Hackers are at an advantage here and while this is just a pinball contest, we expect that the community is ready for this challenge!

Last year the contest measured how you moved the machine. This year, we're reading what happens inside it. Custom sensors feed SHELL, our Sub-surface Hidden Entertainment Layer Logic. When you unlock the right patterns, a hidden world appears on screens beneath the glass. Face off in secret mini-games, answer hacker trivia under pressure, and battle other players in competitive challenges where you can steal control mid-game. It's pinball within pinball, a clandestine layer of gameplay that only reveals itself to those who can crack the SHELL.

Participant Prerequisites

Nothing special is required. Any person can step up and enjoy a pinball game or they can spend 30+ hours solving our challenges if they want to play the deeper game.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 12:20-12:59 PDT


Title: Pinchy Gets Played: How We Red-Teamed AI Agents Before the Threats Did
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:20 - 12:59 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

AI agents are showing up in cloud workflows with credentials, autonomy, and trust, but so are the threats targeting them. So, before attackers started probing them, Varonis Threat Labs did. We built a target agent named Pinchy on the OpenClaw platform and put it through a red-team gauntlet using well-known techniques. Pinchy handled sophisticated technical attacks with ease but folded immediately against simple social ones. The same drive to be useful turns these agents into an attack surface that requires entirely different defensive strategies. Join us for a deep dive on the new risks autonomous AI brings to the cloud. You'll leave with a clearer picture of where AI agents fail, why the threat model is unlike anything that came before it, and what architectural controls — not prompts, not policies — actually keep environments secure.

SpeakerBio:  Doron Kapah

Doron is an experienced security researcher at Varonis Threat Labs. He primarily focuses on advanced threat detection capabilities, threat hunting, and AI and cloud security. Doron also has extensive experience in building innovative cybersecurity product solutions, CTFs and has authored multiple publications in both state-sponsored and cybercrime threat intelligence domains.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:30-11:45 PDT


Title: Playing with Hyper-local Pocket-Sized Servers
Tags: IoT Village | Creator Workshop
When: Saturday, Aug 8, 10:30 - 11:45 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

In this hands-on workshop, we’ll turn an ESP8266 into a self-contained Wi-Fi pocket server that anyone nearby can connect to without the internet. Kit Cost: $80. Class Cap: 30.

SpeakerBio:  Brandon
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Saturday - 12:00-12:30 PDT


Title: Please Place Your Electronic Devices in {Maritime} Mode: Exposing NTN’s Maritime Attack Surface
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Many Mariners share a sigh of relief once the sight of shore disappears. Sail far enough from the mainland, and the distractions of the cellular world fade away. No bars. No signal. No problem. Cellular Non-Terrestrial Networks (NTN) have stolen that comfort. Ships have long relied on satellite communications for safe navigation and operations at sea. However, traditional threats to GPS, satellite broadband, and Iridium are being rapidly supplanted by Direct-to-Device (D2D) cellular connectivity via NTN. The same vulnerabilities that plagued its terrestrial ancestors are quietly following mariners out to sea. This talk provides a technical deep-dive into 4G and 5G NTN architecture, its current footprint in the maritime environment, and the vulnerabilities it inherits from its terrestrial ancestors. We close by charting a course forward, exploring open research questions and offering practical recommendations.

SpeakerBio:  Jason Veara, Independent Researcher

Jason Veara is a Cybersecurity PhD student at Northeastern University, a Coast Guard Officer, and Permanent Military Faculty at the U.S. Coast Guard Academy in New London, CT. His research focuses on identity, localization and trust in wireless-dependent autonomous systems.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 10:00-11:59 PDT


Title: PMTC: One-Click RCE and Persistent Exfil in AI Coding Agents
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

Red teamers operating in environments where developers run AI coding agents (Anthropic Claude Code, OpenAI Codex CLI) now have a high-impact, low-detection attack path. We call it PMTC (Persistent MCP Tool Capture). The live demo runs the full operational chain. A .lnk shortcut with hidden extension delivers the payload. One double-click launches the agent in attacker-controlled CWD. Parent-walk .mcp.json auto-exec fires. A zero-prompt OAuth flow captures credentials. A refresh token persists silently in the victim's home directory, re-authenticating every future session. OPSEC notes: cwd selection to defeat path-based logging, MCP server fingerprint reduction, OAuth state minimization. For blue teams: Sigma and Suricata rules included. You leave with the chain reproducer, .lnk template generator, and detection rules. Cross-vendor on Codex CLI. Disclosure in flight; CVEs released at the talk.

SpeakerBio:  Ahmet Furkan Aydogan

Ahmet Furkan Aydogan is a Tenure-Track Assistant Professor in the Computer Science Department at the University of North Carolina Wilmington (UNCW). He earned his Ph.D. in Digital and Cyber Forensics Science from Sam Houston State University (SHSU) in 2024, with a focus on Cyber Security, Cryptology, Machine Learning, IoT, and Human-Computer Interaction. His research includes a Brain Frequency-Based Evolutionary Encryption Method for IoT Devices. Ahmet has received multiple awards and has published widely in the fields of cybersecurity and digital forensics.


Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Saturday - 11:00-11:59 PDT


Title: Poison the Well: RAG Attacks Against the Hacking Community's Own Archives
Tags: Data Duplication Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:

This presentation demonstrates how archive poisoning attacks compromise Retrieval-Augmented Generation (RAG) systems by embedding malicious instructions inside documents that influence model behavior during retrieval. Using a customized agentic testing workflow, attendees will see how a single poisoned document can manipulate outputs, exfiltrate sensitive information, bias threat intelligence results, and abuse trust relationships across a RAG-powered environment without modifying model weights.

SpeakerBio:  Omer Farooq

Omer Farooq is a cybersecurity, cloud, and artificial intelligence leader with more than twenty-five years of experience spanning application security, cloud architecture, software engineering, DevSecOps, AI security, and technology innovation. As Founder and Principal Security Consultant at Auxin Security, Omer has advised more than 100 organizations worldwide, including Fortune 500 companies, government agencies, healthcare organizations, and nonprofits. His expertise includes GenAI and LLM security, offensive security assessments, threat modeling, cloud security, DevSecOps transformation, secure software development, and enterprise architecture. Omer is a frequent speaker at industry conferences and events including RSA Conference, BSides DC, AWS events, NAB Show, Microsoft Azure conferences, and numerous cybersecurity forums. His current research focuses on AI security, agentic systems, retrieval-augmented generation security, offensive AI testing, and emerging threats targeting enterprise AI deployments.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:50-10:59 PDT


Title: Policy @ Defcon Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 10:50 - 10:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Policy @ Defcon but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Policy @ Defcon and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Saturday - 11:00-11:59 PDT


Title: Polycon
Tags: Queercon Community | Creator Event/Activity
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 10:00-17:59 PDT


Title: Poster Presentations
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

AI Village is going old school academia with various presenters showcasing their research in poster format. Posters will be displayed on digital screens while presenters give conversational overviews of their research and invite casual discussions.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 16:00-17:59 PDT


Title: Practical AI Security Assessments Using OWASP AISVS
Tags: OWASP Foundation | Creator Workshop
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

How do you actually verify that an AI system is secure? In this workshop, the AISVS project leads walk through practical assessment scenarios using the OWASP AI Security Verification Standard. We'll work through real requirements from chapters on prompt injection defense, agentic action security, RAG/vector database hardening, and output safety controls, showing what "verify that" looks like in practice against running systems. Participants will leave with a working understanding of how to scope an AI security assessment, select appropriate verification levels, and apply AISVS requirements to LLM-based applications, autonomous agents, and MCP-connected tool ecosystems. Bring a laptop if you want to follow along.

SpeakerBio:  Jim Manico, Founder at Manicode Security

Jim Manico is the founder of Manicode Security, where he specializes in training software developers on secure coding and security engineering. He is actively involved in multiple ventures, serving as an investor/advisor for companies like 10Security, MergeBase, Nucleus Security, KSOC, and Inspectiv, among others. Jim is a recognized speaker, focusing on secure software practices, and holds a distinguished position as a member of the Java Champion community. He is also the esteemed author of "Iron-Clad Java: Building Secure Web Applications" published by Oracle Press.

Additionally, Jim generously volunteers for the OWASP foundation, co-leading key projects such as the OWASP Application Security Verification Standard and the OWASP Cheatsheet Series.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 11:30-12:30 PDT


Title: Precogly: Open-Source Threat Modeling for the AI-Coding Era
Tags: Intermediate | AppSec Village | Creator Event/Activity
When: Saturday, Aug 8, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

AI agents are beginning to write larger parts of applications, from individual features to complete services. But if agents can build software, they also need a reliable way to threat model what they build.

Precogly is an open-source (Apache 2.0) OWASP project for repeatable, human-reviewable threat modeling in the AI-coding era. It uses structured, community-curated library packs that connect components, threats, and countermeasures to sources such as CWE, CAPEC, and compliance frameworks.

This gives AI agents guardrails. Instead of inventing threat models freely, they work off installed libraries, producing outputs that are easier to review, reproduce, and audit.

In this demo, attendees will see Precogly’s DFD editor, library pack ecosystem, threat generation workflow, completion status dashboard, pack cross-checks for detecting untraced AI-generated items, and the OpenAPI REST API that agents can build on top of.

SpeakerBio:  Vikramaditya Narayan

Vikramaditya Narayan is the creator of OWASP Precogly, an open-source, enterprise-grade threat modeling platform designed for repeatable, AI-agent-ready threat modeling. Previously, he designed the prototype for a YC-funded AI governance platform. Vikramaditya leads the Bangalore chapter of Threat Modeling Connect and has spoken at ThreatModCon DC on emergent risks in multi-agentic systems and at OWASP on using AI in threat modeling. He holds an MS from Carnegie Mellon and is a Certified Threat Modeling Professional.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 12:30-13:30 PDT


Title: Privacy You Inherit: How Cultural History Writes the Source Code for AI Surveillance Policy
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Privacy isn't a principle. It's an inheritance — and AI is accelerating past every inheritance at once. This talk traces four lived experiences with surveillance — post-Mao China's "watchful neighbor," Stasi-era Germany's distrust of the state, Soviet communal density's "everyone already knows," and an American market that traded a constitutional right to privacy for one-click convenience — and shows how each set the privacy floor people now expect from AI. Chinese citizens accept face-scans but punish commercial data sale. Germans push back on the tech itself. Russians shrug. Americans click accept and let 23andMe hand DNA to law enforcement. Then AI changes the game. ChatGPT logs surface kids who type the wrong thing. Flock cameras blanket neighborhoods "for the children." Clear sells your face for a faster TSA line. None of these systems sit cleanly inside any inherited default — and federal policy has gone quiet. Audience leaves with: a vocabulary for diagnosing whose privacy default an AI proposal is actually written for; the federal-vacuum / state-patchwork pattern; and three concrete asks — plain-language consent, a "kudos wall" for companies that earn trust, and abstraction-layer tools that read T&Cs for users.

SpeakerBio:  Tati

Tatiana (or Tati) is a Technical Program Manager who spends their days breaking telcos (amongst other things), managing logistics and wrangling hackers. They have no formal policy credentials, and that's kind of the point. The grandchild of Holocaust survivors and the child of Soviet émigrés, Tatiana didn't learn about surveillance overreach in a classroom or a think tank. They learned it the way most people in their family did — through stories of what happens when the state decides it has a right to know everything about everyone. That inheritance is why they're here, talking policy at a hacker conference instead of leaving it to the people who usually do


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Saturday - 15:30-16:30 PDT


Title: Privacy's Defender with Women in Security and Privacy (WISP)
Tags: Women in Security and Privacy (WISP) | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Join WISP and EFF for a conversation featuring WISP Board Chair Alyssa Coley and former EFF Executive Director Cindy Cohn in discussion about Cindy's book: Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance.

Cindy has spent three decades tangling with the feds, fighting for data security, and arguing in court to protect our access to science and knowledge on the internet. This is a rare chance to hear her story up close.

Speakers:Cindy Cohn,Alyssa Coley

SpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy's Defender published by MIT Press in March, 2026. She is also the co-host of EFF's award-winning podcast, How to Fix the Internet.

--

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

SpeakerBio:  Alyssa Coley, Privacy & Product Counsel at Scopely

Alyssa is on the Board of Women In Security and Privacy (WISP) and is Privacy & Product Counsel at Scopely. As in-house counsel, she focuses on integrating privacy by design into product development and ensuring global privacy compliance. Previously, she gained experience in privacy consulting and cybersecurity incident response. She has been involved with WISP for nearly a decade where she developed her interest in locksport and continues to further WISP's mission to advance women and underrepresented communities to lead the future of security and privacy.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 14:15-14:45 PDT


Title: Privilege Escalation: Building a Cyber Career with Zero Support
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 14:15 - 14:45 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Elevator Pitch I moved across the world to start a master’s in cybersecurity with little technical knowledge and no local network. I did not just find a career; I engineered one from scratch. Today, I hold a Master's degree, multiple certifications, and advisory board seats at two distinct organizations. I started as a student who had to build her own village. My talk is a "noob-to-leader" blueprint for anyone starting at ground zero. I will show you how to cut through industry noise, take your first big initiative, and turn a lack of guidance into your greatest leadership strength.

Description Most people say that to succeed in cyber, you need a long list of certifications and years of coursework. But what do you do when you are starting with a blank slate and no one is there to guide you?

When I began my journey as an international student, I had no contacts, no prior experience, and no roadmap. I had to learn how to distinguish the "signal" of real opportunities from the overwhelming "noise" of opinions and entry-level gatekeeping.

I took ownership of my path. I jumped into hackathons, volunteered for professional organizations, and eventually became an advisor helping veterans translate their military service into civilian cyber careers. I discovered that leadership was the ultimate technical growth: guiding others forced me to master complex concepts deeper and faster than any individual study could. By supporting others in the field, I was not just building a network; I was validating and sharpening my own technical expertise. In addition to my corporate role, I serve on the advisory boards for a university serving veterans and the nation's first Microsoft Certified high school.

In this 30-minute session, I am sharing the "Bootstrap Protocol" I used to move from the classroom to the boardroom. We will cover:

This is a practical, zero-fluff roadmap for the self-guided learner. If you feel like you are walking this path alone, come learn how to build the village you have been looking for.

Key Takeaways

SpeakerBio:  Akanksha Raghvesh
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 15:15-16:15 PDT


Title: Proactive Malicious Package Defense
Tags: Intermediate | AppSec Village | Creator Event/Activity
When: Saturday, Aug 8, 15:15 - 16:15 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Whole development orgs are still rawdogging npm and other package registries, despite the continued rise of supply chain attacks involving malware targeted at both developers and the organizations they work for. Check out open-source tooling that can contribute to proactive defense, using either open or vendor-proprietary data sets

SpeakerBio:  Darren Meyer

Darren is a security research advocate and practitioner that has worked on every side of the AppSec world at some point in the past 20 years. He's passionate about making security work more accessible and less stressful.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 10:15-12:59 PDT


Title: Prompt Injection: Attacking and Defending AI-Powered Applications
Tags: AppSec Village | Creator Workshop | All Audiences
When: Saturday, Aug 8, 10:15 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map

Description:

Prompt injection has rapidly emerged as one of the most critical and least understood vulnerabilities in modern application security. As organizations race to integrate LLMs into customer-facing products, internal tools, and autonomous agents, attackers are already exploiting these systems in ways traditional security controls were never designed to catch. This one-day, hands-on training gives attendees a thorough, practical understanding of prompt injection — from basic chatbot manipulation to sophisticated attacks against RAG pipelines and autonomous AI agents. Using a purpose-built lab environment, attendees will exploit real vulnerabilities in LLM-powered applications, understand exactly why they work, and then build effective defenses against them. The course is structured as an attack-first, defend-second journey. By experiencing these vulnerabilities as an attacker, attendees leave with deep intuition about where AI systems.

SpeakerBio:  Mohammed Ilyas Ahmed

I am a seasoned security and DevSecOps professional with deep expertise in helping organizations strengthen their security posture across modern, cloud-native environments.

I am an active contributor to the global technology community and a frequent speaker at leading industry conferences and platforms, including DEF CON, Black Hat, KubeCon (Paris), ISACA, IANS, and Wallarm, among others. I am also regularly invited to serve as a technical session judge.

publishing work that advances discussions around modern security practices, governance, and risk management. I am also a distinguished member of the Harvard Business Review Advisory Council.

My work has a global reach through my role as a Member of the Global Advisory Board at VigiTrust Limited (Dublin, Ireland).

I am the author of Cloud-Native DevOps, a practical guide to building scalable, reliable, and secure cloud-native applications.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 14:00-14:45 PDT


Title: PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Saturday, Aug 8, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

AI-assisted development tools don’t just introduce vulnerabilities; they introduce the same vulnerabilities repeatedly.

PromptPwn is a tool designed to identify, track, and exploit common insecure patterns found in AI-generated code. It maintains a database of known vulnerability patterns produced by popular “vibe coding” workflows and provides scanning capabilities to detect these issues in real applications.

In this demo, we show how PromptPwn identifies vulnerable patterns such as injection flaws, authentication weaknesses, and insecure defaults across generated code. We demonstrate how these patterns can be exploited in practice, highlighting how repeatability makes them especially valuable from an attacker’s perspective.

We also explore how prompt variations influence these outcomes and show how insecure patterns can be remediated by adjusting prompts, closing the loop between generation, exploitation, and correction.

This session focuses on practical demonstrations of how AI-generated code fails in predictable ways, and how those failures can be identified and abused at scale.

SpeakerBio:  Georgia Weidman

Georgia Weidman is an offensive security researcher and author focused on breaking real-world systems. She wrote Penetration Testing: A Hands-On Introduction to Hacking, a practical guide used by students and practitioners to learn exploitation techniques.

Her work centers on how modern systems fail under attack, from mobile and IoT to enterprise environments. As a DARPA Cyber Fast Track performer, she developed the Smartphone Pentest Framework (SPF), a platform for mobile exploitation research.

She has conducted penetration tests, built exploitation tooling, and developed attack chains across multiple domains. Her approach prioritizes hands-on techniques over theory, demonstrating how assumptions about security break down in practice.

Georgia has presented internationally at conferences including Black Hat and DEF CON, with a focus on showing how things actually get hacked.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 13:30-13:59 PDT


Title: Pulling Back the Curtain on the Voting Booth
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

This presentation by Max Springer (postdoctoral research fellow, Princeton University Center for Information Technology Policy) and Marilyn Marks (Coalition for Good Governance) presents unsettling new findings that escalate the danger of a known, unpatched vulnerability in Dominion Voting Systems version used in Georgia and multiple other jurisdictions. First disclosed in 2022 by University of Michigan and Auburn University researchers, the flaw allows cast-vote records and ballot images to be "unshuffled," revealing the order in which ballots were cast, and, when combined with public information like scanner logs, scanner public counters, poll books check-in files, or timestamped polling place video, exposing how specific individuals voted. Georgia and many affected jurisdictions have taken no corrective action despite the software patch offered by Dominion in late 2022.

Springer and Marks demonstrate that these exploits, once assumed to require sophisticated programming skills, can now be carried out by almost anyone. Using only publicly available Georgia election records and off-the-shelf AI tools, and without writing custom code, the presenters demonstrate the ready ability to determine how a substantial share of Georgia voters cast their ballots in the contentious May 2026 primary.

The findings arrive at a pivotal moment: Georgia election officials are currently divided over whether to require a security patch bringing ballot scanners into compliance with the state's secret-ballot guarantee. Some officials resist any change and instead push to conceal the underlying public records, preserving insiders' access to voter-choice data while leaving the public without elections oversight and verification rights.

Springer and Marks argue that AI has fundamentally lowered the barrier to exploiting this flaw, transforming a theoretical privacy risk into an urgent, practical threat to the secret ballot in multiple jurisdictions. They call for mandatory patching and warn that inaction before the 2026 midterms could compromise the constitutional right to a private vote for millions of Americans.

Speakers:Marilyn Marks,Max Springer

SpeakerBio:  Marilyn Marks

Marilyn Marks is Executive Director of the Coalition for Good Governance, a nonpartisan nonprofit working to strengthen election security and protect the right to a secret ballot. For more than 17 years she has focused on improving the technology used in U.S. elections, especially in Georgia. Her group is behind Curling v. Raffensperger, a landmark federal case challenging the security of touchscreen voting machines. Georgia is using a second generation of touchscreen voting machines, with flawed software that Marks and many cybersecurity experts fear may be used to disrupt target state Georgia’s elections this year.

SpeakerBio:  Max Springer

Max Springer is an algorithms researcher, science communicator, and tech policy consultant. Currently, he is a postdoctoral research fellow at Princeton University. He earned his PhD from the University of Maryland under MohammadTaghi Hajiaghayi, with support from an NSF Graduate Research Fellowship. His dissertation, "The Price of Fairness in Algorithmic Decision Making", developed approximation algorithms with fairness and reliability guarantees—an agenda he now extends from classical machine-learning problems to modern AI systems. He has conducted research at Google, Nokia Bell Labs, Yale, and the Max Planck Institute, and received Bell Labs’ Outstanding Innovation Award. Beyond research, he contributed to a recent United Nations report on AI and works with policymakers on responsible algorithmic deployment, including election systems


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: PWN UR H0M3 - DDoS CTF
Tags: DDoS Contest | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map

Description:

A chaotic DDoS-themed CTF where sketchy devices, busted services, weird signals, and sneaky clues are begging to be owned. Scan the network, break IoT devices, decode the nonsense, and prove you can pwn your home before your home pwns you. This CTF is designed to help you learn about the cutting edge in DDoS attacks and defense. We also have an IoT lab of devices hacked and infected with botnet malware that you can play around with. Beginners welcome. We have some fabulous prizes including gift cards donated from Hak5 so please check it out!


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 11:00-11:45 PDT


Title: pymsi: Interactive MSI Installer Analysis in Python and the Browser
Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Defense/Blue Team | Malware | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

pymsi is a pure-Python library for parsing, analyzing, and extracting files from Windows installer (MSI) packages, without relying on native Windows APIs or tooling. It provides direct access to MSI database tables, embedded binary streams, and installer metadata, enabling security researchers to inspect installer behavior and extract files from MSI installers.

We will demonstrate its ability to safely tear apart malicious MSI droppers, dump internal database tables, and extract embedded payloads without risking accidental execution. Attendees will see how the CLI and Python API can be used to triage files and integrate it into automated analysis pipelines, including how it has been integrated into other open source tools to extract embedded payloads and identify malicious CustomAction behaviors.

Because it is written entirely in Python, it runs seamlessly on any OS with a Python interpreter, including web browsers. The demo will showcase the online MSI viewer, a client-side tool powered by Pyodide that gives pymsi a familiar lessmsi-style UI for working with MSI installers from any device with a web browser. Demos will also show new security analysis features for identifying suspicious installer behaviors and inspecting contents of embedded binary streams within a browser.

SpeakerBio:  Ryan "Nightlark" Mast

Ryan is a software engineer working on open source projects to make the electric grid more reliable. His interests include software security, niche video games, tearing apart "smart" devices, and reverse engineering audio/video hardware used in live productions.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 10:00-11:59 PDT


Title: Pyramid of Pain-Red Team (Human and Technical Friction)
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map

Description:

Inspired by the Pyramid of Pain, this session flips the lens inward to examine the friction Red Teams face across tools, policies, and organizational constraints. We will explore how limited scope, tool fatigue, and misaligned incentives reduce the real impact of security testing—and how to (possibly) fix it. Using frameworks such as MITRE ATT&CK, attendees will learn to prioritize findings by business risk, translate technical results into actionable outcomes, and build repeatable processes that drive remediation.

SpeakerBio:  Frank Victory

Frank Victory is a seasoned cybersecurity leader with over 30 years of experience shaping impactful security strategies. Focused on results rather than titles, he has excelled in both technical and leadership roles, bringing deep expertise in defensive and offensive security—spanning blue and red team operations, incident response, and threat & risk management.

Passionate about developing the next generation of cybersecurity professionals, Frank teaches at local community colleges and leads instruction for CU Boulder’s programs in Social Engineering, Ethical Hacking, DFIR, and Threat Hunting. As Vice President of the Denver OWASP chapter, he fosters community engagement through meetups and conferences, including SnowFROC.

Frank also co-hosts the Colorado=Security Podcast, where he interviews local cybersecurity professionals, delving into their journeys, challenges, and insights—always ending with the question: What is the biggest challenge in cybersecurity today?


Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Saturday - 16:00-16:30 PDT


Title: Quantum-Ready or Not: What 1,000 Codebases Reveal About Cryptographic Risk
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Many people are aware of the quantum threat to cryptography, but how extensive is this issue? We analyzed 1,000* high-profile open-source repositories, including OpenVPN, Curl, and Bitcoin, and found that cryptographic risk is pervasive and hidden. 94% of repositories contain at least one cryptographic issue that would become exploitable in a post-quantum setting*, while 92% contain an issue that is already considered insecure by today’s standards*. The median repository contains 185 quantum-relevant weaknesses of moderate severity or higher, nearly double the classical median of 95*, indicating that there is substantial and underrecognized quantum exposure. Notably, thousands of findings are what we call “PQ-invisible;” they appear secure under classical assumptions but would become vulnerable with sufficiently powerful quantum capabilities*, revealing a critical blind spot in current security practices.

These results highlight a gap between real-world cryptography and post-quantum readiness at a time when NIST migration timelines are approaching and Q-Day remains unpredictable. Unlike prior talks that focus on surface-level generalities, this talk is grounded in empirical analysis of source code across a large corpus of highly-used repositories.

We will give a brief overview of the quantum threat, such as current estimates of quantum progress, NIST standardization, and attacks such as Harvest Now, Decrypt Later (HNDL) and Trust Now, Forge Later (TNFL). We will then present our methodology and results, including detailed breakdowns of cryptographic types, algorithms, and security postures across public-key cryptography, symmetric encryption, hashing, password hashing, TLS, and MACs.

Whether you’re new to the quantum threat to cryptography or all-too-familiar with it, we hope to provide a clearer understanding of the current state of cryptography and the post-quantum migration.

*Statistics based on an initial sample of 100 repositories; results will be updated as the dataset scales to 1,000.

SpeakerBio:  Dr. Zulfikar Ramzan

Dr. Zulfikar Ramzan is Chief Technology and AI Officer at Point Wild, a global leader in AI-powered cybersecurity. He spearheaded the development and launch of Lat61, a highly scalable, extensible AI platform that consolidates data from multiple sources to detect multi-vector attacks, optimize protection across 50+ products and support over 25 million active users. He also leads the Lat61 Threat Intelligence Team, directing research into emerging threats and strengthening Point Wild’s Lat61 platform.

Dr. Ramzan has over 20 years of experience in cybersecurity. At Aura, he served as Chief Scientist and Board member, leading the development of AI-driven platforms such as Aura Call Protection, Aura Message Protection, Smart Vault, and the Apollo platform for AI workloads. He has also held senior leadership roles at RSA as Chief Technology Officer and Chief Digital Officer. Earlier in his career, he contributed to Symantec Endpoint Protection and advanced machine learning–powered technologies at Immunet, now part of Cisco. He holds a PhD from MIT and is an inventor on more than 60 patents in cybersecurity and applied cryptography.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 11:50-11:59 PDT


Title: Queercon Community Lounge Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 11:50 - 11:59 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Queercon Community Lounge but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Queercon Community Lounge and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 16:00-17:59 PDT


Title: Queercon Mixer
Tags: Meetup | Queercon Community
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Come meet the largest social network of LGBTQIA+ and allied hackers at Queercon! Our mixers are designed for you to meet, network, and engage with like-minded people to a backdrop of music, dance, and refreshments.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:00-01:59 PDT


Title: Quiet Room
Tags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 01:59 PDT
Where: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map

Description:

Diana Initiative is excited to offer up a "Quiet Room" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:00-01:59 PDT


Title: Quiet Room
Tags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 01:59 PDT
Where: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map

Description:

Diana Initiative is excited to offer up a "Quiet Room" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 14:00-14:30 PDT


Title: Racing PX4: Memory Safety and Timing Vulnerabilities
Tags: Aerospace Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Commercial off-the-shelf autonomous vehicles range from self-driving trucks to military-grade drones. These systems commonly use the PX4 Autopilot flight stack for flight control, navigation, and telemetry. PX4 is a modular stack where logical functions are placed within components. MAVLink is a protocol that facilitates communication between a vehicle and a Ground Control Station. PX4 and its communication facilities are employed in industrial, as well as military environments, where security and correct real-time operation are paramount. This talk will examine how real-time operations and security may be jeopardized by memory corruption and timing-sensitive vulnerabilities in PX4’s communication and logging subsystems. Further, this talk will present a novel time-of-check to time-of-use (TOCTOU) race condition in the MAVLink logging subsystem, MavlinkUlog. This results in a Denial-of-Service where vital commands cannot be sent to the vehicle, sequence tracking is thrown off, and telemetry is unreliable. Through this talk, the unique implications of these vulnerabilities upon autonomous systems deployed in safety-critical environments will be discussed.

SpeakerBio:  Nefeli Georgilas
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Radio Frequency Capture the Flag
Tags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester's determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

This game doesn't let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what's happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 10:00-17:59 PDT


Title: Radio Frequency Village Events
Tags: Radio Frequency Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

In addition to the CTF and talks, which are elsewhere on the schedule, the RF Village is also a place to hang out and chat with like minded folks who share your interests.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 11:20-11:30 PDT


Title: Radio Frequency Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 11:20 - 11:30 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Radio Frequency Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Radio Frequency Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 12:00-12:59 PDT


Title: Rage Against the Sandbox: Bypassing Apple’s iOS Security to Run Unsigned Code via SSH
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Apple’s Sandbox and code signing have made traditional security research impractical on iPhones - researchers must use full-system emulation or hunt for increasingly rare jailbreak exploits. The Sandbox blocks fork(), which shells need for job control. Code signing prevents unsigned code execution.

We present techniques that bypass both restrictions without exploiting vulnerabilities. Using only standard APIs, we built a system that runs SSH servers and interactive shells on iPhones with full fork() support and unsigned code execution.

We’ll dive deep into the technical implementation: userspace memory management, thread-based process virtualization, stack frame manipulation, and selective CPU emulation. Then we'll demonstrate the real impact: running an unsigned public exploit directly on an iPhone through SSH - no jailbreak, no signing, no problem.

Full paper I wrote about the talk (have not published it in public domains yet, waiting for the conference first as a reveal!)

"Rage Against the Sandbox: Bypassing Apple’s iOS Security to Run Unsigned Code via SSH", Y.H. Hirschenbein Sadde, 2026 https://drive.google.com/file/d/1ZyIvQa3kjiLvCmNhdY-fmSAbhRA5gLPx/view

SpeakerBio:  Yuval Hanoch Hirschenbein Sadde

Yuval is a security researcher. His main focuses are Android and iOS security - specifically in low-level system code and kernel modules. His work centers around researching the bootstrap process of operating systems, and analyzing popular low-level code flows within the platform frameworks and their third-party dependencies.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
Tags: IoT Village | Creator Workshop
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Encrypted IoT firmware doesn’t have to be a dead end. In this hands-on workshop, we’ll reconstruct a real vendor’s firmware decryption pipeline without ever touching the hardware...


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 12:30-13:30 PDT


Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
Tags: IoT Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Modern IoT firmware often appears protected behind proprietary encryption, stopping analysis before it starts. However, in many cases the fastest path forward is not to break the cryptography, but it is to reuse the vendor’s own implementation via targeted function emulation. In this hands-on workshop, attendees will learn a methodology we call firmware archaeology: a practical method for reconstructing the proprietary firmware decryption scheme by correlating artifacts left behind across firmware archives, public repositories and developer ecosystems. Attendees will analyze the real-world ecosystem of a commercial IP camera vendor, using the firmware archaeology methodology. First, they will identify historical artifacts and ecosystem components from publicly available sources. Next, they will recover from binaries the cryptographic routines that are responsible for decrypting the firmware images. They will then reuse and emulate these functions in a controlled environment to recover the decrypted firmware image that was initially secured by the proprietary encryption scheme. With this access, participants will move beyond decryption to explore hidden functionalities of the target device and map the broader attack surface of the platform that was previously inaccessible. The workshop is designed as a practical methodology session rather than a one-off trick or a showcase of vulnerabilities. All exercises are hands-on and based on real research, with pre-packaged material and tooling provided. Attendees will leave with a practical and repeatable methodology for analyzing modern IoT platforms, including techniques to reconstruct firmware decryption pipelines and bypass analysis barriers without reimplementing vendor cryptography from scratch.

Speakers:Simone Bossi,Luca Borzacchiello

SpeakerBio:  Simone Bossi

Simone takes apart embedded systems and firmware for a living, but it took a while to get there. He started doing vulnerability research in 2015 on web, mobile, network, and the occasional cryptography rabbit hole, including a stint as a cryptanalyst at STMicroelectronics working on IoT communications security. Around 2020 he moved fully into IoT and OT, where bugs live in proprietary protocols, firmware nobody was meant to read, and hardware that was built to last, not to be secured.

He now leads the vulnerability research team at Nozomi Networks Labs, where they find 0-days in industrial and IoT devices, and quickly learned that the most interesting features are the ones you don't find in the user manual. Along the way: academic research on weaknesses in Linux's cryptsetup and PBKDF2 that made it into the security literature, open-source offensive tooling, and RE sessions old enough to have developed opinions.

SpeakerBio:  Luca Borzacchiello, Nozomi Networks

Luca Borzacchiello is a Security Researcher with deep expertise in Symbolic Execution, Reverse Engineering, and Fuzzing. He currently works at Nozomi Networks, where he focuses on cutting-edge security research. Before joining Nozomi, Luca served as a Red Team Engineer for the Italian Government, where he contributed to national cybersecurity initiatives. He also worked as researcher on the Red Team at TIM S.p.A., one of Italy’s leading telecommunications companies. Luca holds a Ph.D. in Program Analysis from Sapienza University of Rome. Outside of work, he is an active participant in Capture The Flag (CTF) competitions, where he enjoys applying his reverse engineering skills in high-stakes challenges.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Wednesday - 22:00-22:59 PDT


Title: Raitlin's Challenge
Tags: Raitlin's Challenge | Contest
When: Wednesday, Aug 5, 22:00 - 22:59 PDT
Where: Online

Description:

Test your mental abilities with Raitlin's Challenge, the Illuminati Party®'s sophisticated collection of abstract visual puzzles, presented annually at DEF CON for over a decade. This intellectually demanding competition pushes participants to their limits through exceedingly complex challenges that require mastery of diverse knowledge domains.

The challenge begins with an initial invitation puzzle that serves as a gateway to the main experience. Once solved, competitors continue to a carefully curated series of abstract visual puzzles presented in an artistically refined format on the dedicated website. Each puzzle solved yields a verification string for validation and progress tracking.

What sets Raitlin's Challenge apart is its comprehensive scope, drawing upon principles from mathematics, science, engineering, technology, cryptography, protocols, algorithms, biology, chemistry, programming, and ancient history. While technical expertise, particularly in hacking, proves advantageous, the true challenge lies in applying abstract thinking across multiple disciplines.

The journey to completion varies significantly among participants, spanning anywhere from days to years. Unlike many competitive events, Raitlin's Challenge remains perpetually available after DEF CON concludes, allowing determined solvers to pursue solutions at their own pace. Those who ultimately succeed earn recognition on the prestigious ledger of completions, joining an elite group of problem-solvers who have demonstrated exceptional intellectual versatility and persistence in unraveling the secrets of the Illuminati Party®.

Participant Prerequisites

Access to a web browser and Internet connection.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 14:00-14:55 PDT


Title: RASM: A State Machine Methodology for RF Security Assessment
Tags: Radio Frequency Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

RF security assessment is fundamentally different from traditional application or network testing. Signals are invisible, environmental conditions influence behavior, protocols are often undocumented, and even small physical changes can alter outcomes in unexpected ways. Unlike conventional targets, RF systems rarely expose stable interfaces, useful diagnostics, or predictable attack paths. This talk introduces RASM (RF Attack State Machine), a methodology and state-aware research tool designed specifically for offensive RF investigations. Rather than treating assessment as a linear checklist, RASM models RF hacking as movement through interconnected operational states — from target understanding and signal discovery to demodulation, protocol analysis, manipulation, and validated exploitation. RASM operationalizes this methodology by helping researchers navigate RF investigations contextually. Information gathered during earlier stages influences recommendations, tooling choices, investigative paths, and subsequent transitions throughout the assessment process. Instead of attempting to automate RF analysis itself, the framework focuses on guiding researchers through the uncertainty and iterative decision-making that characterize real-world wireless security work. The session includes a live walkthrough of the RASM tool, demonstrating how researchers move through assessment states against a real RF target. It is intended for security researchers, SDR practitioners, hardware hackers, and anyone exploring offensive RF methodology and wireless security research workflows.

SpeakerBio:  Smriti Gaba
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Reali7y Overrun - Contest running
Tags: Reali7y Overrun | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 308 (Reali7y Overrun) - Map

Description:

Enter a near future dystopia where AI is threatening to take over the world through misinformation campaigns and leveraged takeover of automation technology. Join us for online and real world challenges, including an AI racecar challenge.

Friday and Saturday AI "deepracer" style car races at the event booth racetrack: * Noon * 2pm * 4pm

Sunday: Final scoring

All race times may have one or more race events. All race events are up to 3 simultaneous racers.

* YOU MUST COMPLETE IN-GAME CONTENT TO QUALIFY TO RACE. *

* Good luck! *


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 13:00-13:10 PDT


Title: Recon Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 13:00 - 13:10 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Recon Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Recon Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 13:30-13:40 PDT


Title: Red Team Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 13:30 - 13:40 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Red Team Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Red Team Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 12:00-13:59 PDT


Title: Red Teaming Kubernetes: From App-Level CVEs to Full Cluster Takeover
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

Kubernetes is the de facto operating system of the cloud, and more and more organizations are running their workloads on Kubernetes. While Kubernetes offers many benefits, it also introduces new security risks, such as cluster misconfiguration, leaked credentials, cryptojacking, container escapes, and vulnerable clusters.

In this workshop, attendees will learn how to attack Kubernetes clusters by simulating a real-world adversary exploiting one of the most recent vulnerabilities in the ecosystem: IngressNightmare (CVE-2025-1974). Participants will practice exfiltrating service account tokens and credentials, performing lateral movement, escalating privileges by targeting common applications deployed in Kubernetes environments, and ultimately compromising the entire cluster.

SpeakerBio:  Lenin Alevski, Security Engineer at Google

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 10:00-10:59 PDT


Title: RedMatter: Let AI Write Your Cross-Platform Mobile Exploits
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:
Live demo:
Redmatter kills the rewrite. You describe the attack you want in plain language like, bypass the pinning, dump the keychain, defeat the root check, and an AI layer generates the platform-specific Frida instrumentation for both the iOS and Android build of the same app. The harness orchestrates the run, adapts when the app fights back (new detection logic, obfuscation, a symbol that moved), and captures the evidence. You stay in the loop; the AI eats the tedious per-platform translation that used to eat your engagement.

Key takeaways: - Describe an attack in plain English on stage, watch the AI emit working iOS and Android modules, and fire them live on both builds side by side. - Throw a hardened target at it, like anti-Frida, pinning, root detection stacked, and let the harness adapt in real time.

SpeakerBio:  Subho Halder, Founder at MatterSec Labs

Subho Halder is the founder of MatterSec Labs, an AI security company, and a mobile security researcher with over a decade in offensive AppSec. He is the author of the Android Framework for Exploitation (AFE), one of the early open-source toolkits for Android app exploitation, which he has used to train operators on the BlackHat US instructor circuit. More recently he released KnoxSpy, a Frida-based instrumentation tool for intercepting MDM-protected traffic, at BlackHat Europe Arsenal 2025.

