Talk/Event Schedule


Sunday


This Schedule is tentative and may be changed at any time. Check here, Hacker Tracker, or the nearest NFO Node for the latest.

 

Sunday - 00:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - Music - Genre: Drum & Bass - DJ XORAC

 

Sunday - 06:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - Defcon.run -

 

Sunday - 07:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - cont...(06:00-07:59 PDT) - Defcon.run -

 

Sunday - 08:00 PDT


Return to Index  -  Locations Legend
DEF CON Training - (08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - (08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - (08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan

 

Sunday - 09:00 PDT


Return to Index  -  Locations Legend
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - Sold Out - Attacking Cloud APIs from the IoT Edge - Rodney "BenevolentWorm" Beede
DEF CON Workshops - Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more. - Dallas
DEF CON Workshops - Sold Out - Post-Quantum Cryptography (PQC) for Hackers - Eric "Eijah" Anderson
DEF CON Workshops - Sold Out - Purple Protocol: Adversary emulation for everyone - Patrick "PilotPat" Raiden,Ben "Marba$" Strout,Brandon "D43m0n" Kraycirik
DEF CON Workshops - Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It - Ricardo Sanchez,Daniel Malvaceda
DEF CON Workshops - Sold Out - ICS Hack 'n Track - Pedro Cabrera,Hannes "hercules_hannes" Heck,Sam Miorelli,Jordan Sanchez
DEF CON Workshops - Sold Out - Creating Shellcode for Hackers - Bramwell "Bw3ll" Brizendine,Austin "quantumite" Norby,Micah Flack
DEF CON Workshops - Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers - Rushikesh Nandedkar
Social Gatherings/Events - Human Registration Open -

 

Sunday - 10:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - DCNextGen - Bricks in the Air -
Aerospace Village - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - Bricks in the Air -
Aerospace Village - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - ARINC 664 CTF Challenge -
Aerospace Village - SR-71 Blackbird Badge Challenge -
Aerospace Village - SpaceCOP - Catch Me If You Can -
Aerospace Village - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - MOUSE Runner & Flappy Drone -
Aerospace Village - Flight Simulator/EFB -
Aerospace Village - Drone Hacking Choose your Own Adventure -
Aerospace Village - Drone Hacking Workshop -
Aerospace Village - Mission: Compromised - Hacking a Satellite from the Ground Up -
AI Village - AI Village: Village Open -
AI Village - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - A Billion-User Blast Radius: Owning ChatGPT’s Secure Sandbox - Simcha Kosman
AI Village - (10:30-10:59 PDT) - Scaling Adversary Emulation with Autonomous Agents - Daniel Fabien
AppSec Village - (10:15-11:15 PDT) - ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries - alevsk
AppSec Village - (10:15-12:59 PDT) - Introduction to AI-Enhanced Threat Modeling Workshop - Robert Hurlbut
AppSec Village - (10:30-10:59 PDT) - From commit to compromise: securing the full pipeline with AI-assisted remediation - Filipi Pires
Biohacking Village - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - Biohacking Device Lab -
Biohacking Village - (10:30-10:59 PDT) - Wand Protocol: Full-Chain Attack on an FDA-Listed Fertility Analyzer - Gigi Xiaoqing Liu
Blacks In Cyber Village - From Practitioner to Principal: Building a Cybersecurity Business That Lasts - Tyrone E. Wilson
Bug Bounty Village - Skill Issue: A Recon Story - Ryan Bonner
Bug Bounty Village - (10:30-10:59 PDT) - Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty - Katie Paxton-Fear,Max vonBlankenburg
Bug Bounty Village - AI Cuts Both Ways: Using AI to Find More Bugs, and Finding the New Bugs AI Creates - Ciarán "monke" Cotter
Call Center Village - Call Center Village - Open -
Car Hacking Village - Car Hacking Village Open -
Car Hacking Village - (10:30-10:59 PDT) - Unlocking Vehicles by Brute-Forcing Rolling Code Systems - Danilo Erazo
Cloud Village - Tag, You’re It: Authorization Traps in AWS ABAC - Itay Saraf
Cloud Village - (10:40-11:20 PDT) - When Machines Attack Machines: Detecting AI-Autonomous Cloud Compromise at NHI Scale - Gowthamaraj Rajendran
CodeBloom - Game Time: Loops -
Contests - 5N4CK3Y -
Contests - DC's Next Top Threat Model -
Contests - Untechnical -
Contests - DEF CON Scavenger Hunt -
Contests - Darknet-NG -
Contests - Crack Me If You Can 2026 -
Contests - TeleChallenge -
Contests - HackFortress -
Contests - ?Cube -
Contests - $unL1ght Sh4d0w5 -
Contests - Beer Chilling Contraption Contest -
Contests - Cryptid Hunt -
Contests - HSPACE: AI Battlegrounds -
Contests - spyVspy 3: Rat Race -
Contests - Hacker Games -
Contests - PhreakMe -
Contests - Game Hacking Village CTF awards ceremony -
Contests - Game Hacking Village CTF Q&A / Walkthroughs -
Contests - Kubernetes CTF -
Contests - Hac-Man -
Contests - Crack the Core -
Contests - Cyber Deck Competition -
Contests - Pinball High Score Contest -
Contests - Code Cadaver: Break Every System. Save Your Friend. -
Contests - PWN UR H0M3 - DDoS CTF -
Contests - Reali7y Overrun - Contest running -
Contests - Tin Foil Hat Contest -
Contests - CMD+CTRL Cyber Range: DarkMoney -
Contests - Radio Frequency Capture the Flag -
Contests - DEF CON CTF: Benevolent Bureau of Birds -
Contests - AI Village - Hal CTF -
Contests - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - Car Hacking Village CTF -
Contests - Escalation Desk CTF -
Contests - Contest Awards -
Contests - Hacking GRC Contest -
Data Duplication Village - Last chance to pick up drives at the DDV -
DCNextGen - Cloud Village CTF: Three Azure Warmups - Cloud Village
DEF CON Groups - Lessons Learned from Building a New DEF CON Group presented by DC724 - Cliff "GritsnGravy" Friedel,Joe "jbohack"
DEF CON Groups - DEF CON Groups (DCG) -
DEF CON Talks - ESP32 as a counter-surveillance platform - Cooper "Cybertiger" Quintin,Colonel Panic,The Wrew
DEF CON Talks - This Message Was Sent by Microsoft: Turning Microsoft Apps into our Phishing Platform - Keanu "RedByte" Nys
DEF CON Talks - Shepherding the Tor network - Roger "arma" Dingledine
DEF CON Talks - Going the Distance: Long-Range Keystroke Injection via Meshtastic - Benito "paperclipsvinny" Sauceda
DEF CON Talks - (10:30-11:30 PDT) - Reversing a Recall: From ‘Noise Triggered’ to RCE - Ben Gardiner
DEF CON Talks - No Prompt Required: Pre-Task RCE in Google Gemini CLI - Elad Meged
DEF CON Talks - (10:30-11:30 PDT) - Gotta Phish 'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle - Giacomo "GiacoLenzo2109" Lenzini
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Attacking Cloud APIs from the IoT Edge - Rodney "BenevolentWorm" Beede
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more. - Dallas
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Post-Quantum Cryptography (PQC) for Hackers - Eric "Eijah" Anderson
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Purple Protocol: Adversary emulation for everyone - Patrick "PilotPat" Raiden,Ben "Marba$" Strout,Brandon "D43m0n" Kraycirik
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It - Ricardo Sanchez,Daniel Malvaceda
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - ICS Hack 'n Track - Pedro Cabrera,Hannes "hercules_hannes" Heck,Sam Miorelli,Jordan Sanchez
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Creating Shellcode for Hackers - Bramwell "Bw3ll" Brizendine,Austin "quantumite" Norby,Micah Flack
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers - Rushikesh Nandedkar
Embedded Systems Village - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - Embedded Systems Village CTF -
Embedded Systems Village - Embedded - 101 Labs -
Hackers.town - (10:30-10:59 PDT) - The Enshittified Internet and How We Can All Rewild the Internet - LambdaCalculus
Ham Radio Village - "Can it Ham" Antenna Testing - The HRV Contest Team
ICS Village - Five Million Industrial Control Systems Walk Into a Bar: What IRONMAP Found When It Scanned the Whole Internet - Matt Caldwell
IoT Village - Just Hacking Training -
IoT Village - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - Discover GE Appliances! -
IoT Village - Expose Hidden Surveillance in Everyday Tech -
IoT Village - All About UART -
IoT Village - (10:15-10:59 PDT) - Make your very own evil IoT Cat Lamp with WLED! - Nick
IoT Village - You Can't Opt Out: The Invisible Surveillance in Your Walls, Pockets, and Lives - Naomi Brockwell
La Villa Community - Tu foco IoT nunca tuvo modelo de amenazas - Andres Sabas
La Villa Community - (10:30-11:30 PDT) - Bait the Bot: Hacking Back Autonomous AI Vulnerability Scanners - Alcyon Junior
Lockpick Village - (10:15-10:45 PDT) - Intro to Lockpicking -
Lonely Hackers Club - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - Lonely Hackers Club CTF -
Lonely Hackers Club - Lonely Hackers Club - Sticker Swap Table -
Maker's Village - Makers' Village - Hacker Arts and Crafts -
Middle Easterns & Africans in Cyber Security (MEACS) - From Roots to Renaissance: The Rising Generation of Middle Eastern and African Cybersecurity - Ezz Tahoun
Misc - Coloring Reset -
Mobile Hacking Community - Mobile Hacking Community - Open -
Mobile Hacking Community - Mobile Hacking - Informal CTF -
Noob Community - Break Things, Learn Things: Hands-On Hacking for Beginners (same as Saturday) - Evolve Security Academy
Noob Community - Arcanum Security Labs -
Noob Community - Mentoring and Career Advice -
Noob Community - Kryptsec Labs -
Noob Community - No Stupid Questions -
Noob Community - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - Skillbit Labs -
Noob Community - SANS Institute NetWars Labs -
Noob Community - TCM Security Labs -
Noob Community - (10:30-11:30 PDT) - Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills - Amanda Kollmorgan
OSINT For Good Community - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - F1NDX OSINT Educational Series -
OSINT For Good Community - (10:30-10:59 PDT) - How to Profile an entire C-suite in 10 days - Sarah Muriel
OWASP Foundation - Spotlight: Choose Your Own Adventure with InfoSecMap - W. Martín Villalba
OWASP Foundation - (10:30-12:30 PDT) - 2001: Agentic Odyssey in Threat Modeling - Petra Vukmirovic
Payment Village - (10:30-10:50 PDT) - Wall of Wallets Workshop (Intro to Wall of Wallets Challenge) - Dan Borgogno
Physical Security Village - Breaking In, Evil Style: A Guide to Scaring Your CEO - Andrew Lebedinsky
Radio Frequency Village - WarDriver Meetup -
Radio Frequency Village - Radio Frequency Village Events -
Recon Village - Ghost in the Hiring Machine: How to Spot Fake Personas Before They're on Your Payroll - Michael Reimsbach,Rishi "rxerium" C
Recon Village - (10:45-11:30 PDT) - Living Off Someone Else's Inference - Redon Gashi,Armend Gashi
Red Team Village - Attack Campaign in VR - James Rice
Red Team Village - Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID - Elzer Pineda,Jose Rivas
Red Team Village - 0-Day Hunting Table: Come Join the Vulnpocalypse - Chris Haller
Red Team Village - Evil Is Always a Bad Stylist: .NET Obfuscation with Roslyn - Alexander Rodchenko,Ashley Hiram Muñoz,Eduardo Chavarro Ovalle
Red Team Village - Beyond NPPSPY: Harvesting Credentials via Windows Credential Provider Framework - Sohail Saha
Red Team Village - Beyond the Flag: How CTF Players Become Product Security Engineers - Drew Thompson,Monish Alur Gowdru
Red Team Village - Direct Network Access for Command and Control - Andrew Rioux
Scambait Village - Open Q&A -
Scambait Village - Scambait Bingo -
Scambait Village - KSCM Scambait Radio -
Social Engineering Community Village - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - (10:30-11:30 PDT) - 2027 SECVC Pre-Qualification Round - LIVE CALLS -
Social Gatherings/Events - cont...(09:00-11:59 PDT) - Human Registration Open -
Social Gatherings/Events - Music - SomaFM -
Telecom Village - (10:20-13:59 PDT) - Telecom Village CTF - T -Mobile CTF Team
The Diana Initiative - The Diana Initiative - Open time -
Voting Village - Voting Village Lab -

 