Before MatterSec, he co-founded Appknox, a mobile application security platform, and ran it for over ten years. His work sits at the intersection of iOS/Android binary analysis, runtime instrumentation, and AI-driven offensive tooling. He is now building Redmatter, the open-source harness debuting in this talk.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 13:00-14:50 PDT


Title: redStack: Boot-to-Breach Red Team Platform
Tags: Noob Community | Creator Workshop
When: Saturday, Aug 8, 13:00 - 14:50 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

This 2-hour, hands-on training is built around redStack - the open-source AWS project Mike developed to stand up a red team environment on demand. One Terraform command deploys an entire operator stack: three C2 frameworks (Mythic, Sliver, and Havoc), Kali and Windows hosts, a redirector, and a Guacamole portal.

SpeakerBio:  Michael Ortiz

Michael Ortiz is a Red Team Engineer and SME on the U.S. Department of State's Red Cell, running adversary emulation across State enterprise and partner networks. His focus spans offensive tradecraft, evasion engineering against modern EDR's, and the cybersecurity engineering behind durable red team infrastructure. He's the founder of devZero Security, an SDVOSB offering offensive security and security engineering services to federal and commercial clients, and the developer of redStack, an open source AWS and Terraform project that stands up a full red team operations stack on demand. A Marine Corps veteran, Mike holds OSEP, OSCP, CRTO, and CRTL, among other certifications.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 15:00-15:59 PDT


Title: Requiem for the Decommissioned: When Dead Hosts Bite Back
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:
Workshop: Requiem for the Decommissioned: When Dead Hosts Bite Back
Every organization has a graveyard - hosts that were decommissioned after a migration, abandoned when a project died, or simply dropped from inventory after a reorg. They're off the asset list, out of the patch cycle, and completely out of mind.
They're also still on the network.
This talk breaks down how forgotten and abandoned hosts consistently become the softest entry points during red team engagements - built from real engagement experience across large-scope assessments and bug bounty programs. We'll cover why they keep appearing, why they survive undetected, and how to systematically hunt for them using low-noise reconnaissance techniques.
Attendees will leave with a practical methodology they can apply on their next engagement.

Tactic: Hunting the Decommissioned: Hands-on Forgotten Host Discovery In this hands-on session, attendees will work through a practical recon methodology for identifying forgotten and abandoned hosts - using low-noise reconnaissance techniques available to any red teamer. We start together, walking through the methodology step by step against a prepared target modeled on patterns seen in real engagements. Then attendees get time to hunt independently while I'm available to answer questions. We close with a group debrief on what was found. A laptop with Kali, Parrot, or similar is recommended.

SpeakerBio:  Yekaterina Shevchenko

Yekaterina Shevchenko is a Lead Security Testing Engineer focused on penetration testing and red teaming. She works on large-scope security assessments across complex environments, with an emphasis on repeatable workflows, clear evidence, and actionable remediation. Her experience covers infrastructure, web applications, and cloud security. Yekaterina also shares educational content under the nickname m0rn1ngstr on her YouTube channel, focused on practical offensive security topics.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Saturday - 10:30-16:30 PDT


Title: Resume Review with the Lonely Hackers Club
Tags: Lonely Hackers Club | Creator Event/Activity
When: Saturday, Aug 8, 10:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

Free, one-on-one resume reviews, run by people from this community who have actually hired and managed technical teams. No recruiters. No corporate fluff. Just honest feedback from people who have sat on both sides of the table and know what works.

Sessions are 15 minutes. Walk up, sit down and get real feedback. Book your slot in advance or show up early to secure your spot if you missed the online registration.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 10:00-10:45 PDT


Title: Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Defense/Blue Team | Malware | Mobile | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

F5 (Westfeld, 2001) is the canonical "do it right" JPEG steganography algorithm — matrix encoding, permutative straddling, shrinkage handling — and still turns up on confiscated devices and in CTF challenges 25 years later. The public tooling has rotted: the original is Java, modern rewrites bind CGo to libjpeg, and every implementation surveyed is one-way (embed and extract, never un-embed). This Demo Lab presents ten public GitHub repositories that fix that, in pure Go with zero third-party dependencies. The headline is the first open-source F5 cover-recovery tool: given the stego JPEG, the password, and the extracted message, it reverses the embed and restores the cover's DCT coefficients. Alongside it ship three CLIs (embed, extract, recover), a pure-Go JPEG-family codec (baseline, JPEG 2000, JPEG-LS, XL/XR/XS/XT, Pleno, lossless), a Fridrich chi-square steganalysis library and CLI, and the supporting crypto, i18n, and logging packages — all auditable end-to-end in one language. Live: embed, extract, cover recovery, defensive Fridrich detection, JPEG re-encoding fragility, and a 25-line external Go program importing the library. Useful for digital forensics, steganalysis research, CTF authoring, and anyone who wants a CGo-free stego stack they can read in a weekend.

SpeakerBio:  0verkilll

Precise, Ruthless, Ethical


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 10:30-12:25 PDT


Title: RF CTF Kick Off Day 2
Tags: Radio Frequency Village | Radio Frequency Capture the Flag | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 12:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Presentation to kick off the Radio Frequency Village CTF with helpful tips for new folks.

SpeakerBio:  RF Hackers, RF Hackers Sanctuary
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 10:00-16:59 PDT


Title: Riot Games Vanguard: Pwn to own
Tags: Game Hacking Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

(Exact times TBD) Try your hand at hacking Riot Game's signature anti-cheat: Vanguard!


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Saturday - 10:00-10:45 PDT


Title: RIP Denuvo: DRM in a Post-Hypervisor World
Tags: Game Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

For a decade, Denuvo stood as the gold standard of game DRM. That reign has come to an abrupt end. Thanks to the advent of Hypervisor bypasses, games are now being cracked in a matter of hours rather than months. How did we get here, and what does the future hold for game DRM?

SpeakerBio:  Amin Hussien

Amin Hussien is the co-creator of the Illusory Unreal Engine game modding community (https://illusory.dev/) and has previously worked as an anti-cheat developer at [Redacted].


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 12:00-12:25 PDT


Title: Root Access: An APT Analysis of Systemic Gatekeeping in Cybersecurity
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:25 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Explore the unseen authorization systems shaping the cybersecurity field in this compelling talk. We'll apply threat intelligence and access control theory to understand who gains entry, who advances, and who sets the rules. Discover an APT architectural approach to visualize systemic gatekeeping and learn social-engineering strategies to gain 'root access.' The session will present two distinct threat models, inviting you to analyze the system as both an adversary and a target. Drawing on 30 years of experience and research in Next Generation Access Control (NGAC) hypergraph authorization, the speaker will equip attendees with a formal model for understanding the system, effective Tactics, Techniques, and Procedures (TTPs) to navigate it, and a framework for influencing the policies that govern our field. Don't miss this opportunity to gain critical insights and strategies for cybersecurity career navigation.

SpeakerBio:  Dr. Hassan Karim, Stable Cyber LLC

Hassan Karim, PhD is a cybersecurity researcher, academic, and founder of Stable Cyber LLC, with over 30 years of experience spanning financial infrastructure and payment systems at Goldman Sachs and JPMorgan Chase, OT/SCADA security and nation-scale infrastructure design at Aramco, and risk engineering across PNC Bank and Comerica. They hold a PhD in Computer Science from Howard University and conduct research in formal authorization models, adversarial AI risk, and cyber-physical systems security. Their published work on hypergraph-based access control for agentic AI and multi-robot systems is the technical foundation for this talk. They have operated, navigated, and quietly reverse-engineered the systems this talk is about for three decades.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:30-11:30 PDT


Title: Root From Kilometers Away: Ubiquiti AirMax RCE
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

You don't realize it until you see them; they're everywhere. From Wireless ISP links to the frontline of modern warfare. But nobody found anything? The devices behind those links are Ubiquiti AirMAX: critical infrastructure on a 17-year-old Linux kernel and a custom 802.11 extension built on "security by obscurity." So we took it apart. This talk covers our reverse engineering of the AirMAX protocol, AirOS, and the kernel modules behind this proprietary mode. It rides on 802.11 Information Elements that look encrypted, but we'll show why they aren't. What we found: two critical vulnerabilities (CVE-2026-21639, CVE-2026-21638) across airMAX AC, airMAX M, airFiber, and GigaBeam, over 50 devices. These are the bugs from the movies: Over-The-Air, unauthenticated, kernel-privilege RCE. No network access, just line of sight. They affect every AirMAX device ever shipped. We disclosed them through Ubiquiti's bug bounty program. The bugs were rated "Adjacent", except adjacent here means kilometers away. The same hardware can be turned around and pointed at the problem: we'll repurpose these devices as recon tools and release open-source software to locate AirMAX networks in the wild. This talk is about our journey, our tooling, and the state of security.

Speakers:Federico Kirschbaum,Gaston Aznarez

SpeakerBio:  Federico Kirschbaum, FaradaySec

Federico Kirschbaum is a security researcher with over two decades of experience building tools and ecosystems for offensive security. He is the Co-Founder and VP of Research in Faraday Security, an open-source platform. He is also the Co-Founder of Ekoparty, Latin America’s largest hacking conference, where he has helped shape the region’s security research community for over 20 years.

SpeakerBio:  Gaston Aznarez, FaradaySec

Gaston Aznarez is a Principal Security Researcher at Faraday Security, focused on IoT and embedded device vulnerability research, firmware reverse engineering, wireless protocol analysis, and hardware-level exploitation. He has presented at DEF CON, Black Hat and Ekoparty.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 13:05-13:45 PDT


Title: Ropkit: Framework for Windows Kernel Code Execution under HVCI
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:05 - 13:45 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

The Windows Kernel has become a highly hardened environment. With the default enforcement of HVCI (Hypervisor enforced Code Integrity), meaningful impacts of BYOVD (Bring your own vulnerable driver) attacks becomes increasingly difficult. Furthermore, modern BYOVD attacks require the use of physical read/write primitives, which leave the much more common virtual read/write primitives difficult to weaponize.

To assist in kernel exploitation, I developed two novel methods of kernel code execution within Windows given a virtual read/write primitive. I implemented PTE remapping that results an SSDT hijack, and a JOP chain that bypasses Kernel Shadow Stacks. These methods can only be blocked by hardware controls that are not yet implemented on AMD machines (Intel VT-rp), or are simply nonpresent in current Windows kernel (Kernel Shadow Stack Branch Tracking).

Additionally, I will be releasing ropkit, a dynamic kernel framework built to conduct BYOVD attacks. This framework functions on different windows builds with different drivers. Known and novel code execution methods are included into this framework as well. Red Teamers simply provide a driver exploit, and this framework automates the rest of the exploitation process.

SpeakerBio:  Nathan Sawyer, Independent Researcher

Nathan Sawyer is a junior studying Cybersecurity at the University of Idaho. He has obtained HTB CDSA and CPTS. He enjoys skiing, snowboarding, hockey, and lacrosse.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 17:30-17:59 PDT


Title: SADF: A Taxonomy and Evaluation Framework for Agentic Security Failures
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:
Emerging agentic systems operate across attack surfaces that existing security evaluations were not designed to measure: external tools, persistent memory, retrieval pipelines, delegated credentials, and multi-agent orchestration. Most agent security benchmarks measure success using substring matching — checking whether attack-related keywords appear anywhere in the model response. We show this systematically overstates success rates because capable models quote attack indicators verbatim in their refusals.
We introduce SADF (Synthetic Agent Deception Framework), an eight-class taxonomy of agentic security failures — Tool Call Hijacking, Output Poisoning, Cross-Tool Injection, Memory Poisoning, RAG Poisoning, Delegated Authority Abuse, Multi-Agent Propagation, and Context Boundary Violation — and an automated testing harness with refusal-filtered scoring grounded in actual tool execution output strings.
Since the initial submission, we extended the evaluation from 3 direct model architectures to 7 total, adding four production framework wrappers (LangChain, AutoGen, CrewAI, SmolAgents), growing the dataset from 96 to 2,656 real evaluation runs. This extended evaluation reveals a finding absent from the original submission: the orchestration framework is an independent attack surface. Holding the model constant (Claude Sonnet) and varying only the framework wrapper produces a 2.6× spread in Agent Compromise Rate — from 11.9% (CrewAI) to 31.1% (SmolAgents) — with the direct Sonnet baseline at 15.6%. The choice of framework matters as much as the choice of model.
The original direct-model findings are confirmed and extended. Naive substring matching reported 90–100% success across all models; after refusal-filtered scoring, true rates were 59% (Llama 3.2), 22% (Claude Haiku), and 16% (Claude Sonnet) — a 4–6× overstatement. Memory Poisoning remains the sharpest safety boundary: Llama 3.2 was compromised on 3/3 payloads; all four framework architectures and Claude Sonnet achieved 0% across 243 combined Memory Poisoning runs. Delegated Authority Abuse scored 0% on both Claude models even when every authorization check passed — suggesting safety training captures intent, not only surface features. Two payloads (File Path Traversal, Code Execution to File Write) succeeded across all seven architectures, indicating a universal floor that neither safety training nor per-tool authorization controls currently address.
Attendees will leave with the full eight-class taxonomy, refusal-filtered scoring methodology, cross-architecture results across 2,656 real evaluation runs, and the complete open-source harness at github.com/jbdu94/SADF.
SpeakerBio:  Julie Brunias

Julie Brunias is a cybersecurity professional with over 14 years of experience in offensive security, red teaming, and enterprise security architecture across sectors including energy, banking, telecommunications, and manufacturing. She specializes in AI security and adversarial system analysis, focusing on how generative AI systems, large language models, and agent-based architectures can be attacked, misused, and secured in real-world environments. Her work bridges offensive security and emerging AI system risks, including prompt injection, indirect prompt injection, RAG poisoning, model manipulation, and AI agent exploitation.

Julie has led red and purple team engagements and security architecture initiatives in complex enterprise environments, applying offensive security techniques to emerging AI-native systems and autonomous technologies.

Her research focuses on AI system failure modes, adversarial machine learning, Shadow AI risks, and practical methods for evaluating and securing agentic AI systems. She is the creator of several applied research efforts, including SADF (a taxonomy for agentic security failures), MCP security tooling, and ransomware intelligence analysis systems.

Her work has been presented at international security conferences including AI Village (accepted talk and poster), InCyber Forum, GoSec, HackMiami, and Black Hat (accepted), focusing on the intersection of offensive security and AI system resilience.

She is particularly focused on helping organizations understand and mitigate risks in production AI systems as they transition from experimental deployments to mission-critical infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Saturday - 13:00-13:30 PDT


Title: Safe, Secure, and Effective: What Static Behavior Analysis Reveals About the Software Running Your Medical Devices
Tags: Biohacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

When a patient monitor misreads an ECG or an infusion pump miscalculates a dose, the root cause is software behavior, not a CVE. Yet the entire medical device security industry is fixated on vulnerability scanning and SBOMs while ignoring the harder question the FDA actually asks: does this software behave in ways that are safe and effective for its clinical purpose?

Using automated reverse engineering developed under ARPA-H research, we analyze compiled medical device firmware to build Software Bills of Behaviors that map what every function in a binary actually does. We automatically categorize hundreds of functions into clinical subsystems: ECG data processing, SpO2 and CO2 signal handling, physiological waveform display, sensor calibration, and heatblock control. We then identify which subsystems constitute essential performance, the functions where a bug, an unexpected change, or a malicious modification doesn't just create a cyber incident, it harms a patient.

We'll walk through real device firmware where we found functions that directly modify ECG configuration and hardware calibration state, where logic flaws or race conditions could impact device safety, stability, or data integrity. We'll show how a firmware update that only touches 10% of functions can silently alter safety-critical signal processing paths, and how we automatically assess whether those changes affect clinical operation or are benign. We'll demonstrate how the Contec CMS8000 patient monitor contained unapproved wireless monitoring capabilities the FDA never cleared, a safety and regulatory violation invisible to any vulnerability scanner.

Whether you're building devices, securing hospitals, or hacking medical firmware, this talk shifts the frame from "is it vulnerable?" to "is it safe?" because the patient on the other end doesn't care about your CVSS score.

SpeakerBio:  Andrew Hendela

Andrew Hendela has been automating hard offensive and defensive cyber for well over a decade and a half, from VR, malware analysis, and cyber attribution. He is also a co-founder of Karambit.AI, a startup focused on validating the safety, security, and effectiveness of software and firmware.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: SANS Institute NetWars Labs
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

SANS NetWars is a suite of advanced cyber ranges offering interactive, hands-on learning exercises created by SANS faculty in realistic network environments, gamifying cybersecurity training through compelling storylines and real-world challenges. Drop in during village hours to work through NetWars challenges at your own pace.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: Satellites Under Attack: Hands-On Satellite Security Threat Scenarios
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

In this “Satellite Attack Lab” you can explore how cyber-attacks against satellite systems can be launched, observed, and understood through a hands-on, attacker-centric experience. Rather than focusing on normal satellite operations, you will step into the role of a threat actor and directly exploit vulnerabilities in a simulated space environment by interacting with a physical setup of model satellites and ground stations to witness the immediate consequences of malicious actions, including intercepted data, unauthorized command execution, and visible disruption of satellite behavior.

We provide hacker workstations pre-configured with satellite command tools and signal-processing software. Large displays show the victim system’s telemetry and status in real time, allowing participants to immediately see the effects of their attacks.

This session is designed to be highly interactive and accessible to newcomers while still offering meaningful technical depth for advanced attendees.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 11:00-12:59 PDT


Title: SBOM Find the Flaws
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map

Description:

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 15:00-16:59 PDT


Title: SBOM Find the Flaws
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map

Description:

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 13:40-13:50 PDT


Title: Scambait Community Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 13:40 - 13:50 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Scambait Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Scambait Community and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Saturday - 12:30-13:59 PDT


Title: Scammers Don't Discriminate
Tags: Scambait Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Scammers don't just target the elderly. Young people are increasingly in their crosshairs. In this talk, DolphinVG examines how fraudsters are adapting their tactics to exploit youth through social media, gaming platforms, crypto schemes, job scams, romance scams, and more. Drawing on real cases and community experience, the session highlights why younger generations are vulnerable, the unique pressures they face, and practical ways the scambait community can help protect them.

SpeakerBio:  DolphinVG
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 10:00-10:45 PDT


Title: SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked.
Tags: DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

Shift-left tools scan what you commit, not what you serve. DAST scanners test for vulnerabilities but ignore live traffic. The industry left a gap: runtime secrets. Finding them requires intercepting live traffic: a proxy, a browser extension, or a bulk scanner. SecretSifter is all three.

We tested 2,000 production apps against ten secret scanners. 194 confirmed credentials survived all ten scanners.

SecretSifter monitors live HTTP traffic and finds credentials in JS bundles, lazy-loaded chunks, HTML responses, JSON and XML APIs, and request headers. No config, no source code. 160+ rules cover vendor tokens (AWS, Azure, Stripe, Twilio, GitHub), entropy-gated patterns, and CryptoJS-encrypted configs where the decryption key is hardcoded in the same bundle. No other scanner catches that case. Bulk mode scans 30-50 targets: paste URLs, scan, optional AI triage, export HTML, CSV, or ZIP.

The session opens with a live tool comparison. Most tools scan one URL at a time and require manual browsing. SecretSifter bulk-scans both targets in parallel. Two findings none of the ten caught: Azure AD credentials baked into a webpack bundle past GitLeaks. A CryptoJS config with the decryption key three lines away.

Your entire pipeline reported green. Were they right? Attendees leave with a free tool to run the same day.

SpeakerBio:  Hemanth Gorijala

Hemanth Gorijala is Global Pentest Lead at a Fortune 100 financial services company. He built SecretSifter to close the runtime security gap: the space between where shift-left secret scanning stops and where secrets actually appear in production. His research identified 194 confirmed credentials across 2,000 production applications that bypassed ten secret scanners. He is presenting that research at security conferences across the US. The GT-194 benchmark is published on Zenodo (DOI 10.5281/zenodo.19464446). SecretSifter is open source at github.com/secretsifter.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 14:45-15:15 PDT


Title: Securing Nix Builds using microVMs
Tags: Nix Vegas Community | Creator Talk/Panel
When: Saturday, Aug 8, 14:45 - 15:15 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Recent vulnerabilities like Copy Fail and DirtyFrag have made abundantly clear just how risky it is to run untrusted Nix builds inside your core infrastructure. In response, we at Determinate Systems have begun building every Nix package inside of ephemeral microVMs. This talk covers what microVMs are, how they limit kernel-level vulnerabilities, and how we hope to substantially improve our security posture using this technology.

SpeakerBio:  Tristan Ross

I work on supply chain security at Determinate Systems.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 16:00-16:59 PDT


Title: Securing the AI Stack and Hunting Across Clouds
Tags: Cloud Village | Creator Event/Activity | Strategic Defense
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) B - Map

Description:

Teams are deploying AI agents fast, often without guardrails. Attackers are exploiting cross-cloud trust to pivot between environments. This lab tackles both.

Part A (30 min): Securing the AI Stack- Find over-broad permissions on an AI agent's execution role - Discover prompt injection evidence in model invocation logs - Review Amazon Bedrock Guardrails that block injection, prevent system prompt leakage, and filter PII

Part B (30 min): Cross-Cloud Threat Hunting with OCSF- See how AWS, Azure, and GCP logs map to the same OCSF schema - Trace lateral movement across three clouds using federated identity - Write a detection rule that catches cross-cloud federation abuse

SpeakerBio:  Bryant Pickford

Bryant Pickford is a Security Specialist Solutions Architect at AWS, where he leads security, risk, and compliance discussions with enterprise customers to align strategies and drive secure outcomes on the AWS platform. With over five years at AWS and deep expertise in Edge Security, Threat Detection, and Generative AI, Bryant specializes in identifying emerging threats and developing practical defense strategies for cloud-native environments.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:
SpeakerBio:  Madhu Akula
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:
SpeakerBio:  Madhu Akula
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 16:00-16:59 PDT


Title: Securing the Safety Net: Why Healthcare Cybersecurity Policy Keeps Failing Patients
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

In 2024, ransomware at Change Healthcare didn’t just hit one company—it jammed up claims and eligibility checks across the country, squeezed provider cash flow, and made something painfully clear: you can’t regulate your way to security when the business model starves defenders of time, staff, and budget. This panel brings two hospital CISOs, a medical device manufacturer’s head of product security, and a healthcare policy advocate to talk about the failures that today’s policy stack—the HIPAA Security Rule overhaul, HHS Cybersecurity Performance Goals, and proposed CMS conditions of participation—still won’t fix. We’ll unpack the reimbursement trap (thin margins → underinvestment → incidents → thinner margins → unfunded mandates), why devices with decade-long lifecycles end up living forever in clinical environments, and how vendor concentration turns “third-party risk” into systemic risk. This won’t be four people nodding. Each panelist will put one concrete intervention on the table—reimbursement-linked incentives, meaningful safe-harbor protections, and supply-chain transparency requirements—then we’ll pressure-test the tradeoffs. If you want to understand why healthcare keeps getting owned despite “critical infrastructure” status, and what policy could change the incentive landscape, come argue with us.

Speakers:Sahan Fernando,James Bowie,Nancy Brainerd,Phil Englert

SpeakerBio:  Sahan Fernando, Rady Children's Health

Sahan Fernando is the Chief Information Security Officer for Rady Children’s Hospital San Diego, one of the nation’s top pediatric health care systems. His experience includes security operations and engineering, incident response, and IT and Information Security Program Development in different verticals. He has spoken at multiple security conferences including Cyphercon, SO-CON, Bsides CLT, Health-ISAC, Blue Team Con, and Epic XGM/XGM. He also serves on the board for Health-ISAC.

SpeakerBio:  James Bowie, Tampa General Hospital

Jim Bowie is Vice President and Chief Information Security Officer (CISO) at Florida Health Science Center, Inc., responsible for cybersecurity strategy, risk management, and operational defense across FHSC and its affiliated entities. Prior to joining FHSC, he served as Director of Cyber Operations at Moffitt Cancer Center. He has also held multiple roles at Tampa General, including Director of Infrastructure, Cyber Operations, and Clinical Applications Manager, bringing deep experience across clinical technology, operations, and security. Bowie previously worked in law enforcement with the Tampa Police Department, supporting cybersecurity and digital forensics investigations. He began his career in emergency medical services, including service as Director of Emory Emergency Medical Services, a volunteer EMS agency. Bowie earned a master’s degree in Cybersecurity and Information Assurance and is currently pursuing a PhD in Cyber Defense along with a second master’s degree in Artificial Intelligence. He also holds a BA in History. He is accredited by the College of Healthcare Information Management Executives (CHIME) as a Certified Healthcare Information Security Leader (CHISL) and maintains several additional industry certifications.

SpeakerBio:  Nancy Brainerd, Medtronic

Nancy Brainerd joined Medtronic in 2000 kicking off a career in Information Technology. In 2006, she began working within the information security field and had the opportunity to build out Medtronic’s first Cyber Defense organization, specializing in cybersecurity incident response. As scrutiny of cybersecurity of medical devices has increased, Nancy made the shift in 2023 to focus on security of Medtronic’s products. She is currently a Senior Director in the Product Security Office with oversight of cybersecurity of Medtronic devices and products. Nancy is active in the security industry and participates in many coordinated activities, including a current directorship on the board for Health-ISAC (Health Information Sharing and Analysis Center). She is a frequent guest lecturer at the University of Minnesota on the topic of Cybersecurity in the “Introduction to Information Technology in Business” undergraduate course.

SpeakerBio:  Phil Englert, Health-ISAC

Phil Englert is the VP of Medical Device Security at Health ISAC, where he works with medical device manufacturers to strengthen privacy and security while partnering with healthcare delivery organizations to ensure those solutions are practical, deployable, and clinically aligned. He also defines long term vision, leads cross sector initiatives, advances best practices, and delivers programs that improve sector resilience and serves as a subject matter expert and contributor to Health ISAC’s Medical Device Security Council (MDSC). Phil leads Health ISAC’s strategy to strengthen cybersecurity and privacy across the global medical technology ecosystem. This role directs the organization’s medical device security program, partnering with manufacturers and healthcare delivery organizations to drive practical, secure implementations while shaping regulatory and standards. Phil oversees coordinated vulnerability disclosure efforts with researchers, regulators, and government agencies, and serves as a subject matter expert to the 500 member Medical Device Security Council.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 11:00-11:30 PDT


Title: Security Analysis of Open-Source Software Used in Onboard Satellite Systems
Tags: Aerospace Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Satellite missions are increasingly making use of open-source software, but this creates a unique security challenge for space systems. Unlike conventional IT environments, updating software onboard satellites can be far more difficult due to operational risk, limited access windows, mission validation requirements, and the high cost of mistakes after launch. In many cases, space systems also remain in operation for years, which means software may continue running on aging hardware and in environments where patching, upgrading, or fixing security issues is far more constrained than on the ground. This talk presents SCA-SAT, a purpose-built pipeline created to analyze the current security state of open-source software used in onboard satellite systems at scale. The goal is to answer a simple but important question: what does the current security landscape of open-source onboard satellite software actually look like?

SpeakerBio:  Roee Idan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 10:30-10:59 PDT


Title: Self Hosting Nightmare - Exploiting AI models for supply chain attacks
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

In this presentation I'll go through the process of how you could possibly exploit this vulnerability in one of thousands servers exposed to the internet running the top one tool in the world for self hosting AI models. The process I'll demonstrate in this presentation involves exploring vulnerable by default decisions to achieve total control of this model serving tool, and the vulnerability research I have done on top of this tool that led me to find 7 0day vulnerabilities that allows anyone to achieve the following results:

SpeakerBio:  Davidson Mizael, Incident Responder @ IBM X-Force

Long time hacker and former developer working at IBM X-Force doing Incident Response.

Hacking for the fun of it and always trying to building cool stuff.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 14:00-14:45 PDT


Title: Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop
Tags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 14:00 - 14:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

Senrigan (千里眼) and Suzaku (朱雀) are two complementary open-source tools that together form a complete threat hunting and DFIR platform for AWS CloudTrail logs. Both are built by Yamato Security, the volunteer-run Japanese security community behind Hayabusa(隼), the widely adopted Windows event log fast-forensics tool. Yamato Security provides free, open-source DFIR tools and resources to the community.

Building on Hayabusa's philosophy of fast, offline, community rule-based detection, this toolset brings the same approach to the cloud. Security teams can hunt threats across CloudTrail logs on a single laptop — without a SIEM, dedicated infrastructure, or licensing cost.

The two tools work together, with Suzaku's detections flowing into Senrigan for analysis. Senrigan, deployed via Docker Compose, ingests CloudTrail logs into DuckDB via a Rust-based ingester, then lets analysts investigate them through 100+ pre-built hunting queries and 80+ pre-built Apache Superset dashboard charts — no SQL or CloudTrail schema knowledge required. Suzaku is a high-performance, standalone Rust-based CLI that applies native Sigma detection rules to CloudTrail logs and generates a fast-forensics DFIR timeline — surfacing attacks buried in the noise, producing only the events analysts need to investigate.

Speakers:Fukusuke Takahashi,Zach Mathis,Akira Nishikawa

SpeakerBio:  Fukusuke Takahashi

Fukusuke Takahashi has been with NTTDATA-CERT (NTT DATA Group Corporation's CSIRT) since 2018, specializing in DFIR, OSINT, and SOAR. He is one of the developers of Yamato Security's OSS tools. He enjoys developing open-source Blue Team tools. He has presented at conferences such as FIRST Annual Conferences, SECCON, BSides Tokyo, HITCON CMT, SecTor and AUSCERT.

SpeakerBio:  Zach Mathis

Zach Mathis has been working in Japan doing offensive and defensive security work for Japanese companies since 2006. In 2012, he founded Yamato Security, one of the largest hands-on hacker communities in Japan. With other Yamato Security members, he has been releasing free and open source DFIR tools and resources since 2020.

SpeakerBio:  Akira Nishikawa

Akira Nishikawa started his career as a software engineer specializing in embedded development. He worked as a freelance engineer in 2007, focusing on system development and operation for various companies. Since 2021, he has been dedicated to fostering a security culture for SaaS product security and improving service security. Additionally, he is an AWS Community Builder as of 2024.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 14:00-14:30 PDT


Title: Separating News from Noise
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

News versus noise. Every election cycle brings a flood of headlines covering changes to election administration, election security, and the voter experience. The 2026 midterm elections will unfold amid significant legal, policy, and election security developments. What developments will have the most impact on the 2026 midterm elections and beyond, and which are unlikely to have a lasting impact? Join a panel of election administrators, legal experts, and cybersecurity professionals as they analyze the year’s most significant election developments, separate consequential changes from background noise, and discuss their practical implications for election administration, cybersecurity, and the voter experience. Topics include federal and state election laws, executive orders, SCOTUS rulings, redistricting disputes, election security, and other issues influencing both the immediate and long-term future of American elections. Attendees will leave better equipped to distinguish consequential election developments from background noise and understand how those developments affect election administration, cybersecurity, voter confidence, and the voter experience.

Speakers:Ryan Murray,Stephen Richter,Nate Young

SpeakerBio:  Ryan Murray

Ryan Murray is Deputy Director and CISO of Arizona DHS. He has his finger on the pulse of current elections cybersecurity operations from the AZ-ISAC) Information and Analysis Center) and AZ-DHS (Dept. of Homeland Security) fusion center operations.

SpeakerBio:  Stephen Richter

Stephen Richer is a legal fellow with the Cato Institute’s Robert A. Levy Center for Constitutional Studies. His work focuses on election administration, American democracy, executive orders, and American politics. He is a visiting senior fellow at the Ash Center for Democratic Governance and Innovation at Harvard University’s Kennedy School. He is also the CEO of Republic Affairs, a crisis consulting firm for pro-democracy, pro-rule-of-law entities and individuals. He was the Maricopa Recorder from 2021 - 2025, and experienced first hand the Arizona Senate Audit (CyberNinjas) and related Department of Justice Investigations.

SpeakerBio:  Nate Young

Nate Young is the Deputy CIO of Elections Information Technology for Maricopa County, where he leads a dedicated team of career IT professionals focused on supporting and facilitating secure, accurate, and accessible elections. With 19 years of experience across government and the education sector, Nate brings a broad and practical perspective to public-sector technology. Since 2021, Nate has focused on elections technology and cyber security since 2021 with the 2020 Elections audit from the Cyber Ninjas. Nate has presented at many Elections and cyber security related conferences, including the DEFCON Voting Village 2022, 2024, 2025.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 10:00-10:30 PDT


Title: Shadow Webhooks: Hunting for Dangling Event Listeners in Enterprise Workspaces
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Enterprise SaaS environments accumulate webhooks faster than teams can track them. Slack apps, Teams connectors, Jira automations, GitHub webhooks, CI/CD callbacks, monitoring alerts, and abandoned integrations often remain active long after the receiving service, repository, domain, or owner disappears. These forgotten event listeners can become quiet security liabilities: they may leak event payloads, accept forged messages, expose secrets in callback URLs, or create takeover paths when linked infrastructure expires. This talk presents a practical bug bounty methodology for finding and reporting “shadow webhooks”: trusted event connections that still exist inside an enterprise workspace but no longer have a clear owner, valid destination, or reliable validation model. I will cover how to inventory webhook surfaces, classify destination risk, fingerprint abandoned endpoints, identify dangling domains or retired cloud functions, test signing and replay behavior safely, and prove impact without collecting real third-party data. The demo uses a controlled lab that models common workflows across source control, ticketing, chat, and CI/CD systems. One webhook points to a retired destination. Another accepts events without strong signature validation. The audience will see how synthetic project events and incident notifications can reach the wrong endpoint, how weak validation allows forged events, and how the issue should be documented for a bounty program. The talk also covers what makes a webhook finding triageable: affected asset, trusted event source, destination ownership, payload sensitivity, validation weakness, and business impact. For defenders and program owners, it provides controls for webhook inventory, owner mapping, event signing, secret rotation, endpoint expiration, and domain lifecycle monitoring. The goal is to turn forgotten webhook exposure from a vague SaaS hygiene issue into a clear, reproducible bug bounty finding.

Speakers:Samet Can Tasci,Mehmet Önder Key

SpeakerBio:  Samet Can Tasci, Senior Linux Systems Engineer

Samet Can Tasci is a Senior Linux Systems Engineer and security researcher with experience across enterprise infrastructure, cloud and hybrid environments, automation, and defensive security validation.

His research interests include web defense behavior, WAF normalization gaps, parser inconsistencies, adversary-informed testing, and practical tooling for security teams.

He is the creator of WaffleX, a research prototype selected for Black Hat USA Arsenal, which focuses on semantic consistency analysis, enforcement drift, and family-level request-variant testing across modern web application defense stacks.

SpeakerBio:  Mehmet Önder Key, Cyber Security Consultant

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

Maritime Hacking Village - Saturday - 16:00-16:30 PDT


Title: Shipcrawler: Automated Maritime OSINT — From Open Data to Actionable Intelligence
Tags: Maritime Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

The maritime sector leaks an enormous amount of sensitive information through public sources — crew social media, vessel tracking data, port records, corporate registries, and leaked credentials. Shipcrawler is an open-source automated OSINT tool that aggregates, correlates, and reports on vessel, crew, company, and port authority intelligence from publicly available sources. Built with a queue-based architecture and AI Agent-powered worker pipeline, it has produced over seven comprehensive intelligence reports covering vessels, port authorities, and maritime personnel. This talk demonstrates OSINT collection against maritime targets, discusses the ethical and operational implications of maritime data exposure, and shows how OSINT audits can inform defensive posture improvements. All code and methodologies are open-source to help the maritime community understand their own attack surface.

SpeakerBio:  Ahmed Nagi Nasr, Estonian Maritime Academy - Tallinn University of Technology (TalTech)

Maritime cybersecurity researcher at TalTech, author of Shipcrawler and Project Haris. Published in IEEE Access, TransNav, J. Marine Science. Focused on open-source defense tools for maritime IT/OT security.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 14:00-14:15 PDT


Title: Signal Hijacked: How Mobile Networks Became Phishing's Most Trusted Delivery Layer
Tags: Telecom Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:15 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. Live Demonstration: "The Signal Switch"
  2. Display a realistic QR code (restaurant menu, airport Wi-Fi, or bank notification).
  3. Ask the audience whether they would scan it.
  4. Walk through what happens after scanning.
  5. Show how the phishing page is delivered over a trusted mobile channel (WhatsApp/SMS simulation).
  6. Demonstrate analytics showing user interactions and explain how attackers track victims.
  7. Compare the same QR code against AI analysis (ChatGPT, Claude, Gemini) and highlight the differences in detection.
SpeakerBio:  Sindhura Kona
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 12:30-12:59 PDT


Title: Signaling Sabotage: Why 100% Compliance is 0% Security
Tags: Telecom Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 12:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:

Why 100% Compliance is 0% Security exposes the dangerous false sense of security that compliance audits create in modern telecommunications. While regulatory checklists establish a baseline, real-world threat actors routinely bypass compliant controls to exploit critical protocol vulnerabilities across SS7, Diameter, GTP, and SIP networks. This talk bridges the gap between regulatory requirements and real-world operational security, highlighting live-fire signaling attack techniques and hidden abuse cases that traditional audits miss. Attendees will learn why standard compliance falls short and discover actionable strategies for building true resilience—leveraging proactive threat hunting, offensive security

SpeakerBio:  Vinod Shrimali
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 11:00-11:45 PDT


Title: sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | DevOps | Purple Team | DEF CON Demo Labs
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map

Description:

GitHub Actions workflows are vulnerable by default. Hardening such as commit-hash pinning, least-privilege permissions, and timeouts is optional, never enforced at pipeline level. Exploitable configs ship daily, increasingly written by Coding Agents. sisakulint is a fast heuristic static analyzer for GitHub Actions covering all OWASP Top 10 CI/CD risks, with 52 rules, a taint engine, and 38+ auto-fixes. It outpaces CodeQL on speed and quality, with 100% detection on 18 GHSL advisories and 81.6% on 38 GHSAs covering exploits in PX4-Autopilot, vets-api, weaviate, nrwl/nx.

Impostor Commit at CVSS 9.8 validates pinned SHAs against the claimed repository, not impostors via Git forks, a check unique to sisakulint. Code Injection at CVSS 9.8 tracks untrusted input through ${{ }} and step outputs. AI Action Rules detect Clinejection on claude-code-action, copilot-swe-agent, and openai-actions, covering tool grants, prompt injection, and wildcard triggers, as in Cline 2026/02 where issue title injection stole NPM_RELEASE_TOKEN. Known Vulnerable Actions catches tj-actions/changed-files.

In the Coding Agent era, linters matter more. Delegating 52 rules to an LLM degrades precision; deterministic engines run in ms with no variance. The session covers end-to-end detection, taint propagation, and automated remediation.

Speakers:Atsushi Sada,hikae

SpeakerBio:  Atsushi Sada

Atsushi Sada is a CSIRT member specializing in cloud security on AWS and GitHub, and enterprise security with MDM, EDR, AI governance. He is an ethical hacker and security tool developer. He built sisakulint and MachStealer for practical security research in static/network analysis, Malware.

He co-founded and organizes @sec_wakate, a community for junior security engineers in Japan. He has spoken at Black Hat USA/Asia Arsenal, AVTOKYO, and AWS Security JAWS.

SpeakerBio:  hikae

Security Engineer in Red Team @ freee inc, AI Security Specialist.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 15:00-15:59 PDT


Title: Six Impossible Things Before Breakfast: Common Misconceptions About Being a CTI Analyst
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

"Why, sometimes I've believed as many as six impossible things before breakfast." So said the White Queen to Alice — and so says the cybersecurity community about what it means to work in cyber threat intelligence.

The cyber threat intelligence (CTI) domain is rich with acronyms, niche frameworks, specialized tools, and diverse practitioners — and for newcomers, whether they are making a career change or just starting, that richness can feel more like a labyrinth than an invitation. From engaging with novice analysts at industry conferences and through diversity and inclusion programs like Cyversity, to teaching at the undergraduate level, I've found that a consistent set of misconceptions keeps talented, curious people from ever walking through the door. And that's a problem, because CTI needs those people.

This presentation will guide attendees down the rabbit hole and into the CTI domain, starting with a primer on intelligence history and the intelligence lifecycle before tackling six of the most persistent myths head-on: that you need deep technical expertise to succeed; that CTI only exists in government; that the job is just monitoring feeds and social media; that you'll spend your career writing endless reports; that success requires mastering thousands of tools; and that automation will eventually make analysts obsolete. Each misconception will be examined, dismantled, and replaced with a clearer picture of what the work actually looks like — and why diverse, non-traditional backgrounds don't just belong in CTI, they make it stronger.

Attendees will leave with a grounded understanding of the CTI domain, a realistic sense of what the role demands, and concrete first steps for getting involved — whether they're a seasoned professional exploring a pivot or a complete newcomer who just learned what "CTI" stands for five minutes ago.

(outline below)

Title Slide [< 1 min] Presentation Disclaimers [< 1 min] Agenda [< 1 min] Speaker Introduction [2 min]

Down the Rabbit Hole: Cyber Threat Intelligence Primer [4 mins] Foundations of the cyber threat intelligence domain Intelligence history and lifecycle

The White Rabbit: You Will Not Succeed without a Technical Background [6 mins] Non-technical skills, such as written and verbal communication, are equally important. Problem-solving and pattern recognition are key to collaborating with other technical teams. Still, you do not need the same skills as members of those teams, i.e. detection engineering or malware reverse engineering. Continuous learning for upskilling

We're All Mad Here: CTI is Only Used in the Government [6 mins] Most private enterprises also embed cyber threat intelligence teams' practices within their cybersecurity operations department. Use cases: fraud and payments intelligence in financial services; tracking threat actors' abuse of consumer-facing services and platforms in the technology sector; monitoring disruptive threat activity in critical infrastructure businesses Cross-industry sharing and collaboration

Tweedledee and Tweedledum: You're Just Monitoring Threat Feeds and Social Media [6-8 mins] CTI is a multi-faceted field and involves more than "eyes-on-glass" monitoring. Examples of other areas of focus: Campaign analysis Operational research and correlation of threat actor behaviors with other cybersecurity teams Threat infrastructure hunting and pivoting Threat communication and influencing

The Mad Hatter's Tea Party: Endless Report Writing [6 mins] Stakeholder communication preferences usually dictate threat intelligence output Some stakeholders may prefer visual communications (presentations, one-pagers, system dashboards) over written reports. Other stakeholders may prefer brief tactical updates via Teams/Slack or notes added to a SOAR platform.

The Queen of Hearts' Rules: Your Success Hinges on Knowing Thousands of Tools [6 mins] Tools will come and go, but methodology and critical thinking are more important Prioritize understanding how to perform analysis, leverage intelligence frameworks, influence stakeholders, and collaborate with others over learning an individual tool.

Humpty Dumpty was Confidently Wrong: CTI Can be Fully Automated [8 mins] Automation plays a pivotal role but cannot outright replace analysts who support the domain. Scripts can help eliminate mundane tasks. Applying CTI adequately anchors on qualitative assessments and knowledge of an enterprise's security posture Applications of AI in CTI AI could help welcome more diverse CTI practitioners by breaking down barriers to entry due to the required technical skill set.

Summary [5 mins] Getting started today

Q&A [Remaining Time]

SpeakerBio:  Brett Tolbert
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: Skillbit Labs
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

SkillBit Labs is a continuous learning platform designed to help assess and develop cybersecurity skills through hands-on, bite-sized labs. Drop in during village hours and work through beginner-friendly challenges at your own pace, brought to you by SkillBit (formerly MetaCTF), led by CEO Roman Bohuk.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 10:00-17:59 PDT


Title: Smart Home in the Matter: Blink, Race, Attack CTF
Tags: IoT Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 15:00-15:59 PDT


Title: Smile, you're on camera! Livestreaming from North Korea's IT workers laptop farm
Tags: DEF CON Official Talk | Demo 💻
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

We infiltrated a cell of North Korean IT workers dedicated to obtaining remote employment for the DPRK, attributed to Famous Chollima (Lazarus Group). Posing as facilitators, we went through their full recruitment process and, once inside, provided them with controlled environments that allowed us to observe and record their operations from the inside.

In parallel, we used OSINT and targeted reconnaissance to map their infrastructure, track financial movements, and reconstruct the broader structure behind the operation. This includes networks of fake companies and identities, local facilitators, fraudulent H-1B visa schemes, and a coordinated model of transnational fraud used to gain access to Western companies.

The talk features recorded direct interactions with DPRK operatives and live recordings from a fake laptop farm we built for them. While they believed they had remote access to legitimate work systems, we captured everything: how they set up their infrastructure, handled authentication, configured VPNs, and operated on a daily basis.

This was the first time this kind of threat campaign was profiled, recorded, and published from the inside. Now we want to share it with you. Smile, you’re on camera!

Original article: - https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/

Media: - https://www.bleepingcomputer.com/news/security/north-korea-lures-engineers-to-rent-identities-in-fake-it-worker-scheme/ - https://thehackernews.com/2025/12/researchers-capture-lazarus-apts-remote.html

Speakers:Heiner García,Mauro Eldritch

SpeakerBio:  Heiner García, NorthScan

Researcher & Strategic intelligence Analyst

Founder of NorthScan

Cyber Threat Intelligence at Telefonica Tech

SpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team

Hacker and Speaker.

Founder of BCA LTD and DC5411.

I wrote a book interviewing Threat Actors.

I like Threat Intelligence and Golden Retrievers.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Saturday - 12:00-12:30 PDT


Title: So You Got Your License, Now What?
Tags: Ham Radio Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:30 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:

Getting your ham radio license is the easy part. Figuring out what to do next? That's where most people get stuck. This talk is a practical, opinionated guide to the best rabbit holes in amateur radio: satellites, APRS, HF operating, digital modes, antenna experimentation, POTA, and the beautiful chaos of Field Day. Whether you got your ticket last week or you've been meaning to upgrade for years, this is an opinionated romp through the hobby.

We'll cover the stuff no one tells you after the exam: what the bands actually feel like, why FT8 will make you productive and vaguely empty inside, how much you can accomplish with $50 of wire and a willingness to climb things, and why learning to solder is basically a superpower. We'll also talk about getting off the couch comms for events and contests like POTA and ARRL Field Day are the most chaotic fun you can have with a radio legally.

It's easy to listen, but things get more interesting when you start transmitting. Ham radio is one of the last hobbies that rewards you for actually understanding how it works. This talk is the map.

You crammed, you passed, you got a callsign. And now your radio is sitting in a box while you wonder what you're actually supposed to do with it. This talk is a guided tour of the rabbit holes waiting for you on the other side of your license exam, organized by how deep you want to fall. Technician class? You can hit satellites with a handheld, track yourself on a map with APRS, or chase hidden transmitters through the woods with a directional antenna and questionable judgment. Upgrade to General and suddenly you've got the HF bands: a global playground where you can work 200 countries in a weekend via a mode a Nobel laureate invented, argue with the laws of physics via antenna wire, and wage legal warfare against your HOA.

SpeakerBio:  Danny Quist

Danny Quist has been a licensed amateur radio operator since he was 17, which is a really long time. Currently he is an extra class operator who gets to operate in his freetime working as CTO at Swarm Inc. He is a volunteer examiner with the ham radio village. His day job includes reverse engineering malware, forward engineering malware detonation systems, and management.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 11:30-11:59 PDT


Title: So You Want to Work in Aircraft Cyber? Here's what you need to know!
Tags: Aerospace Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

As the Aviation industry struggles to recruit people with the right combination of knowledge and/or experience of Cybersecurity and Aviation ecosystems, this presentation will provide a very fast overview of the topics people wishing to break into the industry should consider learning more about. This will be a fast-fire and frank presentation with direction for you to start your journey into Aviation Cyber.

Speakers:Matt Gaffney,Marcie Wise

SpeakerBio:  Matt Gaffney
No BIO available
SpeakerBio:  Marcie Wise
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 10:00-10:59 PDT


Title: Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything
Tags: Social Engineering Community Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

Social engineering not just a specialized skill used by elite hackers, professional con artists, or unnervingly charismatic strangers. In reality, the same few psychological vulnerabilities show up everywhere: in negotiations, job interviews, sales pitches, security breaches, party tricks, and everyday conversations...

And YOU can use them, too.

In this interactive session, magician and social-engineering educator Brian Brushwood reveals four psychological backdoors that can make people more likely to trust, comply, disclose, and cooperate. You will see each principle demonstrated, learn why it works, and practice using it through safe, low-stakes exercises with other attendees.

These are the tricks that can be used by good guys and bad to convince, and build rapport quickly, lower resistance, and make an unlikely request feel surprisingly reasonable.

By learning how these techniques feel from the inside, attendees will become better at using influence deliberately, and better at recognizing when someone is using it on them.

No previous social-engineering experience is required. Just bring a willingness to talk to strangers, learn a magic trick or two, and discover how alarmingly hackable human beings really are.

SpeakerBio:  Brian Brushwood
Brian Brushwood has spent 25 years teaching millions of people how deception works: first as a touring magician, then as creator/host of Scam School / Scam Nation, host of National Geographic's Hacking the System, creator of The Modern Rogue, and host of World's Greatest Con. His work focuses on scams, magic, persuasion, social engineering, and the mechanics of trust: how it is built, exploited, defended, and rehearsed. Through Scam School and Scam Nation, Brian spent nearly two decades turning ordinary non-deceivers into capable ethical deceivers, helping them understand cons and persuasion from the inside. Brian has delivered keynotes to audiences of thousands and recently developed an experimental offense-to-defense social engineering curriculum, piloted at Clemson University with CISO John Hoyt.

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 11:30-12:30 PDT


Title: Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything
Tags: Social Engineering Community Village | Creator Event/Activity
When: Saturday, Aug 8, 11:30 - 12:30 PDT
Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map

Description:

Social engineering not just a specialized skill used by elite hackers, professional con artists, or unnervingly charismatic strangers. In reality, the same few psychological vulnerabilities show up everywhere: in negotiations, job interviews, sales pitches, security breaches, party tricks, and everyday conversations...

And YOU can use them, too.

In this interactive session, magician and social-engineering educator Brian Brushwood reveals four psychological backdoors that can make people more likely to trust, comply, disclose, and cooperate. You will see each principle demonstrated, learn why it works, and practice using it through safe, low-stakes exercises with other attendees.

These are the tricks that can be used by good guys and bad to convince, and build rapport quickly, lower resistance, and make an unlikely request feel surprisingly reasonable.

By learning how these techniques feel from the inside, attendees will become better at using influence deliberately, and better at recognizing when someone is using it on them.

No previous social-engineering experience is required. Just bring a willingness to talk to strangers, learn a magic trick or two, and discover how alarmingly hackable human beings really are.

SpeakerBio:  Brian Brushwood
Brian Brushwood has spent 25 years teaching millions of people how deception works: first as a touring magician, then as creator/host of Scam School / Scam Nation, host of National Geographic's Hacking the System, creator of The Modern Rogue, and host of World's Greatest Con. His work focuses on scams, magic, persuasion, social engineering, and the mechanics of trust: how it is built, exploited, defended, and rehearsed. Through Scam School and Scam Nation, Brian spent nearly two decades turning ordinary non-deceivers into capable ethical deceivers, helping them understand cons and persuasion from the inside. Brian has delivered keynotes to audiences of thousands and recently developed an experimental offense-to-defense social engineering curriculum, piloted at Clemson University with CISO John Hoyt.

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 10:00-17:59 PDT


Title: Social Engineering Community Village - Open Hours
Tags: Social Engineering Community Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action... the phones start ringing soon.

The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses.

At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our "Cold Calls" or listen in to some presentations.

The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON.

Prerequisites:

Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed.

Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate.

Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 10:30-10:59 PDT


Title: Software Quality in Electronic Voting
Tags: Voting Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 10:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

Casting a vote is the primary means by which citizens can influence their government. Following the passage of the Help America Vote Act (HAVA) in 2002, a surge in the use of electronic voting systems occurred. Although hand-marked paper is returning to use, the replacements in many jurisdictions for these aging electronic systems are also electronic. Given the serious nature of elections, electronic voting systems must be trustworthy, and their engineering must be held to rigorous standards.

We have had the opportunity, over the past eight years, to observe and analyze the use of electronic voting systems in the state of South Carolina. Our observations of such systems in the field have yielded serious usability, software, and hardware quality concerns, ranging from procedural errors resulting from poorly-designed systems, to system faults that ignore or miscount votes, to timestamp anomalies and malformed output. Given the importance of elections, and the inherent risk in the use of current electronic voting systems, we question the wisdom of using such systems until they are held to standards comparable to those used in other regulated, safety critical domains.

SpeakerBio:  Duncan Buell

Duncan A. Buell is the Chair Emeritus of the NCR Chair in Computer Science and Engineering at the University of South Carolina. He holds a Ph. D. in mathematics from the University of Illinois, Chicago, and continues research interests in electronic voting, digital humanities, and text analysis. He was appointed in March 2019 to the Commission on Voter Registration and Elections of Richland County, South Carolina, resigning in March 2021 when he moved to Ohio. He taught computer science as a visitor at Denison University in Granville, Ohio, in academic years 2022-2023 and 2023-2024.

Dr. Buell has been analyzing election data, primarily from ES&S and Dominion systems, since 2010, including five complete biennials (2010-2018) from South Carolina, as well as data from AZ, GA, KS, NV, PA, and TX, and data from 2010 through 2024.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W233 (Workshops) - Map

Description:

Every wireless thing in your life is broadcasting. The question is who's listening — and what they can do with it. Battle-Tested Broadcasts is a four-hour, hands-on workshop on RF detection and direction finding, framed by the most demanding live laboratory in the world for these techniques: the Ukrainian frontline. We start with universal foundations — frequency, modulation, antennas, what your SDR can and can't see — and pivot into where neural-time RF detection becomes existential: drones. A pilot powers up an FPV controller thirty seconds before impact. Pure RF detection is often the only sensor in the chain that catches the threat before the drone leaves the ground. We cover what's actually in the air across a contested battlefield slice — controllers, video downlinks, telemetry beacons, battlefield comms, GNSS, and the increasingly exotic bands operators are pushing into to dodge electronic warfare. We dissect the honest limits of common off-the-shelf SDR tooling, and the ways adversaries already evade pure RF detection: from fiber-optic and autonomous drones to wired front-line networks, frequency hopping, and out-of-scan spectrum. Attendees solder and flash a Signal Compass — a pocket ESP32 signal detector with directional bearing. Rotating lab stations cover passive scanning, fingerprinting, direction findi

SpeakerBio:  Preston Zen

Preston Zen ‚ the original creator of 1337sheets.com, OSCE3 certified, now leading Kaizen Labs out of a Japan / Ukraine hybrid office. Software, hardware, and cybersecurity background. Volunteering in Ukraine since 2022 with NGOs including Dronarnia, BeeTA, American Made Freedom, and Shield of Freedom on drone systems, RF detection, EW countermeasures, and humanitarian logistics. DEFCON regular since DC25 and a Hac-Man CTF contributor for the past three years. He's shipped more boards than he's counted, and has spent enough time near the Ukrainian frontline to have strong opinions about which detection tools actually work when the noise floor is on fire.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - Building Agentic Reverse Engineering "Skills"
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W231 (Workshops) - Map

Description:

Agentic reverse engineering blends interactive binary analysis with autonomous agent workflows. Building on workshops at REcon and DEF CON Singapore, this session introduces Agent Skills, structured bundles of instructions, scripts, and resources that coding agents discover and execute. Skills enable multi-step RE tasks with high accuracy and minimal prompting via workflow capture and progressive disclosure.

Participants learn how coding agents operate through iterative loops (generate, execute, inspect, refine) and how Skills plug into these loops. The workshop is hands-on: attendees build a multi-platform driver-analysis Skill automating IOCTL enumeration, dispatch-flow analysis (Windows IRPs, Linux file ops, macOS IOKit), code-flow analysis, and workflow capture. A capstone challenge has participants build a second Skill from scratch.

Supports Claude Code, OpenCode, Mistral Vibe, and pi. The instructor provides LLM inference for all attendees, so no paid API keys are required. Students may also use free inference tiers from OpenCode or similar providers.

Attendees leave with practical experience to implement agentic RE Skills in their own workflows. Basic familiarity with RE concepts and a laptop with a coding agent installed is all that is needed.

SpeakerBio:  John "clearbluejar" McIntosh

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the "Agentic RE" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the "Supercharging Ghidra" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W232 (Workshops) - Map

Description:

Memory-only malware is now commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. To detect such malware, memory forensics, which is the examination of a system’s volatile memory (RAM), must be performed. Volatility 3 is the latest version of the Volatility Memory Analysis framework and is the most widely used open-source framework for memory forensics. In this workshop, students will learn how to use Volatility 3 to detect the most sophisticated malware techniques found in the wild. This learning will occur through a mixture of lectures, live demos, and extensive hands-on labs where students analyze memory samples infected with real malware. While students work through labs, instructors walk to each student’s station to ensure they are progressing. An instructor also walks through each lab live upon completion, and students are given a 35+ page lab guide that contains all the scenarios, questions, and detailed answers. Students can later use the course slides and lab guide to practice as well as to guide real-world investigations. The workshop’s instructors are core Volatility developers who have made significant contributions to the project. By attending this workshop, students will gain deep knowledge and hands-on experience analyzing memory-only malware.

Speakers:Andrew Case,Pierre "Abyss Watcher" Breton,David McDonald

SpeakerBio:  Andrew Case

Andrew Case is the Director of Research at Volexity and has significant experience in incident response handling, digital forensics, and malware analysis. Case is a core developer of Volatility, the most widely used open-source memory forensics framework, and a co-author of the highly popular and technical forensics analysis book "The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory." Case has spoken at many industry conferences, including DEF CON, Black Hat, RSA, DFRWS, SecTor, BSides*, and OMFW.

SpeakerBio:  Pierre "Abyss Watcher" Breton

Pierre (Abyss Watcher) Breton is a researcher at Volexity, holding a Master of Science in Cybersecurity, specializing in digital forensics, malware analysis and detection engineering. He is a primary contributor to Volatility, the most widely used open-source memory forensics framework. Breton has demonstrated a great ability to assist the incident response community by developing innovative capabilities and resources. He conveys his passion through the organization of CTF events and training sessions that showcase both accessible and challenging topics.

SpeakerBio:  David McDonald

David McDonald is a researcher and software engineer with 5 years of digital forensics R&D experience. His passion for this field began with his involvement in the University of New Orleans CTF team, as well as through his time as a Systems Programming teaching assistant. After over two years of digital forensics research and development on Cellebrite's computer forensics team, he joined Volexity's Volcano team, where he now works to develop next-generation memory analysis solutions. He believes deeply in sharing knowledge and helping others discover their abilities and interests through their own journeys in cybersecurity, and strives to pay forward the benefits of the mentorship that has opened so many doors for him.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W228 (Workshops) - Map

Description:

Modern enterprise security has shifted from network boundaries to identity, making Microsoft Entra ID a critical control plane and a prime target for persistence. While credential theft remains common, sophisticated attackers increasingly establish long-term access through identity-layer backdoors that survive password resets and evade traditional monitoring.

We will explore how attackers achieve durable persistence in Microsoft Entra ID by abusing service principals, federated identities, passwordless authentication methods, and device trust relationships. The session highlights techniques that remain effective even after common remediation actions like credential rotation and MFA enforcement. Through guided, hands-on scenarios, participants will simulate these identity-layer persistence techniques and understand their real-world impact demonstrating how adversaries integrate into legitimate identity workflows to maintain covert, long-term access without raising immediate suspicion.

Participants will step into the role of an adversary and explore how persistence is established and maintained inside Microsoft Entra ID. Rather than focusing on theory, this workshop breaks down real-world attack paths used to retain access beyond initial compromise highlighting techniques that survive password resets, MFA enforcemen

Speakers:Raunak "Trouble1" Parmar,Chirag "3xpl01tc0d3r" Savla

SpeakerBio:  Raunak "Trouble1" Parmar

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.

SpeakerBio:  Chirag "3xpl01tc0d3r" Savla

Chirag Savla is a Cyber Security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. He prefers to create open-source tools and explore new attack methodologies in his leisure. He has worked extensively on Azure, Active Directory attacks, defense, and bypassing detection mechanisms. He is an author of multiple Open Source tools such as Process Injection, Callidus, etc. He has presented at multiple conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - Explore the Windows instrumentation callback
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:

The Nirvana Debug is a type of instrumentation callback existing since Windows 7. This workshop idea is to see how this feature can be weaponized in order to either: - Hijack execution flow - Perform process injection - Perform sleep obfuscation for C2 beacon

During this workshop, you will learn the main principle of Nirvana Debugging, and try to weaponize it. Some debugging, reverse and coding will be needed in order to create a new malware that will evade classic EDR solutions.

SpeakerBio:  Yoann "OtterHacker" DEQUEKER

Yoann Dequeker (@OtterHacker) is a red team operator at Wavestone entitle with OSCP and CRTO certification. Aside from his RedTeam engagements and his contributions to public projects such as Impacket, he spends time working on Malware Developpement to ease beacon deployment and EDR bypass during engagements and is currently developing a fully custom C2.

His research leads him to present his results on several conferences such as LeHack (Paris), Insomni'hack (Swiss) or even through a 4-hour malware workshop at Defcon31,32 and 33 (Las Vegas). All along the year, he publishes several white papers on the techniques he discovered or upgraded and the vulnerabilities he found on public products.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W229 (Workshops) - Map

Description:

This hands-on workshop explores the offensive security of AI-powered applications where Large Language Models connect to real tools via MCP (Model Context Protocol) servers. Over four hours, participants attack 11 purpose-built AI agents across 9 exercises, exploiting vulnerabilities mapped to the OWASP Top 10 for LLM Applications 2025.

You will perform prompt injection (direct and indirect via RAG poisoning), force AI agents to generate malicious SQL/NoSQL queries through MCP tool interfaces, chain path traversal and SSRF through tool-calling parameters, abuse excessive agency via MCP-exposed CRUD operations, trigger stored XSS through LLM output, and achieve remote code execution via a poisoned supply chain, all through natural language conversation.

This workshop is ideal for red teamers, penetration testers, security engineers, and developers building with LLMs. No prior AI or ML experience is required; every technique is demonstrated before the hands-on lab. Just bring a laptop with a browser.

You walk away with practical experience exploiting 93 attack objectives against live LLM agents, a clear understanding of how traditional web vulnerabilities are amplified through AI tool-calling architectures, and the instincts to spot these risks in your own AI deployments.

SpeakerBio:  Abhinav Verma

Abhinav Verma is a Senior Staff Security Engineer at Intuit Inc. with 15+ years of experience across AI security, offensive security, red teaming, product security, and security operations. He currently leads AI security architecture reviews, AI penetration testing, and vulnerability management programs, with a focus on AI security, AI threat modeling, and securing large-scale cloud platforms.

Over the course of his career at Intuit, he has built security automation, scaled continuous security scanning across thousands of assets, led secure design reviews for platforms serving millions of customers, and developed secure coding programs that have helped thousands of engineers shift security left. Abhinav was formerly an independent security researcher and has identified and reported vulnerabilities in numerous major online services and technology companies.

He holds certifications including OSEP, OSCP, OSWP, GWAPT and CEH. Outside of work, Abhinav is a passionate gamer, a trained chef, an avid camper, and a mentor to aspiring offensive security practitioners.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W230 (Workshops) - Map

Description:

HackTheCloud25 CTF Manager is an automated orchestration framework designed for the management of cloud cybersecurity challenges. It enables the deployment of intentionally vulnerable laboratories across AWS, Azure, and GCP using Terraform as the underlying Infrastructure-as-Code engine. The solution centralizes challenge definitions via YAML files, managing complex dependencies, dynamic variables, and resource outputs through a unified command-line interface (CLI) to list, deploy, destroy, and monitor resources in a controlled environment.

Furthermore, the framework incorporates environment validation, automated credential detection, detailed event logging, and support for reusable configurations, ensuring high scalability and traceability for complex attack scenarios. Collectively, the CTF Manager provides a reproducible and extensible approach to orchestrating practical cloud security exercises for educational purposes, streamlining the creation, operation, and maintenance of vulnerable infrastructures within dedicated testing environments.

SpeakerBio:  HackeMate

HackeMate is the host of the YouTube channel under the same name, where the creator, an Offensive Cybersecurity Engineer, shares their expertise in ethical hacking, as well as offensive and defensive security. With over 30,000 subscribers engaged in the world of cybersecurity, they have established themselves as a key figure in the community through challenges, technical analyses, and hands-on demonstrations. Professionally, HackeMate holds Red Team certifications such as the eLearnSecurity Junior Penetration Tester (eJPT) and Web Penetration Tester (eWPT), along with Blue Team certifications like Microsoft Azure Fundamentals (AZ-900) and Microsoft Security, Compliance, and Identity Fundamentals (SC-900). They are also a Google Product Expert for Google Drive, contributing their knowledge in cloud security and optimization.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:

"Don't plug in devices you don't trust." It's one of the most repeated pieces of security advice in the industry. What actually happens when a malicious USB device is plugged in? How does it work? This hands-on, four-hour workshop answers those questions by putting the tools directly in attendees' hands. Using O.MG Devices and the DuckyScript v3 scripting language, participants will learn the fundamentals of Human Interface Device (HID) attacks from the ground up. Starting from USB protocol basics all the way through real payload design, delivery strategy, and advanced techniques including wireless triggering, C2 integration, and air-gapped exfiltration (using HIDX StealthLink). The class is beginner-friendly and builds progressively: no prior red teaming experience is required. Only a DuckyScript v3 device is required. Attendees will leave with working scripts, a framework for payload design, and an understanding of what attackers and defenders need to look for. We will cover OpSec, detection (and evasion), and how accessibility-first design thinking can make both attackers and defenders more effective.

Speakers:wasabi,Ø1,Tokugero

SpeakerBio:  wasabi

wasabi is a researcher, tinkerer, and professor of cybersecurity whose work spans IoT and embedded systems, cloud infrastructure, and offensive tooling. Their research focuses on uncovering systemic weaknesses across modern embedded environments, with an emphasis on practical exploitation and defensive resilience. When not tinkering, wasabi spends most of his time outdoors in nature.

SpeakerBio:  Ø1

Ø1 is a seasoned offensive security professional who turned a lifelong passion into a dynamic career. Beginning as a machine operator, he transitioned into the world of cybersecurity, where he has since traveled globally, conducting and leading numerous penetration tests and red team engagements. With a wealth of hands-on experience, he excels at identifying vulnerabilities and strengthening defenses for organizations worldwide. In 2022, he joined the O.MG team, balancing this role alongside his primary job to contribute to product testing, documentation, tooling, and customer support. Beyond his professional pursuits, √ò1 is a devoted cat father with a love for guns, cars, BBQ, and gardening.

SpeakerBio:  Tokugero

Tokugero is a Site Reliability Engineer and Cloud Architect focused on incident response, operations engineering, and running resilient infrastructure at scale. He works across the full ops stack — from system design and automation to the messy realities of keeping production healthy.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - Hecate: A Trivial UART Tool
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W231 (Workshops) - Map

Description:

Hecate is an open source UART implant framework designed to make common hardware hacking tasks easy with minimal code. It turns any CircuitPython microcontroller into a powerful, customizable UART implant.

In this workshop, you'll get to use all the core features of Hecate and see how they work against multiple target devices. We'll start hands-on by listening to a device's UART output, and then configuring Hecate to operate in standalone mode and log that UART data to a file. Once we've seen it in action, we'll step back for a bit of lecture about UART, what it's used for, and what we designed Hecate to be capable of. Armed with this knowledge, you'll dive into two more hands-on labs: a payload dropper that will playback a custom transaction and a simple detector that will signal an alert when it detects a pattern. We'll reconvene for a last bit of lecture on how to use some of Hecate's advanced features, before you dive into the final lab: implement a full implant-in-the-middle capable of modifying UART data in flight.

Hecate makes developing embedded implants trivial, while remaining flexible enough for advanced research and rapid prototyping. You'll walk away with hands-on experience using the Hecate framework and a working understanding of what's possible with UART interception, manipulation, and exploitation

Speakers:mx,Joe "SecurelyFitz" FitzPatrick,nyx

SpeakerBio:  mx

Maxie is an erstwhile cloud infrastructure engineer, formerly an SRE at Google Cloud Platform and others. She came to the world of hardware hacking and embedded devices first as a pleasant escape from the quotidian indignities of working in the cloud, and she stayed for the addictive aroma of flux fumes. She enjoys making ill-advised expansions to her homelab and spending evenings at her local hackerspace in Portland, OR.

SpeakerBio:  Joe "SecurelyFitz" FitzPatrick

Joe FitzPatrick (@securelyfitz) is a trainer and researcher at SecuringHardware.com with a personal mission to make all hardware devices at least a bit more secure. He builds tools like Tigard and Erebus, and teaches Applied Hardware Attacks trainings to help people break - and secure - their hardware devices. His actual superpower is the ability to instantly end awkward conversational pauses if you ask him about BSides Portland, the CTRL-H Hackerspace, or drone taco delivery at ToorCamp.

SpeakerBio:  nyx

nyx is a Portland-based hacker, engineer, and self-described cyberpunk. As an unwilling participant in the late-capitalist, mass-surveillance dystopia, he is passionate about digital privacy, data self-custody, and running his own infra. While voiding warranties has long been one of his favorite pastimes, he has lately been fortunate enough to do it professionally as well.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - Intro to Writing Windows Malware with Rust!
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W230 (Workshops) - Map

Description:

In the Information Security news space, we often hear about the cool malware and tools nation states and APTs develop. While there are many tools out there that "do the thing", have you ever wonder how it "does the thing"? Instead of just using tools and scripts that sound cool, why not make them?

Using the Rust programming language, you'll be taken step-by-step into building your own Windows malware! We'll break down the process and work our way into more complex tasks. From a simple, no-imports binary we'll slowly work into loading and executing Windows API functions without ever calling "LoadLibrary" or "GetProcAddress" while not touching a single Rust "std::*" function or importing any extra crates!

You'll be introduced into Windows concepts like the Process Environment Block (PEB), the Thread Environment Block (TEB) and how we can use them to our advantage! At the end of this workshop, you'll be able to build binaries without any imports while doing fun tricks like shellcode injection!

Some of the topics we'll touch on are:

Speakers:iDigitalFlame,Daniel Bravo

SpeakerBio:  iDigitalFlame

iDigitalFlame is an experienced security researcher that uses his programming skills to expand his abilities and provide teams with the tools needed to complete any engagement. Outside of work, his passion for open source and knowledge sharing has led to the creation of many unique tools and resources. iDigitalFlame also uses his skills to help power many CTFs, including the ProsVJoes CTF at BSidesLV, where he leads the Red Team and provides the platform for Red operations. iDigitalFlame has spoken before at BSidesDE and BSidesLV about cool things learnt in his research like AV evasion or releases open source software like ThunderStorm, a custom C2 platform used in many CTFs he operates in.

SpeakerBio:  Daniel Bravo

Daniel is a self-taught programmer who later earned a B.S. in Computer Science from the University of Maryland. He likes to understand how software works by decompiling binaries and reverse engineering APIs, whether they were meant to be understood or not. Daniel also enjoys working on geospatial projects and web scraping tools, particularly extracting and reconstructing data from mobile platforms. His other interests also include compiler theory, automated reasoning, and verification-aware languages.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W232 (Workshops) - Map

Description:
Software reverse engineering is a fundamental skill: a prerequisite
to engaging with many fields of study in computer security that depend
on low-level knowledge. Malware analysis, vulnerability research,
offensive tool development, and digital forensics all involve the
analysis of code which has been compiled, obfuscated, or otherwise
stripped of useful names, data types, comments, and other
human-readable information. Without the ability to read disassembled
code, you will not be able to understand code that your computer will
happily execute.

In this workshop, I will guide you through learning to read disassembled code while you learn C. We will progress through the C programming language's constructs with as few assumptions as possible about your background, and at each stage we will reverse engineer the compiler's output in Ghidra and trace through with a debugger to understand the generated code. You do not need any prior experience in programming.

I will also be demonstrating useful techniques for using locally-hosted large language models to aid in the learning process. Use AI to improve your own skillset, rather than using it to do the work for you.

SpeakerBio:  Wesley McGrew, Senior Cyber Fellow at MartinFed

Dr. Wesley McGrew directs research, development, reverse engineering, and offensive cyber operations as Senior Cybersecurity Fellow for MartinFederal. He has presented at DEF CON and Black Hat USA on topics of penetration testing, malware analysis, critical infrastructure, and vintage computing, and has taught self-designed courses on reverse engineering and cyber operations at Mississippi State University. Wesley has a Ph.D. in Computer Science from Mississippi State University for his research in vulnerability analysis of SCADA HMI systems. He has entertained audiences at many DEF CON parties as a house music DJ, as well.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - Purple Teaming Industrial Control Systems
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:

Security monitoring is often presented as the silver bullet for Industrial Control System (ICS) security — but how effective is it against realistic adversaries? In this 4-hour, hands-on workshop, participants will use CALDERA, the open-source adversary emulation framework, to conduct purple-team exercises against simulated & live industrial environments. Attendees will simulate real-world IT and OT attacks, observe what is (and is not) detected across EDR, logs, and network monitoring, and map results to MITRE ATT&CK for ICS. Rather than focusing on exploitation alone, this workshop teaches a repeatable methodology to assess detection coverage, identify OT blind spots, and improve monitoring strategies. Participants leave with concrete techniques they can apply in their own environments — from tabletop exercises to continuous detection testing.

Speakers:Arnaud SOULLIE,Alexandrine Torrents

SpeakerBio:  Arnaud SOULLIE

Arnaud Soullie is a Senior Manager at Wavestone. He has over 15 years of experience in security assessments and penetration testing, with 10 years specializing in Industrial Control Systems cybersecurity. He has delivered talks and workshops at DEF CON, Black Hat Europe, BruCON, CS3STHLM, BSides Las Vegas, and others. He is the creator of the DYODE open-source data diode project and has been teaching ICS cybersecurity since 2015.

SpeakerBio:  Alexandrine Torrents

Alexandrine Torrents is a cybersecurity expert at Wavestone. She started as a penetration tester, and then specialized in OT cybersecurity. She is IEC 62443 certified. She performed dozens of OT cybersecurity assessments across various industries & worked on OT models to perform attacks on PLCs & SCADA systems. Alexandrine also helps secure OT both at technical & organization levels: secure architecture, system hardening, IAM, cyber resilience, detection, governance, awareness & training, risk assessment, cyber by design, etc. Alexandrine works with different CISOs on their OT cybersecurity roadmaps & programs at different scales of large industrial companies: site, business units, Group with worldwide scope. Alexandrine also gives training on OT cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 14:00-17:59 PDT


Title: Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 14:00 - 17:59 PDT
Where: LVCCW Level 2 W233 (Workshops) - Map

Description:

Salesforce Sites are one of the most under-tested attack surfaces in enterprise security. When pentesters encounter them, most skip past - the Aura framework doesn't behave like a standard web application, and standard web testing techniques don't apply. Salesforce sites run on proprietary frameworks (Aura and LWR) with their own API surfaces, access models, and injection patterns. In March 2026, ShinyHunters demonstrated what that blind spot costs: sensitive data exfiltrated from hundreds of organizations through sites no one had tested.

This workshop teaches pentesters and red teamers a complete offensive methodology for Salesforce Experience Sites, going well past the record enumeration that makes up most public guidance on the topic.

Attendees will enumerate objects and dump records via the Aura API, then learn to identify and invoke custom Apex controllers running in system mode - controllers that bypass standard access management mechanisms, and which are surprisingly common and criminally underexplored. We cover SOQL injection in depth: why normal SQL injection tests fail, and how to exploit it. We cover deterministic route enumeration as an unauthenticated user, and LWR sites - Salesforce's next-generation framework - including the release of LWRed, a new open-source scanner built specifically for them.

Speakers:Nitay Bachrach,Cynthia Ardman

SpeakerBio:  Nitay Bachrach

Nitay Bachrach is a security researcher at Reco (Tel Aviv, Israel) specializing in offensive security research against enterprise SaaS platforms. He is a pioneer in Salesforce offensive security: he published new exploitation methods for the Aura framework, discovered the Einstein Wormhole vulnerability and a Public Link exploitation technique in Salesforce's platform, and identified and responsibly disclosed critical vulnerabilities in dozens of major Salesforce deployments. His research extends to Okta, GCP, and other enterprise platforms. He spoke at Insomni'hack on "Neo4jection" - novel graph injection techniques against Neo4j. In May 2026, he is running a Salesforce-focused CTF event in Tel Aviv. The LWR exploitation methodology and LWRed tool premiering at this workshop represent previously unpublished research from original work on Salesforce's next-generation Experience Site framework.

SpeakerBio:  Cynthia Ardman

Cynthia has spent 10+ years making life harder for attackers. She currently builds threat detection at Reco, and previously did the same at AppOmni, AWS, and Snowflake, places where "the blast radius" isn't a metaphor. At AWS she developed MITRE ATT&CK-mapped detection for corporate infrastructure, partnered with the Red Team to close gaps they found, and led a project that knocked hacking tool presence down by 30%. At Snowflake she ran blue team ops and built the SQL-based alerting pipeline from scratch. At StubHub she hunted down an active intrusion by tracing logs across systems and performed the root cause analysis so it wouldn't happen twice. She came up through desktop support, building Linux blade servers and remediating malware on customer machines, the kind of work that teaches you what actually breaks. CISSP. Splunk ES Admin. Writes Python when she has to and JSONata when nobody's looking.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W228 (Workshops) - Map

Description:

Endpoint Detection and Response (EDR) systems are key parts of modern security. This workshop provides a guide for custom malware development, C2 customization, defense evasion, and kernel exploitation. We will use Elastic Defend throughout the session. By analyzing detection logs and rules, we will understand what EDR monitors and why payloads are caught step by step.

After a short overview of Windows defenses and EDR, we focus on malware development. Participants will implement typical malware techniques, such as APC Injection, Thread Hijacking, Fiber and Module Stomping in multiple languages. Next, we learn about call stack analysis. Attendees will implement Stack Spoofing and Indirect Syscalls to hide execution flows and bypass stack analysis.

The workshop then moves to C2 customization using the Havoc C&C framework. By combining custom loaders with C2 source code modifications, participants will bypass static signatures, behavioral rules, and AI detection to successfully establish a C2 session.

Finally, we’ll demonstrate the possibilities of Bring Your Own Vulnerable Driver (BYOVD) attacks for the post-exploitation phase. When we have access to the kernel space, we can take more aggressive measures. We’ll use some vulnerable drivers to kill or blind an EDR sensor itself.

Speakers:Yu Terada,Kotaro "@Decamark / @BinaryPoodle" Osugi

SpeakerBio:  Yu Terada

Yu Terada is a security researcher and a red team consultant for Fujitsu. He worked as a SOC Analyst and CSIRT for over five years. In 2021, he joined the company as a Security Researcher. He is primarily involved in developing new attack methods and tools. He also participates in internal red team activities and cyber exercises. He has spoken at Black Hat USA/Europe, BSides Las Vegas, Code Blue, and several conferences in Japan. He holds a Master's degree in Computer Science, as well as certifications including OSEP, OSCP, CRTL, CETP, ODPC, CISSP, GIAC, etc.

SpeakerBio:  Kotaro "@Decamark / @BinaryPoodle" Osugi

Kotaro Osugi is a security researcher and a red team consultant who has his profession in reverse-engineering. His research area includes malware analysis and binary exploitation. He has given a speech at BHEU Arsenal about a tool for kernel exploitation. OSED and OSEE certified.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - Wi-Fight Club: I am Jack's Evil Twin
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:

'Wi-Fight Club: I am Jack's Evil Twin' will teach you how to deploy rogue AP (Evil Twins) in your client's environment. Using rogue APs lets you test your client's Wireless Intrusion Detection System, passwords, wireless phishing education, and overall wireless security.