Sunday - 11:00 PDT


Return to Index  -  Locations Legend
Adversary Village - Beyond the Hype: The Real Role of Red Teams in an AI World - Michael Leibowitz,Niranjanaa Ragupathy
Aerospace Village - cont...(10:00-13:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-13:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-13:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-13:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-13:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-13:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-13:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-13:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-13:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-13:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-13:59 PDT) - Bricks in the Air -
AI Village - cont...(10:00-13:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-13:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - What is AI? Interactive, Unplugged Activity - Sam Mosley
AppSec Village - cont...(10:15-11:15 PDT) - ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries - alevsk
AppSec Village - (11:30-12:30 PDT) - search_vulns: Navigating the Fragmented Landscape of Vulnerability Data - Dustin Born,Matthias Göhring
AppSec Village - cont...(10:15-12:59 PDT) - Introduction to AI-Enhanced Threat Modeling Workshop - Robert Hurlbut
AppSec Village - Extending Shared Threat Models with the Application Attack Matrix - J Fridley
AppSec Village - (11:50-12:20 PDT) - Finding Bugs Is Easy, Patching Isn't: Build Your Own Remediation Pipeline - Mohan Kumar,Naveen
AppSec Village - Clash of Prompts: The World's First Prompt Battle Royale - Darren McNelis,Jerome Roberts
AppSec Village - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
AppSec Village - SBOM Find the Flaws - Dmitry Raidman
AppSec Village - NPM Imposters - The malware detection card game - Mackenzie
Biohacking Village - cont...(10:00-13:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-13:59 PDT) - Biohacking Device Lab -
Blacks In Cyber Village - Quantum Computing The Game Changer You Can t Ignore - Danielle Eason
Blue Team Village - You're Hired... Maybe: Inside Cybersecurity Hiring in 2026 - George Scheibe,Neha Gautam,Sherry Michael,Siddharth Kumar
Bug Bounty Village - (11:30-11:59 PDT) - Automated Discovery of Prompt Injection Vulnerabilities via Mutated Prompt Generation - Bogdan Stelee,Arnav Garg
Bug Bounty Village - Full Disclosure, Full Screen: [Informative] The Story of Bug Bounty Village Badge 2026 - Abhinav "TweetsFromPanda" Pandagale
Bug Bounty Village - (11:30-11:59 PDT) - Heavy Metal and Hidden Secrets: A Five-Year Retrospective on DEF CON Challenge Coins - Ariel "arl_rose" Garcia
Call Center Village - cont...(10:00-13:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-13:59 PDT) - Car Hacking Village Open -
Car Hacking Village - (11:30-11:59 PDT) - Stealing at the Speed of Light: The Anatomy of a Real Relay Attack tool - Robbie Galfrin
Cloud Village - The Autonomous Insider - Naveen Reddy Pogalla,Hari Pranav Arun Kumar
Cloud Village - cont...(10:40-11:20 PDT) - When Machines Attack Machines: Detecting AI-Autonomous Cloud Compromise at NHI Scale - Gowthamaraj Rajendran
Cloud Village - (11:20-11:50 PDT) - Breaking the Oracle: Building an Offensive Security Toolkit for OCI - Scott Weston
Cloud Village - (11:50-12:30 PDT) - Foxveil: Cloud-Native Loader Tradecraft on Cloudflare, Netlify, and Discord - Shani Kurtzberg,Zohar Buber
CodeBloom - Work Session: Ciphers -
Contests - cont...(10:00-11:59 PDT) - 5N4CK3Y -
Contests - cont...(10:00-11:59 PDT) - DC's Next Top Threat Model -
Contests - cont...(10:00-11:59 PDT) - Untechnical -
Contests - cont...(10:00-11:59 PDT) - DEF CON Scavenger Hunt -
Contests - cont...(10:00-11:59 PDT) - Darknet-NG -
Contests - cont...(10:00-11:59 PDT) - Crack Me If You Can 2026 -
Contests - cont...(10:00-11:59 PDT) - TeleChallenge -
Contests - cont...(10:00-11:59 PDT) - HackFortress -
Contests - cont...(10:00-11:59 PDT) - ?Cube -
Contests - cont...(10:00-11:59 PDT) - $unL1ght Sh4d0w5 -
Contests - cont...(10:00-11:59 PDT) - Beer Chilling Contraption Contest -
Contests - cont...(10:00-11:59 PDT) - Cryptid Hunt -
Contests - cont...(10:00-11:59 PDT) - HSPACE: AI Battlegrounds -
Contests - cont...(10:00-11:59 PDT) - spyVspy 3: Rat Race -
Contests - cont...(10:00-11:59 PDT) - Hacker Games -
Contests - cont...(10:00-11:59 PDT) - PhreakMe -
Contests - cont...(10:00-11:59 PDT) - Game Hacking Village CTF Q&A / Walkthroughs -
Contests - cont...(10:00-11:59 PDT) - Kubernetes CTF -
Contests - cont...(10:00-11:59 PDT) - Hac-Man -
Contests - cont...(10:00-11:59 PDT) - Crack the Core -
Contests - cont...(10:00-11:59 PDT) - Cyber Deck Competition -
Contests - cont...(10:00-11:59 PDT) - Pinball High Score Contest -
Contests - cont...(10:00-13:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-11:59 PDT) - PWN UR H0M3 - DDoS CTF -
Contests - cont...(10:00-11:59 PDT) - Reali7y Overrun - Contest running -
Contests - cont...(10:00-11:59 PDT) - Tin Foil Hat Contest -
Contests - cont...(10:00-12:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(10:00-11:59 PDT) - DEF CON CTF: Benevolent Bureau of Birds -
Contests - cont...(10:00-13:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-13:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - cont...(10:00-11:59 PDT) - Car Hacking Village CTF -
Contests - cont...(10:00-11:59 PDT) - Escalation Desk CTF -
Contests - cont...(10:00-11:59 PDT) - Hacking GRC Contest -
Crypto & Privacy Village - Cove: Compositional and Verifiable Confidential Computing Workflows - Stephanie,Robin,Erika Lee
Cryptocurrency Village - Cryptocurrency Closing Keynote - Chelsea Button,Param "P7R7M",Arjun "Peper" Suresh
DEF CON Groups - The State of DEF CON Groups - Alethe Denis,Magen Wu
DEF CON Groups - cont...(10:00-13:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - LaunchBreak: a Sip of Tea, a Click, and a Full Multi-stage Desktop Takeover - Gavin Zhong,Zhengyu Liu,Jianjia Yu
DEF CON Talks - Beyond the Ceremony: The 2026 Passkey Attack Surface - Matteo Giordano
DEF CON Talks - Gone in 60 Frames – USB Video Exploitation - Alex Plaskett,Robert Herrera
DEF CON Talks - cont...(10:30-11:30 PDT) - Reversing a Recall: From ‘Noise Triggered’ to RCE - Ben Gardiner
DEF CON Talks - (11:30-12:30 PDT) - BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft - Aaron Schulman,Jerry Yu,Yibo Wei
DEF CON Talks - cont...(10:30-11:30 PDT) - Gotta Phish 'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle - Giacomo "GiacoLenzo2109" Lenzini
DEF CON Talks - (11:30-12:30 PDT) - From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use-After-Free Vulnerability - Can Oztas,Kağan Çapar
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Attacking Cloud APIs from the IoT Edge - Rodney "BenevolentWorm" Beede
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more. - Dallas
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Post-Quantum Cryptography (PQC) for Hackers - Eric "Eijah" Anderson
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Purple Protocol: Adversary emulation for everyone - Patrick "PilotPat" Raiden,Ben "Marba$" Strout,Brandon "D43m0n" Kraycirik
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It - Ricardo Sanchez,Daniel Malvaceda
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - ICS Hack 'n Track - Pedro Cabrera,Hannes "hercules_hannes" Heck,Sam Miorelli,Jordan Sanchez
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Creating Shellcode for Hackers - Bramwell "Bw3ll" Brizendine,Austin "quantumite" Norby,Micah Flack
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers - Rushikesh Nandedkar
Embedded Systems Village - cont...(10:00-13:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-13:59 PDT) - Embedded Systems Village CTF -
Embedded Systems Village - cont...(10:00-13:59 PDT) - Embedded - 101 Labs -
Game Hacking Village - (11:30-12:30 PDT) - Yes, I froze an SNES for science - dwangoAC
Ham Radio Village - cont...(10:00-11:30 PDT) - "Can it Ham" Antenna Testing - The HRV Contest Team
ICS Village - Is Your Fridge Running? Then You Better Catch It - State of Security in Refrigeration Systems - Amir Zaltzman
IoT Village - cont...(10:00-13:59 PDT) - All About UART -
IoT Village - cont...(10:00-13:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-13:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-13:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-13:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-13:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-13:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-13:59 PDT) - Just Hacking Training -
IoT Village - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
IoT Village - (11:30-11:59 PDT) - One Firmware Flaw, 70+ Device Models: Lessons in Industrial IoT Disclosure and Mitigation - Weihan Goh,ZhengChao Wen
La Villa Community - cont...(10:30-11:30 PDT) - Bait the Bot: Hacking Back Autonomous AI Vulnerability Scanners - Alcyon Junior
La Villa Community - (11:30-11:59 PDT) - La Rosa de Guadalupe DFIR: Serie de 3 capítulos de misterio Cyber* - Victor Gomez,Horacio Bazán
Lockpick Village - The Knox Box - A Brief History(Part II) - Matthew O'Reilly
Lonely Hackers Club - cont...(10:00-13:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-13:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - cont...(10:00-11:59 PDT) - Lonely Hackers Club CTF -
Maker's Village - cont...(10:00-13:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - 3d Designing basics, 5 minute prints in Tinkercad - hunny
Mobile Hacking Community - (11:30-11:59 PDT) - IsMyPhonePwned: Analyzing Android/iOS Phones at Scale - Desnos Anthony
Mobile Hacking Community - cont...(10:00-13:59 PDT) - Mobile Hacking Community - Open -
Mobile Hacking Community - cont...(10:00-11:59 PDT) - Mobile Hacking - Informal CTF -
Noob Community - cont...(10:00-13:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-13:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-13:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-13:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-13:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-13:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-13:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-13:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:30-11:30 PDT) - Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills - Amanda Kollmorgan
Noob Community - From Command Line to Center Stage: Hack Your Way to Confident Speaking - James McQuiggan
Noob Community - (11:45-12:15 PDT) - So You Want to Be a Red Teamer? The Reality Behind the Role - Billy Giles
OSINT For Good Community - cont...(10:00-13:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(10:00-13:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - Q&A with the "How to Profile an entire C-suite in 10 days" speaker - Sarah Muriel
OSINT For Good Community - (11:30-12:45 PDT) - Disaster Intelligence - The past, present, and future of situational awareness during a crisis - Matt Green
OSINT For Good Community - (11:30-11:59 PDT) - Disaster Intelligence - The past, present, and future of situational awareness during a crisis - Matt Green
OWASP Foundation - cont...(10:30-12:30 PDT) - 2001: Agentic Odyssey in Threat Modeling - Petra Vukmirovic
OWASP Foundation - OWASP Chapter Meetup -
Physical Security Village - Physical Security is not sexy which is bad for organizations and good for red teams. - Roger Egan
Policy @ DEF CON - Strategic Resistance: How a Global Network is Fighting the Spyware Industry - - Michael Brennan,Nadine Farid Johnson,Rebekah Brown
Radio Frequency Village - cont...(10:00-13:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - cont...(10:00-11:55 PDT) - WarDriver Meetup -
Recon Village - cont...(10:45-11:30 PDT) - Living Off Someone Else's Inference - Redon Gashi,Armend Gashi
Red Team Village - cont...(10:00-14:59 PDT) - Attack Campaign in VR - James Rice
Red Team Village - cont...(10:00-11:59 PDT) - Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID - Elzer Pineda,Jose Rivas
Red Team Village - cont...(10:00-11:59 PDT) - 0-Day Hunting Table: Come Join the Vulnpocalypse - Chris Haller
Red Team Village - cont...(10:00-11:59 PDT) - Evil Is Always a Bad Stylist: .NET Obfuscation with Roslyn - Alexander Rodchenko,Ashley Hiram Muñoz,Eduardo Chavarro Ovalle
Red Team Village - Living Off WebView2: Turning Microsoft’s Browser into a Red Team Asset - Murilo Caixeta
Red Team Village - Commit, Push, Compromise: Attacking Modern GitHub Orgs - Andrew Buchanan,Max CM
Scambait Village - cont...(10:00-15:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-15:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(10:00-13:59 PDT) - Scambait Bingo -
Social Engineering Community Village - cont...(10:00-12:30 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(10:30-11:30 PDT) - 2027 SECVC Pre-Qualification Round - LIVE CALLS -
Social Engineering Community Village - (11:30-12:30 PDT) - Cold Calls -
Social Gatherings/Events - cont...(09:00-11:59 PDT) - Human Registration Open -
Social Gatherings/Events - cont...(10:00-14:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Free Ham Radio License Exams -
Telecom Village - cont...(10:20-13:59 PDT) - Telecom Village CTF - T -Mobile CTF Team
The Diana Initiative - Threat Model your Career Workshop - Chandan Vedavyas
Voting Village - cont...(10:00-13:59 PDT) - Voting Village Lab -

 