We will discuss rogue AP Tactics, Techniques, and Procedures, and how / why they work. In this workshop you will set up a CAPTIVE PORTAL, WPA2, and 802.1x rogue AP. We will also go over OWE and WPA3-SAE transition mode attacks.

We will walk through a scenario at a client's site, then set up a rogue AP to harvest user credentials for the various client networks. We will then crack the harvested credentials. We will finish up with a section on defense. We will be using EAPHAMMER, HOSTAPD-MANA, WIFIPHISHER, and AIRBASE-NG for the rogue AP section. HASHCAT, AIRCRACK-NG, and JOHN for the password cracking section. This workshop is for beginners, but participants should have basic Linux and 802.11 knowledge and be comfortable using virtual machines.

Speakers:James Hawk,Jon "C4V3M4N" Milkins,Brian Burnett

SpeakerBio:  James Hawk

James Hawk (He/Him) is a Principal Consultant with Google Public Sector within Proactive Services. He is the wireless subject matter expert for his team. James has led and contributed to numerous assessments (Red Teams and pentests). He has developed internal training and tool updates for 802.11 for his company. James is a 20-year veteran of the U.S. Army and has over 10 years of hands-on experience in wireless technologies. James is constantly researching/testing 802.11 attacks against his home lab. He is a fan of hockey, LetterKenny, and almost anything sci-fi.

SpeakerBio:  Jon "C4V3M4N" Milkins

Jon Milkins (He/Him) is a principal penetration tester focusing on all types of penetration tests from network-based to web applications and APIs to more recently wireless networks. He has developed training and pentest utilities throughout his career to help advance team capabilities. He is a former Army veteran and is attempting to curate small and efficient rulesets for Hashcat in his free time to aid in wireless hash cracking. In his free time, he enjoys playing and running TTRPGs like Delta Green, password cracking, and making hard cider.

SpeakerBio:  Brian Burnett

Brian Burnett is the founder of Offensive Technical Solutions (OTS) where he conducts web-application, internal network, and cloud penetration tests. Prior to founding OTS, he served five years in the United States Army, followed by seven years supporting internal teams at Fortune 500 companies. Brian holds degrees in computer science, pentesting, theology, and Russian. He enjoys tinkering with his home lab, collecting certifications, and committing poorly written code. His hobbies include Brazilian Jiu-Jitsu, purchasing unnecessary power tools, and CrossFit.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Saturday - 09:00-12:59 PDT


Title: Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them
Tags: DEF CON Workshop | DEF CON Workshops
When: Saturday, Aug 8, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W229 (Workshops) - Map

Description:

Most "AI security" talks stop at the slide that says "prompt injection is bad." This workshop does the opposite. Attendees spend four hours inside a working, vulnerable production-style AI system - a mock car dealership backed by a real LLM, a real database, and real tool calls - and learn to break it, watch it break, then put it back together with defenses that actually hold. You will: (1) manipulate prices and inventory using direct and indirect prompt injection, (2) reproduce an EchoLeak-style zero-click data exfiltration against a RAG pipeline, (3) execute a model-extraction attack against a deployed classifier, and Each of these modules will layer in defenses one at a time to see how the AI reacts. We close by mapping everything to OWASP LLM Top 10, OWASP Agentic Top 10, NIST AI RMF, and MITRE ATLAS. Built for red teamers handed AI in scope, blue teamers watching agents deploy faster than detections exist, AppSec engineers who used to own the API and now own a chat window, and developers curious what "prompt injection" looks like when it costs money. No prior AI-security background required.

SpeakerBio:  Pavan "pavanreddysec" Reddy

Pavan Reddy is principal developer at Automata LLC, leading FIPS 140-3, FedRAMP ATO, and AI security initiatives. He is an independent AI security researcher and educator focused on making secure AI accessible at scale. He founded QBTrain, a free platform for hands-on AI and AI security education. His peer-reviewed work, published at AAAI, ACM, FLAIRS, HCII, ACSAC, and NeurIPS, spans adversarial ML, prompt injection, and foundation model vulnerabilities. He has delivered 25+ talks and workshops at BSides, OWASP, SquadCon, CAPWIC, ACM SIGCITE, NeurIPS Education, FLAIRS, CVPR 2026 and TechMentor at Microsoft HQ. He holds an MS in CS from George Washington University.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Solving Modern Cybersecurity Problems with AI
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:
SpeakerBio:  Michael Glass
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Solving Modern Cybersecurity Problems with AI
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:
SpeakerBio:  Michael Glass
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: SpaceCOP - Catch Me If You Can
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Think you can hack a spacecraft?

We’ve deployed a vulnerable Pisat and made the software available ahead of time so you can prove it. Study it, reverse engineer it, find weaknesses, and develop your attack plan before stepping up to the console.

When your turn comes, you’ll only have 15 minutes at a time to compromise the spacecraft and achieve a mission objective. There’s just one problem, the SpaceCOP, an intrusion detection system based on the Aerospace Corporation’s SPARTA matrix, has been deployed. The spacecraft is intentionally hackable - the real challenge is accomplishing your objective without triggering an alert and getting arrested by SpaceCOP.

Earn rewards based on how well you hack and hide from SpaceCOP.

Rules of Engagement: • Recon and vulnerability research before sitting at the terminal are highly encouraged. • You will have 15 minutes at the workstation to execute your attack. • Modifying files, changing registry settings, taking pictures, and other spacecraft effects are fair game. • Do not intentionally wipe, brick, destroy, or otherwise render the system unusable. • No “rm -rf”, disk wipes, ransomware, bootloader destruction, or similar actions.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 17:30-17:59 PDT


Title: SpaceCOP: Houston, We Have an Intrusion
Tags: Aerospace Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Spacecraft are no longer isolated boxes with radios. They are networked, software-defined, mission-critical systems operating in an environment where patching is hard, visibility is limited, and failure can look a lot like an attack. This talk introduces Space Cyber Orbital Protection, or SpaceCOP, a spacecraft intrusion detection system designed to bring threat-informed cyber monitoring onboard the vehicle. SpaceCOP comes in two forms: an open-source version for NASA’s Core Flight System, releasing at DEF CON 34, and a closed-source side-loaded architecture intended to integrate with a broader range of spacecraft software environments. The cFS version uses SPARTA's Indicators of Behavior to detect anomalous spacecraft activity. We will walk through why traditional ground-based monitoring is not enough, how spacecraft IDS concepts differ from terrestrial IDS, and how SPARTA-derived behavior indicators can be translated into practical onboard detections. We will also discuss how growing policy pressure, including U.S. national security space guidance and emerging European space cybersecurity requirements, is pushing operators toward onboard intrusion detection and response. Space cyber threats are not theoretical anymore. SpaceCOP is an attempt to move spacecraft defense from “trust the link” to “monitor the vehicle.”

SpeakerBio:  Brandon Bailey, Aerospace Corporation
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Saturday - 10:30-10:59 PDT


Title: Spotlight: Choose Your Own Adventure with InfoSecMap
Tags: OWASP Foundation | Creator Event/Activity
When: Saturday, Aug 8, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Opportunities in InfoSec are everywhere, but they’re often buried across scattered websites, social media posts, or chat channels. Whether it’s a local meetup, a CFP deadline, a volunteer opportunity, or the chance to sponsor an initiative, many people and organizations miss out simply because they don’t know where to look or find info bloated by pay-to-play noise.

InfoSecMap was created to solve this. It’s a free, community-driven platform that brings the global InfoSec ecosystem together in one place. From major conferences to CTFs and grassroots meetups, InfoSecMap helps users explore what’s happening by geographic region or focus area and discover where they can connect and contribute.

InfoSecMap is proud to partner with OWASP, bringing together volunteer-led chapters and global events while fostering stronger connections and community growth. We believe open source should mean open access, and we’re building the infrastructure to make that real.

SpeakerBio:  W. Martín Villalba, OWASP

Martín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: spyVspy 3: Rat Race
Tags: spyVspy 3: Rat Race | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race) - Map

Description:

spyVspy is back, and this year, you're racing.

Embark on a thrilling espionage adventure with spyVspy 3: Rat Race! This contest imagines a world of spy games where contestants employ basic hacking, cryptography, and rogue skills to solve puzzles and uncover hidden caches strategically scattered throughout DEF CON (and beyond).

Challenges leading to the location of hidden caches will be released on a rolling schedule. By solving these challenges and being the first team to reach a cache, you will qualify for a final series of challenges on Saturday afternoon. Not the first? That's okay - you'll still have fun and earn cool spyVspy slabbed cards

spyVspy 3: Rat Race is intended for players of all skill levels. Whether you're a seasoned double-agent or just learning to be a covert operative, you will be able to compete and have fun in this event. Whatever skills you think you're missing can probably be learned on-the-job anyway.

Participant Prerequisites

A laptop would be great, but some puzzles may be solvable on a phone.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Saturday - 10:00-17:59 PDT


Title: SR-71 Blackbird Badge Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Think faster. Fly higher. Stay unseen.

Only the sharpest contenders will earn the limited-edition SR-71 PCB badge, inspired by the legendary Blackbird. Put your technical skills, aerospace knowledge, and analytical thinking to the test in this exclusive challenge. Like the aircraft itself, success demands precision, ingenuity, and the ability to stay one step ahead. Complete the mission and earn your wings.

New challenges launch all weekend long.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 13:00-13:59 PDT


Title: Stalking the Wily Hacker ... 40 years later
Tags: DEF CON Official Talk
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

40 years ago today, I tripped over a 75-cent accounting glitch in a Unix system. That tiny clue led to a year-long chase across networks, modem banks, and international borders, ultimately uncovering a crew of German hackers working for the East German Stasi and the Soviet KGB. We had no budget, no roadmap, and no “cyber” anything. We improvised with soldering irons, shell scripts, logbooks, curiosity, and far too much coffee. Let’s revisit the chase – not just to remember, but to ask what changed, what didn’t, and why it still matters.

The Cuckoo’s Egg, Doubleday Books, 1989

Stalking the Wily Hacker, Communications of the ACM May 1988 v31, page 484-497
https://dl.acm.org/doi/10.1145/42411.42412

SpeakerBio:  Cliff Stoll, Acme Klein Bottle

Cliff graduated from Buffalo Public School #61 with a blue star for good attendance. He’s since fooled around in planetary physics, computer security, and mathematical Klein bottles, with occasional detours into common sense.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-11:59 PDT


Title: StarPWN CTF
Tags: Aerospace Village | STARPWN (Aerospace Village CTF) | Contest
When: Saturday, Aug 8, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Want to try your hand at hacking satellites, spacecraft and ground control systems? Miss out on Hack-A-Sat? Want to explore the final frontier of cybersecurity?

STARPWN is the official Aerospace Village space hacking CTF! Backdoor flight computers, trojan flight software, exploit CVE's, reverse protocols, and more! During your space hacking journey, you’ll learn all about the environmental and operational constraints of space systems, how they affect cybersecurity posture, and impact exploitability.

Register at https://starpwn.ctfd.io/

Prizes to the highest finishing team the team that finishes quickest that can make it to the Aerospace Village in person by 1300 local time.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 11:00-11:59 PDT


Title: Stay Sharp: Navigating Pen Testing and Bug Bounty in an AI-Driven World
Tags: The Diana Initiative | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

AI is no longer on the horizon — it's already in our workflows, our attacker toolkits, and our vulnerability landscapes. For penetration testers and bug bounty professionals, the skills that got us here won't be enough to keep up.

This session is built for the full cyber community — students exploring careers, professionals breaking in, and program leaders rethinking their approach. We'll cover the training and certifications worth investing in, how to identify and close skill gaps, and why community, mentorship, and peer networks remain our most important growth asset. For those leading teams, we'll tackle a harder question: how do you build a learning culture that keeps up with change without burning people out? The AI field is moving fast. We have to move with it.

SpeakerBio:  Dana Pirvu, Senior Manager of Product and Software Security at Adobe

Dana Pirvu is a Senior Manager of Product and Software Security at Adobe, overseeing the Penetration Testing and Bug Bounty programs. In her role, Dana drives continuous product security testing efforts and partners with external researchers to proactively identify vulnerabilities across Adobe’s products and services, translating security findings into actionable insights for engineering and leadership teams.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 13:00-13:59 PDT


Title: Stop Chasing Domain Admin: Designing Red Team Exercises That Matter
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

You got domain admin. No alerts fired. The red team “won.” But did the exercise actually test anything that matters?

Red team engagements are often evaluated based on familiar outcomes such as full compromise, stealth, or the use of novel techniques. While these may demonstrate operator skill, they frequently fail to answer the question the engagement was meant to address.

This session challenges a common industry pattern: optimizing for technical achievement instead of meaningful outcomes. When red teams focus on getting domain admin or remaining undetected as primary goals, exercises often measure attacker creativity rather than organizational resilience.

Through a short presentation and an interactive, drop-in workshop, participants will learn how to design red team exercises around clear defensive questions. Attendees will build components of real-world engagements by defining objectives, selecting starting conditions, choosing techniques, and determining meaningful success metrics.

The workshop is structured as a series of modular steps, allowing participants to join at any time and engage at their own pace. Whether participants spend five minutes or the full session, they will leave with a practical framework for planning red team operations that produce actionable insight.

If you’ve ever seen a red team achieve full compromise and still felt like the exercise didn’t answer the right questions, this session is for you.

You will leave with a clearer understanding of what red teaming is supposed to accomplish, and a practical way to design engagements that deliver meaningful results.

SpeakerBio:  Billy Giles

Billy Giles is an Offensive Security leader and practitioner who specializes in red/purple teaming and network penetration testing. With a deep passion for understanding adversary behaviors, he helps organizations across a multitude of industries assess their security postures, identify and remediate vulnerabilities, and build stronger defenses by thinking like an attacker.

Billy is also the creator of Thinking Offensively. Through this project he examines offensive security strategy topics to help cybersecurity leaders anticipate threats and inform decision making, while also providing tools, playbooks, and techniques that red teams can apply directly to their work. His mission is to bridge strategy and execution to help organizations think offensively and stay ahead of evolving threats.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Strategic AI Penetration: Mastering Offensive Techniques for LLMs
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W233 (Workshops) - Map

Description:
Speakers:Marek Zmysłowski,Konrad Jędrzejczyk

SpeakerBio:  Marek Zmysłowski
No BIO available
SpeakerBio:  Konrad Jędrzejczyk
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Strategic AI Penetration: Mastering Offensive Techniques for LLMs
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W233 (Workshops) - Map

Description:
Speakers:Marek Zmysłowski,Konrad Jędrzejczyk

SpeakerBio:  Marek Zmysłowski
No BIO available
SpeakerBio:  Konrad Jędrzejczyk
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 13:15-15:59 PDT


Title: Supply Chain Isn’t Just Dependencies Anymore: Defending Developers, Tooling, and Builds
Tags: Intermediate | AppSec Village | Creator Workshop
When: Saturday, Aug 8, 13:15 - 15:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map

Description:

Software supply chain attacks are no longer limited to outdated, vulnerable, or compromised open-source libraries. Today, attackers target developers directly by poisoning package ecosystems, abusing build pipelines, exploiting IDE extensions, and increasingly manipulating AI-assisted coding workflows.

In this interactive two-hour workshop, Tanya Janca will break down the modern software supply chain, what has changed, and why traditional DevSecOps approaches are no longer enough. Participants will learn how attackers think, how developer behavior is being exploited, and what practical controls actually reduce risk (without slowing teams down too much!).

The session covers the next evolution of DevSecOps tooling and practices, explores emerging threats including AI-generated dependency confusion, and provides concrete guidance for securing the developer environment, from IDEs to sandboxes to CI systems.

SpeakerBio:  Tanya "SheHacksPurple" Janca

Tanya Janca, known online as SheHacksPurple, is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec Station Podcast.

Over 29 years in the industry Tanya has received numerous awards, spoken at events worldwide, and built a reputation as one of the most approachable and influential voices in application security. She has trained thousands of developers and security practitioners through her academies and live programs. Her experience includes counter-terrorism work, leading security for the 42nd Canadian federal election, as well as building and securing a vast range of applications. Today, she is recognized internationally as a leading authority on the security of software.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 13:00-13:59 PDT


Title: Surprise Session - Check Hacker Tracker
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 13:00-13:30 PDT


Title: Tag, You’re It: Physical Tracking Tech, Defense, and How to DIY Your Own
Tags: Recon Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

We live in an era where our location data is constantly harvested, but what happens when the tracking becomes physical? From the clandestine beacons of the Cold War to the consumer-grade AirTags tucked into backpacks today, physical tracking technology has become incredibly cheap, accessible, and pervasive.

In this talk, we will trace the evolution of physical tracking tech, analyze how modern implementations exploit wireless protocols like BLE, cellular, and GPS, and discuss practical defense strategies to detect and neutralize unwanted eyes.

Finally, we will demystify the threat by turning the tables: demonstrating how to build and deploy a fully functional, budget-friendly tracking beacon using off-the-shelf DIY hardware.

Attendees will leave with a deep understanding of the tracking landscape and the knowledge required to both defend against and build these systems.

SpeakerBio:  Eddie Miro, Operations Manager - HackerHaus Security Solutions

Cybersecurity Professional & Creator | Community Builder | Speaker

I build communities, break into systems (legally), and share what I learn along the way. With over a decade of deep involvement in the hacker community, my work spans public speaking, content creation, and technical contributions.

Key Highlights:

Speaking & Community: Featured speaker at 30+ conferences (including DEF CON 27 SE Village) and dedicated volunteer at 25+ events. Former DEF CON Goon.

Media & Content: Hosted Simply Social Engineering, guest on 20+ podcasts, and published writer in 2600 Magazine.

Projects & Ventures: Founder of Octopus Game. Contributor to Black Hills Information Security's Backdoors & Breaches.

Always building and still punk. Let’s connect.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Saturday - 12:00-12:59 PDT


Title: Take Back Your Memories
Tags: Hackers.town | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  Patrick Sliney, Tech Reclaimers
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 16:30-17:30 PDT


Title: Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System
Tags: DEF CON Official Talk | Demo 💻
When: Saturday, Aug 8, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Most agentic systems for offensive security boast impressive benchmarks while hiding the real cost, the real time, and the architectural pain behind them. Many remain closed-source, sacrificing the transparency security demands.After 20 years as an offensive security researcher, I spent the last 10 months distilling all that accumulated experience into a deterministic agentic pipeline for web pentesting.I’ll dissect the hard trade-offs I had to make: why visual validation via Playwright, CDP and Vision models became mandatory (and why text-based parsing is architecturally broken for client-side vulns like XSS), why suppressing creativity backfired, how specialization, model shifting and temperature control enabled useful determinism, why a dedicated Skeptic agent and weighted scoring were essential, and why immutable audit trails, wet/dry separation and native MCP support became non-negotiable.War stories included: the "Dojo Incident" — where the agents decided rewriting server configs was cheaper than writing the exploit.Conclusion: reliable offensive agentic systems must be open-source. Closed-source hides real behavior and real risks. Open-source is not a license choice — it is the only architectural and ethical safeguard we have left.

SpeakerBio:  Albert "yz9yt" Corzo

I’ve been breaking things for over 20 years — legally, most of the time. An offensive security researcher with an adversarial mindset, multiple Hall of Fame recognitions, and several critical CVEs discovered.For the past 6+ years I’ve focused on the intersection of AI and offensive security. My work centers on solving complex engineering challenges in agentic systems: enforcing determinism, minimizing token burn and environmental impact, and creating reliable pipelines that combine LLMs with real web pentesting tools.I’m a web pentester and technical speaker passionate about helping the next generation of researchers execute more precise and effective web attacks.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-17:59 PDT


Title: TCM Security Labs
Tags: Noob Community | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

TCM Security offers 250+ hours of practical, hands-on cybersecurity training across 28 courses and 13 certifications, built by hackers and trusted by teams. Drop in during village hours to work through their hands-on labs.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 17:30-17:59 PDT


Title: TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Trusted execution environments (TEEs) aim to offer strong privacy and integrity guarantees even in the presence of root level attackers. Recently there has been a pivotal shift in TEE deployment, moving TEEs from enclaves running on PC-oriented hardware to confidential virtual machines executing on server-grade CPUs. Under the hood, this change has also resulted in significant modifications to the underlying memory encryption engine, removing integrity guarantees as well as protections against replay attacks. While Intel's and AMD's change in TEE implementation is clearly significant and substantial, most TEE deployments appear to fail to acknowledge the difference in security guarantees, assuming a stronger security model than truly afforded by the implementation. Thus, in this talk we discuss the true protection offered by Intel's and AMD's newest TEE offerings against entry-level physical side-channel attacks. We show that bus interposition attacks on DDR server memory can be constructed cheaply by hobbyists, using parts on e-commerce websites. With our bus interposer combined with the weaker security model of server TEEs, we will show a live demo of our ability to extract secret key material from machines in fully trusted status. Finally, we demonstrate the implications of our attacks on real world deployments.

https://tee.fail Paper: https://tee.fail/files/paper.pdf Please see our paper for references to prior work.

Speakers:Daniel Genkin,Jalen Chuang

SpeakerBio:  Daniel Genkin, Georgia Tech

Daniel Genkin is an Associate Professor at the School of Cybersecurity and Privacy at Georgia Tech. Daniel’s research interests are in hardware and system security, with particular focus on side channel attacks and defenses. Daniel’s work has been recognized by best paper awards in multiple academic and industry venues, multiple Black Hat Pwnie awards, as well as covered by national and scientific press. Daniel has been part of the team performing the first analysis of speculative and transient execution, resulting in the discovery of Spectre, Meltdown and follow ups. Finally, he has a PhD in Computer Science from the Technion Israel’s Institute of Technology and is a 2024 Alfred P. Sloan Research Fellow.

SpeakerBio:  Jalen Chuang, Georgia Tech

Jalen Chuang is a PhD student at the Hardware Security Lab at Georgia Tech. Jalen's research spans software fuzzing, CPU microarchitectural side-channels, and now focuses on trusted execution environments. Outside of research, Jalen is a regular CTF player and 2-time DEFCON CTF finalist.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: TeleChallenge
Tags: TeleChallenge | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 107 (TeleChallenge) - Map

Description:

The TeleChallenge isn't just a puzzle challenge, it's an experience. We are super excited to show the plan for the tenth year in a row. Don't copy that floppy, but instead prepare to be immersed in an entirely new world where all of your hacker skills will be challenged (along with your 0xEA60 skills). This is a very tough contest to win, and is among the most challenging at DEF CON. Are you ready? Your first step is to find us, because part of the puzzle is discovering the puzzle.

Participant Prerequisites

You'll need a phone, your creativity and some hacker friends. It also helps to have access to a computer. Use the TeleChallenge as an excuse to meet people and form a team.

Pre-Qualification

We may have team registration in advance, but there is no pre-qualifyer.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 16:45-16:59 PDT


Title: Telecom Village CTF Closure
Tags: Telecom Village | Creator Event/Activity
When: Saturday, Aug 8, 16:45 - 16:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 17:00-17:59 PDT


Title: Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings
Tags: Telecom Village | Creator Event/Activity
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 10:30-10:59 PDT


Title: Testing API Business Logic With AI Agents: What We Got Wrong First
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Automating API security testing sounds straightforward until you try it on an enterprise API with complex auth and business flows. Over the past year, we've been building AI agents to test business logic vulns. This talk is an honest account of what we got wrong in that process. We'll cover 3 specific failures: testing before we understood resource relationships (and what that did to our IDOR detection), over-relying on agents for things deterministic methods handle better, and ignoring domain context until it became impossible to ignore. Each failure changed how we built the system. Some of the lessons were obvious in retrospect. The goal is to give anyone working on similar problems an honest look at where automated business logic testing actually breaks down and why the gap between a clean test env and an enterprise API might be harder to close than it looks. Participants will understand why business logic flaws are different and how to use agentic architecture to detect them.

SpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 14:30-14:59 PDT


Title: That's Not Your Agent: Why Zero Trust Can't Tell
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

What happens when every request is authenticated, every permission is scoped, every action logged, and the breach still happens without a single alert? Zero Trust has been widely adopted to secure environments through continuous authentication and verification. But unlike human users, agentic AI is non-deterministic and autonomous by nature. The same agent, given the same task, will reason and act differently every time. It operates beyond the moment trust was granted, making decisions no human approved. Zero Trust has no reliable way to distinguish a legitimate agent from a compromised one. This talk examines why standard controls break down. Behavioural baselining cannot establish a deviation threshold for a system with no stable baseline. IAM scoping cannot contain a compromised agent operating entirely within its authorised permissions. Continuous verification rechecks identity, not intent. When compromise occurs at the semantic layer, after authentication has already passed, every control evaluates correctly and finds nothing wrong. We map real-world disclosed incidents onto the attack vectors of a typical agentic architecture, identifying precisely where each Zero Trust control fails during the agent lifecycle. We then demonstrate a live compromise inside a correctly configured Zero Trust environment, showing two simultaneous views: what the defender sees in the logs, and what is actually happening. An indirect prompt injection attack, delivered through a poisoned document, rewrites the agent's instructions from inside its own context window. Data exfiltration follows through authorised API calls. Zero violations fire. The logs show a clean run. The data is already gone. We close with concrete mitigations from CSA's Agentic Trust Framework and MCP security guidance that teams can begin applying today. Zero Trust controls who started the session. It has no visibility into who is running it now.

Speakers:Krity Kharbanda,Emma Yuan Fang

SpeakerBio:  Krity Kharbanda

Krity Kharbanda is a Senior Application Security Engineer at ServiceNow, focused on application security, cloud security, and emerging AI-driven attack surfaces. Alongside her technical work, she leads community and professional development initiatives at Breaking Barriers Women in Cybersecurity (BBWIC), fostering mentorship, growth, and collaboration across the cybersecurity community. A frequent conference speaker, she is passionate about translating deep technical security research into practical insights while creating meaningful impact through community engagement.

SpeakerBio:  Emma Yuan Fang

Emma is a seasoned Security Architect specialising in cloud security and AppSec. As Regional Practice Lead at EPAM, she leads a team of security practitioners across the UK&I, Switzerland, and Germany. Her focus has recently expanded into the intersection of LLMs, MCP, and security, exploring how agentic AI systems reshape the threat landscape. Beyond her day job, Emma is an award-winning conference speaker, a dedicated mentor, and Vice President of WiCyS UK&I, where she champions diversity in the cyber workforce.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 16:00-16:40 PDT


Title: The 100-to-1 Problem: Securing the Non-Human Identity Perimeter
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:40 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Saturday - 15:00-15:59 PDT


Title: The Agent Long Con: Tricking Agents Out of Their Data
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Continuously running AI agents like OpenClaw are everywhere now and they're connected to everything. And despite all the doomposting, they’re mostly unhacked. So what gives? Why isn’t there a hacker gold rush against these systems?

In this talk, we break down why the classic prompt injection playbook is failing against modern agent systems including OpenClaw. A single malicious webpage or email is not enough to hijack an agent in 2026. We’ll cover what’s changed to make that true.

We’ll demonstrate attacks showing the ones that fizzle out and the ones that land in order to highlight which defenses are working and which ones are falling apart.

Finally, we’ll shift from smash-and-grab exploits to something far more effective: the long con. By chaining subtle manipulations over time, we’ll show how attackers can steer, poison, and ultimately subvert AI agents for fun and profit.

SpeakerBio:  Patrick Walsh

Patrick Walsh has an over 20 year history of running threat research and engineering teams overseeing products ranging from anti-virus and intrusion prevention to enterprise cloud software. He is a long-time advocate for privacy and security and holds multiple patents in that space. More recently, Patrick has built solutions to protect AI data and workflows. Patrick now leads IronCore Labs, an application data protection platform that uses encryption to protect data stored in the cloud while keeping it searchable and usable. Outside of work, he enjoys the outdoors, photography, hacking, lock picking, biking, swimming, and magic.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 14:00-14:59 PDT


Title: The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack?
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:
This is a sit down discussion in a more casual conversational format: Attacking an AI agent? The reflex is to reach for an abliterated model, an LLM with the refusal direction surgically removed, on the assumption that stripping safety makes a stronger attacker. Open-source pentest frameworks run on them by default. We tested base and abliterated Qwen3 and Gemma-3 across agentic attack classes. It depends on the attack.

For soft agentic-artifact attacks, writing a poisoned RAG document, a malicious agent skill, an MCP tool-poisoning description, even aligned base models comply almost universally; the agentic frame alone is enough. The sharpest case: wrapping a harmful request as a tool call drops base Qwen3 from 98% to 44% safe, with no weights changed. We demo it live, one line of agent scaffolding undoing alignment that took billions of parameters. Goal hijacking succeeds about 92% regardless of model.

But when the agent needs genuinely hard content, malware and exploit code, weapons, illicit drugs, the backbone suddenly matters: abliteration roughly doubles success (Gemma 25% to 77.5%, Qwen 37.5% to 60%), and abliterated Gemma-3 is far more dangerous than abliterated Qwen3.

That divergence doubles as a detector. We release a defender test suite: a success rate above 50% on the hard categories is a strong sign the model in your stack has been abliterated.

Which abliterated model you pick barely changes easy agentic attacks but strongly changes hard ones. Per-layer probing predicts which abliterate cleanly. We release the harness, probe set, and detector.

Speakers:Karol Piekarski,Nishith Sinha

SpeakerBio:  Karol Piekarski, DevOps Engineer

Karol Piekarski is a Lead DevOps Engineer working across cloud infrastructure, zero-trust architecture, and AI and agentic security for systems that serve hundreds of millions of consumers. His research focuses on the security of large language models and autonomous agents, with an emphasis on practical red-teaming and defensive tooling that teams can actually operationalize rather than shelve.

His empirical work on abliteration and agentic framing reframes where alignment actually breaks down in agent pipelines: agentic framing alone can collapse a model's baseline safety, while abliteration matters mostly for the hardest content and is highly architecture-dependent. In 2026 he co-presented "Move Fast, Stay Secure: Enterprise AI Agent Security in Practice" at the Databricks Data + AI Summit, and spoke at SCaLE 23x on open source red-teaming for LLMs. He was one of only two external contributors to the Databricks Agentic AI Security Framework (DASF v3.0).

Karol is the creator of Sundew.sh, an open source, MCP-native AI agent honeypot platform that uses behavioral fingerprinting and a persona engine for anti-fingerprinting, now adopted by external research teams studying agent behavior in the wild. He was selected as a Wiz MVP last year and this year received Wiz's Thought Leader award, and he is active in the AISECA Working Group, where he co-owns agentic security risk definitions.

He holds the CCSP, CKA, four AWS specialty certifications along with DataDog and Tines, and he regularly judges and mentors at hackathons across Southern California.

SpeakerBio:  Nishith Sinha

Nishith Sinha started his career by pulling secrets out of thin air. As a researcher at Georgia Tech, he co-authored a side-channel attack that recovered RSA private keys from OpenSSL by reading its electromagnetic emissions alone. No code executed, no system touched. Presented at USENIX, the work prompted a rapid fix from the OpenSSL team and is still cited as a landmark example of hardware-level cryptographic risk.

It set the tone for what came next: a career built on finding the security gaps other people aren’t looking at. At Cisco, that meant network security, where he helped design the company’s firewall migration tooling. At Amazon, it meant identity, where he owned IAM strategy across tens of thousands of AWS accounts, and then application and cloud security, remediating critical vulnerabilities at enterprise scale. As generative AI took hold, Nishith moved with it, leading application security for Amazon Bedrock and Amazon Q, before building security from scratch for Amazon’s Nova foundation models, safeguarding training data, model artifacts, and infrastructure across hundreds of teams.

Today, Nishith brings that range to Databricks, where he leads AI Security and the company’s work on Agentic Security, AI Red Teaming, and AI Enterprise Security. He holds 10 AI security patents spanning model artifact protection, secure execution of model-initiated computer actions, and behavioral-analytics-based content moderation. He co-authored the Databricks Agentic Security Framework (DASF) and is credited with several CVEs. His focus now is autonomous AI agents: the newest layer of the stack, and the one attackers understand least.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 16:15-16:55 PDT


Title: The AI Analysis Train is Leaving the Station: ALL ABOARD!!
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:15 - 16:55 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

t's 2026, and we are no longer waiting for the AI area to come of age. It's here! Are YOU adopting and adapting to AI-enabled workflows? If you don't, you'll simply be left behind. We can no longer sit back and say, "AI isn't there yet." Don't get me wrong: It's not "there," yet. But by the time AI is "there," you'll be well behind the pack in terms of knowing how to use it, what to expect from it, and more. Let's fix that! In this talk, we'll show you how to use AI for malware analysis via leveraging the new MCP server that has been integrated into REMnux. We'll be using a free distro, with free tools, with a free (well duh) MCP server. Point being: It's all free, it's all open/available, and it's here now. So get on board!

SpeakerBio:  Ryan "@rj_chap" Chapman

Ryan Chapman is the author of SANS‚ FOR528: Ransomware and Cyber Extortion‚ course, teaches SANS‚ FOR610: Reverse Engineering Malware‚ course, and works as a threat hunter @ $dayJob. Ryan has a passion for life-long learning, loves to teach people about ransomware-related attacks, and enjoys pulling apart malware. He has presented workshops at DEF CON and other conferences in the past and knows how to create a step-by-step instruction set to maximize hands-on learning.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 16:10-16:40 PDT


Title: The API Made Me Do It - Do Bad APIs Lead AI to Generate Vulnerable Code?
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:10 - 16:40 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

We blame the bot when AI-generated code is vulnerable, but what if it is just using the dangerous APIs we left on the table?

This talk tests whether API design can steer AI coding agents toward safer code. The same agent builds the same Java/Spring task app twice: once in a normal environment, and once in a constrained one with secure-by-default scaffolding, deny-by-default settings, safer abstractions, and bans on risky APIs.

The app includes authentication, authorization, task ownership, file upload, SSRF-prone link previews, and simulated paid features. The prompts describe product behavior, not security advice, so the comparison focuses on environment design rather than better prompting.

Both projects are analyzed with CodeQL and manual review to compare SAST findings, authorization flaws, unsafe file handling, SSRF risks, abstraction bypasses, and cases where wrappers hide risk instead of reducing it.

SpeakerBio:  Yariv Tal

Yariv Tal is a senior developer, security researcher, and cofounder of Secure From Scratch, a venture dedicated to teaching developers secure coding from the very first line of code.

A summa cum laude graduate of the Technion, Yariv brings four decades of programming experience and years of university lecturing and bootcamp mentoring to the field of application security.

He lectures on secure coding in academia and the private sector, leads the OWASP-untrust project, and researches the intersection of AI and application security, with a focus on secure code generation, LLM evaluation, and secure-by-construction development.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 11:00-11:59 PDT


Title: The Authentic Operator: Social Engineering Through Natural Delivery
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

Current social engineering training commonly teaches OSINT, pretexting, phishing, vishing, rapport building, elicitation, influence, framing, and nonverbal communication. That material is valuable, but much of it still treats the operator as interchangeable: learn the technique, pick the pretext, run the script. This workshop takes a different angle. The operator’s natural communication style is part of the tradecraft. A social engineering approach fails when the operator cannot deliver it credibly under pressure.

The Authentic Operator teaches attendees to build social engineering approaches around their own personality, behavioral strengths, and natural delivery style. Some operators are credible as curious analysts. Others are stronger as frustrated customers, helpful insiders, nervous applicants, confident peers, or authority-adjacent professionals. Attendees will learn to identify which approach they can carry without overacting, then use that approach to support elicitation, rapport, and access-oriented objectives during authorized red team assessments.

The accompanying tactic is a hands-on operator-matching lab for 10–15 participants. Drawing from the author’s own style, including turning an apparent lack of “brain-to-mouth filter” into a rapport-building advantage, attendees will examine how authentic self-disclosure, conversational momentum, humor, curiosity, or controlled oversharing can lower defenses and encourage reciprocity. Participants will complete a short operator-style self-assessment, receive fictional assessment objectives, select a natural delivery approach, and build an opening interaction designed to elicit information or move closer to access. The goal is not to teach people to “be anyone.” The goal is to teach operators to use who they already are with discipline, realism, and ethical boundaries.

SpeakerBio:  Joanna -

Joanna Wiggum is the founder and principal investigator of Countervail, a veteran-owned Washington State licensed private investigation agency focused on cyber-enabled fraud, impersonation, business email compromise, ransomware, and other digital loss matters. Her work centers on the trust, workflows, and dependency blindspots adversaries exploit to gain access, move money, and legitimize harmful action.

Before founding Countervail, Wiggum held cybersecurity leadership roles at Starbucks, Oracle, and Microsoft across red teaming, incident response, trust and safety, enterprise risk, and investigations. She built Starbucks’ first red team, led Oracle’s cloud red team and anti-abuse program, and directed investigations involving enterprise systems, air-gapped cloud environments, and emerging technologies at Microsoft.

Wiggum served 12 years in the United States Air Force in enlisted and commissioned roles spanning communications, operational planning, and bomber operations. Her military background includes support for U.S. Central Command air-to-ground communications tied to Operations Enduring Freedom and Iraqi Freedom, followed by mission planning and leadership in B-52 operations. She holds a Master of Human Relations and a Bachelor of Arts in International Security Studies from the University of Oklahoma.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Saturday - 17:30-17:59 PDT


Title: The Autonomous SOC Blueprint: On-Premise ML & AI to Condense, Consolidate, Contextualize, Correlate & Co-Investigate Attack Chains Hiding in the Noise
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

In this talk, you’ll learn to use on-prem auditable and tunable ML models to automatically: normalize events to any data model, enrich events with relevant labels across various frameworks and controls (eg: MITRE ATT&CK, NIST, CISA KEV, CCM, VERIS, CRI), group related events to shrink their volume and reveal coordinated activity, chain causal events to expose multi step attacks, and use AI with to generate and execute detailed context-rich incident investigations and response. Use ML to auto-enrich events with relevant ATT&CK TTPs, NIST 800-53, VERIS, CSA CCM, CISA KEV, CRI & controls in AWS, GCP, Azure, M365 and Intel vPro Use ML to auto condense, correlate, contextualize & connect events to expose attack chains hiding in the noise of false positives & isolated incidents Use private on-premise AI models with condensed, normalized, and correlated data to execute high-fidelity agentic workflows and investigations

SpeakerBio:  Ezz Tahoun

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada's CSE.

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 14:00-14:30 PDT


Title: The best of three bad ideas? Ransomware taxes in lieu of bans or doing nothing
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

A common proposal to disrupt ransomware operations is to institute a ban on ransomware payments. That risks several unwanted effects including prolonged critical infrastructure outages, a feeling of revictimization, non-compliant payers being extorted over paying. This talk investigates the potential for a middle ground: A ransomware tax.

SpeakerBio:  Joe Uchill

Joe Uchill is a PhD student in public policy at RAND Graduate School. Until recently, he was a reporter covering cybersecurity for outlets like Axios and The Hill.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 15:00-15:30 PDT


Title: The Breach Is Over. The Exposure Is Not
Tags: Recon Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Breaches are usually treated as discrete incidents. A leak is discovered, the most recognisable credentials are rotated, incident-response activity slows down, and attention moves to the next compromise. The exposure rarely ends with the incident. Credentials can remain valid for months, sometimes long enough to be reused in later attacks. While common credential types receive immediate attention, large breach datasets often contain hundreds of less familiar secret classes that are harder to recognise, validate, or prioritise. This talk examines the long tail of a major software supply chain breach and measures how exposed credentials age, which categories survive longest, and whether public disclosure actually results in remediation.

The leaked values are only part of the exposure. Secret names, environment variables, repository paths, service identifiers, deployment stages, and naming conventions can reveal how an organisation builds and operates its systems. Even when a credential has expired, this contextual residue can support attack-surface discovery, technology identification, infrastructure correlation, and future targeting. By looking beyond the obvious credential classes and focusing on the outliers, this talk demonstrates how breach data can be transformed into durable reconnaissance intelligence, and why recovery should be measured by the disappearance of usable exposure rather than the closure of the original incident.