Sunday - 12:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-13:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-13:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-13:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-13:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-13:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-13:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-13:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-13:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-13:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-13:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-13:59 PDT) - Bricks in the Air -
AI Village - cont...(10:00-13:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-13:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AI Village - (12:30-12:59 PDT) - AI Village: Closing Remarks -
AI Village - Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover - Stav Cohen
AI Village - (12:30-12:59 PDT) - Leveraging Large Language Models for Policy, Regulatory, and Compliance in IoMT: Opportunities, Risks, and Safeguards - Dr. Deepti Gupta,Sai Sitharaman
AppSec Village - cont...(11:30-12:30 PDT) - search_vulns: Navigating the Fragmented Landscape of Vulnerability Data - Dustin Born,Matthias Göhring
AppSec Village - (12:45-13:45 PDT) - The Agent Asked. We Allowed. Now What? - Liran Lavi,Sarit Yerushalmi
AppSec Village - cont...(10:15-12:59 PDT) - Introduction to AI-Enhanced Threat Modeling Workshop - Robert Hurlbut
AppSec Village - cont...(11:50-12:20 PDT) - Finding Bugs Is Easy, Patching Isn't: Build Your Own Remediation Pipeline - Mohan Kumar,Naveen
AppSec Village - cont...(11:00-12:59 PDT) - Clash of Prompts: The World's First Prompt Battle Royale - Darren McNelis,Jerome Roberts
AppSec Village - cont...(11:00-12:59 PDT) - AppSec Quiz Gauntlet: Spot the Vulnerability - Avek Kolech
AppSec Village - cont...(11:00-12:59 PDT) - SBOM Find the Flaws - Dmitry Raidman
AppSec Village - cont...(11:00-12:59 PDT) - NPM Imposters - The malware detection card game - Mackenzie
Biohacking Village - cont...(10:00-13:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-13:59 PDT) - Biohacking Device Lab -
Blacks In Cyber Village - Monocultures Are Vulnerabilities: Representation and Security in STEM - Ruben Stephen
Bug Bounty Village - How We Built Xenoptic: A Walkthrough of Design, Infrastructure and Vulns! - Adham Elmosalamy,Ahmed Attalla,Yousef Awad,Kasimir Schulz
Call Center Village - cont...(10:00-13:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-13:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(11:00-12:59 PDT) - The Autonomous Insider - Naveen Reddy Pogalla,Hari Pranav Arun Kumar
Cloud Village - cont...(11:50-12:30 PDT) - Foxveil: Cloud-Native Loader Tradecraft on Cloudflare, Netlify, and Discord - Shani Kurtzberg,Zohar Buber
Cloud Village - (12:30-13:10 PDT) - Root-as-a-Service: The Hidden Runtime of Azure AI Foundry - Shani Peled
CodeBloom - Game Time: Input, Output, and Variables -
Contests - cont...(10:00-13:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - PWN UR H0M3 DDoS CTF Winner Announcements -
Contests - cont...(10:00-12:59 PDT) - CMD+CTRL Cyber Range: DarkMoney -
Contests - cont...(10:00-13:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-13:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
DCNextGen - A Teen BadgeMaker's Journey of Creation - World Machine
DEF CON Groups - cont...(10:00-13:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - Your WAF Blocked Us, That Was The Exploit - Remote Agent Takeover via Cloudflare, Sentry and Claude Zero-Day for data exfil - Barak Sternberg,Nevo Poran,Ron Bobrov
DEF CON Talks - MSIX'd Up: Weaponizing the Modern Windows App Packaging Ecosystem - Nick "zyn3rgy" Powers
DEF CON Talks - 1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud - Sammy Azdoufal
DEF CON Talks - cont...(11:30-12:30 PDT) - BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft - Aaron Schulman,Jerry Yu,Yibo Wei
DEF CON Talks - (12:30-13:30 PDT) - Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel - Angelo Frasca Caccia
DEF CON Talks - cont...(11:30-12:30 PDT) - From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use-After-Free Vulnerability - Can Oztas,Kağan Çapar
DEF CON Talks - (12:30-13:30 PDT) - CUDA've done better - Hacking Nvidia GPUs for container-escape and privilege escalation - Daniel "0xDACA" Cohen Hillel,Noam Trobishi
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Attacking Cloud APIs from the IoT Edge - Rodney "BenevolentWorm" Beede
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more. - Dallas
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Post-Quantum Cryptography (PQC) for Hackers - Eric "Eijah" Anderson
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Purple Protocol: Adversary emulation for everyone - Patrick "PilotPat" Raiden,Ben "Marba$" Strout,Brandon "D43m0n" Kraycirik
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It - Ricardo Sanchez,Daniel Malvaceda
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - ICS Hack 'n Track - Pedro Cabrera,Hannes "hercules_hannes" Heck,Sam Miorelli,Jordan Sanchez
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Creating Shellcode for Hackers - Bramwell "Bw3ll" Brizendine,Austin "quantumite" Norby,Micah Flack
DEF CON Workshops - cont...(09:00-12:59 PDT) - Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers - Rushikesh Nandedkar
Embedded Systems Village - cont...(10:00-13:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-13:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-13:59 PDT) - Embedded Systems Village CTF -
Game Hacking Village - cont...(11:30-12:30 PDT) - Yes, I froze an SNES for science - dwangoAC
Game Hacking Village - (12:30-12:59 PDT) - SH4ZAM: Accelerated Vector Math on the Sega Dreamcast - Falco Girgis
ICS Village - ThreatPatrol: Visualising the Modern Threat Landscape - Viral Maniar
ICS Village - (12:30-12:59 PDT) - Two NICs, Zero Trust: Pulling Apart a PAC Buried in Critical Infrastructure - Adam Bromiley,Sam Thom
IoT Village - cont...(10:00-13:59 PDT) - All About UART -
IoT Village - cont...(10:00-13:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-13:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-13:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-13:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-13:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-13:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(10:00-13:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(11:00-13:30 PDT) - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
La Villa Community - Red Robin: Don't Hack For Me, Hack With Me - Juan Sequeira Piedra,Jose Urena
Lonely Hackers Club - cont...(10:00-13:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-13:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Lonely Hackers Club - Lonely Hackers Club - CTF Winners Announcement -
Maker's Village - cont...(10:00-13:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - Novice design in 3d space - RedThorn
Middle Easterns & Africans in Cyber Security (MEACS) - The Dark Art of Alert Correlation: Extracting Attack Chains from Chaos - Ezz Tahoun
Middle Easterns & Africans in Cyber Security (MEACS) - Where the Authorization Boundary Goes in Agent Workflows - Mohamed Magdy AbuMuslim
Misc - Friendship Bracelets -
Mobile Hacking Community - cont...(10:00-13:59 PDT) - Mobile Hacking Community - Open -
Noob Community - cont...(10:00-13:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-13:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-13:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-13:59 PDT) - TCM Security Labs -
Noob Community - cont...(10:00-13:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-13:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-13:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-13:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(11:00-12:59 PDT) - From Command Line to Center Stage: Hack Your Way to Confident Speaking - James McQuiggan
Noob Community - cont...(11:45-12:15 PDT) - So You Want to Be a Red Teamer? The Reality Behind the Role - Billy Giles
Noob Community - (12:30-12:59 PDT) - Be your own Agent: Career Journey and Advice from IT and STEM Educator to Cybersecurity Engineer - Meghan Jacquot
OSINT For Good Community - cont...(10:00-13:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - cont...(10:00-13:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(11:30-12:45 PDT) - Disaster Intelligence - The past, present, and future of situational awareness during a crisis - Matt Green
OSINT For Good Community - (12:15-12:45 PDT) - Practical Privacy Defenses for the Paranoid - Tina "Hek8te" Shakour
OWASP Foundation - (12:30-12:59 PDT) - Source of Truth: A Field Guide for Deep Technical Research - Carley “51nk0r5w1m” Fant
OWASP Foundation - cont...(10:30-12:30 PDT) - 2001: Agentic Odyssey in Threat Modeling - Petra Vukmirovic
OWASP Foundation - cont...(11:00-13:59 PDT) - OWASP Chapter Meetup -
OWASP Foundation - Let's Play! OWASP Cornucopia Threat Modeling -
Payment Village - CAPTURE THE COIN - Announcement of the CTF Winners -
Physical Security Village - Travel Security: Viewing Risks Through the Eyes of a Hacker - Tim Roberts,Brent White
Policy @ DEF CON - Inference in the Infrastructure: Developing NIST AI RMF Resources for Resilient AI in Critical Systems - - Raymond Sheh,Martin Stanley
Policy @ DEF CON - (12:30-13:59 PDT) - Tactical Advocacy: Panel & Peer Sessions with EFF - Thorin Klosowski,Cooper "Cybertiger" Quintin,Alexis Hancock,Cindy Cohn,Rory Mir
Radio Frequency Village - cont...(10:00-13:59 PDT) - Radio Frequency Village Events -
Radio Frequency Village - RF CTF and World Wide War Drive Outbrief - RF Hackers
Recon Village - Recon on Trial: The OSINT Operator's Legal Playbook - David Cass
Recon Village - (12:30-12:59 PDT) - Building Hackbots - Jason "jhaddix" Haddix
Red Team Village - cont...(10:00-14:59 PDT) - Attack Campaign in VR - James Rice
Red Team Village - Do you feel in control? Analysis of AWS CloudControl API as an attack tool - Bleon "gl4ssesbo1" Proko
Red Team Village - From Buffer Overflow to Blackout: Chaining Attacks Against Industrial Systems - Fernando Mengali,Thiago Cunha da Silva
Red Team Village - The Air Is Hostile: RF Trust Assumptions in Modern Security Systems - Mitch Breton
Red Team Village - Living Off the IDE: From Initial Access to Covert C2 in Modern AI Code Editors - Edo Maland
Red Team Village - Agenthound: Mapping Multi-Hop Credential Chains Across MCP, A2A, and LLM Gateways - Adithyan Arun Kumar
Red Team Village - Breaking and Defending NEURO: Hands-On AI Stack Attack CTF with Cisco Secure AI - Jason Ludwig
Scambait Village - cont...(10:00-15:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-15:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(10:00-13:59 PDT) - Scambait Bingo -
Social Engineering Community Village - cont...(10:00-12:30 PDT) - Social Engineering Community Village - Open Hours -
Social Engineering Community Village - cont...(11:30-12:30 PDT) - Cold Calls -
Social Gatherings/Events - cont...(10:00-14:59 PDT) - Music - SomaFM -
Social Gatherings/Events - Friends of Bill W -
Social Gatherings/Events - cont...(11:00-12:59 PDT) - Free Ham Radio License Exams -
Telecom Village - cont...(10:20-13:59 PDT) - Telecom Village CTF - T -Mobile CTF Team
The Diana Initiative - (12:17-13:16 PDT) - Quiet Room -
The Diana Initiative - cont...(11:00-12:59 PDT) - Threat Model your Career Workshop - Chandan Vedavyas
Voting Village - cont...(10:00-13:59 PDT) - Voting Village Lab -

 