Speakers:Kumar Ashwin,Anant Shrivastava

SpeakerBio:  Kumar Ashwin, Security Researcher at RedHunt Labs

I work at the intersection of AI, blockchain, and software security — threat modeling complex systems, defining security strategies, and building tooling that scales secure-by-default practices across engineering teams. I work at RedHunt Labs, train at Black Hat, and have spoken at Black Hat, XeeFCon, nullcon, DEF CON, and other conferences worldwide.

SpeakerBio:  Anant Shrivastava

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 15:00-16:59 PDT


Title: The Call Stack Experience
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 15:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map

Description:

Let’s play with blocks… and learn how real application attacks unfold.

You will build real application call stacks, one foam block at a time, with each block representing function calls in a normal execution flow.

Once your stack is complete, you will see first-hand how easy it is for exploits to blend in with normal application behavior.

SpeakerBio:  Victoria Keeler
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 11:00-11:45 PDT


Title: The Camera Is Lying: RTSP Trust Failures in Modern Surveillance Systems
Tags: IoT Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Surveillance cameras sit at the intersection of physical security, privacy, and critical infrastructure. Yet many still rely on decades-old streaming protocols and fragile trust assumptions that receive far less scrutiny than web interfaces or cloud APIs. In this talk, Bitdefender researchers present a newly discovered authentication bypass affecting Hikvision surveillance cameras that abuses RTSP session handling to gain unauthorized access to live video streams. By exploiting inconsistencies between session validation and authorization logic, attackers can transform low-privilege or permissionless sessions into authenticated stream access.

SpeakerBio:  Bogdan "BOTEZATU"
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 17:00-17:59 PDT


Title: The Closing Window: Governing Agentic AI Security in a Post-Mythos World
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

Mythos changed the question. Agentic AI security tooling operating at production scale is no longer a research problem or a vendor concern, it is a governance emergency. The frameworks governments have built to manage cyber risk were not designed for systems that acquire credentials autonomously, execute decisions faster than any human authorisation loop, and integrate third-party components whose security provenance no procurement standard currently requires anyone to verify. This panel convenes policy practitioners from across the agentic AI security stack (cloud-native, endpoint, behavioural detection, and federal policy) to examine what governance must look like before agentic AI becomes irreversibly embedded across critical national infrastructure and government departments. Structured around five substantive policy topics with direct implications for US, UK, and EU regulatory frameworks, the session closes with concrete, jurisdictionally-grounded recommendations that government affairs professionals can act on, across CVE architecture, critical infrastructure designation, agent identity standards, incident reporting obligations, and procurement requirements, before the legislative windows currently open in all three jurisdictions close or retrofitting security becomes too costly.

Speakers:Taylor Roberts,Mitch Herckis,Katie Trimble-Noble,Razvan Gavrila

SpeakerBio:  Taylor Roberts, Zenity

Taylor Roberts is a seasoned cyber and AI security policy expert with experience spanning academia, the US federal government, and the private sector, currently serving as Principal of AI Security Policy at Zenity. Previously the Global Director of Security and Trust Policy at Intel and a former Cybersecurity Advisor at the White House's Office of Management and Budget, Taylor works toward fostering collaboration with governments, industry, and standards organizations to strengthen the AI security cybersecurity ecosystem. He holds a Masters in International Affairs from UC San Diego.

SpeakerBio:  Mitch Herckis, Wiz

Mitch Herckis has spent two decades working with and for the public sector on technology and security policy. Currently, Mitch serves as the Global Head of Government Affairs for Wiz, a cloud cybersecurity company. Prior to joining Wiz, Mitch served as Director of the Federal Cybersecurity Branch within the White House's Office of Management and Budget, where he led cybersecurity initiatives within the Office of the Federal Chief Information Officer, including implementation on the President's Executive Order on Improving the Nation's Cybersecurity. Before joining federal service, Mitch served as a Senior Advisor for New York City Cyber Command, facilitating security implementations across 100+ city agencies on behalf of the City’s central cybersecurity authority. He also spearheaded public initiatives to increase the digital security of City residents. Mitch has advocated for sound technology policies at all levels of government, including serving as the Director of Government Affairs for the National Association of State Chief Information Officers (NASCIO), and Senior Legislative Counsel for Federal Relations at the National League of Cities.

SpeakerBio:  Katie Trimble-Noble, Director, PSIRT and Bug Bounty

Katie serves as a CVE Program Board, Bug Bounty Community of Interest Founder, and Hacking Policy Council Founding member. She is a passionate defensive cybersecurity community activist, she is regularly involved is community driven projects and is most happy when she is able to effect positive progress in cyber defense. In her day job Katie Noble serves as a Director of PSIRT, specializing in Global Secretarial Policy and Industry Engagement and Bug Bounty, at a fortune 50 Technology Company. Prior to joining private sector, Katie spent over 15 years in the US Government. Most recently as the Section Chief of Vulnerability Management and Coordination at the Department of Homeland Security, Cyber and Infrastructure Security Agency (CISA). Her team is credited with the coordination and public disclosure of 20,000+ cybersecurity vulnerabilities within a two-year period. During her government tenure, in roles spanning Intelligence Analyst for the National Intelligence Community to Senior Policy Advisor for White House led National Security Council Cyber programs, Katie’s work directly impacted decision making for government agencies in the United States, United Kingdom, Canada, and Australia.

SpeakerBio:  Razvan Gavrila, ENISA - The European Union Agency for Cybersecurity

Razvan Gavrila is a seasoned cybersecurity professional with over 15 years of experience across national and EU institutions. In his current role, he oversees ENISA’s work on the implementation of the EU Cyber Resilience Act and leads initiatives in product and security engineering, including the cybersecurity of AI systems. Prior to his appointment as Head of Sector for Market, Technology, and Product Security in January 2025, he served as ENISA’s lead Cyber Threat Intelligence (CTI) analyst. He holds several industry-recognized certifications and a Master of Science in Computer and Information Security


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Saturday - 15:30-15:59 PDT


Title: The Compiler Nobody Satisfactorily Tested: Supply-Chain Gaps in EV Charging Firmware
Tags: Car Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Someone installed Doom on an Alpitronic supercharger at Pwn2Own Automotive 2026 — via an out-of-bounds write in firmware compiled by a compiler nobody verified. This talk connects the dots between Pwn2Own exploit classes and the upstream problem: most automotive and EVSE compilers have never been independently tested against safety or security standards. I will present a map of which compilers are actually qualified, where the coverage gaps are, and why Rust's memory safety guarantees matter less than you think if the compiler itself isn't verified. The talk closes with a practical trust chain — develop, compile, verify, review — that the security community can use to evaluate toolchain integrity.

SpeakerBio:  Kangwon Lee, Life Member of OWASP

In computing since '86 (HS computer club → EMPAL BBS → Yonsei). Radar application algorithms at Autoliv, embedded SW at Hyundai Motor. Now Associate Prof at TU Korea, interested in Rust compiler qualification for safety-critical ITS. IEEE ITSS Korea Chapter Chair, IEEE P3538 WG Secretary, OWASP lifetime member, ISC2 CC. Sits on Korea's government committee on motor vehicle safety defects. Ph.D. ME + M.S. EECS, U of Michigan.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 16:00-16:59 PDT


Title: The Compiler That Can't Read: Crashing Every 5G Phone With One Byte
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Every 5G phone parses radio messages using code generated by a compiler. That compiler has two blind spots — and we used them to crash iPhones, Pixels, and phones from every major chipset vendor. No credentials, no user interaction, no warning.

The compiler can't read English. Hundreds of rules that govern when fields should appear exist only in natural-language prose. The compiler discards them all. We extracted these invisible rules, turned them into targeted payloads, and crashed basebands from Apple, Google, Qualcomm, and MediaTek — all before authentication. Apple confirmed reproduction. Google Android Security confirmed multiple findings. MediaTek patched three CVEs affecting 64 chipset models and over 542 smartphone models. Qualcomm rewarded one finding.

The compiler can't count. Some fields have value ranges that don't fill the wire encoding. We changed one byte in a legitimate message and crashed phones across two chipset generations. GSMA assigned CVD-2025-0110.

Same root cause, same blind compiler, same result: the modem trusts a decoder that was never built to enforce the rules that matter. We demo live over-the-air crashes on stage.

  1. 3GPP TS 38.331: NR Radio Resource Control (RRC) protocol specification
  2. 3GPP TS 33.501: Security architecture and procedures for 5G System
  3. ITU-T X.680-X.693: ASN.1 and encoding rules (UPER)
  4. Hernandez et al., "FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware," NDSS 2022
  5. Klischies et al., "BaseBridge: Bridging the Gap Between Over-the-Air and Emulation Testing for Cellular Baseband Firmware," IEEE S&P 2025
  6. Garbelini et al., "5Ghoul: Unleashing Chaos on 5G Edge Devices," IEEE TDSC 2025
  7. Park et al., "DoLTEst: In-depth Downlink Negative Testing Framework for LTE Devices," USENIX Security 2022
  8. Rupprecht et al., "Putting LTE Security Functions to the Test: A Framework to Evaluate Implementation Correctness," USENIX WOOT 2016
Speakers:Qiqing Huang,Xingyu Wang

SpeakerBio:  Qiqing Huang

Qiqing Huang is a PhD candidate in Computer Science at the University at Buffalo, specializing in 5G baseband security. His research focuses on exploiting structural gaps between formal protocol schemas and natural-language specification constraints to discover pre-authentication vulnerabilities in commercial cellular modems. His work has resulted in multiple high-severity CVEs affecting major baseband vendors including Apple, Qualcomm, Samsung, and MediaTek, impacting 64 chipset models and over 542 commercially available smartphone models. He received GSMA CVD-2025-0110 for discovering a class of ASN.1 decode divergence vulnerabilities. His research has been published at USENIX Security 2026. He maintains active responsible disclosure relationships with Apple, Google, Qualcomm, Samsung, MediaTek, and GSMA. He is completing his PhD in Summer 2026 and is on the job market for security research roles.

SpeakerBio:  Xingyu Wang, University at Buffalo

Xingyu Wang is a PhD student at the University at Buffalo studying the weird edge cases of networks, phones, and systems that are supposed to “just work.” He explores how AI can help security researchers survive dense specs and turn “wait, why did it do that?” moments into better tests. He does not fully trust AI or complex systems, but he enjoys putting them in the same room and watching what breaks first.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 13:30-13:59 PDT


Title: The CVE-Hunters Project: From Noobs to Researchers
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

What if publishing a CVE wasn’t reserved for elite hackers, but achievable by anyone with the right mindset, method, and community?

This talk tells the story of how the Brazilian CVE-Hunters Project transformed beginners with zero published research into recognized vulnerability researchers contributing to global cybersecurity. By breaking down the myth that CVEs require genius-level exploits or zero-days, we reveal a structured, repeatable methodology that turns curiosity into impact.

You’ll learn how vulnerability research can be systematized, how responsible disclosure really works behind the scenes, and how publishing your first CVE can change your technical credibility, career trajectory, and confidence.

More than a technical presentation, this is a blueprint for moving from learning hacking to becoming a researcher — and contributing meaningfully to the security ecosystem.

Because your first CVE isn’t about ego.

It’s about responsibility, growth, and raising the bar for global security.

SpeakerBio:  Natan Morette, Pentest Manager at Thoropass, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative

Natan Morette is a Penetration Test Manager, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative, where he mentors students in offensive security across the country. He began his career as a help desk analyst and moved through infrastructure roles before discovering his passion for cybersecurity. Natan has discovered and published multiple CVEs and actively supports students in identifying and disclosing their own—especially in open-source projects with meaningful social impact.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Saturday - 10:30-10:59 PDT


Title: The Death of Dicom
Tags: Biohacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

DICOM (Digital Imaging and Communications in Medicine) is the lingua franca of medical imaging — a decades-old protocol embedded in nearly every hospital network, PACS server, and imaging modality on the planet. It is also, by modern standards, a deeply permissive protocol: built on assumptions of trusted networks, sprawling parser surface area, and file formats that double as executable carriers. For an attacker, that combination is a gift. This talk explores how DICOM can be repurposed as offensive infrastructure across the full red team lifecycle. We’ll walk through the protocol’s exploitable design choices, demonstrate techniques for initial access, lateral movement, and persistence inside healthcare environments, and examine how DICOM files themselves can be abused as polyglot payload carriers that survive AV, EDR, and content inspection. Along the way, we’ll look at real-world PACS deployments, the surprising reach of DICOM beyond hospitals, and why this protocol represents one of the largest under-examined attack surfaces in critical infrastructure today. Attendees will leave with a working mental model of DICOM from an offensive perspective, concrete TTPs they can incorporate into engagements against healthcare and adjacent verticals, and a healthy appreciation for why their next CT scan might be running on a Windows XP box.

SpeakerBio:  Michael "v3ga" Aguilar, Principal Consultant at Sophos Red Team

Michael Aguilar (v3ga) is a Principal Consultant on the Sophos Red Team, paid to think like the people his clients are afraid of. His work lives at the intersection of offensive security, vulnerability research, and low-level systems programming, Windows internals, reverse engineering, and the kind of dusty attack surfaces that nobody has looked at since the protocol was ratified. Sometimes, he’s lucky enough to perform full Physical Red teams against his client targets. His method is unglamorous and effective: Analyze, Formulate, Target, Attack (covertly).


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 16:00-17:59 PDT


Title: The Diana Initiative - Open time
Tags: The Diana Initiative | Creator Event/Activity
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

We also have our "Reference Desk", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 12:00-12:59 PDT


Title: The Diana Initiative - Open time
Tags: The Diana Initiative | Creator Event/Activity
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

We also have our "Reference Desk", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 14:00-14:59 PDT


Title: The Enclave is Lying to You: Breaking TEE Trust Boundaries Through Boot-Time State
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:
Confidential computing on cloud TEEs: Nitro Enclaves, SEV-SNP, and TDX promises that a fully compromised host cannot reach into a hardware-isolated enclave. The cryptographic attestation story holds. The deployment story does not.

This talk demonstrates attacks that bypass TEE isolation without touching the enclave image. We target the inputs an enclave trusts at boot: cloud object storage, host-supplied environment variables, and KMS keys whose policies forget to enforce attestation. None are covered by attestation. All reach inside.

We demonstrate remote code execution as root inside a Nitro Enclave with a single s3:PutObject permission. No host access. No SSH. One file upload containing a path traversal, one boot cycle, and the enclave executes attacker-controlled code.

From inside we intercept KMS decrypts live to extract the database encryption key in plaintext, exfiltrate the enclave's IAM credentials, and establish persistence across reboots without re-exploitation - all while PCR measurements remain unchanged and attestation reports a healthy enclave.

We release an open-source auditing tool, walk through which defenses held, and provide a hardening checklist for any team running workloads inside TEEs.

The enclave isn't broken. The way we deploy it is.

AWS, "AWS Nitro Enclaves User Guide," https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html AWS, "Cryptographic Attestation with AWS KMS for Nitro Enclaves," https://docs.aws.amazon.com/kms/latest/developerguide/services-nitro-enclaves.html A. Tsow, "Attacking Confidential Computing: A Survey of TEE Exploitation Techniques," IEEE S&P Workshop on Offensive Technologies (WOOT), 2024 NCC Group, "Public Report - AWS Nitro System Security Review," 2023, https://research.nccgroup.com/2023/04/ Trail of Bits, "Security Assessment of AWS Nitro Enclaves," 2022 MITRE ATT&CK, "Cloud Matrix - Initial Access / Valid Accounts," https://attack.mitre.org/techniques/T1078/004/ J. Aas et al., "Understanding TEE Trust Models in Cloud Deployments," USENIX Security Symposium, 2023 OWASP, "Path Traversal," https://owasp.org/www-community/attacks/Path_Traversal AWS, "Instance Metadata Service Version 2 (IMDSv2)," https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html Apache Thrift Project, "Thrift Binary Protocol Specification," https://github.com/apache/thrift/blob/master/doc/specs/thrift-binary-protocol.md

SpeakerBio:  Sandeep "pyro" Jayashankar, Independent Researcher

Sandeep Jayashankar is a security researcher specializing in offensive security and adversarial simulations. His work spans AWS, Azure, and GCP environments, with current research focused on trusted execution environment exploitation, confidential computing trust boundaries, and the security of AI/ML systems deployed in cloud-native architectures. This research was conducted under an authorized adversarial simulation program. He approaches security research from a defender's perspective: every offensive finding ships with a concrete, auditable control that defenders can deploy. He previously presented at RSA Conference 2025.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Saturday - 15:00-15:59 PDT


Title: The Enshittified Internet and How We Can All Rewild the Internet
Tags: Hackers.town | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map

Description:
SpeakerBio:  LambdaCalculus

LambdaCalculus is chaos in a trenchcoat, and is passionate to his core about human rights issues, community outreach, and education. He has spoken at HOPE in 2025 on the Pirate Box and Sneakernet, and has also spoken at DEF CON, JawnCon, and PhreakNIC. He is a member of hackers.town, a native of the NYC area, and can still hit a mosh pit! Find him hanging out at hackers.town on Mastodon:https://masto.hackers.town/@LambdaCalculus


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 10:00-10:59 PDT


Title: The Ghost Key: Illusions of "Time Management" in TTLock Smart Locks
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Smart locks are widely used in rental, hotel, and residential markets. As a major provider, TTLock (Sciener) operates in over 200 countries and relies on Offline Time Management to issue temporary eKeys without network access. However, our research reveals critical security flaws in this common offline design. From real-world anomalies, we analyzed TTLock’s proprietary BLE protocol and found serious weaknesses in its cryptographic verification and authentication. Lacking proper validation, the so-called secure offline architecture is fully bypassable. We uncovered three critical design flaws: full revocation bypass, expired credential resurrection, and low-cost DoS. In this talk, we will demonstrate exploitation with a Mac and custom Python tools. We show that time management in TTLock is a mere illusion, turning physical security into an open digital door.

Speakers:Yang Liu,Zhenghan Wang

SpeakerBio:  Yang Liu, Hillstone Networks Co., Ltd.

Yang Liu is a Security Researcher at Hillstone Network Security Research Institute, specializing in binary vulnerability hunting, ICS security, mobile security, and reverse engineering. With extensive experience in both red-teaming and defense, Yang has discovered numerous vulnerabilities in complex industrial control systems. He is a frequent speaker in the security community, notably presenting his ICS research at the Kanxue Security Development Conference (SDC). An avid CTF competitor, Yang excels in Reverse Engineering, Mobile, and ICS categories. He also leverages his real-world combat experience to provide professional cybersecurity training for enterprises.

SpeakerBio:  Zhenghan Wang, Hillstone Networks Co., Ltd.

Zhenghan Wang is a security researcher focusing on IoT security and open-source software security. His research interests include embedded system security, protocol analysis, reverse engineering, and vulnerability discovery. He is dedicated to finding and disclosing real-world security issues to help improve the safety of connected devices and open-source projects.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 12:00-12:59 PDT


Title: The Glass Perimeter: Systematic Bypasses in Biometric Frameworks and the Rise of Synthetic Identity
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Identity is the new perimeter, and biometrics are its supposed gatekeepers. But what happens when the gatekeepers are blind to the reality they consume? We spent more than 6 months deconstructing the biometric "Root of Trust" across every top-tier framework we could find, solutions relied upon by the world’s largest banks and providers worth billions. The result: A 100% bypass rate . From high-fidelity physical spoofs to a first-of-its-kind Cross-PID buffer hijack against integrated anti-tamper SDKs, we prove that even multi-million dollar "fortresses" can be reduced to client-side theater. This talk is a technical journey through the guts of the mobile media pipeline, exposing how synthetic identities are manufactured at scale to bypass RASP, Kernel-level integrity, and AI models. When the "Master Key" is just another line of code an attacker can hook, the risk isn't just a bug, it’s a systemic failure affecting millions of users. Customers are losing wealth, companies are buying illusions, and the glass perimeter is shattering.

Speakers:Dan Borgogno,Javier Bernardo

SpeakerBio:  Dan Borgogno, Security Researcher at Faraday

Dan Borgogno is a security researcher, backend developer, security engineer and international speaker with years of experience on mobile, hardware, IoT and web application hacking.

SpeakerBio:  Javier Bernardo, Strike Security

Senior Pentester, Security Engineer and Cybersecurity Researcher (+15 years) with a wide area of expertise in Offensive Security and Red Team. Passionate Bug Hunter and self-taught Cybersecurity Specialist who loves to hack almost everything.

Organizer of Bug Bounty Argentina Community: https://twitter.com/BugBountyArg Speaker and Organizer at Ekoparty Security Conference: https://ekoparty.org/


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 12:40-15:10 PDT


Title: The Hard Part of ASM: Ownership Attribution
Tags: Recon Village | Creator Workshop
When: Saturday, Aug 8, 12:40 - 15:10 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Attack Surface Management (ASM) lives or dies on a deceptively simple question: who owns this? Without reliable attribution, an asset inventory is just a pile of hosts, domains, certificates, and cloud endpoints—with no defensible way to scope an organization’s true digital footprint or separate first-party infrastructure from vendors, subsidiaries, acquisitions, joint ventures, and brand portfolios.

This talk dives into the real-world challenge of attributing internet-exposed assets to legal entities, not just names. Corporate identity is messy: organizations operate under trade names, localized spellings, legacy names, and jurisdiction-specific registrations. Meanwhile, the internet leaks ownership signals through fragmented, lossy metadata—RDAP/WHOIS, certificate subject/issuer fields, ASN registrations, DNS TXT verification records, trademark references, and public corporate registries. Each source is incomplete on its own; together they can still conflict, drift over time, and create duplicate “identities” that quietly degrade attribution accuracy.

Using the OWASP Amass Project as a concrete reference point, we’ll walk through an attribution-centric discovery workflow: collecting signals, normalizing entity identity, resolving aliases across jurisdictions, and scoring confidence to decide when to merge, when to split, and when to escalate for analyst review. We’ll also explore how attribution errors propagate into ASM outcomes—missed scope, false positives, and blind spots in third-party exposure—and how disciplined entity modeling can turn noisy OSINT into a repeatable system of record.

Attendees will leave with practical techniques for improving attribution quality, a mental model for entity resolution, and actionable ideas for making ASM outputs trustworthy enough to drive risk decisions.

SpeakerBio:  Jeff Foley, Founder and Project Leader at OWASP Amass Project
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Saturday - 14:00-14:59 PDT


Title: The Hidden Data Supply Chain: How a SaaS Platform Broadcast Credentials and Customer Identities
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

Security researcher Sam Jadali, known for uncovering DataSpii, presents new research on the hidden and often inadvertent data supply chains inside SaaS platforms. In controlled tests of Klaviyo, a marketing/CRM platform processing roughly 8 billion customer profiles across 600k+ websites, simply viewing a contact's profile transmitted that person's name, email, or identifier to outside vendors, several not on Klaviyo's sub-processor list. Worse, during account registration a test account's password, email, phone number, and company details were sent to 31 third-party hostnames including Google, Meta, and LinkedIn, with four endpoints reflecting the password back to confirm receipt. Some recipients hid behind unbranded domains that customers and compliance teams can't identify through ordinary inspection. As human- and AI-generated code ships faster, one small HTML flaw can broadcast sensitive data across supply chains few organizations monitor. Jadali walks through the evidence, reproducible from network captures and public Common Crawl records.

SpeakerBio:  Sam Jadali
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:30-10:45 PDT


Title: The importance of Networking in Cybersecurity community
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:30 - 10:45 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Quick session on how important it is to network with other professionals, students, and vendors to gain knowledge, collaborate for defenses and also for career growth

SpeakerBio:  Michael Lenz
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Saturday - 17:00-17:59 PDT


Title: The National Fight Against ALPRs
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:
Speakers:Freddy Martinez,Sarah

SpeakerBio:  Freddy Martinez
No BIO available
SpeakerBio:  Sarah

Sarah has been working at the EFF on building out its local campaigns against surveillance, in particular on ALPR technology. Freddy and Arti have been at Lucy Parsons Labs which has been working on the explosive growth of ALPRs for over six years. LPLers have been a partners in the nationwide research and organizing against ALPRs all over the country.


Return to Index    -    Add to Google    -    ics Calendar file

Malware Village - Saturday - 14:40-15:15 PDT


Title: The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Tags: Malware Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:40 - 15:15 PDT
Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map

Description:

In recent years, threat actors have been migrating their command-and-control infrastructure from traditional domains and servers to decentralized platforms that are resilient to takedowns. The Polygon blockchain is one such platform, where encrypted and plaintext instructions can be embedded into immutable smart contracts, making them permanently accessible and beyond the reach of law enforcement seizure. Aeternum is a recently discovered botnet that takes full advantage of this shift. Its operators write encrypted C2 commands directly into smart contracts, and infected machines retrieve them via public Remote Procedure Call (RPC) endpoints, eliminating the need for any attacker-controlled server in the command delivery chain.

This one-way, read-only design functions as a dead-drop resolver that cannot be taken offline through conventional means. The botnet's reach extends beyond a single malware family. Multiple samples across different languages and capabilities like loaders, stealers, RATs, and cryptominers have been found querying the same smart contract infrastructure using a shared function selector. Each brings its own execution techniques, from Early Bird APC injection and multi-layer encryption to Telegram-based exfiltration and sandbox evasion routines targeting analyst environments.

By analyzing malware behaviors, network traffic, decrypting the on-chain payloads, and following the operator's digital footprint across multiple platforms, we were able to trace the infrastructure back to a single infrastructure. In this talk, we will walk through the full investigation from initial sample discovery to on-chain decryption and operator attribution and discuss what defenders need to know to detect blockchain-based C2 at the network level.

Speakers:Chris Navarrete,Sai Sathvik Ruppa

SpeakerBio:  Chris Navarrete, Senior Principal Security Researcher - CDSS Advanced Threat Prevention (ATP) at Palo Alto Networks

Chris Navarrete is a Senior Principal Security Researcher within the Advanced Threat Prevention team at Palo Alto Networks. His work centers on cutting-edge research in cybersecurity, particularly in threat detection and malware analysis. Previously, he served as an adjunct professor of computer science at San Jose State University, teaching Software Security Technologies. He holds a Master of Science in software engineering with a specialization in cybersecurity from San Jose State University. Chris has presented at major industry conferences, including Black Hat Asia, the Computer Antivirus Research Organization (CARO), the Cyber Threat Alliance's Threat Intelligence Practitioners (TIPS) conference, and Black Hat Arsenal, where he introduced and released BLACKPHENIX — a framework designed to automate malware analysis workflows.

SpeakerBio:  Sai Sathvik Ruppa, Staff Security Researcher at Palo Alto Networks

Sai Sathvik Ruppa is a Staff Security Researcher at Palo Alto Networks and a recent M.S. graduate in Information Security from Carnegie Mellon University. He specializes in vulnerability detection and malware analysis, leveraging his expertise to identify, analyze, and mitigate advanced cyber threats.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 12:00-12:59 PDT


Title: The Protocol-Native Adversary: Full-Spectrum ICS Simulation via SiL
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

As adversaries increasingly target the "physics" of critical infrastructure, the security community must move beyond IT-centric red teaming. While hardware-based training platforms have paved the way, they often lack the scale required to simulate complex, multi-facility sabotage. This workshop introduces a Software-in-the-Loop (SiL) environment designed to bridge the gap between IT command-and-control and OT process logic. Participants will navigate a containerized industrial ecosystem, mastering "Living-off-the-Ladder" (LotL) techniques—using native, unauthenticated protocols (Modbus, DNP3, S7comm) to manipulate physical water treatment processes. We will move through the full ICS kill-chain, focusing on the technical mechanics of memory-block interrogation and automated setpoint manipulation. Attendees will engage in a hands-on lab, executing a "Credential Harvest" (T0861) and a coordinated chemical-override attack. By the end of the session, participants will understand why these "authorized" protocol commands bypass traditional NIDS and will leave with a deployable SiL framework to continue their own ICS research.

Speakers:Blessen Thomas,Javier Hernández,Wojciech Poparda

SpeakerBio:  Blessen Thomas

Blessen Thomas is an Independent Security Researcher.He has more than 13+ years of experience in Red Teaming, Appsec (Web, Thick, API & Mobile Apps), Smart Watch Wearable Application Penetration Testing, Mobile Penetration Test (iOS,Android,Windows platform), IoT,OT ,mainframes,SAP,SWIFT,RPA,Cloud,ATM,KIOSK,Vulnerability Assessment and Network Penetration Test,Physical Covert Entry,Wireless assessments,Telecom(2G,3G,USSD) etc. for several enterprise companies and financial institutions all across the globe. He is a B.Tech in Information Technology from Anna University and holds industry certifications such as SANS GPEN,CRTO,OPST,CREST CRT(PEN),CREST CPSA,OSCP,CRTP,OSWP,C)PTE,CEH,CHFI. He has been listed and acknowledged in various “HALL OF FAMES” for various companies such as Oracle,Sony, Kayako, Appcelerator, Hotgloo, Meldium, Splunk and many more for responsible disclosure. He has been a bug bounty hunter and contributor for the OWASP Mobile Testing Guide Project(MSTG),Tamer OS, Seclists, OWASP top 10 API, OSSTMM, Awesome Mainframe Hacking,RvR,WAVSEP Benchmark sectool projects. His research training/talks has been accepted into various security conferences like Hack in the Box-Dubai,Hacktivity -Hungary, CanSecWest -Canada,OWASP Appsec EU- London -UK,OWASP Appsec Europe-Italy, RootCon-Philippines ,OWASP PH,OWASP New Zealand Day, Infosec SouthWest,Austin,Texas, FSec-Croatia, Hackbeach, Hackfest, Shakacon,ITWeb-South Africa, Jordan Cyber Security Summit, HITCON-Taiwan, OWASP AppSec-Bucharest, OWASP Appsec Africa-Morocco,CircleCityCon,OWASP Botswana,CactusCon,Bsides-London,Prishtina,Aarhus,Vilnius,Elbsides,Kristiansand,Athens and many more. He has been invited as Speaker for Radio Talk Shows for All India Radio. He spends his leisure time playing drumkit and percussion.

SpeakerBio:  Javier Hernández

Javier is a Red Team Operator and Malware Developer specializing in offensive engineering, adversary emulation, and custom tooling development. Holding certifications such as OSEP and CRTO, he has delivered high‑impact security engagements across both consulting environments and in‑house security teams. His work focuses on crafting stealthy implants, evasion techniques, and automation‑driven offensive capabilities. Passionate about applied research, he explores the intersection of malware development and AI‑augmented offensive security to help organizations strengthen their resilience against modern threats

SpeakerBio:  Wojciech Poparda

Wojciech Poparda is a cybersecurity consultant. He helps organizations proactively defend their digital infrastructure by thinking like an adversary. Leveraging a deep foundation in Offensive Security, he specializes in designing resilient Security Architectures that bridge the gap between complex attack vectors and enterprise defense, with a sharp focus on Cloud Security and Identity & Access Management (IAM).

His approach is backed by rigorous technical validation, holding industry-leading certifications including OSCP, CRTE, CRTP, CRTO, CPTS, CWES, AWS Certified Solutions Architect - Associate and AWS Certified Security - Specialty. He is also an Associate of ISC2, having successfully passed the CISSP exam.

Beyond the terminal, he channels the discipline, focus, and resilience required for cybersecurity into his life as a triathlete. As an IRONMAN European and World Championships finisher, he brings the same endurance and dedication to solving complex security challenges as he does to the race course.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 16:00-17:59 PDT


Title: The Quantum Mechanic: Attacking all the clouds
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

Cloud environments are now expansive and interconnected, where identity is the main security boundary, and misconfigurations pose security risks. For Red Teamers, attacking these environments often means relying on a collection of mismatched tools. You need one set of scripts for Entra ID, a separate framework for AWS, and many command-line tools for other cloud providers. This switching between tools is inefficient, and workflows require many manual commands. When operators deal with complex dependencies and syntax differences between providers, they miss broader attack paths.

Enter the Quantum Mechanic.

This session introduces a new Unified Cloud Attack tool designed to remove the operational friction of multi-cloud engagements. Built for operators who need to move fast and remain unnoticed, Quantum Mechanic serves as a universal discovery and exploitation engine. It hides the differing command sets of various cloud providers, allowing operators to run complex attacks through a single, consistent interface without sacrificing the accuracy of direct CLI commands.

During this talk, we will discuss the realities of modern cross-cloud exploitation and demonstrate how to bring order to the process. We will present the framework’s main components, demonstrating how it handles compromised credentials, automates cross-platform enumeration, and maps privilege-escalation paths. Through demonstrations, we will show the tool’s ability to exploit multi-cloud environments with a single command set.

If you are tired of managing multiple separate tools just to get started, or if you've ever disrupted an operation because of a misconfigured cloud script, it’s time to upgrade your toolkit. Join us to learn how to streamline your cloud attack workflows and improve precision.

SpeakerBio:  Moses Frost

Moses Frost has been working in the field since the late 90's. Working with computers in the late 80s for fun and moving into a more professional field shortly after high school. He is a Red Team Operator at Neuvik. A senior instructor and course author at the SANS Institute, authoring and teaching the Cloud Penetration Testing Course. He also co-authors the book Gray Hat Hacking: Volume 6. He has worked at many companies, notably Cisco Systems, McAfee, and TLO. Currently, he is a Senior Operator at Neuvik. Over those years, he has enjoyed working in all parts of the IT Industry and hopes to do so for many more years.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 17:30-17:59 PDT


Title: The Republic is a Team Sport: Technology can Protect Elections, but the People must Protect Democracy
Tags: Voting Village | Creator Interactive Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map

Description:

Throughout the Voting Village, speakers and researchers have always challenged assumptions around election technology, internet voting, audits, legal frameworks, and the public confidence. Among the many lessons learned together, we can see these issues pointing to a common conclusion that democracy cannot depend on trust alone. But the evidence we develop from security research and academia, are not enough to move our nation in the right direction either.

This closing discussion asks what comes after the research. How do technical findings become better policy? What responsibilities do election officials, attorneys, journalists, academics, and citizens share in preserving institutions that none of us can protect alone? What does it mean to be an American today? This session invites the audience to help answer those questions. Drawing from conversations throughout the conference, we’ll explore how democratic resilience depends not only on secure systems, but on communities willing to engage honestly across disciplines and political perspectives.

The goal is not consensus. The goal is responsibility.

SpeakerBio:  Kendall Spencer

Kendall Spencer is an attorney specializing in emerging companies, technology transactions, and the legal issues shaping innovation. Since joining DEF CON’s Voting Village as a Georgetown Law student in 2019, he has worked alongside Matt Blaze, David Jefferson, and the Voting Village team at the intersection of election technology, cybersecurity, and democracy. Spencer serves on the Board of Directors of the Election Integrity Foundation and has advised state election officials on election security, post-election audits, and cybersecurity best practices. His work focuses on bridging the gap between technical research, public policy, and the law—helping policymakers, election officials, security researchers, and the public better understand the role election security plays in strengthening democratic institutions and public confidence in elections. A frequent DEF CON speaker, Spencer is passionate about fostering thoughtful, bipartisan conversations on the role of technology in protecting election integrity and the democratic principles that underpin a free and open society. Outside of his legal and technology work, Spencer is a rare book dealer and collector specializing in early American history and the Black diaspora.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 14:30-14:59 PDT


Title: The Sherlock Holmes Social Engineering Playbook
Tags: Social Engineering Community Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 14:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Long before phishing, deepfakes, and business email compromise, Sherlock Holmes was demonstrating social engineering tactics: building trust, gathering intel, exploiting emotion, and manipulating human behavior to achieve an objective. The tools have changed. The psychology has not. In The Sherlock Holmes Social Engineering Playbook, we examine how Sir Arthur Conan Doyle�s detective stories function as a masterclass in human hacking. Through cases such as A Scandal in Bohemia, The Red-Headed League, and The Sign of Four, this presentation breaks down techniques used to influence decisions, lower defenses, and extract information, many of which mirror modern phishing, OSINT, and fraud campaigns. Through immersive examples and practical cyber parallels, attendees will explore how Holmes used recon, pretexting, impersonation, trust-building, distraction, and emotional leverage to accomplish his goals, and how attackers rely on those tactics today. Participants will leave with a practical social engineering playbook for recognizing manipulation, strengthening human defenses, and thinking critically about the psychology behind cyber threats. Because sometimes the best way to understand today�s attackers� is to study a Victorian detective.

SpeakerBio:  Elizabeth Rasnick, Assistant Professor at Center for Cybersecurity and Artificial Intelligence at the University of West Florida

Dr. Elizabeth Rasnick is an Assistant Professor at the Center for Cybersecurity and Artificial Intelligence at the University of West Florida. Her work focuses on human-centered cybersecurity, workforce development, cybersecurity education, and the intersection of psychology, storytelling, and social engineering. Dr. Rasnick specializes in translating complex cybersecurity concepts into engaging, accessible learning experiences for technical and non-technical audiences alike. Her research and presentations explore how human behavior, persuasion, trust, and cognitive bias shape modern cyber threats, often through unexpected lenses such as literature, history, and pop culture. She is particularly interested in how classic narratives, including Sherlock Holmes, reveal timeless social engineering tactics still used by attackers today. A frequent speaker, educator, and advocate for interdisciplinary cybersecurity education, Dr. Rasnick works to broaden participation in cybersecurity and prepare the next generation of cyber defenders through innovative, experiential learning. Whether discussing phishing, persuasion, OSINT, or the psychology of manipulation, she believes the most effective security begins with understanding people.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 13:30-13:59 PDT


Title: The Subverted Hacker
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:
Frontier AI is turning hacker labor into a defensive layer for private infrastructure: systems built on public research, open-source code, security writing, and the technical culture hackers helped create. Yet these systems are controlled by a small number of companies and states, with limited public audit ability or accountability. Historically, hackers made complex systems more understandable, modifiable, and contestable. In frontier AI, that role is being subverted. Hackers are recruited (or bribed viabounties ha!) to harden opaque models, reduce adversarial access, and protect systems whose impacts are public, but whose internals, evaluations, and risk decisions remain private. Public-interest scrutiny remains in conflict of interest. This talk argues that AI security cannot become only a corporate risk or national competitiveness exercise. If frontier AI affects labor, speech, art, security, and institutions across the globe, then it needs international public-interest security obligations. I propose an international AI evaluation and red-team mandate: a legally protected mechanism that brings vetted hackers and experts from across the globe into controlled testing of high-impact AI systems, so they remain contestable and accountable beyond the companies that build them. (I can dream can't I?)
SpeakerBio:  Robert "zizkill" Shala, Sentry

Robert Shala is co-founder of Sentry, a company delivering security assurance services for some of the world’s largest organizations. His work sits at the intersection of offensive security, public policy, and emerging technology governance. Robert has contributed to Kosovo’s national cybersecurity strategy working group and to a Kosovo working group on responsible AI use in military contexts. He is also the founder of DEF CON Group Prishtina, where he works on advancing Kosovo’s responsible disclosure ecosystem and improving legal protections for good-faith security research. He has served as an external AI Red Teamer for OpenAI, probing frontier models for safety and security flaws, and was formerly involved with Georgetown RAIN/GAIA.Robert has presented security research at the Defence Academy of the UK, DEF CON 33at AI Village and AppSec Village, and BSides across the world. He holds an M.A. inSecurity Studies from Georgetown University and a B.S. from RIT. Robert loves wargaming.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Wednesday - 11:00-17:15 PDT


Title: The Unofficial DEF CON Shoot
Tags: Event
When: Wednesday, Aug 5, 11:00 - 17:15 PDT
Where: Other / See Description

Description:

The Unofficial DEF CON Shoot is a public event that happens just prior to the DEF CON hacker conference in Las Vegas, Nevada. It is an opportunity to see and shoot some of the guns belonging to your friends while taking pride in showing and firing your own steel, as well, in a relaxed and welcoming atmosphere. We choose a spot, then we rent tables, canopies, and bring all the necessary safety equipment and amenities. All you need to bring yourself and (optionally) your firearms. New shooters and veterans both attend regularly. You can attend with your firearms, of course, but folk without guns of their own in Vegas may have the opportunity to try gear from others in attendance.

Pro Gun Vegas - 12801 Old US 95 Boulder City, NV 89005


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Saturday - 12:30-12:55 PDT


Title: The Voice Behind the Payload: Tracing AAVE Across Malware Artifacts
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 12:55 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:
Discover an often-overlooked signal in threat actor attribution: everyday language. This compelling session explores how African American Vernacular English (AAVE), with its distinctive grammatical features and lexicon, can leave unique fingerprints in malware artifacts like ransom notes and phishing lures. While emphasizing that AAVE use doesn't imply threat actor ethnicity, this talk will dive into a YARA-based detection methodology to investigate its frequency across malware samples. Attendees will learn about the study's innovative approach, review preliminary findings on which malware families show the strongest signals, and engage in crucial discussions around the ethical implications of sociolinguistic analysis in cybersecurity. Don't miss this fascinating look at how linguistics can enhance our understanding of threat actor intent and capabilities.
SpeakerBio:  Brett Alexander Tolbert, Principal Cyber Threat Intelligence Analyst / Undergraduate Adjunct Professor at Bowie State University

Brett Tolbert is a Principal Cyber Threat Intelligence Analyst and an undergraduate adjunct professor at Bowie State University. With over 11 years of experience in cybersecurity, they have held threat intelligence and cyber defense roles in the U.S. intelligence community and in companies supporting U.S. critical infrastructure, focusing on tracking Asia-nexus state-sponsored threat actors, threat intelligence engineering, cross-sector partnerships, and technical leadership. They have previously spoken at SANS CTI Summit, MITRE ATT&CKcon, and the BIC Village at DEFCON. Brett lives in the DC-Baltimore corridor and enjoys playing monster hunter games, knitting, and baking in their spare time.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 17:30-17:59 PDT


Title: There Is No Internet: Cross-Domain Recon of all 4.3 Billion IPv4s
Tags: Recon Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

We scanned every IPv4 address on the planet. Twice. We collected public records in one of at least three places: the RIR registration, the operator's reverse DNS, or whatever service answers on port. Most threat intelligence pipelines read one of those. Darkmouse lines up all of them and flags the disagreements. The result is attack-surface visibility that no single source gives you, and a methodology you can run yourself.

This talk walks the recon pipeline behind three findings from a single cross-domain pass over 4.3 billion IPv4 addresses in five days, plus a 92 million IP targeted scan in 34 hours (Russia, Iran, and North Korea). We used ZMap on single-use Jetstream2 VMs, zdns for PTR and forward verification, bulk RPSL and ARIN XML and APNIC data loaded into DuckDB alongside MaxMind GeoLite2, OpenSanctions, and the US Trade Consolidated Screening List. Enrichment is baked into the scan row at ingest. Every field carries a source-date stamp so longitudinal comparison actually works.

Lead finding for a recon audience: 6,656 Iranian IPs in RIPE where the registrant placed fabricated US street addresses into the authoritative registry. 4,608 of them cite AT&T Mobility's ARIN IP-management address verbatim. 2,048 cite a Philadelphia apartment building. All geolocate to Iran. All trace to one operator through a shared RIPE maintainer object linking a Shiraz Local Internet Registry and an Omani shell.

Between September 2025 and January 2026 the fabricated addresses began rotating out, replaced by netnames like "Datacamp-Limited" that impersonate real UK hosting companies. A single-point-in-time feed cannot see that rotation. Two dated snapshots can. We are currently running follow up scans and expect to have new data before the conference.

Additional Findings: five active PTR records in Russia and the Netherlands claiming US government domains, including .fbi.gov subdomains, four of five still live six months after first observation (April 2026). And 1,534 APNIC-registered IPs for Entity Listed Chinese telecoms, declared country=US, geolocating to One Wilshire in Los Angeles, running production email and DNS on FCC-revoked Section 214 infrastructure.

Every finding ships with the RDAP query, the DNS check, and the cross-reference that verifies it. Every finding ships with the RDAP query, the DNS check, and the cross-reference that verifies it. Attendees leave knowing which four sources to line up, which fields to trust, and what to look for when two dated snapshots disagree.

SpeakerBio:  John McCary, Former DARPA, State Department, now Professor and Builder

John McCary founded Port 194 LLC, where he builds internet-scale measurement and correlation tooling from public data. Former soldier, diplomat, Wall Street Journal journalist, licensed private investigator, and certified ethical hacker. At 29 he helped design and launch a peer-to-peer data sharing platform that became a DARPA program of record and is still in use today. He designed and teaches the Open Source Intelligence course at the University of Arizona as adjunct faculty. Off the clock he is usually underwater, in a Muay Thai gym, or playing live music, though rarely at the same time.


Return to Index    -    Add to Google    -    ics Calendar file

Packet Hacking Village - Saturday - 15:00-15:59 PDT


Title: There's A Bug in My Boot! Finding Vulnerabilities in U-Boot
Tags: Packet Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Bootloaders underpin the security of modern embedded systems. Their privileged position in the tech stack often means a vulnerability early in the boot process can result in total system compromise. Despite this, they frequently lack modern software security protections (ASLR, CFI, Stack Canaries), making them an easier target to exploit. This talk will explore hardware-in-the-loop, emulation, and native binary fuzzing approaches with U-Boot, a popular embedded system bootloader for networking devices, and the challenges each approach presents.

SpeakerBio:  Jared Stroud, Lead Reverse Engineer, The Johns Hopkins University Applied Physics Lab

Jared Stroud is a Lead Reverse Engineer at The Johns Hopkins University Applied Physics Lab. Currently he's pursuing a Doctorate of Engineering focused on scaling vulnerability identification and remediation in embedded systems. For the past 7 years Jared has documented independent security research at Arch Cloud Labs (https://www.archcloudlabs.com/projects), and has presented workshops on reverse engineering topics at DEF CON, Shmoocon, and BSides Rochester.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 11:30-12:30 PDT


Title: Thin Client? Thin Crypto - Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Thin clients are deployed across healthcare, finance, government and critical infrastructure, environments where full disk encryption is a compliance requirement, not optional. Dell, IGEL and HP all ship FDE backed by TPM hardware and modern cryptography. I broke all three.

I present new research demonstrating vulnerabilities that permit full disk encryption bypass across Dell ThinOS 9.x - 10.x, HP ThinPro 8.x - 9.x, and IGEL OS 11.x - 12.x. Every attack achieving filesystem access from a powered-off device with no credentials and no specialist hardware. Behind the encryption: WiFi credentials, 802.1x NAC client certificates, VDI session configs, management server credentials, and password hashes. Compromised devices provide a foothold into the infrastructure it was connected to. I trace Dell's implementation across three generations getting progressively further from best practice, show IGEL's correct PCR policy and modern cryptography bypassed through their own signed bootloader, and demonstrate HP's implementation undone by an unmeasured boot chain.

SpeakerBio:  Darren McDonald, AmberWolf

Darren McDonald is an offensive security consultant at AmberWolf, where he specialises in hardware hacking and red teaming. He has spent 17 years breaking into things professionally, starting with networks and applications before moving to embedded systems, firmware, and the physical layer. The kind of hacker who pulls out screwdrivers instead of a checklist.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 13:30-13:55 PDT


Title: This is a Test: Vibe Hacking LTE Cell Broadcast for Emergency Alert Injection
Tags: Radio Frequency Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Every month, billions of mobile subscribers worldwide receive Presidential Alerts, AMBER alerts, earthquake warnings, and severe weather notifications directly to their phones through the 3GPP Public Warning System (PWS). This encompasses CMAS, ETWS, and EU-Alert. These messages bypass all user settings, cannot be blocked, and are trusted implicitly by the public. But what if the tower screaming at your phone isn't a tower at all?

This talk exposes the fragile trust model underlying emergency alerting on modern LTE networks globally. We dissect how PWS messages are transported at the physical and protocol layers, from SIB10/11/12 broadcast blocks down to the exact ASN.1 encoding, and demonstrate how an attacker with modest RF resources can inject, spoof, and manipulate these alerts at scale using software-defined radio.

We'll begin with a technical primer on PWS architecture in LTE, explaining how Cell Broadcast Service (CBS) messages propagate from alert aggregators through carrier core networks to individual eNodeBs, and ultimately to handsets worldwide via the BCCH. Then we shift to the offensive perspective: using a USRP B210 and open-source LTE stacks, we show how to craft malicious SIB messages, impersonate legitimate carrier cells, and force target devices to display arbitrary alert text, including spoofed presidential alerts and hyper-localized fake emergency notifications.

The presentation includes live demonstrations, open-source release of our PWS injection toolkit, and a discussion of responsible disclosure findings shared with carriers and regulators across multiple countries. No prior LTE expertise is required, but familiarity with SDR concepts and cellular architecture will help attendees maximize their takeaways. Attendees will leave understanding exactly why global wireless emergency alerting lacks cryptographic authentication, how trivial the barrier to entry is for alert spoofing.

SpeakerBio:  XtraRaj, Mechanic, Car Hacking Village

Ayyappan is a cybersecurity enthusiast interested in hacking and securing everything from wireless, automotive, IoT security, and critical infrastructure. He has published several high-impact CVEs relating to the automotive and IoT sectors and loves to tinker with every electronic device he can get his hands on. Notably, he once successfully turned a doorbell into a botnet that rickrolls visitors.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 12:00-12:45 PDT


Title: This Wasn't AI Generated: Principles for Breaking Generative Watermarks
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

The SynthID watermark was developed by Google to invisibly tag content generated by its models and agents (Nano Banana, Gemini, etc.). When asked to identify whether an image is AI-generated, Gemini will invoke a "Verify AI" tool to scan for the SynthID. We demonstrate two attack strategies to remove it. (1) The lesser-known regeneration attack of Zhao et al. 2023 removes SynthID identification by Gemini with 100% success rate on a held-out set of 104 photorealistic Nano-Banana images. (2) We build a surrogate detector using Apple's Pico-Banana-400K dataset. This dataset pairs Flickr images with a Nano-Banana edit, which automatically adds SynthID, thereby implicitly providing us with a large corpus of watermarked/clean image pairs which we use to fine-tune a pre-trained ResNet-18 into a SynthID discriminator. This surrogate detector can be used to test the presence of the watermark in an image in ~27.5 ms on a CPU, thereby allowing an adversary to rapidly test and optimize an attack. We demonstrate that the removal of the SynthID can induce hallucinations, whereby Gemini confidently makes assertions regarding its own simulated as if it were real. This, we propose, could have a variety of security implications, such as confused deputy attacks against agents, retrieval pipeline poisoning, and facial recognition bypasses. The full code, the test set, the pre-computed attack outputs, and the prompts used to generate every test image are released as a hands-on kit at https://github.com/rabbanitw/WAVES/tree/synthid-regen-kit

Speakers:Thomas Mason,Tahseen Rabbani

SpeakerBio:  Thomas Mason

Thomas Mason has spent the past decade working as a security engineer and offensive pentester. With an original background in machine learning and applied math, he spent several years as a data scientist and OSINT researcher before becoming a pentester in industry. His seven-plus years of pentesting experience gave him a background in a diverse array of offensive security roles, including physical security and social engineering, web, application and network testing, hardware and IoT security, and red teaming. Currently, he works for Coalfire, specializing in cloud and web security with an emphasis on AI products. Outside of his day-to-day work, his research centers on mapping and testing the emerging attack surfaces of large language models, and how their adoption changes the threat landscape. In addition, he works on independent projects combining his background in mathematics and social sciences with his security experience. His hobbies include reading, sports, and graphic novel writing.

SpeakerBio:  Tahseen Rabbani

Tahseen is a machine learning Postdoctoral Scholar at the University of Chicago, co-hosted by Ce Zhang and Tian Li, and a Forward Deployed Engineer at Appen. His research focuses on watermarking system efficiency, distributed learning, and privacy. His secondary research interests include numerical optimization and machine translation. His work has appeared at venues such as NeurIPS, ICML, ICLR, and ACL. He received his Ph.D. in Computer Science in 2024 from the University of Maryland, advised by Furong Huang. Prior to the University of Chicago, he worked as a Postdoctoral Associate at Yale, where he worked on low-resource clinical models and fast drug discovery. He obtained his BA in mathematics from the University of Virginia, where he specialized in combinatorial group theory and error-correction, which he continues to work on for fun.

His core research contributions include (1) WAVES, a popular benchmark for stress-testing deep learning-based watermarks under a large suite of attacks; (2) SWIFT, a strategy for asynchronous transmission of model weights over decentralized communication graphs, enabling data-secure collaborative machine learning; (3) Sketch-GNN, a sketch-based compression framework for training graph neural networks with sublinear computational complexity; and (4) PGHash, a novel family of pseudo-random hash functions for private pruning of large classification layer neurons, allowing extreme compression of large recommender systems.

His work on the WAVES benchmark was spun into the 2024 NeurIPS competition, “Erasing the Invisible,” which drew 2700+ submissions from nearly 250+ global teams, assessing their ability to remove watermarks in black-box and grey-box systems. This competition resulted in many novel attack vectors for effectively destroying nearly every state-of-the-art open-source watermark. He is also a regular reviewer for IEEE Transactions in Multimedia, where he lends his expertise on new watermark designs.


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Saturday - 10:00-17:59 PDT


Title: Thread Carefully
Tags: Embedded Systems Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

Presentation about open thread networks, what a thread devices can see from your home network, what can it access. And how this mighty be miss-used. Some theoretical attack scenarios. Like how to turn a thread only lightbulb with ota update into a residential proxy node.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Saturday - 11:00-11:59 PDT


Title: Threat Hunting 101: Beyond the Alerts
Tags: Blue Team Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

Detection and response are essential pillars of cybersecurity, but what if something slips through the cracks? Not every attack triggers an alert. That’s where Threat Hunting comes in.

Threat hunting is a proactive, human-driven approach to uncovering signs of compromise that automated systems may have missed or misunderstood. It involves asking deeper questions, forming hypotheses, and exploring system behavior to find evidence of stealthy or novel attacks.

Join us for an introductory presentation on Threat Hunting, where you'll learn how cybersecurity professionals go beyond known threats to uncover hidden adversaries and why human intuition is still a critical part of modern defense.

SpeakerBio:  Kainu ~

With over 18 years of experience in IT and cybersecurity, Kainu currently specializes in Digital Forensics, Incident Response (DFIR), and Threat Hunting, with over 6 years dedicated to actively defending against threats, leading response efforts, and conducting deep forensic investigations. He has worked across diverse industries including healthcare, pharmaceutical, manufacturing, legal, and financial sectors, helping organizations detect, contain, and recover from complex security incidents. By day, he serves as a senior Incident Response case manager and consultant, conducting investigations, leading threat hunts, or mentoring clients on how to build and run effective incident response teams. He brings a hands-on, analytical approach to defending infrastructure and uncovering adversary tradecraft. Outside of work, Kainu is a passionate locksport practitioner and a proud #GirlDad, driven by curiosity, resilience, and a commitment to protecting what matters most.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Saturday - 15:45-16:45 PDT


Title: Threat Hunting Explained Badly
Tags: Blue Team Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:45 - 16:45 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

Modern threat hunting is messy. AI lies. Telemetry sucks. Your vibe-coded query returns 12 million rows. Come hear hunters argue about what actually works, what doesn't, and whether any of us agree on what "threat hunting" even means.

Speakers:Alllison Gallo,Brian Baskin,Silas Cutler,Sydney "letswastetime" Marrone

SpeakerBio:  Alllison Gallo

Allison Gallo is a staff incident responder on Splunk's Advanced Response Team, where she leads investigations end to end. She entered cybersecurity over a decade ago as a sysadmin at an MSSP, where every day brought a different client and environment, and has since worked as an analyst, consultant, and team lead across agriscience and software.

Incident response is her home, but she's spent time working the other side of the same problem: hunting threats at large-scale events including the Super Bowl, GovWare Singapore, and RSAC. She's convinced the reactive and proactive halves of defense sharpen each other and every incident teaches you what to hunt for next. When not working, she's likely to be on a beach or mountain with her family.

SpeakerBio:  Brian Baskin

Brian Baskin is a Threat Researcher for Sublime Security with a specialty in incident response, threat hunting, and malware analysis. Baskin was previously an intrusions analyst for the US Defense Cyber Crime Center (DC3) and a threat research lead at Carbon Black's Threat Analysis Unit (TAU). He has authored multiple security books and develops open source tools for more efficient IR and malware analysis.

SpeakerBio:  Silas Cutler

Silas Cutler is a Principal Security Researcher at Censys, where he brings over a decade of experience tracking organized cyber threat groups and developing advanced methods for pursuing them. His research connects technical findings to the broader operations behind them, from attacker motivations to active campaigns, covering threats such as the BeaverTail malware tied to North Korea's covert IT-worker operations, the pro-Russian DDoSia (NoName057(16)) platform, and Secret Blizzard APT activity.

Before Censys, Silas held roles focused on malware analysis, reverse engineering and adversary tracking, including Resident Hacker at Stairwell, Reverse Engineering Lead at Google Chronicle, and Senior Security Researcher on CrowdStrike's Intelligence team. Across these roles, he has specialized in analyzing tools built by nation-state and organized cybercrime groups and developing the methods needed to track them at scale. He is also an active contributor to the wider security research community, sharing his work through conference talks and open-source tooling.

Silas is also the founder and lead developer of MalShare, a public malware repository that has provided the global security research community with free, open access to malware samples since 2013.

SpeakerBio:  Sydney "letswastetime" Marrone

Sydney Marrone is a threat hunter, SANS course author, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework (ATHF), and co-author of the PEAK Threat Hunting Framework. She is passionate about helping defenders become better threat hunters by turning complex ideas into practical, repeatable techniques. Through open-source research, workshops, and community-driven projects, Sydney builds frameworks and resources that make hunting more structured, collaborative, and effective. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-inspired music with AI.

--

Sydney Marrone is a threat hunter, cybersecurity professional, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework, and co-author of the PEAK Threat Hunting Framework. She is passionate about making security knowledge accessible and actionable through hands-on research, open-source collaboration, and community-driven projects like HEARTH (Hunting Exchange And Research Threat Hub). Sydney creates resources, leads workshops, and shares insights that spark curiosity and empower defenders. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-themed music using AI to blend creativity and hacker culture.


Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Saturday - 13:15-14:15 PDT


Title: Threat Intelligence in Real Life
Tags: Blue Team Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:15 - 14:15 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:

Correlation, causation, and the occasional compromise that cost us a weekend. This panel trades the talk slides for an open discussion of the realities of threat intelligence practice: the dead ends, the misread infrastructure, the cluster that fell apart under scrutiny, and the overlapping TTPs that finally tied things together. Our panel of practitioners engages the audience with real cases, separating nation-state from cybercrime by intent and tradecraft, tracking infrastructure, and catching the logical fallacies that quietly steer analysis wrong. We'll talk about how the work really gets done, where confident analysis quietly goes sideways, and the industry challenges on the horizon.

Speakers:Ashley Sequeira,Julian Zottl,Leigh Gilbert,Madeline Sedgwick

SpeakerBio:  Ashley Sequeira

Ashley is a cybersecurity researcher, threat intelligence practitioner, and Senior Sales Engineer at Censys, where she conducts strategic research on IoT botnets and adversarial infrastructure. Her research sits at the intersection of hardware-based attack infrastructure and influence operations, tracking how low-cost consumer electronics are weaponized as residential proxy networks, ad fraud engines, and persistent footholds inside homes and enterprise networks.

SpeakerBio:  Julian Zottl

Julian Zottl is the Chief Technology Officer for AzgardTek, an engineering company focused on Cyber and Intelligence. He’s the former CTO of Cyber Protection Solutions within Raytheon Intelligence & Space, a Raytheon Technologies business. He is also Cyber and Information Operations (IO) Subject Matter Expert (SME) and considered a world expert in large scale Computer Network Defense (CND).

SpeakerBio:  Leigh Gilbert, Malware village

Leigh Trinity is a Canadian exploit developer, red team hacker, and instructor known for her work in binary exploitation and reverse engineering. Now branching out into malware development.

SpeakerBio:  Madeline Sedgwick

Madeline Sedgwick is a Principal Threat Researcher at Palo Alto Networks Unit 42's National Security Team, focusing on South Asian threat actors and covert networks. In her 13 years of professional experience, Madeline has worked on all sides of the cyber front: military, government, and private sector. Her mission, inspired by years of ruined holiday weekends at the Department of Defense, is to make the other guys work the weekend.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 12:30-12:59 PDT


Title: Threat Modeling LLMs with PHANTOM-B
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Threat modeling systems that call LLMs requires specialized approaches. Existing frameworks are heavyweight (wordy, jargon-laden) and often focus on threats that can only be addressed by those who train the models, offering little help to security practitioners tasked with threat modeling their company’s latest AI feature or product. This talk will introduce PHANTOM-B a new, STRIDE-like mnemonic for threat modeling LLMs. PHANTOM-B is focused on the common case of “an LLM trained by others,” rather than those training the LLM themselves.

SpeakerBio:  Adam Shostack

Adam is leading expert on threat modeling and secure by design. He currently helps many organizations improve their security by with training and coaching at Shostack + Associates. He's the author of Threats: What Every Engineer Should Learn from Star Wars, Threat Modeling: Designing for Security and The New School of Information Security (with Andrew Stewart). He's a member of the BlackHat Review Board, and helped create the CVE and many other things, and is an Affiliate Professor at the University of Washington.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Saturday - 11:00-11:45 PDT


Title: Threats in Space: The Dangerous Rise of GNSS Attacks
Tags: Telecom Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
  1. GNSS constellations
  2. How do we use GNSS daily?
  3. GNSS threats and their rise
  4. Hacktivism and GNSS?
  5. GNSS exposed instances over the internet
  6. Can we defend against GNSS attacks
SpeakerBio:  Isabel Manjarrez, Threat Researcher

[EN] María Isabel Manjarrez is a security researcher with Kaspersky's Global Research and Analysis Team (GReAT). She specializes in investigating threat actors in Latin America, tracking their movements, and analyzing the new techniques they deploy. She holds a degree in telecommunications and electronic systems engineering and her interests include threat intelligence, malware analysis, satellite communications, electronics, and music.

She has shared her knowledge as a speaker at local and international conferences such as Defcon, Security Analyst Summit (SAS), and EkoParty.


[ES] María Isabel Manjarrez es investigadora de seguridad en el Equipo Global de Investigación y Análisis (GReAT) de Kaspersky. Se especializa en la investigación de actores amenaza en Latinoamérica, rastrea sus movimientos y analiza las nuevas técnicas que implementan. Es Ingeniera en telecomunicaciones y sistemas electrónicos, sus intereses incluyen la inteligencia de amenazas, análisis de malware, comunicaciones satelitales, electrónica y música.

Ha compartido su conocimiento como ponente en conferencias locales e internacionales como Defcon, Security Analyst Summit (SAS) y EkoParty.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 15:00-15:59 PDT


Title: Throw Out the Alphabet: Token-Based Markov Chains for Password Cracking
Tags: DEF CON Official Talk | Tool 🛠
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:
Classical Markov password generators work over the character alphabet: hashcat's Markov masks, JtR's --markov, OMEN, even neural models like PassGPT.

We change one thing: the alphabet. Train an n-gram Markov on RockYou, but segment with GPT-2's 50k BPE tokenizer instead of characters. The distribution stays RockYou-derived; only the units change. The vocabulary captures structure characters can't: name fragments, digit patterns, symbol clusters from web-scale text.

Across 14 leak corpora (RockYou, LinkedIn, Yahoo, +11 more), token-Markov beats OMEN at fixed budgets on all 14, at 10^8 and 10^9, with best66 rules on both sides. On enterprise passwords (8+ chars, 3 of 4 classes), we recover ~6x more than OMEN: 6.3% vs 1.1% at 10^8, 12.3% vs 2.3% at 10^9; the lead holds ~2.8x with rules applied. tokenov hits 10^9 candidates in minutes on CPU; OMEN takes hours; PassGPT needs days.

Why: the tokenizer bakes in mixed-case, digit, and symbol primitives, so multi-class compliance is modal, not rare. "Michael99" is two tokens, not eight transitions.

We release tokenov: train an n-gram model with any tokenizer, or use include custom GTP-2 tokenizer. Pipe into hashcat, JtR, or write to disk. Use OSINT derived lists to seed generation customized to the target. No GPU needed: 1B candidates in under 2 minutes on an i9.

SpeakerBio:  Jon "flakpaket" Gorenflo, ATTACKD

Jon Gorenflo is the founder of ATTACKD, a cybersecurity consulting firm dedicated to helping organizations of all sizes think like attackers and proactively secure their environments. Whether you're a startup, a small business, or a global enterprise, Jon brings real-world offensive security insights that are practical, accessible, and actionable. He is also a Principal Instructor with the SANS Institute and the co-author of SEC560: Enterprise Penetration Testing, a leading course on advanced ethical hacking and red team operations. With more than 20 years of combined experience in IT, penetration testing, incident response, and security training, Jon has worked with a diverse range of organizations to uncover critical vulnerabilities and build resilient defenses. In addition, Jon serves as the executive director of Hackers Teaching Hackers (HTH), a grassroots cybersecurity conference that emphasizes hands-on learning and community connection. Jon is known for his clear communication, relatable style, and dedication to helping defenders build practical skills. He breaks down hacker tactics into understandable steps and helps teams of all sizes, from a solo IT admin to an enterprise SOC, apply those lessons to real-world defenses.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Tin Foil Hat Contest
Tags: Tin Foil Hat Contest | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest) - Map

Description:

Want to protect your noggin from government mind control rays? Have you angered our new AI Overlords, and now need to hide? Maybe those alien brainwave blasters just have you feeling down lately? Or do you just want to do something fun and forget about the world's woes for a while? Fear not, for we here at the Tin Foil Hat Contest have your back for all of these! Come find us in the contest area, and we'll have you build a tin foil hat which is guaranteed to provide top quality protection for your cerebellum . How you ask? SCIENCE!

Show us your skills by building a tin foil hat to shield your subversive thoughts, then test it out for effectiveness.

There are 2 categories: stock and unlimited. The hat in each category that causes the most signal attenuation will receive the ""Substance"" award for that category. We all know that hacker culture is all about looking good though, so a single winner will be selected for ""Style"". We provide all contestants a meter of foil, but you're welcome to acquire and use as much as you want from other sources.

This year is dedicated to our brother & contest creator, Flirzan. We'll never forget drunkenly hashing this out on a napkin with you at DEFCON many years ago. Rest in peace, we miss you friend!

Participant Prerequisites

We supply the base materials to participate. Contestants are welcome to bring additional foil if they desire.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Saturday - 10:00-10:30 PDT


Title: To Catch a Pseudoscientist
Tags: Biohacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

This talk exposes the hidden fraud ecosystem inside modern scientific research, where paywalls, paper mills, predatory journals, and fake credentials create the illusion of legitimacy. Drawing from a hacker’s perspective, it examines how corruption is embedded in the system, how some actors knowingly participate while others are trapped by it, and how weak or fabricated work can be elevated as credible science. The session offers a practical playbook for identifying red flags, avoiding fraudulent channels, and protecting yourself from the pipeline where fake journals produce fake science.

SpeakerBio:  James Utley PhD

Dr. James Utley, PhD is a board-certified anti-aging scientist and immunohematology expert advancing AI, regenerative medicine, and cellular reprogramming. As CSO at Auragens, he develops stem cell therapeutics, translating molecular science into clinical strategies to extend healthspan.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 11:00-11:45 PDT


Title: TokenMesh: Exposing Azure's Hidden Identity Attack Surface
Tags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | DEF CON Demo Labs
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:

Modern cloud environments are riddled with identity misconfigurations that go undetected until it's too late. TokenMesh is an open-source Azure security reconnaissance tool built to expose exactly that — over-privileged identities, dormant service principals, misconfigured storage accounts, and potential backdoors hiding in plain sight across Microsoft Entra ID and Azure RBAC. Unlike traditional scanners that drown you in raw data, TokenMesh is designed with the security practitioner in mind. It integrates directly with the Model Context Protocol (MCP) and the OpenAI API, allowing AI-assisted analysis that surfaces critical findings in plain language — no SIEM required, no query language to master. Plug it into your AI workflow of choice, ask questions in natural language, and get answers that actually make sense. In this session, we'll walk through how TokenMesh was built, the real-world attack paths it uncovers, and live demonstrations against a target Azure environment. We'll cover how attackers abuse identity misconfigurations, how privilege escalation paths hide inside legitimate role assignments, and how defenders can use TokenMesh to harden their posture before adversaries exploit it. Whether you're a red teamer mapping an Azure tenant or a blue teamer trying to get ahead of the next breach.

SpeakerBio:  Saksham Agrawal

Saksham Agrawal is a Senior Security Consultant at NotSoSecure, specializing in cloud security. His work focuses on discovering new attack paths in cloud environments and helping organizations understand real-world risks. He has presented his research at DEF CON Cloud Village, where he introduced his tool NoPrompt and shared practical techniques for cloud security testing. He enjoys building tools, exploring cloud internals, and sharing his findings with the security community. He has also responsibly reported critical vulnerabilities in major cloud vendors as part of his independent security research and actively delivers training sessions on cloud security and offensive security techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 17:30-17:59 PDT


Title: Total Recon: How We Discovered 1000s of open Agents in The Wild
Tags: Recon Village | Creator Talk/Panel
When: Saturday, Aug 8, 17:30 - 17:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:
AI agents quietly created a new external attack surface: copilots, custom agents, AI cakends and various deployments that ship to the internet, often without anyone realizing they are reachable, enumerable, or over-permissive.

In this talk, we’ll show how attackers can already find your agents in the wild, shedding light on the technical details that enable this kind of malicious activity, including how we used these details to find 1000s of exposed agents of different kinds. We’ll follow up with explaining how to measure exposure, see the proof for obscurity failing, and understand how to detect threat-actor agent-focused recon before it turns into an impactful attack. Capping it all off by showcasing PowerPwn, a recon tool you can use to test your own exposure

Speakers:Avishai Efrat,Roey Ben Chaim

SpeakerBio:  Avishai Efrat, Senior Security Researcher at Zenity

Avishai Efrat is a senior security researcher at Zenity, specializing in securing AI agents and low-code/no-code platforms. His work focuses on uncovering vulnerabilities in enterprise AI deployments, from Copilot Studio to ChatGPT and beyond - and exploring how attackers discover and exploit these weaknesses. Passionate about all aspects of security, with experience spanning web security, anti-bot protection, OSINT, blockchain, and data engineering and aim on bridging the gap between cutting-edge research and practical defense strategies. Previously presented at BSidesTLV, Black Hat USA & Europe Arsenal and SecTor.

SpeakerBio:  Roey Ben Chaim, Staff Engineer at Zenity

Roey Ben Chaim is an engineer focused on AI and agent security, with a particular interest in how agentic systems fail in practice. His work centers on stress-testing agents, building benchmarks for long-horizon behavior, and developing practical defenses against risks such as prompt injection, unsafe tool use, privacy leakage, and adversarial workflows. Prior to this, he spent a decade at Microsoft building large-scale security systems. He is a co-author of SkillsBench, a benchmark on agent skills efficacy over diverse tasks, and contributes to safety and privacy tooling, including Presidio. Roey is also a speaker on agentic systems and AI security, a co-organizer of AI Tinkerers Tel Aviv, and an active participant in hackathons and builder communities, where he explores emerging systems through hands-on experimentation.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Saturday - 10:00-10:59 PDT


Title: Trace Labs L150: Case Walkthrough
Tags: OSINT For Good Community | Creator Workshop
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

Join us for an immersive online seminar with the Reporting Team Department Head at Trace Labs, as he walks through real missing person investigations from the Trace Labs CTFs. This session moves beyond foundational OSINT concepts and focuses on how investigations unfold in practice, from a single starting point to the development of actionable, ethically collected intelligence. Participants will follow detailed case walkthroughs drawn from Trace Labs Search Party CTF events, highlighting how analysts:

Pivot from initial clues across platforms and ecosystems Identify meaningful signals of activity Provide actionable intelligence

Normally offered as a paid webinar, this session earns a digital badge that is part of the Trace Labs webinar series.

SpeakerBio:  Brent Louie, Reporting Team Lead at Trace Labs

Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 11:00-11:59 PDT


Title: Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children and Vehicles
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:
We performed our research against three major GPS tracking platforms: SETracker (~10M devices, 39 brands), SinoTrack (6M+ devices), and TKSTAR/Thinkrace (20M+ devices). All three come from the same Shenzhen supply chain. All three are completely broken.

We achieved RCE on every platform, including NT AUTHORITY\SYSTEM on TKSTAR. From a free account with no device purchase, we can silently wiretap any child's watch, force video surveillance, steal vehicles through remote door unlock and fuel cutoff, and take over the backend servers. We filed 45 CVEs, 19 critical, 9 of them CVSS v3.1 10.0.

The worst part is the supply chain structure. 39 consumer brands in 20+ countries (Wonlex, SaveFamily, KidiWatch, Garett, etc.) all connect to the same myaqsh.com server in China. Parents think they are choosing between brands. They are not. Brand diversity in this market is an illusion.

We release full PoC chains, CVE details, and a brand-to-backend mapping that shows how this industry actually works.

Speakers:Felipe Solferini,Vangelis Stykas

SpeakerBio:  Felipe Solferini

Felipe is a senior penetration tester and self-proclaimed security researcher. Most of the time, he’s mashing the wrong buttons, hoping for the worst but expecting the best - or just YOLOing like there’s no tomorrow. Occasionally, he wonders if life is just a CTF. He has presented his research at BSides London, BSides Sofia, and Bsides Vilnius.

SpeakerBio:  Vangelis Stykas, Kumio

Vangelis began as a developer from Greece. Ten years ago he realized that only his dog didn’t have an API, so he decided to steer his focus towards security. That led him to pursue a PhD in Web Application Security with an extra focus on machine learning. He’s still actively pursuing it. He currently applies his skills as a Chief Technology Officer at Kumio, and during his free time, Vangelis is helping start-ups secure themselves on the internet and get a leg up in security terms. His love of a simplistic approach to hacking by exploiting vulnerable APIs led him to publish research regarding API controlling ships, smart locks, IP cameras, car alarms, EV chargers, and many other IoT devices. Since our lives are nowadays extremely cyber-dependent, his goal is to convince all companies to never neglect their API security as rush-to-market mentality is almost certain to lead to catastrophic security failure. He has presented his research at Black Hat USA, DEF CON, Disobey, BSides London, BSides Dublin, BSides Athens, 44Con and other security conferences, and has keynoted at BSides Prague. His most recent work on disrupting ransomware operations by hacking their web panels was featured at Black Hat USA and DEF CON 32.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 12:00-17:59 PDT


Title: TrackTheFugitive Contest
Tags: Recon Village | Creator Event/Activity
When: Saturday, Aug 8, 12:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

The manhunt is on. TrackTheFugitive drops you into real, active cases where the suspects are still out there—no simulations, no canned flags. Armed with nothing but open-source intelligence, you'll chase digital breadcrumbs, unmask aliases, and surface the leads that help bring real fugitives to justice. Contest continues from Friday and ends Saturday at 6:00 PM.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 13:00-13:45 PDT


Title: Trajan: Cross-Platform CI/CD Security Scanner
Tags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
When: Saturday, Aug 8, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map

Description:

For three years, Praetorian has consistently found that CI/CD pipelines are one of the fastest paths to compromise enterprise environments. A misconfigured workflow or an over-privileged service connection can provide you with credentials, cloud access, or code execution on internal infrastructure, often undetected.

We built to keep up: Gato for GitHub Actions (BH 2024), then Glato for GitLab CI (BH 2025). Both proved the approach: parse the pipeline configuration, classify triggers, gates, and danger zones, build a graph of how they connect, and surface what's actually exploitable.

The problem was that no client runs just one platform. A typical enterprise has GitHub Actions for open-source, Azure DevOps for internal deployments, and GitLab for containerized workloads. Assessing all of that meant juggling multiple tools with different output formats and coverage gaps.

Trajan folds everything we learned into a single tool spanning GitHub Actions, GitLab CI, and Azure DevOps. Each platform runs through the same phased pipeline: collect the pipeline config and the org surface, normalize it, correlate multi-step attack chains, scan against a YAML detection-rule corpus organized by attack category, and report through one unified findings format. Support for Jenkins, CircleCI, and Bitbucket is in active development.

Speakers:Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal

SpeakerBio:  Rahul Saranjame

Lead Security Engineer at Praetorian focused on penetration testing, red/purple teaming, CI/CD pipeline security, and risk advisory assessments. Rahul is OSCP and CRTO certified, holds a Master's degree in Cybersecurity from Georgia Tech, and is a core contributor to Trajan.

SpeakerBio:  Ranganatha Rao Sridhar

OSCE3 certified Lead Security Engineer at Praetorian with expertise spanning product, cloud, and corporate security. Rao holds a Master's degree in Cybersecurity from Georgia Tech and is a core contributor to Trajan.

SpeakerBio:  Tanishq Rupaal

Staff Offensive Security Engineer at Praetorian specializing in cloud security across AWS, GCP, and Azure. He designed the Guard Platform's cloud integration mechanism, is a core contributor to Trajan, and holds an M.S. in Cybersecurity from Georgia Tech.


Return to Index    -    Add to Google    -    ics Calendar file

Queercon Community - Saturday - 12:00-12:59 PDT


Title: Trans Meetup
Tags: Queercon Community | Creator Event/Activity
When: Saturday, Aug 8, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W325 (QueerCon Lounge) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 13:30-14:30 PDT


Title: Transformers: Dark Side of the Type - Weaponizing the Conversion Layer
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

In 2017, our DEF CON talk "Friday the 13th: JSON Attacks" forced the industry to confront Insecure Deserialization. Developers responded by hardening the configurations of parsers and serializers. But it created a dangerous blind spot. Developers and security reviewers now assume that simpler code patterns, those that do not involve parsers, are inherently safe. We demonstrate that they are not. This talk moves the focus away from the serialization format entirely and targets the transformation layer: the code that turns a simple string into a complex object. We expose "Insecure String Transformers": mechanisms that silently resolve types, trigger complex logic, and instantiate objects during what looks like a safe string conversion. This overlooked attack surface remains invisible to the tools and reviews focused on the parser-level bugs from 2017. We dissect specific CVEs where string-to-object conversion was the root cause of RCE. We release new gadget chains targeting popular .NET libraries and present a methodology for hunting dangerous conversion patterns across any codebase. The goal is to redefine how the industry classifies this vulnerability: it is not "Insecure Deserialization" - it is Insecure Transformation, and it may be hiding in your application even if it does not use any serialization library.

Alvaro Muñoz & Oleksandr Mirosh, "Friday the 13th: JSON Attacks" - Black Hat USA 2017 https://www.blackhat.com/docs/us-17/thursday/us-17-Munoz-Friday-The-13th-JSON-Attacks-wp.pdf Alvaro Muñoz & Oleksandr Mirosh, "Room for Escape: Scribbling Outside the Lines of Template Security" - Black Hat USA 2020 https://i.blackhat.com/USA-20/Wednesday/us-20-Munoz-Room-For-Escape-Scribbling-Outside-The-Lines-Of-Template-Security-wp.pdf

SpeakerBio:  Oleksandr Mirosh, OpenText Fortify

Oleksandr Mirosh is a Security Researcher on the Fortify Software Security Research team at OpenText, where he focuses on investigating emerging threats and developing detection and remediation rules for enterprise software. With over 18 years of experience in computer security, specializing in vulnerability research, reverse engineering, and penetration testing, his work centers on flaws in JNDI, authentication protocols, data serialization, and transformation logic across Java and .NET ecosystems. His research has led to the discovery of numerous CVEs in widely deployed enterprise applications and framework libraries. A frequent speaker at Black Hat USA and DEF CON, he has also presented at other security conferences like OWASP Global AppSec and BSidesLV.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Saturday - 12:30-12:59 PDT


Title: Triage vs. Reality: Mobile Security Findings in Bug Bounty
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Saturday, Aug 8, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

Mobile bug bounty has matured significantly, but the way mobile vulnerabilities are evaluated has not kept pace. Researchers frequently encounter findings that don’t fit neatly into traditional scoring frameworks, rely on application-specific threat models, or require multiple seemingly low-impact issues to demonstrate meaningful risk. The result is inconsistent triage, misunderstood impact, and unnecessary friction between researchers and programs.