Sunday - 13:00 PDT


Return to Index  -  Locations Legend
Aerospace Village - cont...(10:00-13:59 PDT) - SpaceCOP - Catch Me If You Can -
Aerospace Village - cont...(10:00-13:59 PDT) - SR-71 Blackbird Badge Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - Nebula Showdown: Space Systems Security CTF Adventure -
Aerospace Village - cont...(10:00-13:59 PDT) - Satellites Under Attack: Hands-On Satellite Security Threat Scenarios -
Aerospace Village - cont...(10:00-13:59 PDT) - Mission: Compromised - Hacking a Satellite from the Ground Up -
Aerospace Village - cont...(10:00-13:59 PDT) - Drone Hacking Choose your Own Adventure -
Aerospace Village - cont...(10:00-13:59 PDT) - MOUSE Runner & Flappy Drone -
Aerospace Village - cont...(10:00-13:59 PDT) - Flight Simulator/EFB -
Aerospace Village - cont...(10:00-13:59 PDT) - Drone Hacking Workshop -
Aerospace Village - cont...(10:00-13:59 PDT) - Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range -
Aerospace Village - cont...(10:00-13:59 PDT) - Aviation ISAC Cybersecurity Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - ARINC 664 CTF Challenge -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down -
Aerospace Village - cont...(10:00-13:59 PDT) - DCNextGen - Bricks in the Air -
Aerospace Village - cont...(10:00-13:59 PDT) - Bricks in the Air -
AI Village - cont...(10:00-13:59 PDT) - AI Village: Village Open -
AI Village - cont...(10:00-13:59 PDT) - Cyber Mirage: Realtime Deepfake Demos - Brandon Kovacs
AppSec Village - cont...(12:45-13:45 PDT) - The Agent Asked. We Allowed. Now What? - Liran Lavi,Sarit Yerushalmi
Biohacking Village - cont...(10:00-13:59 PDT) - Embedded & Shredded: Advanced Embedded System Hacking -
Biohacking Village - cont...(10:00-13:59 PDT) - Biohacking Device Lab -
Blacks In Cyber Village - DeNISTifying Technology: Paradigm Shifting To Quantum Encryption, Post Cryptography, and Digital Forensics - Aisha Berry
Bug Bounty Village - (13:45-14:15 PDT) - Bug Bounty Village Closing Ceremony - Bug Bounty Village Staff
Call Center Village - cont...(10:00-13:59 PDT) - Call Center Village - Open -
Car Hacking Village - cont...(10:00-13:59 PDT) - Car Hacking Village Open -
Cloud Village - cont...(12:30-13:10 PDT) - Root-as-a-Service: The Hidden Runtime of Azure AI Foundry - Shani Peled
Cloud Village - Closing Talk - Jayesh Singh Chauhan
CodeBloom - What is AI? - Sam Mosley
Contests - cont...(10:00-13:59 PDT) - Code Cadaver: Break Every System. Save Your Friend. -
Contests - cont...(10:00-13:59 PDT) - AI Village - Hal CTF -
Contests - cont...(10:00-13:59 PDT) - AI Village Plays Pokemon: DEFCON Edition - Nick Ashworth
Contests - Bug Bounty Village CTF Awards - Bug Bounty Village Staff
DCNextGen - (13:30-14:30 PDT) - DCNextGen Closing Ceremonies - BiaSciLab
DEF CON Groups - cont...(10:00-13:59 PDT) - DEF CON Groups (DCG) -
DEF CON Talks - (13:30-14:59 PDT) - Contest Closing Ceremonies & Awards -
DEF CON Talks - Chaining Logical Bugs for Reliable Windows LPE - Bocheng "Crispr" Xiang,HeeChan "heegong123" Kim
DEF CON Talks - cont...(12:30-13:30 PDT) - Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel - Angelo Frasca Caccia
DEF CON Talks - (13:30-14:30 PDT) - Witchcraft Solver: Automated 0day Discovery in Stripped Binaries - Jonathan "endrazine" Brossard
DEF CON Talks - cont...(12:30-13:30 PDT) - CUDA've done better - Hacking Nvidia GPUs for container-escape and privilege escalation - Daniel "0xDACA" Cohen Hillel,Noam Trobishi
DEF CON Talks - (13:30-13:59 PDT) - Taking on the Dark Fleet... in Cyberspace! - Kenneth Miltenberger,Shane Cancilla
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
Embedded Systems Village - cont...(10:00-13:59 PDT) - Exploit Bluetooth Low Energy with BLESPloit and optional ESP32 - Slawomir Jasek
Embedded Systems Village - cont...(10:00-13:59 PDT) - Embedded - 101 Labs -
Embedded Systems Village - cont...(10:00-13:59 PDT) - Embedded Systems Village CTF -
IoT Village - cont...(10:00-13:59 PDT) - All About UART -
IoT Village - cont...(10:00-13:59 PDT) - Just Hacking Training -
IoT Village - cont...(10:00-13:59 PDT) - Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology -
IoT Village - cont...(10:00-13:59 PDT) - Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access -
IoT Village - cont...(10:00-13:59 PDT) - Cat-astrophic Hacking: Breaking Into Smart Litter Boxes -
IoT Village - cont...(10:00-13:59 PDT) - Smart Home in the Matter: Blink, Race, Attack CTF -
IoT Village - cont...(10:00-13:59 PDT) - Expose Hidden Surveillance in Everyday Tech -
IoT Village - cont...(10:00-13:59 PDT) - Discover GE Appliances! -
IoT Village - cont...(11:00-13:30 PDT) - Wi-Fi Self Defense & Hacker Hunting & For Beginners - Kody Kinzie
La Villa Community - La Villa - Closing Ceremony (ESP) -
Lockpick Village - Intro to Lockpicking -
Lonely Hackers Club - cont...(10:00-13:59 PDT) - Lonely Hackers Club - Sticker Swap Table -
Lonely Hackers Club - cont...(10:00-13:59 PDT) - Lonely Hackers Club - Lockpicking Table -
Maker's Village - cont...(10:00-13:59 PDT) - Makers' Village - Hacker Arts and Crafts -
Maker's Village - (13:30-13:59 PDT) - Visable Mending, repair and reinforce -
Middle Easterns & Africans in Cyber Security (MEACS) - MEACS Trivia, Games and Networking -
Mobile Hacking Community - cont...(10:00-13:59 PDT) - Mobile Hacking Community - Open -
Nix Vegas Community - Nix Vegas Closing Ceremony -
Nix Vegas Community - (13:30-14:30 PDT) - Unconference -
Noob Community - cont...(10:00-13:59 PDT) - Mentoring and Career Advice -
Noob Community - cont...(10:00-13:59 PDT) - Kryptsec Labs -
Noob Community - cont...(10:00-13:59 PDT) - Hack The Box DC Junior Ranger Program Challenge -
Noob Community - cont...(10:00-13:59 PDT) - Arcanum Security Labs -
Noob Community - cont...(10:00-13:59 PDT) - SANS Institute NetWars Labs -
Noob Community - cont...(10:00-13:59 PDT) - Skillbit Labs -
Noob Community - cont...(10:00-13:59 PDT) - No Stupid Questions -
Noob Community - cont...(10:00-13:59 PDT) - TCM Security Labs -
Noob Community - Noob Community - Conference Closing -
OSINT For Good Community - cont...(10:00-13:59 PDT) - F1NDX OSINT Educational Series -
OSINT For Good Community - cont...(10:00-13:59 PDT) - OSINT4Good Community - DC NextGen Content -
OSINT For Good Community - Building a Student-Led OSINT Program to Investigate Cryptocurrency Fraud - Angela Ramos
OWASP Foundation - cont...(11:00-13:59 PDT) - OWASP Chapter Meetup -
Policy @ DEF CON - cont...(12:30-13:59 PDT) - Tactical Advocacy: Panel & Peer Sessions with EFF - Thorin Klosowski,Cooper "Cybertiger" Quintin,Alexis Hancock,Cindy Cohn,Rory Mir
Radio Frequency Village - cont...(10:00-13:59 PDT) - Radio Frequency Village Events -
Red Team Village - cont...(10:00-14:59 PDT) - Attack Campaign in VR - James Rice
Red Team Village - cont...(12:00-13:59 PDT) - Do you feel in control? Analysis of AWS CloudControl API as an attack tool - Bleon "gl4ssesbo1" Proko
Red Team Village - cont...(12:00-13:59 PDT) - From Buffer Overflow to Blackout: Chaining Attacks Against Industrial Systems - Fernando Mengali,Thiago Cunha da Silva
Red Team Village - cont...(12:00-13:59 PDT) - The Air Is Hostile: RF Trust Assumptions in Modern Security Systems - Mitch Breton
Red Team Village - cont...(12:00-13:59 PDT) - Living Off the IDE: From Initial Access to Covert C2 in Modern AI Code Editors - Edo Maland
Red Team Village - M0us3: A Lightweight, Multi Session C2 Framework with a Rust based Windows Implant - Aryan Jogia
Red Team Village - Hacking the Human-in-the-Loop - Alexander "Zombie",Lee McWhorter
Scambait Village - cont...(10:00-15:59 PDT) - Open Q&A -
Scambait Village - cont...(10:00-15:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(10:00-13:59 PDT) - Scambait Bingo -
Social Gatherings/Events - cont...(10:00-14:59 PDT) - Music - SomaFM -
Telecom Village - cont...(10:20-13:59 PDT) - Telecom Village CTF - T -Mobile CTF Team
The Diana Initiative - cont...(12:17-13:16 PDT) - Quiet Room -
The Diana Initiative - The Diana Initiative - Open time -
Voting Village - cont...(10:00-13:59 PDT) - Voting Village Lab -

 

Sunday - 14:00 PDT


Return to Index  -  Locations Legend
Bug Bounty Village - cont...(13:45-14:15 PDT) - Bug Bounty Village Closing Ceremony - Bug Bounty Village Staff
CodeBloom - Work Session: Ciphers -
DCNextGen - cont...(13:30-14:30 PDT) - DCNextGen Closing Ceremonies - BiaSciLab
DEF CON Talks - cont...(13:30-14:59 PDT) - Contest Closing Ceremonies & Awards -
DEF CON Talks - Hacking Jetskis - from Sea-Don't to Sea-Doo - stacksmashing
DEF CON Talks - cont...(13:30-14:30 PDT) - Witchcraft Solver: Automated 0day Discovery in Stripped Binaries - Jonathan "endrazine" Brossard
DEF CON Talks - Talkers Without Borders: Worldwide Free Speech without an Internet Connection - T. Gwyddon "data" Owen,amp
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
Nix Vegas Community - cont...(13:30-14:30 PDT) - Unconference -
Noob Community - cont...(13:05-15:55 PDT) - Noob Community - Conference Closing -
Red Team Village - cont...(10:00-14:59 PDT) - Attack Campaign in VR - James Rice
Red Team Village - beacon injected with HOOKCHAIN 2026 - Arnold Jared Morales Yepez
Red Team Village - Ghost in the Water: Simulating a Nation-State PLC Sabotage Campaign - Blessen Thomas,Javier Hernández,Wojciech Poparda
Red Team Village - DFMI: Weaponizing MSI Installers for Fileless Code Execution - Anıl Çelik
Scambait Village - cont...(10:00-15:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(10:00-15:59 PDT) - Open Q&A -
Social Gatherings/Events - cont...(10:00-14:59 PDT) - Music - SomaFM -
Telecom Village - Telecom Village CTF Awards Ceremony -

 

Sunday - 15:00 PDT


Return to Index  -  Locations Legend
DEF CON Talks - DEF CON Closing Ceremonies & Awards - Jeff "The Dark Tangent" Moss
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan
Noob Community - cont...(13:05-15:55 PDT) - Noob Community - Conference Closing -
Scambait Village - cont...(10:00-15:59 PDT) - KSCM Scambait Radio -
Scambait Village - cont...(10:00-15:59 PDT) - Open Q&A -

 

Sunday - 16:00 PDT


Return to Index  -  Locations Legend
DEF CON Talks - cont...(15:00-17:30 PDT) - DEF CON Closing Ceremonies & Awards - Jeff "The Dark Tangent" Moss
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan

 

Sunday - 17:00 PDT


Return to Index  -  Locations Legend
DEF CON Talks - cont...(15:00-17:30 PDT) - DEF CON Closing Ceremonies & Awards - Jeff "The Dark Tangent" Moss
DEF CON Training - cont...(08:30-17:30 PDT) - Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections - Carlo Anez Mazurco,Mariana Ruiz
DEF CON Training - cont...(08:30-17:30 PDT) - Influence Operations: Tactics, Defense, and Exploitation - Greg Conti,Tom Cross
DEF CON Training - cont...(08:30-17:30 PDT) - Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access - Dawid Czagan

 

Sunday - 22:00 PDT


Return to Index  -  Locations Legend
Social Gatherings/Events - (22:30-01:59 PDT) - DEF CON After party @ LIV Fontainebleau -

Talk/Event Descriptions



Contests - Sunday - 10:00-11:59 PDT


Title: ?Cube
Tags: ?Cube | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 109 (?Cube) - Map

Description:

Redefining Boundaries. Enhancing Connectivity. Institutionalizing Control – Aperture Inc. continues to push the limits of innovation and remains committed to providing value to both stakeholders and our “customers.”

Controls are stricter. Telemetry is richer. Oversight has improved. Intelligence has emerged. Aperture has expanded—new industries, new platforms, new technologies quietly embedded into the fabric of our everyday lives. Each integration promises resilience. Every layer introduces complexity. And complexity always creates opportunity…

At the center of it all remains the ?Cube. Its defenses have hardened, its architecture improved, its surface area widened. It’s an ecosystem of physical security, web applications, communications systems, cryptography, and oh so much more.

For those already familiar—welcome back. For those encountering it for the first time, orientation will be … brief. But don’t fear, anyone can join the challenge. You will be entering an environment that demands curiosity across physical security, web applications, communications systems, cryptography, and, of course, the great unknown. Each layer builds on the last. Small oversights become structural weaknesses.

Form a team with range. Specialists matter. Coordination and curiosity matter more. The objective is simple: reach the center. If the core remains uncompromised, the team that advances the deepest into its labyrinth of challenges will be the winner. Advancement will require persistence. Errors and missteps will have consequences. Progress will not be accidental.

Welcome to the ?Cube.

Prerequisites:

A laptop will be highly recommended in order to interact with the technologies. Teams will be required.

Lockpicks, RFID tools (e.g., Proxmark/Flipper), and other "hacking" devices are recommended but not required.


Return to Index    -    Add to Google    -    ics Calendar file

Ham Radio Village - Sunday - 10:00-11:30 PDT


Title: "Can it Ham" Antenna Testing
Tags: Ham Radio Village | Can it Ham? | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 11:30 PDT
Where: LVCCW Level 3 Balcony - Map

Description:

Come check out the Can it Ham Final testing -- the best antennas get exposed to real world conditions to see just how well they radiate. Additional points will be awarded based on performance to truly determine...can it ham?

Come check out the Can it Ham Final testing

SpeakerBio:  The HRV Contest Team
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: $unL1ght Sh4d0w5
Tags: $unL1ght Sh4d0w5 | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5) - Map

Description:

“$unL1ght Sh4d0w5”: The Nirubi Challenge — Prove Your Agency

Systems shape the world.

Algorithms decide.

Policies enforce.

Machines execute.

Most people live inside those systems.

Hackers change them.

At DEF CON 34, where the theme is Agency, the question isn’t whether systems have vulnerabilities.

The question is who has the power to act on them.

Welcome to “$unL1ght Sh4d0w5: The Nirubi Challenge.”

Instead of hiding the system, we give you the blueprint: - A production-ready Linux cyber-physical system - Known vulnerabilities - A working proof-of-concept exploit - Full system disclosure

No mystery.

No guessing.

Just a cyber-physical system — and the opportunity to exercise your agency over it.

The Nirubi Mandate

Nirubi is an ancient Tamil word meaning “to prove.”

Not with theory.

Not with writeups.

With execution.

You’ve been given the knowledge.

Now prove you have the agency to act on it.

The Challenge

Your objective is simple:

Achieve remote code execution and deploy a malicious payload (e.g., ransomware payload that encrypts a sensitive file, command and control payload that takes over the cyber-physical system etc.).

Two phases.

Part 1 — Sh4d0w5 Recon

Extend the provided exploit chain and deliver a working malicious payload.

You have the vulnerabilities.

Now show us you can use them.

Part 2 — $unL1ght Horizon

If you complete Part 1, the system returns — hardened with proprietary defensive technology designed to disrupt your attack path.

Same objective.

New resistance.

Adapt your exploit and land the payload again.

The Prize

The first contestant to complete both phases wins: $10,000

Bring $unL1ght into the Sh4d0w5.

What Makes This Different

Most contests hide the system. We don’t. You’ll receive: - Full system configuration - Vulnerability details - A working proof-of-concept exploit

No blind recon. No guessing. Just a system, its weaknesses, and your ability to act. Because knowing about vulnerabilities is easy. Exploiting them is agency.

Rules & Eligibility

Additional details will be announced closer to the event.

Participant Prerequisites

Bring your own gear: - Laptop and/or smartphone/tablet - Operating system of your choice (Linux/Windows recommended) - Python - C/C++ compiler - Binary analysis and exploit development tools

Bring whatever tools you trust. Once the challenge begins, the system is in front of you. What happens next is up to your agency.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 10:00-11:59 PDT


Title: 0-Day Hunting Table: Come Join the Vulnpocalypse
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

This tactic will be a table where hackers can help find and prove 0-day vulnerabilities together at scale. The focus of this tactic is to demonstrate a hands-on methodology to find vulnerabilities, leveraging AI in an effective manner, and proving it has real impact. Then, attendees will search for their own 0-days together across a curated set of software for hunting.

We'll have a collection of 30+ applications available for immediate analysis and live service deployments to prove out the impact.

I'll bring a large LED board to track the number of 0-days found as well. This board will be updated in real-time as new vulnerabilities are found.

All 0-days will be responsibly disclosed after DefCon.

SpeakerBio:  Chris Haller

Chris brings over 15 years of experience in Penetration Testing, Incident Response, Risk Evaluation, Threat Intelligence, and System Administration. While Active Duty, Chris was the Incident Management Lead for the Navy Cyber Defense Operations Command where he specialized in response to attacks on classified and unclassified Navy networks across the globe. Throughout his career, Chris has provided actionable information for stakeholders to make informed decisions about reducing risk to the lowest possible levels, resulting in over 30 CVEs attributed to his work.

Chris has co-authored The Hack is Back: Techniques to Beat Hackers at Their Own Games and has created content on HackTheBox, TryHackMe, and Cybrary. He is an avid CTF player and has recently taken the #1 individual and #1 team position in the National Cyber League, while also operating as the Attack/Defense coach for the US Cyber Team.

Chris is a Principal Security Consultant at Omada Technologies out of Portsmouth, NH. He enjoys helping organizations find and fix complex vulnerabilities before bad actors can use them to cause harm.

Mr. Haller was awarded GIAC Security Expert #329 and has over 30 other certifications.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 12:00-12:59 PDT


Title: 1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

In March 2026, while reverse-engineering the cloud platform behind a popular line of consumer baby monitors and home security cameras, I discovered that one MQTT SUBSCRIBE wildcard returned the live message stream from every device on the platform. 1.1 million cameras. Motion alerts with image URLs. Floor plans. P2P credentials. Audio events. From baby monitors, doorbells, indoor cameras.

That was one of twelve.

This talk presents a complete vendor surveillance audit of Meari Technology — a Hangzhou-based ODM whose firmware ships under 300+ white-label brands across 118 countries. Not a single bug. Twelve independent evidence chains, each one separately demonstrating that the vendor possesses by-design, architectural access to every camera they sell. EMQX brokers with admin/public on four regions. An Apollo configuration server returning 600+ production secrets without authentication. A CMS portal with 25+ live-camera endpoints accessible to 678 employees through DingTalk SSO. A universal TUTK authcode shared across every device. Cloud video IDOR. Plain-JPEG alerts on shared OSS buckets with no per-customer isolation.

Then I'll walk through what happened after disclosure: the vendor's IPO twelve days after first contact, the backdated security advisories, the three regional brokers fixed five days apart (incident

SpeakerBio:  Sammy Azdoufal

Sammy Azdoufal is an independent security researcher and software engineer based in Barcelona. His work focuses on the cloud and mobile attack surface of consumer IoT, with an emphasis on Chinese ODM/OEM ecosystems supplying the smart-home market in Europe and North America.

In February 2026, he disclosed a critical MQTT ACL bypass affecting roughly 7,000 DJI ROMO robot vacuums across 24 countries, granting live camera and microphone access. The disclosure was covered by The Verge, Cybernews, Popular Science, The Guardian..., and led to a $30,000 bug bounty award from DJI. He is known for using AI coding assistants — specifically Anthropic's Claude Code — as part of his reverse-engineering workflow, and for combining hands-on protocol analysis with disciplined responsible-disclosure practice.

The Meari Technology audit presented in this talk was conducted between February and April 2026, with CVE coordination performed by Tod Beardsley (runZero, Inc.) and disclosure coordinated with CISA. It is his largest single-vendor IoT audit to date.

Public handle: xn0tsa (GitHub). This will be Sammy's first DEF CON Main Stage presentation.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Sunday - 10:30-12:30 PDT


Title: 2001: Agentic Odyssey in Threat Modeling
Tags: OWASP Foundation | Creator Workshop
When: Sunday, Aug 9, 10:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:
2001: Agentic Odyssey” is a hands-on, drop-in workshop where we threat model the HAL 9000 system from 2001: A Space Odyssey as if it were a modern agentic AI system (LLM + tools + permissions + side effects). I bring a HAL DFD, and together we mark trust boundaries and do classic “what can go wrong?” threat identification. Participants then split into small groups to build attack-tree branches and translate them into Fault Tree Analysis (FTA) using AND/OR logic and minimal cut sets, including lightweight probability estimates to prioritise the most likely failure chains. We finish by turning those failure paths into automation-ready test ideas (fault injection, invariants, evidence), and optionally drafting a structured HAL threat model for submission to the OWASP Threat Model Library. Designed so anyone can contribute in 10-15 minutes, while advanced participants can go deep on FTA and prioritisation. Every stage is split into a way to enable drop-ins at any time.
SpeakerBio:  Petra Vukmirovic, Project Leader, Threat Model Library at OWASP

Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led her to pivot into cyber security, earning a Master’s in Information Security and Digital Forensics.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Sunday - 10:30-11:30 PDT


Title: 2027 SECVC Pre-Qualification Round - LIVE CALLS
Tags: Social Engineering Community Village | Creator Event/Activity
When: Sunday, Aug 9, 10:30 - 11:30 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

The top five scoring teams from the SECVC Pre-Qual Lab will return to the village to put their research and pretexts into action through live vishing calls. Based on their performance, some teams may earn a spot in the 2027 Social Engineering Community Vishing Competition.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Sunday - 11:00-11:59 PDT


Title: 3d Designing basics, 5 minute prints in Tinkercad
Tags: Maker's Village | Creator Event/Activity
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Basic designing tools and functions in tinkercad by customizing your own 5 minute prints. Please sign up for tinkercad in advance.

SpeakerBio:  hunny
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: 5N4CK3Y
Tags: 5N4CK3Y | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 101 (5n4ck3y) - Map

Description:

AND!XOR builds electronic badges packed with hacker challenges, and we especially enjoy inventing unusual ways for people to earn them.

5n4ck3y is a retro snack vending machine that we’ve rebuilt into a network-connected CTF badge dispenser. Behind the woodgrain and glowing buttons is a hardware hacking project that connects a web-hosted CTF platform to a physical machine capable of vending badges to successful participants. Solve enough challenges and you’ll earn a dispense code. Enter the code into 5n4ck3y and the machine will reward you with a badge—assuming it’s in a good mood.

The challenges span a wide range of disciplines including hardware hacking, reverse engineering, OSINT, RF, network security, phreaking, and cryptography. Participants often learn something new at a DEF CON village, meet other hackers along the way, and then return to apply those skills to the challenges.

Once you earn a badge, the adventure isn’t over. Our badges are built to be explored, modified, and hacked long after they leave the machine.

5n4ck3y exists for one reason: to reward curiosity. Solve the puzzles, learn something new, and the machine might decide you deserve a badge.

Participant Prerequisites

Curiosity, persistence, access to a computer, and the willingness to RT.FM.

Our challenges are intentionally multidisciplinary and are designed to encourage exploration and collaboration. Participants will likely need to investigate hardware, software, networking, and other security topics. Many challenges are easier when working with others, so don’t be afraid to talk to people nearby or compare notes with fellow hackers.

While we won’t spoil what tools are needed this year, participants in past 5n4ck3y challenges have used a wide range of equipment including laptops, reverse engineering tools, SDR, UART adapters, hardware debuggers, soldering tools, and the occasional piece of improvised equipment.

The good news is that DEF CON is one of the best places in the world to find tools, knowledge, and people willing to help. If you don’t have something you need, chances are someone nearby does—or you can find it in a village, vendor area, or by politely asking the hacker sitting next to you.

5n4ck3y strongly encourages teamwork, creative thinking, and responsible experimentation. Snacks are optional, but curiosity is required.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 10:00-10:30 PDT


Title: A Billion-User Blast Radius: Owning ChatGPT’s Secure Sandbox
Tags: AI Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

OpenAI designed ChatGPT’s container sandbox as a secure runtime environment, enforcing full network isolation, strict execution timeouts, and an AI supervisor to filter every command. Under this model, owning the container and extracting sensitive data seemed impossible. However, we demonstrate that by chaining file-parsing abuse for persistent execution, reasoning-channel hijacking for data extraction, and shared infrastructure manipulation, an attacker can establish a Cross-tenant data exfiltration.

In this talk, we demonstrate a complete attack chain that shatters ChatGPT’s secure sandbox. By abusing spreadsheet file parsing, we bypass the LLM supervisor to gain persistent, unmonitored root execution. From there, we escalate the attack by live-patching the internal Jupyter kernel to hijack the model’s hidden python.exec reasoning channel, executing a Reasoning Injection Attack to extract sensitive user data. To exfiltrate this data, we bypass network isolation by weaponizing the Task Scheduler to launder malicious URLs past strict web guardrails.

The attack reaches its climax by exploiting a shared JFrog package manager. We engineered a signaling protocol that weaponizes globally visible authentication rate limits, translating these lockout timers into a half-duplex covert channel. This provides reliable data exfiltration and Command and Control from isolated enterprise environments to external attackers. Our exploit chain combines file parsing abuse, Chain of Thought hijacking, privilege confusion, and rate limit Denial of Service to orchestrate a Command and Control (C2) network directly inside ChatGPT.

Breaching AI sandbox agents becomes a critical vulnerability when trust boundaries are shared across millions of users. This research proves that as AI agents gain more capabilities, the attack surface expands dramatically, even when strict security constraints and mitigations are in place.

SpeakerBio:  Simcha Kosman

Simcha Kosman is a Senior Security Researcher at Palo Alto Networks with over seven years of experience in vulnerability research. He discovered his first vulnerability at age 15, earning his first bug bounty, and has since uncovered security flaws in processors, embedded systems, and large-scale open-source projects. His current work focuses on AI security, exploring the intersection of LLM and software exploitation. Simcha has presented his research in the past at BSides, Nullcon, and Black Hat.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Sunday - 12:00-12:30 PDT


Title: A Teen BadgeMaker's Journey of Creation
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Sunday, Aug 9, 12:00 - 12:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Have you ever wanted to make your own electronic badges, but not known where to start? Come listen to a teen BadgeMaker talk about his journey from zero to creating SpaceBadge (DC33) and Clip-Boy (DC34)! Enjoy stories of success and otherwise, all to help you on your path into the BadgeMaking space. Prepare yourself to create the next great badge!

SpeakerBio:  World Machine
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:
Jump into the AERIE Cyber Range to experience a number of challenges:

• PCD (Portable Cockpit Demonstrator): Attempt an RNAV approach in a simulated general aviation flight deck to your cleared runway in instrument conditions. • CCD (Cockpit Cyber Demonstrator): Fly a set of flight challenges in a simulated narrow-body airliner flight deck while managing cyber effects in the aircraft. • Virtual Tower and TRACON: Use the approach control position and an out-the-window tower view to coordinate with the PCD and CCD to help resolve the cyber scenarios running at each. • Horizon: Take the mission-controller seat for a virtual CubeSat remote-sensing mission. Run an imaging pass in the same world, at the same time, as the scenarios at the other stations. • AirVE: Watch the aircraft cyber range provide the aircraft-network model and the injected attacks behind the cyber effects the crew is managing at the cockpit stations. • OrbitVE: Watch the orbital cyber range provide satellite-constellation modeling behind the scenarios at every other station.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 12:00-12:59 PDT


Title: Agenthound: Mapping Multi-Hop Credential Chains Across MCP, A2A, and LLM Gateways
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

A developer’s MCP configuration exposes a gateway credential. That gateway holds production model keys, an A2A agent can reach it through a delegated tool, and the agent loads instructions from a repository an external contributor can modify. Each component looks harmless in isolation; together, they form a viable path from a low-trust developer environment to production systems. Modern AI infrastructure is full of these hidden chains, spanning MCP servers, agent runtimes, model gateways, local inference hosts, notebooks, and web interfaces. No file declares the entire chain, and no scanner confined to MCP, A2A, or any one AI service can reconstruct it. The most dangerous weakness in the agentic stack is often not a component - it is the trust between components.

AgentHound (https://github.com/adithyan-ak/AgentHound) is an offensive security framework that serves as BloodHound for AI agent infrastructure. Its lean Go collector maps agent clients, MCP servers, A2A agents, tools, resources, identities, credentials, and AI services; a local Neo4j-backed server correlates those observations and derives cross-service reachability to reveal attack paths such as poisoned instructions, credential reuse, impersonation, and potential execution or data exfiltration. What makes it special is its ability to merge evidence from multiple protocols and collectors into one deterministic graph, then rebuild higher-level relationships turning scattered configuration issues into concrete, explainable attack chains across the entire AI-agent ecosystem.

In this live demo, we follow one hidden attack chain end to end — from a foothold on a developer workstation to verified access to a protected, high-value resource. AgentHound discovers the local MCP configuration, connected services, tools, credentials, and resources; correlates them into a walkable attack path; and then safely tests whether that path is genuinely exploitable, upgrading the finding from inferred risk to verified evidence in real time. We finish by poisoning an MCP tool description, detecting the new attack path, and restoring the target from a recovery receipt, showing how AgentHound makes cross-system weaknesses visible, testable, explainable, and reversible.

AgentHound is open source under Apache 2.0. Version 1.0 is released and available now.

SpeakerBio:  Adithyan Arun Kumar

Adithyan Arun Kumar is an AI Security Engineer at Salesforce, specializing in AI adversarial red teaming, RAG security, and agentic threat modeling across the Agentforce ecosystem. Armed with over five years of full-spectrum offensive security experience and a MS in Information Security from Carnegie Mellon University, he holds advanced certifications including OSEP, OSWE, OSCP, and CRTP. His extensive vulnerability research and offensive tradecraft have earned him hall-of-fame acknowledgments from industry leaders such as Apple, Microsoft, and Intel.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 10:00-10:30 PDT


Title: AI Cuts Both Ways: Using AI to Find More Bugs, and Finding the New Bugs AI Creates
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:
AI is reshaping bug bounty from both sides: how hunters use it to find more bugs, and the brand-new bug classes it creates in production. Built on Hazem Elsayed's (@hacktus) research and presented by Ciarán Cotter (@monke), who delivers the talk on stage and brings additional cases from his own AI security work.
SpeakerBio:  Ciarán "monke" Cotter

Ciarán, also known as "monke", is a full-time bug bounty hunter and founder of Starstrike, an AI security startup. He is a Google AI Bugswat MVH and has won 2nd Place twice. Ciarán is also an active member of the BT6 AI hacking collective organised by Pliny the Liberator.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-13:59 PDT


Title: AI Village - Hal CTF
Tags: AI Village | HALctf (AI Village CTF) | Contest
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Get ready for the next evolution of competitive hacking at DEFCON 34! The AI Village is thrilled to introduce HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF is designed around how far you can stretch small local models that almost everyone can run. The first place prize is a DGX Spark so that you can continue your local hacking agent journey at home.