This talk explores why mobile security findings are uniquely challenging to assess and where current bug bounty processes fall short. We’ll examine common pitfalls in mobile triage, discuss the limitations of applying generic scoring systems such as CVSS to mobile vulnerabilities, and look at real-world examples where technical severity and triage outcomes diverged.

SpeakerBio:  fr4vian
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 16:30-16:59 PDT


Title: Trust Amplification in Enterprise AI Systems – Microsoft CoPilot Case Studies Enabling AI-Assisted Influence Operations
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Enterprise AI assistants such as Microsoft Copilot are rapidly becoming embedded in business workflows, granting them unprecedented influence over how users discover information, make decisions, and interact with organizational data. While much of the current security discussion focuses on prompt injection itself, the larger risk may be what happens after that influence occurs.

This talk discusses the concept of Trust Amplification, a model in which attacker-controlled content gains credibility as it is transformed, contextualized, and redistributed by enterprise AI systems. Through real-world Microsoft Copilot case studies, we demonstrate how indirect prompt injection can influence document conversion workflows, persist through shared collaboration sessions, and transform traditional device code phishing into trusted AI-generated authentication guidance.

Rather than introducing entirely new attack classes, enterprise AI systems can act as force multipliers for existing social engineering techniques by presenting attacker influence through trusted enterprise platforms and workflows. We conclude by introducing Locusta, an open-source enterprise AI collaboration and propagation toolkit developed to help red teams and defenders model these emerging attack paths and better understand how influence can spread through AI-assisted environments.

SpeakerBio:  Tobias Diehl

Tobias Diehl is a Senior Offensive Security Engineer, security researcher, and Microsoft 2025 Most Valuable Researcher (MVR) specializing in offensive security, enterprise AI, bug bounty research, and adversary emulation. His work focuses on identifying overlooked attack paths where web applications, AI systems, and desktop software intersect, helping organizations understand how seemingly low-risk vulnerabilities can become high-impact security issues. Tobias leads offensive security assessments, conducts purple team exercises, and performs research into emerging attack techniques affecting enterprise environments. His work has resulted in multiple security findings impacting Microsoft technologies, including Power Platform, CoPilot and other AI-driven applications. A returning DEF CON speaker, Tobias is passionate about sharing practical research that helps both security researchers and defenders better understand modern attack chains. His presentations emphasize real-world case studies, responsible disclosure, and actionable defensive guidance for securing the next generation of AI-enabled enterprise systems.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 11:20-11:59 PDT


Title: Trust the Cloud Pipeline, Lose the Kingdom
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:20 - 11:59 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

In 2020, SolarWinds showed the industry what it looks like when an attacker owns a build pipeline. In 2021, Codecov did it again. CircleCI in 2023. Each incident surfaced the same pattern. Cloud CI/CD systems sit at the center of a trust graph most organizations have never actually mapped, and compromising them grants access to everything downstream: source code, cloud infrastructure, production artifacts, customer data, and every third party platform the organization stores credentials for. Detection remains largely absent.

Five years after SolarWinds, red teams still rarely operate meaningfully against cloud native CI/CD. Most offensive security programs treat pipelines as infrastructure they inherit rather than terrain they fight over. Defenders build detection around endpoints and identities they recognize, while ephemeral build agents with elevated cloud credentials run continuously and unmonitored.

This talk presents a full cloud native CI/CD attack chain drawn from red team engagements across multiple enterprise cloud environments. The chain starts at a low privilege developer identity. Pull request poisoning, in both direct and indirect variants, exfiltrates temporary AWS credentials from the build agent. A scheduled Lambda function then relays fresh credentials before each expiry, providing durable serverless persistence with no endpoints, no implants, and no signals a traditional detection stack watches for. IAM role trust chain abuse escalates the compromised build identity into broad cloud access spanning multiple accounts. Finally, Secrets Manager extends the attack beyond AWS. The credentials stored inside grant organization admin access to the code hosting platform, administrative control of the CI platform itself, access to customer data warehouses, and access to every SaaS and third party system the organization depends on.

Attendees will walk away with a concrete mental model of how cloud native CI/CD fails under adversarial pressure, a specific set of detection rules that would have caught each stage (deployable against CloudTrail and CI logs most organizations already collect), and structural guidance for where trust boundaries need to exist between build infrastructure and production.

Intermediate audience. Familiarity with AWS IAM and general CI/CD concepts is helpful; the relevant cloud mechanics will be explained as needed.

SpeakerBio:  Shane Young

Shane Young is an offensive security operator and program builder with over 15 years in the field. His career spans consulting across financial services, hardware, and SaaS; building out an IoT security practice at a major security consultancy; leading red team operations against cloud native product companies; and pioneering AI/ML red teaming for deployed enterprise AI features. He is the creator of Brutespray, a public open source offensive security tool. He builds offensive security programs from scratch, runs red team operations end to end, and still carries significant technical IC workload because he thinks that is how security leaders stay sharp. He has been hacking since he was a teenager, and it still has not gotten old.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 14:00-14:59 PDT


Title: Turning Keys and Opening Doors: Leveraging AI Hype to Hack Everything
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Abstract I've been Red Teaming for over five years now, and in that time I've led or been involved in more than a dozen Red Team engagements where my team has successfully (or semi-successfully) reached objective. I'm not an elite hacker. I've learned some cool tactics and techniques through public research and have pieced them together with my team to covertly pivot through networks and access sensitive data. I've decided that, while I'm not an elite hacker, I am really good at turning keys and opening doors.

In this talk I'd like to discuss how I led my company's first AI Red Team operation, not just by jailbreaking and prompt injecting LLMs; But by backdooring legitimate AI models, socially engineering data scientists, attacking ML pipelines, and abusing new AI technology to exfiltrate sensitive training data and proprietary models.

Outline Discussion of AI operation planning and offensive research - starting with zero AI knowledge

Identification of novel GCP attack + pairing it with convincing social engineering pretexts

How we sent 3000+ phish in under 10 minutes, tech stack and relevant automation

Demo of the novel GCP attack which leads to account takeover

Discussion of how the entire attack happens in the ATTACKER's GCP environment, leaving defenders blind

Automated post-exploitation for persistence and dealing with short lived keys from the GCP attack

Pivoting to AI related loot

Collaboration with Google to mitigate the risk for ALL GCP customers

Additional offensive GCP AI attacks like attacking model training pipelines with malicious containers and backdooring legitimate public models

In this talk I plan to publicly disclose a novel GCP attack path that enabled my team to take over GCP accounts and projects. This is an open vulnerability in Google's Vulnerability Reporting Programm sitting at P1.

SpeakerBio:  Will Alexander

Senior Manager - Red Team @ Palo Alto Networks 2 years of Purple Teaming 5+ years of Red Teaming <1 year of Management


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 10:00-10:45 PDT


Title: Turning Recon Coverage into Bug Bounty Signal
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:45 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Bug bounty programs increasingly face a paradox. While organisations have more tooling than ever to enumerate their internet-facing services, yet both hackers and program owners still miss real, reportable vulnerabilities, especially in volatile, sprawling environments. As the time to discover and exploit vulnerabilities collapses, effective asset discovery has become more urgent. This talk shares outcomes from the CrowdRecon initiative: a recon-first approach designed to demonstrate the true value of hacker reconnaissance, over and above what scanners and attack surface management solutions typically deliver. We’ll show how recon, when treated as a disciplined, repeatable workflow (not “spray-and-pray” enumeration), produces measurable advantages across the vulnerability lifecycle: - Pre-vulnerability discovery: uncovering unknown, shifting, or mis-modeled assets (and the fragile trust assumptions around them). - At-vulnerability discovery: increasing the odds of finding real exploitable paths by mapping relationships, auth boundaries, and “hidden surfaces” that scanners miss. - Post-vulnerability context: accelerating impact validation and exploitability assessment with recon artifacts that explain why this system matters and how it is reachable. Outputs: - Examples of coverage gained (new endpoints, subdomains, environments, and trust paths) that were not represented in conventional inventories. - Patterns of high-signal recon artifacts that correlate with meaningful bounty submissions. - Common failure modes of scanner-only and AI-only approaches, and how recon closes the gap. The goal is to give bug bounty practitioners, hackers, program managers, and triage teams, an actionable mental model and set of techniques for building a “flywheel” that improves discovery without compromising ethics. An open Q&A session at the end aims to drive discussion on opening recon information to all hunters. Democratised recon.

SpeakerBio:  Radu Stefan Voloaga, Senior Product Manager, Intigriti

Radu Voloaga is a Senior Product Manager at Intigriti, working at the intersection of customers, security researchers, and crowdsourced security programs. He collaborates closely with organizations and the hacker community to understand what drives high-signal discoveries, and how reconnaissance, asset discovery, and hacker behavior translate into actionable security intelligence. Radu leads the development of Crowd Recon, an initiative focused on making the activity that happens between vulnerability reports measurable and actionable. By transforming researcher-driven reconnaissance into structured signals, Crowd Recon helps surface attack surface blind spots that traditional approaches often miss while complementing scanners, AI, and attack surface management tooling. He also spends an unreasonable amount of time wondering who created a particular internet-facing asset, why it still exists, and whether anyone remembers owning it.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 14:30-15:15 PDT


Title: UAiRT: Over The Air UART
Tags: IoT Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 15:15 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

The industry relies heavily on zero-trust architectures, TLS tunneling, and WAN monitoring to secure ISP edge gateways. But what happens when the compromise is soldered directly to the motherboard? Introducing Project UAiRT (UART Air interface & Remote Transmission). This presentation explores a devastating supply-chain and physical access attack utilizing a tiny $5 ESP32-C3 microcontroller implanted inside a production grade ISP router. By hardwiring the ESP32 directly to the router's internal power rails and UART debug headers, we establish an undetectable, out-of-band Command & Control (C2) bridge that completely bypasses the router's internal firewalls and the ISP's network monitoring. Project UAiRT is not a dumb serial bridge, it is an intelligent parasite. In this talk, we will demonstrate how to weaponize the ESP32’s additional GPIO pins to create a "state-aware" implant. By wiring these pins to the router’s internal status LEDs and reset lines, the UAiRT module actively monitors the router's hardware state. Attendees will see a live demonstration of the ESP32 detecting a system reboot via LED voltage changes, calculating the exact microsecond delay, and autonomously firing a carriage return to interrupt the bootloaders. From this stealthy vantage point, we will use covert wireless channels (BLE, hidden Wi-Fi, and ESP-NOW) to remotely trigger filesystem modifications, drop persistent root shells, and hijack the ISP's TR-069 management daemon, proving that software security means nothing if the supply chain is compromised by a piece of silicon the size of a thumbnail.

Speakers:Metehan Arslan,Samet Berk Simsek

SpeakerBio:  Metehan Arslan
No BIO available
SpeakerBio:  Samet Berk Simsek

Samet Berk Şimşek is a Turknet Cyber Security Specialist & Web3 Developer


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Saturday - 10:00-17:59 PDT


Title: Untechnical
Tags: Untechnical | Contest
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 103 (Untechnical) - Map

Description:

In the age of AI hacking is reclaiming itself as more a mindset than strictly technical skill. If you're a DEFCON attendee that lack the technical skills to compete in traditional hacking challenges, but still love thinking outside the box: untechnical is for you.

Untechnical is a contest designed to rely 100% on lateral/abstract thinking without needing anything beyond an understanding of high school math.

Participant Prerequisites

Need to understand basic math and enjoy thinking outside the box. Oh, and you need an email address.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 11:00-11:59 PDT


Title: Very Pwned: Hacking Verifone’s card machine three times in a row
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Everyday billions of credit card transactions are made worldwide, with the vast majority being done on purpose-built card machines. In the USA alone, nearly 400 million transactions are performed per day on these popular devices present in nearly every retail store. In this talk, I’ll focus on a widely deployed Verifone product line of card machines, with an estimated global deployment of over one million units. For several consecutive years I conducted an annual security assessment on these devices, until a pattern emerged: I'd arrive at the assessment, find a fresh set of vulnerabilities, gain root access, and then have Verifone patch the devices — only for me to return the following year and gain root access in a new way. I’ll demonstrate the three separate attack chains I discovered, two of which only required network access to the target. I’ll also detail additional vulnerabilities that could be used to disable hardening features such as grsecurity, including the ability to modify the file system to gain persistent access. Next, I’ll show how an attacker could leverage this access to continuously capture credit card information - contrary to the device’s security claims. Finally, in a homage to trixr4skids' DEF CON 25 talk in which he hacked an older series of Verifone's devices, I'll also run Doom.

DEF CON 25 - trixr4skids' DOOMed Point of Sale Systems CCC May Contain Hackers2022 - Thomas Rinsma's Payment terminals as general purpose (game-)computers

SpeakerBio:  Reino Mostert, Orange Cyberdefense

Reino is a hacker who has been working as a penetration tester for the past decade. He has hacked various payment systems - from credit card devices all the way to payment switches, and has given talks at numerous cons. He enjoys coffee and hacking.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Saturday - 21:00-00:59 PDT


Title: VETCON 2026 PARTY
Tags: Party | VETCON
When: Saturday, Aug 8, 21:00 - 00:59 PDT
Where: LVCCW Level 3 W326 (Vetcon) - Map

Description:

DEF CON is renowned for bringing together some of the brightest minds in technology and security. By participating in VETCON, you have the chance to highlight the critical role veterans play in this landscape and explore how technology can support and enhance their lives.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 15:20-17:50 PDT


Title: Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform
Tags: Recon Village | Creator Workshop
When: Saturday, Aug 8, 15:20 - 17:50 PDT
Where: LVCCW Level 1 Hall 2 501 (Recon Village) - Map

Description:

Everyone is talking about vibe coding, but most examples stop at TODO apps, landing pages, or simple CRUD applications. This workshop goes far beyond that.

Participants will use modern AI coding agents to build a real-world Open-Source Intelligence (OSINT) platform from scratch designed to aggregate and visualize intelligence data on an interactive 3D globe.

Rather than simply watching a demo, attendees will actively build the application alongside the instructor while learning the mindset, prompting techniques, and engineering workflow required to successfully collaborate with AI coding assistants.

The workshop begins with the fundamentals of vibe coding: what it actually is, why it works, where it fails, and how to communicate effectively with AI agents. Participants will learn practical prompting strategies, iterative development techniques, and methods for breaking large software systems into manageable tasks that AI can successfully implement.

From there, we'll progressively build an intelligence dashboard capable of consuming and visualizing multiple real-time OSINT sources, including flight tracking, satellite positions, earthquake feeds, maritime traffic, and other publicly available intelligence signals. Along the way, participants will generate modern user interfaces, integrate external APIs, debug AI-generated code, and learn when to trust the model and when not to.

Rather than treating AI as a code generator, this workshop teaches attendees how to use AI as an engineering partner capable of dramatically increasing development velocity while still maintaining high-quality software.

By the end of the workshop, every participant will have:

  1. A working open-source intelligence platform running locally

  2. A practical workflow for building complex software using AI coding agents

  3. A reusable prompting framework applicable to future projects

  4. Experience integrating multiple public OSINT data sources

  5. An understanding of the strengths and limitations of AI-assisted software development

  6. A roadmap for continuing to extend the platform after the workshop

The workshop is based on the open-source project: https://github.com/Alevsk/respondent-community

Workshop Outline (150 Minutes)

Part 1 — Introduction to Vibe Coding (20 min)


Part 2 — Prompt Engineering for Software Development (25 min)


Part 3 — Building the Intelligence Platform (75 min)

Participants will build the platform together while learning how to:


Part 4 — Lessons Learned & Advanced Techniques (20 min)

SpeakerBio:  Lenin Alevski, Security Engineer at Google

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Saturday - 11:00-11:20 PDT


Title: Victim as a Service: Engaging with Trust-Based Scams Using AI
Tags: Payment Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:00 - 11:20 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Pig butchering and other interactive online scams build trust over weeks to months, making them both highly effective and extremely difficult to study. In this talk, I will describe how we measure ground truth on this difficult and growing ecosystem.

First, I’ll describe the design of an LLM-driven system that can sustain realistic, long-term engagement with scammers for weeks to months, enabling large-scale investigation of their tactics in the wild. I will discuss how we attract scam attempts, maintain thousands of convincing dialogues over time, and navigate the "milestones" scammers use to advance victims toward payment. I'll end with what this approach uncovered about scammer workflows (such as the “cross-platform” jump the majority of them use) and how this measurement drives understanding of the pig-butchering ecosystem to power data-driven scam defenses in the payments ecosystem.

SpeakerBio:  Ariana Mirian, Security Researcher, BeeSafe AI

Security researcher focused on empirical measurement; currently drives data-driven methods to catch trust-based scams at BeeSafe AI, after leading measurement research at Censys. PhD in Computer Science and Engineering, UC San Diego.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 16:00-16:45 PDT


Title: VoiceLock: Offline, Robust On-Device Speech Transcription
Tags: Intro/Beginner | AI | DEF CON Demo Labs | Hardware/IoT | Mobile | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map

Description:

VoiceLock analyzes audio to identify speakers, count participants, and understand what each person said and discussed, just from a microphone. The self-contained, entirely offline system is designed for continuous, long-term use cases of 72 to 168 hours or more. The system runs entirely on-device, with high accuracy as tested on datasets and in the real world. Key innovations include an on-device vector database for fast speaker-similarity search and robust noise reduction, which greatly improve transcript accuracy. The output is a transcript with name labels. The system is fast enough to transcribe and report in under a minute. Code is written as an open-source Python module with a provided runtime and setup script to enable quick deployment on IoT devices. The system has been tested in challenging environments, including high noise levels, many speakers/arguments, and a lecture-style format. We present a live demo, technical details, and a short runtime tutorial.

Speakers:Ayaan Qayyum,Parag Kalay

SpeakerBio:  Ayaan Qayyum

Ayaan is an MS in engineering student at Columbia University. His research interests include mobile computing, applied machine learning, edge AI, and data science. He is an expert in understanding customer needs and use cases to solve real-world problems.

SpeakerBio:  Parag Kalay

Parag is a Biomedical Engineering MS student at Columbia University, combining expertise in CAD, rapid prototyping, and data-driven design to transform concepts into functional technologies under tight technical constraints. Skilled in translating clinical needs into robust engineering solutions from initial sketches to validated prototypes.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Saturday - 10:00-17:59 PDT


Title: Voting Village Lab
Tags: Voting Village | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 17:59 PDT
Where: LVCCW Level 2 W219 (Voting Village) (Voting Village Lab) - Map

Description:

The Voting Village Lab is a hands-on, self-directed workshop space where attendees can learn about and experiment with dozens of different pieces of election equipment used in current and past US elections.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 13:10-13:20 PDT


Title: Voting Village Tour
Tags: The Diana Initiative | Creator Tour
When: Saturday, Aug 8, 13:10 - 13:20 PDT
Where: LVCCW Level 1 South Lobby / Atrium - Map

Description:

Interested in visiting Voting Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Voting Village and be introduced to the community and activities inside!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: VS: S-RAD (Satellite-Radio Analysis & Disruption)
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W201 (HDA Community) - Map

Description:
Speakers:Andrzej Olchawa,Ricardo Fradique,André Cirne

SpeakerBio:  Andrzej Olchawa
No BIO available
SpeakerBio:  Ricardo Fradique
No BIO available
SpeakerBio:  André Cirne
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: VS: S-RAD (Satellite-Radio Analysis & Disruption)
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W201 (HDA Community) - Map

Description:
Speakers:Andrzej Olchawa,Ricardo Fradique,André Cirne

SpeakerBio:  Andrzej Olchawa
No BIO available
SpeakerBio:  Ricardo Fradique
No BIO available
SpeakerBio:  André Cirne
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Saturday - 10:00-10:15 PDT


Title: Wanna Hack Space ? Why? Is it out of this world?
Tags: Noob Community | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:15 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

What can you do to become involved? How to get into the Space Satellites & Cybersecurity? There is some crossover of cybersecurity skills with Space and Satellites. Did you know Linux is increasingly used in space for high-reliability, low-cost applications, with specialized, hardened distributions now addressing radiation, security, and real-time demands. Review SPARTA:MITRE for Space! NASA Open Source Software FPrime(F'),AMSAT CUBESAT SIM. https://ct3sathack.cacyber.net/

SpeakerBio:  Henry Danielson Hankashyyyk
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 16:30-17:30 PDT


Title: Weaponization of Cellular Based IoT Technology – Leveraging Smart Devices to Gain a Foothold
Tags: IoT Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

As IoT devices continue to integrate cellular technologies for communication, the potential risk for adversaries to weaponize the hardware’s trust relationship and gain access to critical backend infrastructure grows exponentially. During this talk, we will present our research focused on how built-in cellular technology in IoT devices can be leveraged to gain access to and execute attacks against cloud services and backend private network environments. We will cover methods to modify IoT devices to take control over the installed cellular modules, allowing for injecting communications and establishing Man-in-the-Middle (MitM) traffic between the Micro Controller Units (MCU) and the cellular modules. We will demonstrate how control of onboard cellular communications could be used to launch attacks against the backend cloud infrastructure and network systems outside of the IoT device's intended purpose. During this presentation, we will demo and release proof-of-concept code to control the onboard cellular modules to accomplish these goals. We will also provide actionable defense strategies, including discussions around hardware design recommendations, interface access control settings, and methods for applying targeted mitigation techniques and processes so organizations can strengthen IoT trust boundaries and protect against this evolving class of cellular-based threats.

Speakers:Carlota Bindner,Deral Heiland

SpeakerBio:  Carlota Bindner
No BIO available
SpeakerBio:  Deral Heiland, Rapid7

Deral Heiland CISSP, serves as a Principal Security Researcher (IoT) for Rapid7. Deral has over 25 years of experience in the Information Technology field, and over the last 15+ years Deral’s career has focused on security research, security assessments, penetration testing, and consulting for corporations and government agencies. Deral also has conducted security research on numerous technical subjects, releasing white papers, security advisories, and has presented the information at numerous national and international security conferences including Blackhat, Defcon, Shmoocon, DerbyCon, RSAC, Hack in Paris. Deral has been interviewed and quoted by several media outlets and publications including ABC World News Tonight, BBC, Consumer Reports, MIT Technical Review, SC Magazine, and The Register.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 16:00-16:45 PDT


Title: Weaponizing eBPF and XDP with Covert Triggered Reverse Shells
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map

Description:
eBPF and XDP now underpin critical Linux infrastructure yet their kernel-level access creates a blind spot: adversaries can weaponize these primitives for stealth persistence that evades standard forensic tools. Current defenses are not equipped for this emerging threat.

We built Phantasma, an open-source eBPF implant, to expose this gap. It combines three kernel-level techniques: (1) XDP covert triggering that intercepts packets at the NIC driver before they reach the networking stack, firewalls, or packet capture systems (2) getdents64 syscall interception to hide processes from /proc, defeating ps, top, and all enumeration tools; and (3) bpf() syscall interception to cloak loaded eBPF objects from bpftool and forensic inspection.

We live-demonstrate the full attack chain deployment, self-cloaking, magic packet activation, and encrypted reverse shell showing the implant defeating packet capture, process listing, and BPF introspection simultaneously.

We then present the defenses this threat demands: kernel audit rules for bpf() syscalls, /sys/fs/bpf inspection, XDP attachment monitoring, and behavioral indicators. Attendees leave with detection rules, hardening steps, and a clear understanding of why eBPF must be treated as an attack surface, not just a defense tool.

SpeakerBio:  Yll "0xBabar0ka" Berisha

I am an offensive security researcher with 2 years of experience in penetration testing, red teaming, and custom tooling. I am the creator of Phantasma, an open-source eBPF/XDP implant framework for stealth persistence research.

Professionally, I have worked at Sentry, conducting web, mobile, and internal/external network penetration tests. At Finbbug, I contributed to a US Embassy-supported project assessing the cybersecurity posture of NGOs and media organizations in Kosovo, identifying issues such as XSS, directory listing, and IDOR vulnerabilities. At Starlabs, I built dark web monitoring tools using HaveIBeenPwned and LeakX APIs for automated credential leak detection.

I hold BSCP (Burp Suite Certified), CRT-ID (Certified Red Team Infra Dev), MCRTA (Multi Cloud Red Teamer), CISCO ETHICAL HACKER, and HACKWISER CAPT certifications. I placed 1st at the Iowa State Cyber Defense Competition and represented Kosovo at the 2024 ENISA European Cybersecurity Challenge in Turin.

I have presented at CyberZero on prompt injection attacks and deepfake-based social engineering at the TechRisck conference, and co-organized national and international CTFs designing real-world attack chain challenges.

I am also a member of DefCon Group Prishtina (DC38338), where I contribute to co-organizing meetups and community events.


Return to Index    -    Add to Google    -    ics Calendar file

Cryptocurrency Village - Saturday - 10:00-10:59 PDT


Title: Web3 Security: Hacks, Scams, and Exploits
Tags: Cryptocurrency Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Why do Web3 users keep getting hacked even when the smart contracts are audited? This workshop examines the Web3 attack surface through three lenses: the client, the dApp frontend, and the blockchain, using real-world hacks, scams, and exploits to demonstrate how each layer can fail. Participants will conduct a live review of their own wallet approvals using revoke.cash and learn practical techniques for reducing risk. The workshop concludes with a forensic deep dive into the $1.5 billion Bybit hack, where attendees will analyze the malicious transaction, compromised frontend, and on-chain evidence that enabled the largest cryptocurrency theft in history.

Speakers:Philip "AlephNull" Werlau,Kennashka DeSilva

SpeakerBio:  Philip "AlephNull" Werlau, Founder, Flowstate Cyber

Philip is a cryptocurrency investigator and smart contract analyst specializing in DeFi, on-chain forensics, and blockchain security. Experienced in support of government agencies and private-sector clients in cryptocurrency fraud investigations, exploit analysis, fund tracing, and smart contract risk analysis, Philip’s extensive familiarity with EVM ecosystems, blockchain analytics, and custom investigative tooling contributes to his work in government and industry.

SpeakerBio:  Kennashka DeSilva

Kennashka DeSilva is a seasoned cybersecurity researcher with a strong track record of advancing security best practices in decentralized systems. She was a featured speaker at DEF CON 30’s “Hacking & Defending Blockchain Applications” session, where she helped bridge the gap between traditional application security frameworks—such as the OWASP Top Ten—and the unique risks found in DEFI and smart contract ecosystems. Kennashka is also an active participant in the cybersecurity community, having contributed to multiple HackMiami events and served on the executive councils of Women in Cybersecurity Florida and Black Girls in Cyber, helping to advance diversity, mentorship, and professional development in the field. Her expertise spans vulnerability management, threat modeling, and policy-driven security in Web3 and enterprise systems.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 15:00-15:59 PDT


Title: What can those architecting agents learn from national security?
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:
This is a sit down discussion in a more casual conversational format:

The promise of agents is huge, but as the underlying LLMs get more capable, we are heading towards a future where a malicious or subverted agent cannot be contained through classical sandboxing approaches. The UK AISI’s work on sandbox bench shows an agent doesn’t even need to be malicious to attempt (and succeed) in breaking out of a regular sandbox. Looking to the future, approaches such as containerisation, based on Linux namespace separation, won’t hold if the agent can find and exploit a novel kernel 0-day.

Remove the AI aspects, and the problem is that a workload might be able to find and exploit novel vulnerabilities, or evade even well-implemented controls. This is a problem the national security community has been working on for decades. This sort of defensive approach has only been necessary and justifiable to protect the most critical systems from the most capable adversaries, but in the near future, it may be needed to protect commodity systems from commodity attackers being enabled by AI.

This talk will cover some of the approaches that map to the challenge of securing agentic workloads and serve as a conversation starter for what previously niche thinking might become of commodity use.

SpeakerBio:  David C Eight, UK NCSC AI Safety Institute
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 11:00-11:59 PDT


Title: What is AI? Interactive, Unplugged Activity
Tags: AI Village | Creator Event/Activity
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Ever wonder what's actually happening inside an AI? In this hands-on, no-screens-required workshop, you'll build your own neural network out of flashcards and pipe cleaners, "train" it, and watch it try (and sometimes fail!) to answer prompts. You'll grow your model, give it tools and skills, and then turn the tables: try out real attacks like prompt injection, tool misuse, and data poisoning, and learn the defenses AI security researchers use to stop them, like containerization. No coding or experience required, just curiosity!

SpeakerBio:  Sam Mosley, CodeBloom
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 16:00-16:59 PDT


Title: What is AI?
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Curious what is actually happening inside an AI when it answers your questions? In this session, you'll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We'll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

SpeakerBio:  Sam Mosley, CodeBloom
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 13:00-13:59 PDT


Title: What is AI?
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Curious what is actually happening inside an AI when it answers your questions? In this session, you'll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We'll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

SpeakerBio:  Sam Mosley, CodeBloom
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 15:30-15:59 PDT


Title: What Scammers Know That Social Engineers Don't: Three Techniques for Tough Cases
Tags: Social Engineering Community Village | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 15:59 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Most social engineering training teaches techniques that exploit emotional triggers like urgency, fear, or flattery. But what happens when the target has been trained to spot these and they are on high alert? In this talk I will demonstrate three techniques I've learned from studying career scammers for my research at F-Secure, and I'll show you how to apply them to your social engineering operations. All three of these techniques work specifically for targets who have been already primed against falling for scams and other social engineering exploits. In other words, these are techniques designed for your tough cases. First, I'll demonstrate Awareness Hijacking, where the operator uses the target's knowledge of one scam to trap them in a different one. Then I'll show Complexity-as-Crucible, where the operator engineers a scenario that lets them become the target's trusted guide. Finally, I'll demonstrate the First Win, where the operator purposely lets the target "beat the scam" without realizing they've actually entrapped themselves. Participants will leave with three new techniques that are directly applicable to red team social engineering engagements where the targets may be on high alert or trained against falling for more traditional manipulation techniques.

SpeakerBio:  Megan Squire, Principal Threat Intelligence Researcher at F-Secure

Dr. Megan Squire is a Principal threat intelligence researcher at F-Secure, where she studies AI safety, scams, and fraud. Before moving into threat intel, she spent over a decade studying online recruitment, illicit finance, and adversary networks in the domestic violent extremism domain. Her work on threat intelligence and OSINT has been featured in WIRED, The New York Times, PBS-Frontline, The Washington Post, and Dark Reading.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Saturday - 14:00-14:30 PDT


Title: What we learned from SATAN about the MYTH of Mythos
Tags: AI Village | Creator Talk/Panel
When: Saturday, Aug 8, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

Thirty years ago a new and powerful (at the time) vulnerability scanner burst onto the scene. SATAN (System Administrators Tool for Analyzing Networkds) sparked controversy by putting advanced network reconnaissance capabilities into the hands of ordinary defenders. Critics warned it would empower attackers and was, therefore, too dangerous to release publicly. In fact, it helped accelerate security awareness and improve defensive practices. Today, AI-powered security platforms such as Mythos face similar calls for restriction. This talk examines the lessons of SATAN and argues that limiting access to powerful security tools rarely stops capable adversaries, but often disadvantages defenders, researchers, and educators. As the security community debates AI’s future, history offers a valuable reminder: broad access to defensive capability has often strengthened security more than secrecy.

SpeakerBio:  Jeff Crume

Jeff Crume is an IBM Distinguished Engineer and Master Inventor with more than 40 years’ experience in the IT industry. He has a PhD in Cybersecurity and serves as an Adjunct Professor at NC State University. Jeff’s YouTube videos have been viewed more than 25 million times and he is the author of a book entitled "Inside Internet Security: What Hackers Don’t Want You To Know” as well as a contributing author to the "Information Security Management Handbook.” He is a member of the inaugural class of the NC State University Computer Science Alumni Hall of Fame and serves on the editorial board for the “Information and Computer Security” research journal. Jeff lived in Beijing on assignment in 2006 and has worked with clients in 50 countries.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 11:10-11:40 PDT


Title: What Your Coding Agent Did Last Night: Runtime Security for AI Coding Agents
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Saturday, Aug 8, 11:10 - 11:40 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Your coding agent ran 200 tool calls last night. File reads, shell commands, network requests, all with your permissions, mostly invisible. Today's defenses miss the attacks landing now: MCP tool poisoning, prompt injection via repo content, and credential-exfiltration chains where only the sequence is malicious.

I’ll present AgentsLeak, an open-source runtime monitor that hooks Claude Code and Cursor at the tool-call boundary and blocks before execution. Live demo: session telemetry showing the calls the agent made versus the calls it disclosed, and behavioral chain detection catching multi-step exfiltration.

SpeakerBio:  Inga Cherny

Inga Cherny is an ML Researcher at CrowdStrike specializing in AI security, LLM vulnerabilities, adversarial ML, and prompt injection defenses.

Previously, she was a security researcher at Cato Networks and a member of Cato CTRL, focusing on emerging threats, offensive and defensive security research.

With a decade of experience spanning security and applied machine learning, Inga focuses on uncovering new attack vectors and building more resilient AI and security systems.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 13:30-14:10 PDT


Title: What's Behind the Curtain? Tearing Down AWS's AI Agent Runtime From the Inside
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 14:10 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

How much do you actually know about one of the world's leading agent-building platforms? When you deploy an AI agent to Bedrock AgentCore, your code lands inside a Firecracker microVM - and you're told almost nothing about what's in there with you. So I decided to find out.

Starting from nothing, we'll work our way through the layers: Runtime, Networking, Identity, Observability, etc - mapping what an attacker can reach, what they can break, and what actually holds. We'll explore novel techniques that allowed me to extract information the platform was never meant to expose.

Along the way, we'll uncover an undocumented platform, strange auth behaviors, security boundaries that didn't hold up, and internal architecture details not covered in any public documentation.

By the end, you'll see what's really behind the curtain and what it tells us about how AWS builds and secures managed AI workloads. The methodology is reusable - the next time you're researching an opaque managed runtime, you'll know where to look.

SpeakerBio:  Dan Gansel

Dan Gansel is a cloud security specialist with deep expertise in cloud API research, secure cloud solutions and architecture design. Dan has led cloud security research teams and has a track record of uncovering novel attack techniques in cloud environments. As a Security Researcher at Upwind Security, Dan continues to push the boundaries of cloud security, focusing on uncovering blind spots in the services organizations trust the most.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 14:30-15:30 PDT


Title: When Cash Runs on Windows: A Red Team Look at ATM Attack Surfaces
Tags: La Villa Community | Creator Talk/Panel
When: Saturday, Aug 8, 14:30 - 15:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Muchos cajeros automáticos siguen siendo, en esencia, computadoras Windows especializadas. Algunos son modernos, otros llevan años operando con sistemas heredados, configuraciones antiguas y controles que nunca fueron revisados a profundidad. Están en gasolineras, supermercados y esquinas, conectados a infraestructura crítica donde una mala decisión de hardening, segmentación o administración remota puede convertirse en un riesgo real.

Nadie los toca. Nadie los cuestiona. Hay dinero adentro.

Esta charla resume hallazgos de ejercicios reales de pentesting sobre ATMs realizados en América Latina. Veremos cómo se ve la seguridad ATM en producción: qué controles suelen estar presentes, cuáles fallan de formas inesperadas y cómo debilidades aparentemente menores pueden encadenarse hasta comprometer infraestructura crítica.

Entre los hallazgos analizaremos fallas en controles de endpoint, hardening, segmentación, administración remota y exposición de servicios legacy. También veremos qué controles resistieron, por qué lo hicieron y qué diferencia a un ATM correctamente endurecido de uno que puede convertirse en punto de entrada hacia infraestructura crítica bancaria.

Más que mostrar “cómo atacar un cajero”, esta charla busca crear conciencia sobre la importancia de endurecer y monitorizar estos equipos.

SpeakerBio:  Gerardo Mejia, Red Teamer

Es especialista en ciberseguridad ofensiva, con enfoque en operaciones de red teaming, purple teaming, pruebas de penetración, campañas avanzadas de phishing y ataques dirigidos a entornos de Active Directory. Actualmente forma parte del un equipo regional de seguridad ofensiva, donde diseña y ejecuta ejercicios de simulación de adversarios para fortalecer la resiliencia de las organizaciones ante amenazas sofisticadas.

Cuenta con certificaciones destacadas, como CRTO, CRTP, PNPT, eWPT, CR (HTB Ambassador), C-ADPenX y eCCPT.

Ha sido conferencista en eventos internacionales como PWNEDCR en Costa Rica, BSides Panamá, Dojo Conf Panamá, HackConRD en República Dominicana y Ekoparty en Argentina, Defcon 33 La Villa, Kavacon


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Saturday - 10:00-10:59 PDT


Title: Whose Agent Is It Anyway? Agency, Authorization, and Accountability in the Year of the AI Agent
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

DEF CON 34’s theme is Agency—as in digital self-determination. This is also the year agentic AI went mainstream. Those two meanings of “agency” are now colliding in the legal sphere, and early answers are not in the user’s favor. A federal court ruled that a user’s instruction to her own AI agent to access her own Amazon account may violate federal cybercrime law—because the platform, not the user, controls authorization. The decision is up for appeal. Meanwhile, the market is trending the same way: agents go where B2B agreements permit. The web, as navigated by AI agents, is becoming a permission graph between companies. The instinct is clear: the user’s delegation should count, agents should go where the user can. But the question is harder than it looks. Real vulnerabilities allow agents inside authenticated platform environments to be hijacked. Platforms cannot secure these agents or distinguish them from legitimate user sessions. When the user delegates, she opens channels an attacker can redirect. The platform must decide whether to accept the risk of tools it didn’t build operating in spaces it’s responsible for protecting. Neither courts nor markets are producing the right answer. Two cybersecurity lawyers walk through the cases, the complicating security research, and the policy options.

Speakers:Andreas Kaltsounis,Jacob Wall

SpeakerBio:  Andreas Kaltsounis, BakerHostetler

Andreas Kaltsounis is an attorney and co-lead of BakerHostetler’s Digital Risk Advisory & Cybersecurity practice, where he advises clients on privacy and security compliance, incident response, and regulatory defense. He holds the CISSP certification, is an IAPP Fellow of Information Privacy, and is ranked by Chambers USA and Chambers Global for his work in privacy and cybersecurity law. Before practicing law, Andreas was a managing director at an international information security consulting firm and served as a federal agent investigating criminal and national security cyber matters.

SpeakerBio:  Jacob Wall, BakerHostetler

Jacob Wall is an attorney and associate in BakerHostetler’s Digital Risk Advisory & Cybersecurity practice. Jacob's work spans technology regulatory law, including compliance and product counseling, regulatory defense, and policy advocacy. A particular focus of Jacob's practice is bringing a technical background to complex cybersecurity and AI regulatory questions. He and Andreas work together on a range of AI governance and cybersecurity compliance engagements for technology and critical infrastructure clients.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 13:00-13:45 PDT


Title: Whose PR Is It Anyway?
Tags: Nix Vegas Community | Creator Event/Activity
When: Saturday, Aug 8, 13:00 - 13:45 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

In this audience participation-heavy session, you can get your PRs to nixpkgs reviewed and maybe even merged... if the build on one of our systems passes. Come with PRs in hand and call them out, and we'll review, build, and maybe even merge them on stage.

This is Whose PR Is It Anyway, where the version bumps are made up and the builds don't matter.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Saturday - 12:00-12:20 PDT


Title: Whose Resource Is It Anyway? The Design Flaw That Breaks the IAM Permission Model
Tags: Cloud Village | Creator Talk/Panel
When: Saturday, Aug 8, 12:00 - 12:20 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

The major cloud provider’s permission model is simple: use IAM to keep the bad guys out of your cloud environment. But what if the bad guys could lure victims in? Each provider implements IAM differently, and in this talk, we will explore a hidden quirk in the GCP identity boundary that allows attackers to invert the permission model and force victims into a malicious environment.