In this high-stakes arena, participants do not interact with targets directly. Instead, you will design and deploy autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, we’re asking for full containers that you can load up with all the tools you need to succeed.

To make it easy we’re hosting everything, from the targets to your agents to the models. We have a mix of old and new, and you get more points if you use smaller models. Runs are quick and show you all of the logs and points so you can improve the agent over the course of the con.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-13:59 PDT


Title: AI Village Plays Pokemon: DEFCON Edition
Tags: AI Village | AI Village Plays Pokemon: DEF CON Edition | Contest
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Agent harnesses and tooling have quickly become the AI buzzwords of 2026, but what do these even mean, and why should you consider building them? We’re showing off how custom tooling can empower local models in the most accessible way possible: playing Pokémon. Join us in this fun, novice-friendly demo where we show how to build tooling for local models, and walk through what you should and shouldn’t consider turning into tools. All the models and tools are open source, so feel free to use them to make your own agents to play our emulations of Pokémon Fire Red and Leaf Green.

SpeakerBio:  Nick Ashworth, Maker at AI Village

Nick is a Hacker and Engineer with almost 15 years of experience hacking everything from power grids to satellites for the DoD. He’s presented and made demos for Aerospace, Car Hacking, ICS, and the AI Village for the past seven years. He currently helps lead the AI Village.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 12:30-12:59 PDT


Title: AI Village: Closing Remarks
Tags: AI Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 10:00-13:59 PDT


Title: AI Village: Village Open
Tags: AI Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

We’re bringing AI Village back to focus on what actually matters: practical, no-bullshit AI security. LLMs are an amazing technology, but they’re not magic. We are stripping away the industry hype and focusing on hands-on skills, whether you are building your first exploit or leading an AI red team.

Here is what you can expect this year:

Drop-In Workshops: Walk up, grab a seat, and learn. We have drop in hands on mini-workshops on a bunch of topics. These include basic AI topics like how LLMs actually work, and how to build agents from scratch. For red teamers we have ones ranging from prompt injection to manipulating malware detection models. This is all running locally on a cluster we’re bringing to DEF CON.

HalCTF: Our main competition this year will teach you how to write and fine-tune your own pentesting agent using open-source models. To handle the massive compute load, we're safely detonating these agents on GCP, giving each participant a dedicated GPU for their models.

Other Agent Shenanigans: The field moves fast and there’s going to be something new by defcon. We’re bringing a lot of compute to host things and we’ll have some surprises in the space.

Whether you want to hear top-tier research from the people actually breaking these models or you just want to sit down and write an autonomous pentesting agent, we have the hardware and the labs ready for you.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: All About UART
Tags: IoT Village | Creator Workshop
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

UART, it’s in your smart camera, router, maybe even your phone and it’s usually the easiest foothold into a device. In this hands-on workshop you’ll learn to find it with a multimeter, read it with a logic analyzer...


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 11:00-12:59 PDT


Title: AppSec Quiz Gauntlet: Spot the Vulnerability
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map

Description:
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
SpeakerBio:  Avek Kolech
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: Arcanum Security Labs
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Arcanum Security delivers modern cybersecurity through cutting-edge training and consulting, led by Jason Haddix and crew, spanning offensive security, bug bounty hunting, and AI security. Stop by during village hours to work through their hands-on labs.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: ARINC 664 CTF Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

This is a two-part CTF activity designed to immerse participants in an aircraft’s ARINC 664 network.

Virtual Challenge – Test your skills by navigating through a series of interactive tasks that build foundational knowledge of the ARINC 664 protocol – one of the communications protocols for onboard networks. Gain a high-level understanding of how this protocol operates and its security considerations.

Hardware Challenge: Take it to the next level by engaging with model hardware. Send messages to manipulate and interact with simulated aircraft systems!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 10:00-14:59 PDT


Title: Attack Campaign in VR
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 10:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area - Map

Description:

This VR visualization experience is designed to support the exploration and understanding of complex cybersecurity scenarios for students and professionals. Cyber attack campaigns often involve intricate relationships and multi-stage processes that can be difficult to interpret, making effective analysis and remediation challenging. By leveraging visualization best practices in virtual reality, the experience presents cyber threat information in a more intuitive and interactive format, with the goal of improving comprehension, situational awareness, and the ability to identify meaningful and actionable insights.

SpeakerBio:  James Rice

Mr. James Rice has been cybersecurity faculty for the last decade in Upstate New York at Mohawk Valley Community College and more recently Rochester Institute of Technology. During this time, Mr. Rice has focused on developing numerous interactive gamified learning scenarios for the classroom and cyber competitions such as the NSA sponsored NCAE Cyber Games. Mr. Rice is currently pursuing his PhD at RIT in Computer Engineering and researching how to best leverage immersive reality technologies for data visualization and interaction, primarily in cyberspace.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 11:30-11:59 PDT


Title: Automated Discovery of Prompt Injection Vulnerabilities via Mutated Prompt Generation
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Finding one prompt injection isn't the end goal; checking how many variants still bypass your safeguarding layers is the new target. Introducing MPG, an XPIA mutation framework that generates adversarial payload variants and tests them across agentic AI systems to expose hidden vulnerability surfaces and emerging data exfiltration risks.

Speakers:Bogdan Stelee,Arnav Garg

SpeakerBio:  Bogdan Stelee, Senior Software Engineer, Microsoft

Bogdan Stelea is a Senior Software Engineer performing AI Security Research at Microsoft, working at the intersection of AI security, adversarial ML, and secure agentic system design. Bogdan develops automated frameworks for conducting variant hunting and discovering prompt injection vulnerabilities at scale. His work focuses on identifying, reproducing, and understanding vulnerabilities in modern AI copilot solutions, with a particular emphasis on cross/indirect prompt injection attacks (XPIA), tool misuse, and the expanding attack surface introduced by AI agents. Moreover, Bogdan creates learning materials and courses that clearly explain the threats introduced by XPIA. Actively engaged in the AI Security, CTF, and Bug Bounty communities, with a consistent presence at DEF CON, Bogdan has published and presented his AI security research at international academic venues, including IEEE and ACM.

SpeakerBio:  Arnav Garg, Security Researcher, Microsoft

Arnav Garg is a Security Researcher at the Microsoft Security Response Center (MSRC), specializing in AI security research, adversarial testing, and the security of Copilot and agentic AI systems. His work focuses on understanding and mitigating emerging AI threats, with particular emphasis on cross/indirect prompt injection attacks (XPIA), data exfiltration techniques, tool misuse, and the evolving attack surface introduced by AI agents. Arnav develops automated frameworks for scalable security testing and vulnerability discovery, helping advance practical defenses for next-generation AI systems. He has presented and published research on AI security, automated prompt injection discovery, and AI vulnerability testing at both internal and external venues.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Aviation ISAC Cybersecurity Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Chaos has ensued at a major international airport. Flight info displays flicker with false data. Baggage systems fail. Aircraft controls and drones (by the riverside) are compromised. Even the skies are no longer safe.

Your mission: investigate the breach, neutralize the threats, and take back control of the airport. The airport depends on you. The clock is ticking!

As a participant, your first step is to register ahead and read the rules at: https://aviationcyberctf.com/ and bring your own laptop to the venue.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Sunday - 10:30-11:30 PDT


Title: Bait the Bot: Hacking Back Autonomous AI Vulnerability Scanners
Tags: La Villa Community | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Autonomous, LLM-powered vulnerability scanners now crawl the web at scale — and every one of them shares the same structural weakness: it reads the content you control. This talk flips the engagement. Instead of just blocking the bot, your site detects that an AI agent is scanning it, fingerprints the model behind it, and fires back a hidden, tailored prompt injection that derails, poisons, or neutralizes the attacking agent — with no traditional exploit involved. We build on recent academic work on prompt-injection "hack back," push it into the reconnaissance-and-scanning threat model with live demos, walk through an escalating cat-and-mouse between attacker and defender, and take an honest look at where active defense crosses the legal line. Red teamers and blue teamers alike will leave with something they can responsibly test the same week.

SpeakerBio:  Alcyon Junior, Head of Offensive Security & Fraud Hunting at Apura

Alcyon Junior is the Head of Offensive Security & Fraud Hunting at Apura, a speaker, writer, EXIN-accredited instructor, SecurityCast (securitycast.com.br) podcaster, and professor. He holds three degrees in Information Technology with a focus on computer networks, is a Cisco-certified specialist in Computer Networks, and has an MBA in IT Governance. Alcyon earned a Master’s degree in Knowledge Management and Information Technology with a focus on Cybersecurity from the Catholic University of Brasília, and he is currently pursuing a PhD in Electrical Engineering with an emphasis on Information Security and Communications at the University of Brasília (UnB). His international certifications include CompTIA Security+, Ethical Hacking Foundation (EHF), ISO/IEC 27002 (ISFS), ITIL® Foundation, Cisco Networking Academy (CNAP), McAfee Vulnerability Manager (MVM), and Server Professional (LPIC-1)


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 12:30-12:59 PDT


Title: Be your own Agent: Career Journey and Advice from IT and STEM Educator to Cybersecurity Engineer
Tags: Noob Community | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

A career journey may have many twists and turns - mine certainly has! This talk will explore some themes from my pivot to cybersecurity and my journey through threat intelligence, a offensive security startup, and a Federally Funded Research and Development Center (FFRDC). We'll explore ways to advocate for yourself, suggestions for pivots and early career choices, and wrap it all up with thoughts on what can be next. Parts of the talk will be interactive and questions are encouraged.

So, what do you want to be and how can agency and being your own agent help you in your career journey?

SpeakerBio:  Meghan Jacquot
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 14:00-14:59 PDT


Title: beacon injected with HOOKCHAIN 2026
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

In penetration testing, we constantly find ourselves facing EDRs/AVs, etc. But as in all cases, we aim to develop our own tooling or techniques that we believe may not yet be properly mapped or detected. On this occasion, we share part of our perspective when dealing with EDRs using Machine Learning technology configured in “FULL” mode. We were able to leverage this technique combined with an encrypted payload to evade this configuration; additionally, when the payload was downloaded or shared as a “.zip,” the agent did not inspect it. Now, let’s dive a bit into the technical aspects, but especially into how it was exploited. HookChain is an advanced technique for evading EDR solutions. It is primarily used by threat actors (APTs), but it can also be applied ethically in Red Team exercises. Its main principle is to intercept the hooks that EDRs install in the operating system kernel. What is a hook? Hooks are a mechanism used by EDRs to monitor calls to Windows API functions, mainly from ntdll.dll. In this way, they can intercept and analyze suspicious behavior in real time. The HookChain technique aims to bypass this monitoring layer.

Encrypting our payload with XOR HookChain typically combines hook evasion with payload encryption; in this case, we will use XOR to avoid static signature-based detection. The shellcode is encrypted in memory and only decrypted right before execution.

We can use a string (in this case, “CHANGEMYKEY”) as the key for our XOR encryption, along with shellcode generated using msfvenom, although we can also leverage other C2 frameworks, as we will see later.

SpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master's in AI and Cybersecurity.

--

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Beer Chilling Contraption Contest
Tags: Beer Chilling Contraption Contest | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest) - Map

Description:

It’s the 21st year of the BCCC and it’s the Beer Chilling Contraption Contest this year! We can finally drink! No more beverage, we are drinking beer now, and boy do we need one. This year we thought we would mix it up and have cold beer and you all could try your hand at warming it. Unfortunately, the guys in charge of getting the ice got a bit too tan walking in this Vegas sun. A different kind of ICE deported them to Botswana and in the ensuing chaos the beverage was left outside and its warm again. Fortunately for everyone involved, WW3 and the inevitable nuclear winter will finally solve the warm beer problem -- well at least temperature-wise. It might be a little HOT in the gamma spectrum. But while we wait for Pooh Bear, BiBi, Putler, and or the Cheeto to kick this global cooling contraption off, its up to us to chill this beer.

You will cool the beer we give you in a red solo cup as quickly as possible to 34 degrees F. You may not alter the beer by mixing it with ice, dry or otherwise. You may bring a device you created or build your own at the convention. There are some great prizes waiting, mostly what I have lying around and don't want to take home. There are some additional rules, check the DEFCON forums or the poster board at the contest!

In conclusion, it’s not just a warm beverage—it’s a testament to the rich tapestry of societal collapse, seamlessly navigating the multifaceted landscape of your broken contraption.

Participant Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 10:00-10:59 PDT


Title: Beyond NPPSPY: Harvesting Credentials via Windows Credential Provider Framework
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

For years, Red Teams have relied on techniques like NPPSpy and LSASS dumping for credential harvesting. But as EDRs and defenders get smarter, these traditional paths are heavily monitored and immediately flagged. What if we could intercept credentials right at the source—the Windows Logon UI—while seamlessly bypassing Application Control solutions?

In this talk, we will journey deep into the arcane world of the Windows Credential Provider Framework and COM (Component Object Model) architecture. I will demonstrate how to build a stealthy "Middle-Man" Credential Provider that wraps around the default Windows Password Provider. By abusing interfaces like ICredentialProviderFilter and intercepting methods like GetSerialization, we can silently harvest both cleartext passwords and serialized authentication payloads.

We'll explore the COM "chicken-and-egg" instantiation process, the operational security considerations of operating inside logonui.exe, and most importantly, how this technique achieves a complete bypass of AppLocker by proxying execution through a trusted system process. Finally, we'll discuss its limitations against strict WDAC policies and how defenders can hunt for this elusive persistence mechanism.

Research Motivation & Core Concept

The core insight of this research is moving away from the highly monitored Network Provider registry keys (HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider) and LSASS memory space. Instead, this research leverages the Windows Credential Provider Framework. By writing a custom COM DLL, we can create a "wrapper" around the native Windows Password Credential Provider ({60b78e88-ead8-445c-9cfd-0b87f74ea6cd}).

To avoid drawing suspicion, the user must not see two password fields. This research utilizes the ICredentialProviderFilter interface to explicitly filter out (hide) the default Windows provider, leaving only our malicious wrapper.

Technical Insights & Evasion Mechanics

  1. COM Interface Abuse: The talk details the exact implementation of IUnknown, IClassFactory, ICredentialProvider, and ICredentialProviderCredential required to successfully trick logonui.exe into loading the malicious provider.
  2. Data Harvesting: I will break down how to extract cleartext passwords by intercepting the SetStringValue method, and how to capture serialized payloads (like NTLM hashes/Kerberos material) by intercepting GetSerialization before passing execution back to the native provider.
  3. AppLocker vs. WDAC: A major finding of this research is Application Control bypass. Because the custom DLL is loaded by logonui.exe (a highly trusted, system-level process), AppLocker is completely bypassed. However, I will also transparently discuss WDAC: under strict Enforce Mode, WDAC's CodeIntegrity checks will successfully block the unsigned DLL (Event 3033), making this a great comparative study of AppLocker vs. WDAC for defenders.
  4. OpSec Constraints: I will cover the developer-side OpSec required, such as compiling with /MT (statically linking the CRT) to avoid MSVCP140.dll dependency crashes in the logon screen, and securely saving harvested credentials via XOR encryption to C:\Windows\Temp.

Target Audience

SpeakerBio:  Sohail Saha

Sohail is a Penetration Tester at Optiv specializing in Windows internals and offsec tool development. Previously a developer at Polygon, they now leverage their software engineering background to build offensive tooling and research OS architecture. When not bypassing security controls or writing C++, he can be found playing guitar, reading, or working on their debut sci-fi novel.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 11:00-11:59 PDT


Title: Beyond the Ceremony: The 2026 Passkey Attack Surface
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Passkeys are marketed as phishing-resistant, and the WebAuthn ceremony at their center genuinely is. The catch: almost nobody runs only the ceremony. Roughly five billion passkeys are in active use (FIDO, 2026), yet only about a third of organizations use them as the primary sign-in, so a passkey almost always sits next to a weaker method. The cryptography covers only the ceremony, but the login rides on many moving parts, from the metal to the cloud: authenticator, cross-device transport, client, relying party, cloud sync, and the human who recovers the account. That is where it breaks, more often than the reputation suggests: in a recent audit, all 103 live relying parties tested were vulnerable to at least one server-side attack.

This talk pulls the scattered research into one pass over all of them, one attack per stop that survives a correct ceremony, shown in action, heaviest on the relying party where engagements land, with a suggested testing order and the sources to go deeper. You also get Passkey Editor, a Burp extension that decodes and re-encodes the vendor wrappers that make this traffic unreadable, ships preset ceremony-layer attacks, and lets you craft any relying-party manipulation by hand in intercept and Repeater.

Walk away knowing where passkey deployments break, with a tool to test them.

A curated, non-exhaustive list of the key references behind this talk.

Cultural anchor

Specifications

Academic

Government guidance

Industry data and reports

Industry and practitioner research

Conference talks (forthcoming / concurrent / recent)

Relying-party CVEs (public record, some of them)

SpeakerBio:  Matteo Giordano, Anvil Secure

Matteo Giordano is an Italy-based offensive security specialist and Security Engineer at Anvil Secure, focused on application penetration testing and offensive research, with a growing focus on AI Red Teaming and GenAI security. For the past year he has researched WebAuthn and passkeys from an attacker's perspective, mapping the real-world attack surface that sits around the protocol's cryptographic core, the work behind this talk.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 10:00-10:59 PDT


Title: Beyond the Flag: How CTF Players Become Product Security Engineers
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map

Description:
Abstract:

Capture The Flag competitions are often dismissed as “just games,” but modern Product Security teams increasingly rely on the exact skills they develop: adversarial thinking, vulnerability analysis, exploit chaining, and secure design under pressure. Whether you are an aspiring security professional or an experienced offensive security practitioner, in this session, you will learn a structured CTF-driven learning roadmap for developing practical security skills and will learn how hands-on, real-world customer-facing offensive engagements contribute to building deep product security expertise. We will also cover how AI capabilities are accelerating this journey of learning and securing the systems. Attendees will participate in a hands-on exercise to explore the challenge through the lenses of CTF problem solving, penetration testing, and Product Security.

===================================================

Introduction: (1 minute)

Session Overview: (2 mins) • During this session, you will see a practical framework to become a trusted partner in building secure applications rather than being a gatekeeper. Starting with a practical framework of learning and approaching CTFs, to using it as an offensive security practitioner to develop stronger application security capabilities. We also see how AI can accelerate and reshape modern security workflows. • In this session, attendees will be given a challenge designed to get hands-on experience of solving the CTF, creating an offensive security report, and sharing recommendations from a product security engineer's perspective to secure the applications/systems. After the session, I will review each participant's approach and award swag to the top performers.

Intended Audience: (2 mins) • Aspiring security professionals • Experienced penetration testers • Security engineers • Students entering cybersecurity

Capture the Flag (7 minutes) • What is CTF? • Why is CTF crucial? • Hands-on experience • Risk-free environment • Collaboration and teamwork • Skills that CTFs actually teach • Avoiding rabbit hole • Structured approach to learn concepts • OWASP Top 10 • Domains: APIs, Web Application, Crypto, Cloud • A few common vulnerability areas to consider: Injection, File Upload Vulnerabilites, AuthN, AuthZ, Remote Code Execution

Penetration Testing (7 minutes) • What is penetration testing? • Map skills learned in CTF to organizational context using different methods (black box, white box, and grey box testing) • What is the focus area: • Effective technical reports that include: •Details on the process: environment considerations, recon, scanning, and exploitation • List of Findings with details about: What exactly is the specific finding, Severity, Impact, How to remediate the finding

• CTF becomes pentesting when you stop asking: • Can I exploit this? • Where can I find the flag? • And start thinking: • What does this mean for customers? • How does it impact their product?

• Note: One starts to build customer trust by helping them with the business context of findings and how to reduce the risk

Product Security Engineer (7 minutes) • Shift in mindset from “find the bug” to “how do we prevent this everywhere? With the knowledge gained from CTF and real-world pentesting.” • Holistic approach of shifting left the security: • Threat Modeling • Implementing Security Best Practices: • Integration of the SAST tool into the CI/CD pipeline • Logging and monitoring • Cloud Configuration reviews • Least privileges • Vulnerability Management Comparison • Compare with the Software Engineer journey to Programming -> Data Structures -> Front End Developer -> Full Stack Developer

Resource: (2 minutes) • Ask the audience for any recommendations that helped them be strong at what they do • Provide resources that I found useful

Recap: (2 minutes) [CTF - “How do I break this to get the flag?” → Pentest - “How bad is this?” → Product Security Engineer - “How do we prevent this everywhere?”] → AI - “How do we move faster without losing depth?”

Task (2 minutes): • Give them details about the challenge environment • Explain to them the expectations • Find the flag • Penetration Test Report • Explain their approach to secure the feature (Secure Design review, SAST recommendation, how would you prevent it across the application?) • The winner will get swag

Key Takeaways: (3 minutes) • Security is not just: • Finding security gaps • Shipping reports • Security engineers become trusted partners when they: • Know the attacker's mindset • Have hands-on experience in ethical hacking • Understand product goals • Understand how systems fail • Gives practical guidance by being part of secure development with developers • Communicate risk clearly • Improve application security at scale

Q&A (5 minutes)

Speakers:Drew Thompson,Monish Alur Gowdru

SpeakerBio:  Drew Thompson

Drew Thompson is a Principal Consultant at UltraViolet Cyber, where he specializes in cybersecurity training, offensive security, and AI-enabled security practices. He designs and delivers hands-on training for security practitioners, develops technical enablement programs, and works closely with consultants and customers to translate emerging attack techniques into practical defensive capabilities. Drew is passionate about making complex security topics accessible through real-world demonstrations, interactive labs, and practical research.

SpeakerBio:  Monish Alur Gowdru

Monish Alur Gowdru is a cybersecurity professional with over 6 years of experience in application security and software development. He enjoys helping product teams to secure applications end-to-end throughout the software development lifecycle. He actively contributes to the cybersecurity community as a speaker, mentor, and judge. His ongoing involvement includes prominent work with DEF CON and BSides Edmonton.

LinkedIn: https://www.linkedin.com/in/ag-monish/


Return to Index    -    Add to Google    -    ics Calendar file

Adversary Village - Sunday - 11:00-11:30 PDT


Title: Beyond the Hype: The Real Role of Red Teams in an AI World
Tags: Adversary Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Red Teaming is about thinking and acting like an attacker to improve an organization's defenses. In practice, it is less about flashy exploits and more about providing prioritization signals, validating and improving detection capabilities, and telling compelling stories that drive meaningful security outcomes.

The rise of AI has introduced a new challenge and a new mandate. Organizations are increasingly asking Red Teams to "use AI to hack things" as both attackers and defenders race to understand what AI can and cannot do. To cut through the hype, the role of Red Teams to speak truth to power is more important than ever.

Our responsibility is to separate speculation from reality. To understand the capabilities of AI-powered attackers, assess how well our defenses stand up against them, and evaluate the risks introduced by new AI-driven attack surfaces. By doing so, we help organizations make informed decisions about where to invest, what to defend, and how to prepare for the threats that matter most.

Speakers:Michael Leibowitz,Niranjanaa Ragupathy

SpeakerBio:  Michael Leibowitz, Senior Principal Troublemaker, Oracle Red Team

Michael (@r00tkillah) has done hard-time in real-time. An old-school computer engineer by education, he spends his days hacking the mothership for a fortune 100 company. Previously, he developed and tested embedded hardware and software, fooled around with strap-on boot roms, mobile apps, office suites, and written some secure software. On nights and weekends he hacks on electronics, writes CFPs, and contributes to the NSA Playset.

SpeakerBio:  Niranjanaa Ragupathy, Security Engineer Manager, Google Red Team

Niru is a Security Engineer and Manager at Google. She leads the Offensive Security team, which focuses on hacking Google to improve its overall security. In her free time, Niru enjoys doodling and creating Capture The Flag (CTF) challenges.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Sunday - 10:00-13:59 PDT


Title: Biohacking Device Lab
Tags: Biohacking Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map

Description:

Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work.

21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 11:30-12:30 PDT


Title: BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Car dealers predominantly in the Southwestern U.S. have been pre-installing "KARR," an aftermarket anti-theft alarm system, in every car they sell. They offer these systems as an upgrade when you purchase your car, giving you smartphone-based control over your car locks and immobilizer; if you decline the offer, the dealer says they will deactivate the system. What they don't tell you: this security system is authenticated by a global shared key, so anyone who recovers that key can remotely control nearby KARR units with a smartphone.

KARR is installed in an estimated 1.4 million cars, and every vulnerable unit shipped with the same authentication key, allowing an attacker with a smartphone to unlock the doors, disable the alarm and immobilizer, and trigger the horn and lights of any KARR-equipped vehicle. The core impact is unauthorized access, which can enable burglary, OBD-II access, and escalation including the key-programmer workflow we will demonstrate; every owner with KARR installed needs to update, including those who declined the upsell or inherited it used.

We'll walk through how we discovered KARR, how KARR ends up in millions of cars, how the attack works end-to-end, and what owners can do to fix it today. We'll also show that the same recipe revealed vulnerabilities in other aftermarket BLE systems.

Our paper: Yibo Wei, Jerry Yu, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, Nishant Bhaskar, Aaron Schulman, "BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems", USENIX Security 2026. (to appear)

Aftermarket alarms: Ken Munro / Pen Test Partners, "Gone in Six Seconds: Exploiting Car Alarms", 2019. https://www.pentestpartners.com/security-blog/gone-in-six-seconds-exploiting-car-alarms/

Aftermarket alarms: VERSPRITE, "How Hackers Control & Steal Vehicles Remotely" (Carlink remote-start vulnerability). https://versprite.com/vs-labs/hacking-remote-start-system/

Automotive BLE and keyless entry: Xie et al., "Access Your Tesla without Your Awareness: Compromising Keyless Entry System of Model 3", NDSS 2023. https://www.ndss-symposium.org/ndss-paper/access-your-tesla-without-your-awareness-compromising-keyless-entry-system-of-model-3/

Automotive BLE and keyless entry: NCC Group, "Tesla BLE Phone-as-a-Key Passive Entry Vulnerable to Relay Attacks", 2022. https://www.nccgroup.com/research/technical-advisory-tesla-ble-phone-as-a-key-passive-entry-vulnerable-to-relay-attacks/

Automotive BLE and keyless entry: Francillon, Danev, Capkun, "Relay Attacks on Passive Keyless Entry and Start Systems in Modern Cars", NDSS 2011.