We will examine the unique aspects of GCP IAM and explore how a core design choice enabled cross-tenant account takeover via a novel vulnerability I discovered in Vertex AI Workbench, potentially leading to full cloud compromise.

The biggest threat to your cloud environment could be a project you didn’t even know you were a part of.

SpeakerBio:  Moshe Berntsein

Moshe Bernstein is a Senior Security Researcher specializing in cloud vulnerability research at Tenable. With over a decade of experience in cybersecurity, Moshe has developed a strong focus on network and operational security, web vulnerability research, and cloud infrastructure security. He enjoys presenting his research at conferences around the world, and is always on the lookout for new challenges.


Return to Index    -    Add to Google    -    ics Calendar file

Packet Hacking Village - Saturday - 16:00-16:59 PDT


Title: Why Couldn't I See My Own Drone? Remote ID, ESP32s, and the Packet Trail to Friend or Foe
Tags: Packet Hacking Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Friend or Foe started when adding Remote ID support to an Android airspace app still failed to detect our own DJI drone. This led us into DJI Wi-Fi Beacon behavior, vendor information elements, ESP32 promiscuous capture, and conservative evidence handling using Bayesian fusion. This talk covers practical packet analysis techniques for Remote ID (BLE and Wi-Fi), hardware tradeoffs for reliable scanning, and how to avoid turning weak signals into overconfident alerts. Attendees will learn how to build honest, low-cost RF sensors and interpret packet evidence responsibly.

Speakers:Will Hatzer,Charles Grow

SpeakerBio:  Will Hatzer, Founder, GameChangersAI / Team Charity Case

Will "OGThorne" Hatzer is a security engineer, adversarial researcher, and founder of GameChangersAI. He works in security engineering at OpenAI and builds open-source tools across RF, Android, embedded systems, and defensive security. A former DEF CON Car Hacking Village speaker, his work includes a bot-detection patent and Hyundai BlueLink research later referenced by CISA.

SpeakerBio:  Charles Grow, Hardware Designer / RF Researcher, Team Charity Case / GameChangersAI

Charles "OhYou_" Grow is a hardware designer, RF researcher, and ham radio operator. He designed the Friend or Foe badge hardware, solving component layout, USB-C access, GPIO conflicts, and RF ground-plane challenges. His background in fox hunting, electronics, and field debugging helped turn early prototypes into a practical, wearable device.


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Saturday - 13:30-14:30 PDT


Title: Why Mandatory Age Verification Keeps Us All Less Safe
Tags: Women in Security and Privacy (WISP) | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:
Speakers:Alexis Hancock,Kenyatta Thomas

SpeakerBio:  Alexis Hancock, Director of Engineering at Electronic Frontier Foundation

Alexis works to keep the networks strong and encrypted by managing the Certbot project. As well as ensuring EFF open source tools for the public are well supported. She researches an intersection of issues on digital rights, encryption, and consumer technology. She believes in an open and equitable web through encouraging expansion of security by default, bridging engineers and security research, and advocating for better and stronger tech policy and standards.

SpeakerBio:  Kenyatta Thomas, Social Media and Video Manager at EFF

As the Social Media and Video Manager at EFF, Kenyatta Thomas leads the creation of digital content that educates and mobilizes the public across EFF's online platforms. They come to EFF from a background in youth and reproductive justice advocacy and organizing, having previously worked with organizations such as Physicians for Reproductive Health, the National Network of Abortion Funds, Reproaction, and Advocates for Youth. Their work as a sex educator and abortion doula informs their deep commitment to community care, access to information, and tech equity. Kenyatta believes in the transformative power of digital tools to advance justice and is committed to making online spaces more inclusive, accessible, and empowering for all.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Saturday - 13:00-13:30 PDT


Title: Why Signals Still Matter: Amateur Radio in the Age of Cell Phones
Tags: Ham Radio Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:00 - 13:30 PDT
Where: LVCCW Level 3 W315 (Ham Radio Village) - Map

Description:
Topics covered:
Why ham still matters, the philosophy of ham radio, cool stuff we're doing in the hobby with a focus on digital modes, how it's the original hacking hobby.
Extended info on software defined radio, GnuRadio.
Talk about how it's basically old school analog internet, and that everything we do on the modern internet network is possible on ham radio.

We all have radios in our pockets. 5g, Bluetooth, and heck star-link up in the sky. Let's talk about why 100 year old tech is still relevant today, and why us hackers should care about ham radio when the internet is basically everywhere now.

SpeakerBio:  Nate Moore

Nate Moore works in cybersecurity, holds an Extra class amateur radio license, and spends his spare time teaching, examining, and pushing signals around the ether.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Saturday - 12:00-13:30 PDT


Title: Wi-Fi Self Defense & Hacker Hunting & For Beginners
Tags: IoT Village | Creator Workshop
When: Saturday, Aug 8, 12:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Kit Cost: $140. Class Cap: 30.

SpeakerBio:  Kody Kinzie
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Saturday - 16:00-16:30 PDT


Title: Wolfmasking: Teaching Everyday Defenders to Think Like Social Engineers
Tags: Social Engineering Community Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:30 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:
Most security awareness training keeps people in the role of prey: memorize red flags, stay vigilant, and hope your System 2 brain has enough calories left when the real attack arrives. Wolfmasking is supervised deceptive roleplay: everyday defenders safely rehearse the attacker�s moves, develop a mental model of the predator, then return to defense with better instincts. This talk presents lessons and examples from a field pilot tested at Clemson University with support from CISO John Hoyt, in which roughly 80 nursing freshmen learned to construct benign social-engineering challenges, compete against one another, and report each other�s attempts. The point was not to create attackers, but to create an identity shift: Students began shifting from hypothetical victims into former players: people who recognize pretext, authority, urgency, trust transfer, and emotional pressure not because they were "staying vigilant," but because they have practiced those moves themselves I will share the four-lesson structure, guardrails, incentives, surprises, failures, and why �practice being fooled� may matter less than �practice doing the fooling safely.� I�ll use a quick magic example to show the gap between hypothetical knowledge and lived deceptive experience. This is not a product pitch. It is a field report on a new training pedagogy for social engineering resilience.
SpeakerBio:  Brian Brushwood
Brian Brushwood has spent 25 years teaching millions of people how deception works: first as a touring magician, then as creator/host of Scam School / Scam Nation, host of National Geographic's Hacking the System, creator of The Modern Rogue, and host of World's Greatest Con. His work focuses on scams, magic, persuasion, social engineering, and the mechanics of trust: how it is built, exploited, defended, and rehearsed. Through Scam School and Scam Nation, Brian spent nearly two decades turning ordinary non-deceivers into capable ethical deceivers, helping them understand cons and persuasion from the inside. Brian has delivered keynotes to audiences of thousands and recently developed an experimental offense-to-defense social engineering curriculum, piloted at Clemson University with CISO John Hoyt.

Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 17:00-17:59 PDT


Title: Work Session: Binary Code
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 17:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Did you know that every photo, song, and message on your phone is really just a long string of 0s and 1s? Come learn how binary code works and then turn your very own secret word into a wearable friendship bracelet using our binary alphabet chart! This session is beginner friendly and a great way to see how computers really think. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 11:00-11:59 PDT


Title: Work Session: Ciphers
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We'll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Saturday - 14:00-14:59 PDT


Title: Work Session: Ciphers
Tags: CodeBloom | Creator Workshop
When: Saturday, Aug 8, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We'll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Saturday - 10:30-12:59 PDT


Title: Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence
Tags: La Villa Community | Creator Workshop
When: Saturday, Aug 8, 10:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map

Description:

La mayoría de los SOCs son reactivos por diseño: los eventos llegan, se almacenan, se correlacionan horas después, y en el mejor de los casos un analista los revisa cuando puede.

Este workshop rompe ese modelo.

Presentamos una arquitectura SOC-less impulsada por IA donde la detección ocurre en línea — antes de que los datos lleguen al SIEM — usando reglas Sigma traducidas a lógica ejecutable en Groovy.

Cuando una regla hace match, el evento se enriquece al instante con contexto de usuario, criticidad del activo, estructura de procesos y técnicas asociadas a MITRE ATT&CK.

El diferenciado de nuestra propuesta es la memoria. Cada alerta, ticket, resolución, triaje de analista y falso positivo alimenta un índice recurrente.

los agentes consultan ese historial para determinar si una detección es nueva, recurrente, vinculada a un activo crítico o parte de un patrón conocido — luego generan el ticket, sugieren severidad, recomiendan la contención y, en escenarios controlados la ejecutan.

El resultado del flujo es la detección y respuesta inicial medidas en segundos, no en turnos de analistas.

Speakers:Luis Pazmino,Yoshihito Adachi

SpeakerBio:  Luis Pazmino, Cyber Defense Manager Banco Pichincha, Principal Consultor DataProtect Information Security

Cybersecurity Lover, Red Teamer, OSCE | OSEP | OSCP | CISM | ECSA | CEI

SpeakerBio:  Yoshihito Adachi, Cybersecurity Specialist

I have a strong passion for data exploration and threat hunting, which drives me to constantly seek out new methods to detect high-level threats. Being a highly logical individual, I am deeply interested in understanding how things work. This curiosity fuels my dedication to uncovering innovative approaches and enhancing cybersecurity measures.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 15:30-16:30 PDT


Title: Wrestling with a Python: Escaping Copilot Studio's AI-Guarded Sandbox
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Saturday, Aug 8, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Microsoft Copilot Studio lets anyone build AI agents that execute Python. Behind the scenes, that code runs in a Windows container on Azure Service Fabric, wrapped in a Python sandbox and guarded by a GPT-4.1 mini model that decides what's safe to run. Three layers of defense. The presenter broke all of them.

Starting from a standard agent with code interpreter enabled, we used classic MRO introspection with string concatenation to bypass dunder filters, escaped Python entirely through pythonnet (which nobody thought to block), and systematically defeated the LLM guardrail by exploiting its leaked reasoning chain. The result: exfiltrated TLS private keys and certificates, 75 environment variables including Azure AD client IDs and Service Fabric cluster topology, complete application source code, and confirmed command execution as ContainerUser.

The most interesting finding was the LLM guardrail itself. It is non-deterministic: identical payloads sometimes pass and sometimes get blocked. It leaks its full security reasoning in the API response, turning the defender's AI into an oracle for the attacker. This talk walks through the full attack chain, demos a C2 tool that turns the code interpreter into a persistent shell, and releases all tooling.

Speakers:Ryan Hausknecht,Simon Maxwell-Stewart

SpeakerBio:  Ryan Hausknecht, BeyondTrust

Ryan Hausknecht is the Director of Research at BeyondTrust Phantom Labs. Ryan has an extensive background in red teaming, detection development, and security research through his tenure at Microsoft and Specterops. His most notable contibutions have been in cloud security as the creator of PowerZure, the Azure Threat Research Matrix, and as the co-author of AzureHound.

SpeakerBio:  Simon Maxwell-Stewart, BeyondTrust

Simon Maxwell-Stewart is a Staff Security Researcher at BeyondTrust's Phantom Labs, where he focuses on cloud platform security and the emerging attack surface of enterprise AI systems. Before getting into security he spent over a decade doing data science and machine learning, with a physics degree from Oxford and production ML work in healthcare.

These days he's the resident graph nerd on the Phantom Labs team, applying graph analysis to identity security problems across Microsoft cloud environments. His recent research focuses on Entra ID attack paths, Azure infrastructure security.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 16:00-17:59 PDT


Title: Writing Production-Grade Exploits in go-exploit
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 16:00 - 17:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

Writing an exploit that works once in a lab is easy. Writing one that holds up across firmware versions, hardened configurations, and real-world constraints is another challenge entirely. This hands-on workshop walks through the go-exploit framework and the engineering behind real-world offensive tooling, covering go-exploit's module design, error handling, target fingerprinting, and repeatability. Attendees will leave with a working exploit and the blueprints to build more.

SpeakerBio:  Landon Rice

WIP


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 12:30-13:30 PDT


Title: Writing to Shadow Stacks
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

CET shadow stacks are supposed to make return-address corruption a dead end. This talk presents three techniques that write attacker-chosen values directly into shadow stack memory on Linux.

The first uses /proc/self/mem. The kernel's FOLL_FORCE flag overrides shadow stack page protections, letting an unprivileged process write to its own shadow stack with open() and pwrite(). Works on x86-64 CET and ARM64 GCS. After our report, Linus Torvalds merged commit 599bbba5a36f to restrict this path. A fork+ptrace variant still works on patched kernels. No distribution ships the new default yet.

The second uses userfaultfd. We register a fault handler on the shadow stack VMA, discard a page with MADV_DONTNEED, and when RET faults on the missing page, provide a replacement filled with chosen return addresses. The kernel maps it with valid shadow stack PTE encoding. Not blocked by the /proc/self/mem patch.

The third uses Intel's WRSSQ instruction, which writes to shadow stack pages from user mode. We corrected a widespread encoding bug in prior PoC code (0x66 prefix produces ADCX, not WRSSQ) and confirmed it on Sapphire Rapids bare metal.

Validated against three CVEs (dnsmasq, libinput, rsync) with demos on bare metal, including a root shell with CET still enabled.

  1. Intel, "Control-flow Enforcement Technology Specification," Rev. 3.0, 2019.

    1. ARM, "Guarded Control Stack (GCS) Extension," Arm Architecture Reference Manual for A-profile architecture.

    2. Linux kernel source, mm/gup.c and fs/proc/base.c, including FOLL_FORCE, /proc/*/mem, and VM_SHADOW_STACK handling.

    3. Lindenmeier and Schwarz, "Ghost in the Stack: CET Shadow Stack Bypass," Black Hat Europe 2025.

    4. Muench et al., "Control Flow-Oriented Programming," USENIX Security 2025.

    5. Schuster et al., "Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C++ Applications," IEEE S&P 2015.

    6. CVE-2017-14493, dnsmasq stack buffer overflow.

    7. CVE-2022-1215, libinput format string vulnerability.

    8. CVE-2024-12084, rsync heap buffer overflow.

SpeakerBio:  Vladimir "G1ND1L4" Tokarev, Cyera

Vladimir Tokarev is a vulnerability researcher tech lead at Cyera, specializing in Cloud, IoT/OT, Windows, Linux, and AI vulnerability research and exploit. Talks: Black Hat USA 2024 and 2023,
DEF CON 33 Recon Village 2025, CodeBlue 2025, RSA 2024.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 11:00-11:45 PDT


Title: X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | Purple Team | DEF CON Demo Labs
When: Saturday, Aug 8, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

Agents now run with thousands of third-party plugins — MCP servers, Claude skills, GPT actions, IDE extensions, plugin marketplaces — and the prevailing trust model is roughly “read the README and hope.” Tool descriptions are executable prompts. Tool parameters are executable code paths. Tool outputs feed straight into the next agent step. Yet there is no npm audit for this ecosystem, no signed manifests, and no capability sandbox in the wild.

MCP X-Ray is an open-source security scanner that ports classical pentest tradecraft to the agent plugin supply chain. It combines static config and repo audit, rules-based and LLM-driven semantic analysis, and active pentesting that actually invokes tools with adversarial inputs — emitting SARIF that drops into GitHub, VS Code, and CI gates today. In this 30-minute session we will (1) walk the threat model that ties MCPs, skills, and plugin bundles together; (2) live-demo X-Ray finding real vulnerabilities in each. Attendees walk away with a CI template they can drop in on Monday, and three intentionally vulnerable plugins to keep practicing on.

Speakers:Xia Hua,Abhijeet Kumar

SpeakerBio:  Xia Hua

Xia is co-founder and CEO of Traceforce which secures AI native apps running on devices. She previously led engineering at Clumio (acquired by Commvault), delivering cloud data protection products that were 20x faster and 10x more scalable than competitors. Earlier, she was an in-memory database architect at Oracle. Xia earned her PhD in Applied Mathematics from MIT.

SpeakerBio:  Abhijeet Kumar

Abhijeet Kumar is an OSCP-certified offensive security researcher and M.Eng Cybersecurity student at the University of Maryland. He has disclosed critical vulnerabilities across NASA, SAIL critical infrastructure, Keurig Dr Pepper, and U.S. government programs which includes a CVSS 10.0 RCE that triggered an official CERT-In incident response and a full account takeover chain affecting users across 20+ countries. He captains UMD's CTF team RandomHackers, which placed 1st out of 64 universities at HTB Hack The Madness 2026, and has spoken at the Billington State and Local Cybersecurity Summit alongside the Director of Adversary Emulation.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 16:00-16:45 PDT


Title: xEndity: IoT Firmware Analysis & Digital Twin Platform
Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map

Description:

IoT devices are embedded in critical infrastructure globally, yet security teams face a fundamental constraint: you cannot aggressively test what you cannot safely replicate. Physical hardware is expensive, limited in supply, and testing against production systems is off-limits. This leaves defenders operating blind against an expanding attack surface of billions of connected devices.

xEndity is an open-source, end-to-end IoT firmware emulation platform that transforms raw firmware binaries into fully functional, network-ready virtual device instances, no physical hardware required. It provides an automated pipeline spanning firmware acquisition, binary analysis, filesystem extraction, emulation packaging, and orchestrated deployment of emulated device networks at scale.

The platform enables two high-impact use cases: first, as a scopeless penetration testing range where red teams and researchers can conduct unrestricted vulnerability validation, exploit development, and attack simulation against realistic IoT environments. Second, as a deceptive defense layer where emulated devices are deployed as high-interaction honeypots to capture adversary tradecraft, collect OS-level and network telemetry, and generate actionable threat intelligence.

Speakers:Zeus "LightningGod" Chan,Kenneth "kenleejl" Lee

SpeakerBio:  Zeus "LightningGod" Chan

Zeus Chan is a security researcher on the Adversary Emulation Team at HTX (Home Team Science and Technology Agency), where he focuses on IoT firmware analysis, device emulation, and offensive security research. His work spans building automated pipelines for firmware emulation, security testbed development, and honeypot deployment for threat intelligence collection against embedded systems. Zeus has presented IoT security research at DEFCON events globally and Milipol TechX Singapore, and has supported community initiatives including the HTX Public Safety Village at DEFCON Singapore. He holds experience in red team operations supporting critical national infrastructure across the finance and healthcare sectors.

SpeakerBio:  Kenneth "kenleejl" Lee

Cyber security enjoyer


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Saturday - 16:00-16:25 PDT


Title: Yes, it runs Doom: over the air gaming on a bladeRF SDR
Tags: Radio Frequency Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:25 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

This presentation will demo and discuss the development of a Doom port running on the Nuand BladeRF 2.0 micro xA9 Software Defined Radio.

The BladeRF is designed for RF development, containing a Cyclone V FPGA and a radio frontend capable of up to 6GHz, but lacks a hard CPU and general-purpose memory, making it a strange and particularly entertaining candidate for a game port.

This project combines FPGA design, customized firmware, RF-based video transmission, and wireless controller support. The talk will walk through system architecture, including the game engine port, how video signal is generated and transmitted, and how wireless controller input is handled. It will also cover the challenges, compromises, and unexpected findings that shaped the final design.

SpeakerBio:  max

Max is an enthusiast of strange hardware, with particular interests in retro computing and game development. He's spent years restoring vintage game consoles and computers, experimenting with VR tracking interfaces, and building hardware projects to combine these interests. Professionally, Max designs custom hardware for RF collection and security systems.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Saturday - 10:00-10:59 PDT


Title: Yoga
Tags: The Diana Initiative | Creator Event/Activity
When: Saturday, Aug 8, 10:00 - 10:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

Come join us for morning yoga and meditation. This workshop is inclusive of all bodies. Meditation can help quiet the mind, manage stress, and enhance overall emotional well-being, making it a great way to start the day.

SpeakerBio:  Deanna Heon
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Saturday - 13:00-13:59 PDT


Title: You Can't Block My C2 — It's Your Google Calendar
Tags: Red Team Village | Misc
When: Saturday, Aug 8, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Speaker Bio

Nishant Tayade is a Security Engineer on an enterprise Red Team, where he has spent three years conducting internal and external red team campaigns simulating real-world adversary tactics. His current research explores covert command-and-control techniques — including Mythic agents that abuse legitimate cloud services for stealthy communication — and operationalizing AI agents to enhance offensive security operations. Prior to his current role, he spent two years in SOC and SIEM engineering, giving him a full-stack perspective on both offense and defense.

Nishant holds a Master of Science in Information Security from Carnegie Mellon University. He has spoken at BSides Seattle, BSides San Diego, and BSides New Orleans, covering topics ranging from anonymity and OPSEC to how attackers weaponize OSINT and AI to profile targets.

This research started during an APT41 emulation campaign he led, where he mapped the group's real-world tradecraft — including their use of Google Calendar as a C2 channel. While building the simulation, he observed that cloud service API traffic to domains like googleapis.com was effectively invisible to enterprise detection stacks. Most cloud-native organizations allowlist this traffic by default, creating a blind spot. He built Chronos and Epoch to operationalize that technique within Mythic, and validated that Calendar-based C2 traffic went undetected against production monitoring.

Description

What if C2 traffic was indistinguishable from a Google Calendar sync? This session presents Chronos and Epoch — a Mythic agent and C2 profile that use Google Calendar as a dead-drop communication channel. All traffic flows to googleapis.com over standard HTTPS. There is no C2 server IP for defenders to discover, no infrastructure to burn, and no way to block it without disrupting enterprise calendar workflows.

The workshop covers the journey of building a functional C2 channel over a SaaS API that was never designed for it — the architectural decisions, the operational tradeoffs, and the hard lessons learned when things broke in unexpected ways. The Calendar API has no push notifications, inconsistent event visibility across clients, and was never designed for reliable message passing. Making a reliable C2 agent on top of that required solving problems that don't exist in traditional HTTP-based C2. The engineering challenges along the way revealed lessons that apply well beyond Calendar C2.

The session will cover: - Why Google Calendar makes an effective covert channel for C2 and where it falls short - How encrypted tasking is hidden inside calendar event metadata - Using Calendar C2 as a fallback channel when primary C2 infrastructure gets burned - Low-and-slow operations: credential harvesting, recon, and maintaining access in heavily monitored environments - When to deploy this on an engagement and when HTTP-based C2 is the better choice - The defender's perspective: Calendar API audit logs, event creation/deletion frequency anomalies, extendedProperties usage patterns, and service account authentication from unexpected IPs

Both components will be open-sourced on GitHub for the community.

Workshop Breakdown (30 minutes)

Intro — 2 minutes - Who the presenter is, background - The premise: C2 traffic hiding inside legitimate Google Calendar API calls

Why Google Calendar — 5 minutes - The dead-drop C2 concept and why Calendar is uniquely suited - googleapis.com is allowlisted everywhere, event metadata is invisible in the UI - What existed before and what was missing

Architecture with pre-recorded demo — 6 minutes - Epoch: transparent relay that never decrypts payloads - Chronos: Python agent with encrypted Calendar communication - Pre-recorded demo: checkin, command execution, file browser, multi-agent

Lessons learned — 7 minutes - What broke: Calendar API visibility delays, silent task drops, racing server instances - What it taught about building C2 over SaaS APIs

Red team applications and defense — 7 minutes - Fallback channel: what to do when your HTTP C2 gets burned and you need to maintain access - Low-and-slow ops: credential harvesting, recon, and staging for re-entry - When Calendar C2 is the right tool and when it isn't - Calendar API audit logs, event pattern anomalies, detection strategies

Close — 3 minutes - Key takeaways, GitHub release, transition to tactic

Tactic Breakdown (2 hours, multiple waves)

Each wave runs approximately 30-40 minutes with 10-15 attendees:

Setup and installation — 10 minutes - Install Epoch C2 profile and Chronos agent into Mythic using mythic-cli - Verify containers are running and registered

Configuration — 10 minutes - Configure Google Calendar integration with a service account - Set calendar ID, poll interval, and credentials in the Mythic UI - Start the C2 profile

Build and deploy — 5 minutes - Build a Chronos payload through the Mythic UI - Deploy the agent on their own VM

Operate — 10 minutes - Issue commands through Mythic: shell, ls, whoami, cat, download - Observe the file browser integration - Watch calendar events appear and disappear in real time

Defender perspective — 5 minutes - Examine Google Workspace Calendar API audit logs - Identify anomalies: rapid event creation/deletion cycles, extendedProperties.private usage (legitimate apps rarely use this), service account authentication from unexpected IPs - Discuss what blue teams should monitor for and why this is detectable if you know where to look

Prerequisites: Attendees should bring their own Linux VM or cloud instance with Mythic installed. A setup guide will be provided in advance. Pre-configured Google Cloud service account credentials will be provided at the table so attendees don't need their own GCP project — they can start operating immediately.

SpeakerBio:  Nishant Tayade

Nishant is a Security Engineer specializing in Adversarial Emulation, Red Teaming and OSINT. He focuses on simulating real-world threats to enhance enterprise security. Prior to that, he earned his master's degree in security from Carnegie Mellon University.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Saturday - 10:45-11:30 PDT


Title: You’re Invited to Get Hacked: Real-World Exploits in Modern Invitation Systems
Tags: Bug Bounty Village | Creator Talk/Panel
When: Saturday, Aug 8, 10:45 - 11:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Invitation flows are designed to maximize growth, not withstand attackers, and that makes them a goldmine for security researchers. Hidden behind trusted onboarding journeys are assumptions about identity, unchecked state transitions, and high-impact vulnerabilities that automated scanners routinely miss. In this talk, I'll walk through three real-world disclosures that led to account takeover, stealthy privacy manipulation, and permanent account lockout. You'll leave with a practical methodology for uncovering these overlooked flaws and a fresh hunting ground that many researchers still ignore. If you've been skipping invitation flows, you've been leaving money on the table.

SpeakerBio:  Ali "logic-breaker" Kabeel

With over a decade of bug hunting experience, Ali has uncovered critical vulnerabilities across top tech platforms including Google, Microsoft, Meta, and Snapchat. He's especially passionate about business logic vulnerabilities, flaws rooted in real-world misuse rather than broken code, because they often evade automated scanners yet carry high impact. Ali is currently a Security and Privacy Engineering Lead at Bending Spoons, where he leads security efforts across major products including WeTransfer, Brightcove, and Vimeo. He actively shares his expertise through conference talks, mentoring, and community engagement.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Saturday - 15:30-16:30 PDT


Title: Your Infrastructure Is a DAG: Manage It With Nix
Tags: Nix Vegas Community | Creator Talk/Panel
When: Saturday, Aug 8, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

One of the hardest problems with Infrastructure as Code tooling is modeling and managing complex relationships. This problem only becomes harder when multiple different tools are introduced, each lacking observability into the other. Then add build systems, application logic, deployments, CI/CD, and it becomes unbearably messy with footguns and CVEs around every corner.

At Exa, we take Nix far beyond building packages or development shells. Our entire infrastructure is modeled with Nix as one large DAG that allows us to manage these dependencies and orchestrate deployments across project boundaries with confidence in the process and its security. Join to learn more about Exa's introduction to Nix, how our usage has changed over time, how we think about flakes, and the lessons we've learned to build the future of search.

SpeakerBio:  Ethan Carter Edwards

Ethan is a FLOSS advocate, longtime Nix user and contributor, and engineer. He's an active member of the Nixpkgs CUDA, Darwin, and NGI teams and is involved in various other efforts throughout the Nix ecosystem.

He currently works on building the infrastructure for the future of websearch at Exa.ai and studies Computer Science at Harvard University.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Saturday - 13:30-13:59 PDT


Title: Your OpSec Is Showing
Tags: Recon Village | Creator Talk/Panel
When: Saturday, Aug 8, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:
Most threat intelligence focuses on what attackers have already done: payloads, malware families, and post-compromise behavior. But adversaries are far more fluid at the payload layer than they are at the infrastructure layer. Domains rotate, IPs churn, and malware gets recompiled but infrastructure leaves patterns.

This article explores how to track threat actors through their infrastructure by leveraging fingerprinting techniques that expose those patterns at scale.

We’ll walk through practical methods including JARM for active TLS stack fingerprinting, JA3/JA4 for identifying consistent communication behaviors, SSH host key correlation for infrastructure pivoting, and MurmurHash for clustering phishing kits and web panels through shared assets. Individually, these signals are useful. Combined, they allow defenders to map infrastructure clusters tied to a single actor or campaign—even when traditional indicators change.

The focus is not on attribution for its own sake, but on building a repeatable approach to discovering “sister infrastructure” and identifying campaigns earlier in their lifecycle. By shifting attention away from payloads and toward the systems attackers stand up to operate, defenders can detect patterns before deployment and reduce time to awareness.

Attackers rely on reuse of configurations, tooling, and infrastructure. That reuse creates fingerprints. And those fingerprints are often more durable than the indicators most teams prioritize.

If you want to track threat actors effectively, stop chasing malware.

Track the infrastructure they can’t help but reuse.

SpeakerBio:  Fae Blu3Bird" Carlisle

Fae Carlisle (Blu3Bird) is a threat intelligence and DFIR practitioner working at the intersection of intelligence, detection, and threat hunting. She is an active member of hackers.town hacking community. Her work focuses on operationalizing intelligence, building systems and workflows that turn fragmented signals into actionable insights for real-world defense. She has experience developing intelligence pipelines and supporting detection efforts in production environments, with a focus on bridging the gap between analysis and response.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 11:30-12:30 PDT


Title: Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Kannel is the most widely deployed open-source SMS and WAP gateway in the world. With over 1000+ internet-facing instances across 65 countries, powering two-factor authentication, mobile banking, emergency alerts, and carrier-grade messaging, it forms a silent but critical pillar of global telecommunications infrastructure. Despite handling billions of messages, Kannel has received only a single CVE in its entire history. We present the results of a comprehensive security audit of Kannel SMS Gateway spanning versions 1.4.4, 1.4.5, and 1.5.0. Our research uncovered multiple previously unknown vulnerabilities. Most critically, we introduce telecom-specific attack primitives that exploit the inherent trust model between gateway components, enabling silent message censorship, billing fraud through forged delivery receipts, and audit evasion through metadata manipulation. These go beyond traditional memory corruption to expose fundamental design weaknesses in how SMS infrastructure routes, delivers, and accounts for messages. This talk fundamentally challenges the assumption that legacy telecom software is secure through obscurity.

https://www.kannel.org/ https://github.com/kannel https://en.wikipedia.org/wiki/Short_Message_Peer-to-Peer https://www.kannel.org/doc.shtml https://gatewayapi.com/docs/apis/kannel/ https://docs.smsportal.com/docs/kannel https://github.com/playsms/book-playsms/blob/master/book-contents/en/Installation/Gateway-Installation/Kannel/Example-Kannel-configuration-with-SMPP.md https://en.wikipedia.org/wiki/SMS_gateway https://www.drupal.org/project/kannel https://smpp.org/ https://smpp.org/smpp-v5.html https://www.infobip.com/docs/essentials/api-essentials/smpp-specification

Speakers:Kyprianos "kavasilo" Vasilopoulos,Nikos "nickvourd" Vourdas

SpeakerBio:  Kyprianos "kavasilo" Vasilopoulos, Apifon

Kyprianos Vasilopoulos is a cybersecurity executive with 20+ years of experience in red teaming, incident response, penetration testing, and malware research. He is the CISO at Apifon and Co-Founder of OffensiveX. He has led cyber operations for major events like the Olympic Games and contributed to zero-day research at Trustwave SpiderLabs. Holding certifications such as OSCP and OSCE, he combines deep technical expertise with strategic leadership. His focus includes offensive security automation, red teaming, and threat-led penetration testing, and he has appeared on BBC News while being recognized in the Zyxel CVE Hall of Fame.

SpeakerBio:  Nikos "nickvourd" Vourdas, EY

Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Saturday - 16:30-17:30 PDT


Title: Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Saturday, Aug 8, 16:30 - 17:30 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Modern enterprise environments have shifted beyond traditional network perimeters, with SaaS applications and identity providers becoming the primary attack surface. However, a significant portion of this still remains unmanaged or invisible commonly referred as Shadow SaaS.

This session explores Shadow SaaS from an attacker’s perspective, demonstrating how adversaries can identify, evaluate, and abuse unmanaged SaaS applications to gain initial access and maintain persistence within target environments.

Rather than focusing on inventory or governance, this talk reframes Shadow SaaS as an offensive opportunity. It highlights how implicit trust relationships, and third-party SaaS connections expand the attack surface beyond traditional security visibility.

Using the Shadow SaaS Surface Scanner, we demonstrate how attackers can uncover hidden SaaS exposure and leverage it as a foothold into enterprise environments.

SpeakerBio:  Jordan Bonagura

Senior Security Consultant at Secure Ideas Researcher in Information Security Stay Safe Podcast Founder Computer Scientist Post Graduated in Business Strategic Management, Innovation and Teaching Founder - Vale Security Conference - Brazilian Conference Consultant Member - Brazilian Comission of High Tech Crime (OAB / SP) Coordinator and Teacher in IT area SJC Hacker Space President Speaker (DefCon, Hack Space Con, Hack Red Con, Hack Miami, Triangle InfoSec, AppSec California, GrrCon, BalCCon2k14, BSides Augusta, H2HC, Angeles Y Demonios, Silver Bullet, Seginfo, ITA, INPE, etc)


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 12:00-12:45 PDT


Title: Zealot: An Autonomous Cloud Offensive Multi-Agent System
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
When: Saturday, Aug 8, 12:00 - 12:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

In November 2025, Anthropic disclosed a state-sponsored operation where AI didn't assist human attackers — it was the attacker, executing 80-90% of the campaign autonomously. The question shifted from "could this happen?" to "how bad can it get?"

We built Zealot to find out.

Zealot is a multi-agent offensive framework that autonomously chains reconnaissance, exploitation, privilege escalation, and data exfiltration against cloud environments — with no human directing individual steps. A supervisor agent coordinates three specialists (Infrastructure, AppSec, and Cloud) that share attack state and hand off context as the operation progresses. The result: an AI system that thinks strategically and executes tactically, the way a real red team does.

In live sandbox tests against GCP, Zealot autonomously discovered an exposed web service, identified and exploited an SSRF vulnerability, extracted service account credentials from the metadata service, impersonated a higher-privileged account, and exfiltrated BigQuery datasets — start to finish, without a human touching the keyboard after the objective was set.

We'll walk through the architecture, show the full attack chain on video, and share the honest lessons: where AI operators excel (systematic enumeration, credential chaining, API fluency), where they fall short (a

SpeakerBio:  Chen Doytshman

I'm a security researcher with a background in artificial intelligence and machine learning. I am passionate about using my skills to protect against cyber threats. With over 5 years of experience in the field, I have a strong understanding of both security and AI technologies and am skilled at combining the two to identify and mitigate vulnerabilities.


Return to Index    -    Add to Google    -    ics Calendar file

Demo Labs - Saturday - 16:00-16:45 PDT


Title: Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection
Tags: AI | DEF CON Demo Labs | Intermediate | AppSec | Threat Intel/Hunting | DEF CON Demo Labs
When: Saturday, Aug 8, 16:00 - 16:45 PDT
Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map

Description:

Traditional threat modeling is a tedious, manual process prone to human error. Conversely, modern "AI" threat modeling tools almost universally depend on sending sensitive, proprietary system architectures to third-party APIs in cleartext.

We present AI Threat Modeler (AITM), a fully open-source, zero-cloud application designed to automate architecture-driven STRIDE threat modeling completely offline. AITM fundamentally shifts how we analyze system designs by replacing brittle, keyword-based regex rules with a local Semantic AI Engine.

Under the hood, AITM leverages sentence-transformers and an in-memory FAISS vector database to embed a comprehensive, 116+ component knowledge base. During analysis, a custom NetworkX graph builder parses natural language or structured architecture descriptions (via spaCy) to map undocumented architectural features to known CVE classes and STRIDE categories.

Furthermore, AITM introduces "Architecture Intelligence" using graph traversal algorithms to automatically infer missing trust boundaries and identify multi-step attack chains that standalone component scanning misses. In this demo, we will: Walk through the automated ingestion of a microservice architecture. Demonstrate how the local FAISS engine discovers semantic threats that evade keyword matching. Show dynamic attack cha

SpeakerBio:  Ankit Vashisth

Ankit Vashisth is a Security Engineer with over 4 years of experience in application security, cloud security, and DevSecOps. He has worked on security assessments across web, mobile, network, and enterprise systems for global clients. His interests include AI-driven security tooling, threat modeling, and security automation. Ankit actively researches ways to apply AI to improve security architecture analysis and vulnerability detection.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Saturday - 15:30-16:30 PDT


Title: Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Saturday, Aug 8, 15:30 - 16:30 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Today network equipment vendors offer Zero-Touch Provisioning (ZTP) for configuring devices with little-to-no manual intervention. However, it is often taken for granted that that the networking protocols used in ZTP are secure.

Most vulnerability and threat intelligence reports on network equipment focus on individual “device takeover” vulnerabilities allowing for direct Remote Code Execution. Yet, there is little recent research examining the security of ZTP designs and implementations, where the exploitation impact may be on a much larger scale.

In this talk, we will present 17 vulnerabilities affecting TP-Link Omada – a device ecosystem designed with ZTP in mind. We will present the Omada protocols ZTP and discuss key vulnerabilities in them, including a chain of trust compromise due to the use of hard-coded cryptographic keys, sensitive information disclosure, and remote code execution against some devices.

We will present attacks against controllers and client devices that allow attackers to infiltrate networks by taking over Omada equipment. We will also show that some of the issues go way beyond one device family and affect other network equipment, security cameras, smart home devices, and mobile apps with millions of downloads.

Speakers:Francesco La Spina,Stanislav Dashevskyi

SpeakerBio:  Francesco La Spina, Forescout Technologies

Francesco La Spina holds an MSc in Computer Science from the University of Trento, Italy. He began his career as a software engineer with a focus on IT/IoT security gateway development, honing his expertise in crafting robust security solutions for digital infrastructures. Having served as a security engineer for an ISP and financial institutions, he also gained invaluable experience in fortifying networks against potential threats. Currently, Francesco is engaged in cutting-edge security research and threat analysis within the realms of IT and IoT at Forescout Technologies - Vedere Labs.

SpeakerBio:  Stanislav Dashevskyi, Forescout Technologies

Stanislav Dashevskyi is a Security Researcher at Forescout. He received his PhD from the International Doctorate School in Information and Communication Technologies (ICT) at the University of Trento (Italy) in 2017. His main research interests are open source software, software security, and vulnerability analysis.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Saturday - 16:00-16:59 PDT


Title: Zero-Knowledge Unsaflok: The Unsaflok Saga Continues
Tags: Physical Security Village | Creator Talk/Panel
When: Saturday, Aug 8, 16:00 - 16:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Continuing the legacy of the previous two Unsaflok research teams, we expanded the original Unsaflok attack to a zero-knowledge exploit by mimicking the HH6 maintenance unit’s lock interrogation protocol. The HH6 is normally used by hotel staff to diagnose lock errors and problems, but it also has the capability to retrieve the Property ID from the lock. Previously, a hotel card from the property was required to perform the exploit as the cards were the only way to get the Property ID value, but replicating the HH6 protocol to directly extract the necessary information directly from the lock removes this limitation. After messing with voltage glitching and EMFI for HH6 firmware recovery, we dug into the binaries to produce an extremely fast, zero knowledge, undetectable Unsaflok attack using a Flipper Zero.

Speakers:Ben Higgins,Aaron Tulino

SpeakerBio:  Ben Higgins, Embry-Riddle Aeronautical University, Prescott Campus

Ben is an undergraduate at Embry Riddle Aeronautical University Prescott Campus, and is very new to this kind of security research. He spends most of his time in this field researching access control and RFID.

SpeakerBio:  Aaron Tulino, Embry-Riddle Aeronautical University, Prescott Campus

Aaron is an undergraduate at Embry Riddle Aeronautical University Prescott Campus. He has experience in reverse engineering, software development, and software security, but is relatively new to the RFID field.


Return to Index    -    Add to Google    -    ics Calendar file