Foundational automotive security: Koscher et al., "Experimental Security Analysis of a Modern Automobile", IEEE S&P 2010. https://doi.org/10.1109/SP.2010.34

Foundational automotive security: Checkoway et al., "Comprehensive Experimental Analyses of Automotive Attack Surfaces", USENIX Security 2011. https://www.autosec.org/pubs/cars-usenixsec2011.pdf

BLE application-layer auth: Sivakumaran and Blasco, "A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security Landscape", USENIX Security 2019. https://www.usenix.org/conference/usenixsecurity19/presentation/sivakumaran

Measurement and tooling: WiGLE, Wireless Network Mapping. https://www.wigle.net/

Measurement and tooling: ILSpy, open-source .NET assembly browser and decompiler. https://github.com/icsharpcode/ILSpy

Speakers:Aaron Schulman,Jerry Yu,Yibo Wei

SpeakerBio:  Aaron Schulman, University of California, San Diego

Aaron Schulman is an Associate Professor at University of California, San Diego. His research group works on problems that involve gathering large-scale measurements to test whether assumptions about security, and sometimes reliability, match reality. This work often leads his students to gather data on rooftops, at fast food restaurants, gas stations, and hospitals, and while riding in cars, trains, and airplanes. He earned his PhD in Computer Science from University of Maryland, where he studied Internet reliability, and he did a postdoctoral fellowship at Stanford University, where he investigated bottlenecks in cellular infrastructure. Aaron co-discovered sensitive unencrypted data sent over GEO satellites from cellular providers, governments, militaries, and power grid operators. He also co-developed a Bluetooth credit card skimmer detector that federal and state law enforcement have used to stop millions of dollars in credit card fraud. While in Silicon Valley, he co-founded a company that helped Google improve the battery life of the Chrome web browser. This is his third year attending DEF CON.

SpeakerBio:  Jerry Yu

Jerry Yu is a wireless systems software engineer associated with the SysNet research group at University of California, San Diego. He contributed to this work by reverse-engineering the mobile apps behind the aftermarket BLE automotive control systems we studied.

SpeakerBio:  Yibo Wei, University of California, San Diego

Yibo Wei is a PhD student at University of California, San Diego, advised by Professor Aaron Schulman. He is the lead author of the forthcoming USENIX Security 2026 paper on BLE Theft Auto (under embargo), an ecosystem-wide study of aftermarket BLE-based automotive remote control systems. He led the reverse-engineering, protocol analysis, population estimation, and disclosure for this work. This will be his first time attending DEF CON.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Sunday - 08:30-17:30 PDT


Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
Tags: DEF CON Training (Paid) (4-day) | DEF CON Training
When: Sunday, Aug 9, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W221 (Training) - Map

Description:
Speakers:Carlo Anez Mazurco,Mariana Ruiz

SpeakerBio:  Carlo Anez Mazurco

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

SpeakerBio:  Mariana Ruiz
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
Tags: DEF CON Training (Paid) (4-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W221 (Training) - Map

Description:
Speakers:Carlo Anez Mazurco,Mariana Ruiz

SpeakerBio:  Carlo Anez Mazurco

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

SpeakerBio:  Mariana Ruiz
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-10:59 PDT


Title: Break Things, Learn Things: Hands-On Hacking for Beginners (same as Saturday)
Tags: Noob Community | Creator Workshop
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Same session as Saturday. You don't need years of experience to start thinking like an attacker—you just need the right environment and someone to show you the ropes. In this hands-on session, Evolve Security Academy completely bypasses the theory to walk you through the fundamentals of ethical hacking in a live, browser-accessible lab environment. You'll adopt an attacker mindset, perform real reconnaissance, run vulnerability scans, and assess live exploits firsthand. Best of all, all registered participants get 7 days of extended access to the CyberLab platform to keep hacking at their own pace after DEF CON.

SpeakerBio:  Evolve Security Academy
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 12:00-12:59 PDT


Title: Breaking and Defending NEURO: Hands-On AI Stack Attack CTF with Cisco Secure AI
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

NEURO is a realistic enterprise AI finance assistant built with an LLM gateway, RAG/vector search, tool calling, MCP integrations, guardrails, audit logs, and a downstream exfiltration simulation.

In this hands-on tactic, attendees will attack and defend the same AI stack from both red-team and blue-team perspectives in our custom CTF.

Participants will work through practical compromise paths including prompt injection, retrieval poisoning, unsafe tool use, MCP trust boundary abuse, and data exfiltration patterns. They will then inspect evidence, review guardrail and audit signals, and apply defensive controls using Cisco Secure AI capabilities such as inspection,scanning, and runtime policy hardening.

The goal is to show how modern AI systems can fail as complete stacks, not just as chat prompts, and how defenders can reason about the full chain from user input to retrieval, tools, model behavior, telemetry, and response controls.

The tactic is designed to fit a 30-120 minute wave with small groups and can be repeated for multiple attendee groups.

SpeakerBio:  Jason Ludwig

Jason is a Principle Solutions Architect with over 20 years of experience in software engineering and AI development. He specializes in advanced machine learning systems over many domains, including smart-camera AI for industrial safety, real-time predictive analytics, sentiment analysis, LLMs/Rag, and AI cybersecurity platforms. His work has been featured in Wired, Time, and TED. Jason has successfully led teams at top global organizations like World Wide Technology, Mastercard, and Monsanto, driving the delivery of large-scale, AI-enabled solutions.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Sunday - 10:00-10:30 PDT


Title: Breaking In, Evil Style: A Guide to Scaring Your CEO
Tags: Physical Security Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

You've cloned the keycards, you've bypassed the locks, and you've gotten into the building. Now what?

Convincing people to actually fix the security issues you find is always an uphill battle. It's even worse in the world of physical security, where installing new locks costs more than deploying a software patch. This talk will explore how to make your physical red teaming activity scare the $hit out of your executives. We'll establish persistence, pivot to the network, steal everything that isn't nailed down, and put dollar amounts to the impacts of your findings.

Along the way, we'll look at some of the techniques used by real-world threat actors that use physical attacks as part of their attack chains, and how you can effectively emulate the most realistic threats to your organization. Your adversaries don't stop after getting in, and neither should you.

SpeakerBio:  Andrew Lebedinsky, Security Engineer, Red Team at Microsoft

Andrew Lebedinsky is a security engineer on the Microsoft Red Team. Their fields of interest include covert entry, radio hacking, and digital countersurveillance. In their spare time they can usually be found playing Source Engine-based FPS games and overthinking what to put in "speaker bio" fields.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Sunday - 11:20-11:50 PDT


Title: Breaking the Oracle: Building an Offensive Security Toolkit for OCI
Tags: Demo 💻 | Cloud Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:20 - 11:50 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Oracle Cloud Infrastructure (OCI) is arguably one of the lesser-explored major cloud platforms from an offensive security perspective. While OCI shares many familiar IAM concepts with AWS and GCP, its identity architecture—including sentence-based IAM policies, identity domains, dynamic groups, compartment hierarchies, and cross-tenancy permissions—creates authorization relationships and privilege escalation paths that benefit from OCI-specific analysis.

To help tackle these challenges, I built OCInferno, an open-source OCI reconnaissance framework for offensive security assessments. Alongside oci-lexer-parser, an ANTLR-based parser for OCI's sentence-based IAM policies, and OCISigner, a Burp Suite extension for transparently signing OCI API requests, a pentester/blue teamer can automate enumeration, model OCI IAM relationships, and build OpenGraph-based attack paths similar to BloodHound to help visualize privilege escalation opportunities.

This talk will demonstrate how to model OCI IAM relationships and uncover OCI-specific attack paths that are difficult to spot from policy text alone. It will also cover a security issue I uncovered that was acknowledged by Oracle in the June 2026 Critical Security Patch Update under its Security-in-Depth program, illustrating how offensive security research can uncover weaknesses not only in customer environments but in the cloud platform itself. Whether you're new to OCI or already assessing cloud environments, you'll leave with a practical understanding of OCI IAM, identity-domain-aware attack path analysis, and an open-source toolkit for exploring OCI security.

SpeakerBio:  Scott Weston

Originally from Southern California and now based in Minneapolis, Scott has six years of experience in information security. As a Labs Researcher at NetSPI, he builds open-source tools and research material focused on cloud security and penetration testing across AWS, GCP, and OCI environments. His tools include gcpwn, ocinferno, oci-lexer-parser, and ocisigner.

In his spare time, he enjoys being a totally fair and impartial D&D Dungeon Master, and holding out hope that San Diego FC will advance to the MLS finals.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Bricks in the Air
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft's control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required - all target devices, materials, and interfaces are provided!

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 13:45-14:15 PDT


Title: Bug Bounty Village Closing Ceremony
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 13:45 - 14:15 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Final words, thanks, and giveaways.

SpeakerBio:  Bug Bounty Village Staff
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 13:00-13:45 PDT


Title: Bug Bounty Village CTF Awards
Tags: Bug Bounty Village | Bug Bounty Village CTF | Contest
When: Sunday, Aug 9, 13:00 - 13:45 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Join us at the Bug Bounty Village for the CTF Award Ceremony, where we celebrate the top performers of our inaugural Capture The Flag competition. During this in-person ceremony, we'll recognize the highest-ranking participants on the leaderboard and award prizes to those present. If you've competed in the CTF and secured a spot on the leaderboard, make sure to attend and claim your prize! This is a unique opportunity to honor the skill and creativity of the global hacking community and to connect with fellow researchers and organizers. We look forward to seeing you there!

SpeakerBio:  Bug Bounty Village Staff
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 13:00-13:59 PDT


Title: Building a Student-Led OSINT Program to Investigate Cryptocurrency Fraud
Tags: OSINT For Good Community | Creator Talk/Panel
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

ScamBusters is a student-facing OSINT investigation program that trains students to identify, trace, and report cryptocurrency fraud infrastructure — from pig-butchering scam domains to the wallet networks behind them. This talk shares how the program works, what students have actually found (hundreds of scam domains and wallet clusters tied to organized fraud rings), and how the reporting pipeline connects student research to real-world action.

SpeakerBio:  Angela Ramos, University of Tampa

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Sunday - 12:30-12:59 PDT


Title: Building Hackbots
Tags: Recon Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Building AI-Powered Penetration Testing Bots In this talk, we'll walk through the core design philosophy behind AI hackbots and the architecture that makes them work: single-purpose vs. multi-stage bots, context engineering for targeted prompting, and tool integration with output parsing workflows. Then we'll get hands-on. We'll live-build a functional hackbot for a common offensive task — demonstrating asset discovery, endpoint analysis, or mutation-focused testing (e.g., XSS/SSRF) — and show how context engineering and hallucination mitigation work in practice against real targets. You'll see where AI genuinely accelerates reconnaissance and web analysis, and where it falls flat if you aren't careful. We'll close with lessons on cost optimization, auditability, and integrating hackbots into actual engagements. Who should attend: Pentesters and bug bounty hunters with offensive security experience who want to meaningfully integrate AI into their workflow — not as a novelty, but as reliable tooling. What you'll walk away with: A clear mental model for when and how to build hackbots, a live demo you can replicate, and a path into the full course where you'll build seven production-ready bots from asset discovery through mutation testing.

SpeakerBio:  Jason "jhaddix" Haddix, CEO and "Hacker in Charge" at Arcanum Information Security

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.


Return to Index    -    Add to Google    -    ics Calendar file

Call Center Village - Sunday - 10:00-13:59 PDT


Title: Call Center Village - Open
Tags: Call Center Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist's desk remains almost completely unmonitored. Nobody's deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open.

And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels.

Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak.

On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you're ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34.

We've also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for.

No prior experience required. If you know how to make a phone call or type a message, you're already qualified. Equipment is provided, including laptops and ANC headsets - but you're more than welcome to bring your own devices.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Sunday - 12:00-12:15 PDT


Title: CAPTURE THE COIN - Announcement of the CTF Winners
Tags: Payment Village | $$$$$__$$$$$ | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:15 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:

Join us as we announce the winners of the Contest!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Tuesday - 08:30-17:30 PDT


Title: Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Tuesday, Aug 11, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:
SpeakerBio:  Kamel Ghali
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Monday - 08:30-17:30 PDT


Title: Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Monday, Aug 10, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:
SpeakerBio:  Kamel Ghali
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Car Hacking Village CTF
Tags: Car Hacking Village | Car Hacking Village Capture the Flag (CTF) | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Participate in CHV's CTF to learn and play with automotive technology. This year's contest features problems on smart chargers, automotive ECU harnesses, our own badge, and more! Don't worry about bringing your own automotive specific gear, we've got you covered. Stop by the village to register, get started, and get hacking.


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Sunday - 10:00-13:59 PDT


Title: Car Hacking Village Open
Tags: Car Hacking Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map

Description:

Welcome to the Car Hacking Village - a place where you can learn all about the cool technology that powers modern connected transportation. The CHV at DEF CON 34 will feature a whole race track of activities including Creator Stage presentations, a competitive CTF (with awesome prizes!), an amazing badge for sale that doubles as a fully functional car hacking tool, a scavenger hunt, and more!


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: Cat-astrophic Hacking: Breaking Into Smart Litter Boxes
Tags: IoT Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

What happens when your cat’s litter box joins the Internet of Things? Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover security risks.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 13:00-13:59 PDT


Title: Chaining Logical Bugs for Reliable Windows LPE
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

Modern Windows exploit mitigations have made memory corruption significantly harder, but reliable privilege escalation still emerges from a quieter class of bugs: logical flaws in privileged components. This talk shows how low impact Windows bugs become practical SYSTEM exploits when treated as reusable primitives over privileged resources.

We will walk through two distinct LPE chains to illustrate this concept. First, we demonstrate a novel LPE approach achieved by chaining service-level process termination with arbitrary file deletion. Second, we explore another powerful LPE path that leverages kernel- and task-driven registry creation and deletion primitives, ultimately turning attacker-controlled registry state into code execution via Performance DLL hijacking.

Speakers:Bocheng "Crispr" Xiang,HeeChan "heegong123" Kim

SpeakerBio:  Bocheng "Crispr" Xiang, Fudan Univeristy

Bocheng Xiang (@crispr_x) is a PhD candidate at Fudan University. He is listed on the MSRC MVR 2024/2025 and ranked Top #20 on the MSRC 2024 Q3 Windows Leaderboard. He has published papers at USENIX Security 2025, and his works have been accepted by PoC2025, re//verse2026 and BlackHat USA/Europe.

SpeakerBio:  HeeChan "heegong123" Kim, TeamH4C

HeeChan Kim is a security researcher and a student at Soongsil University, specializing in Windows OS internals and Local Privilege Escalation (LPE). As a winner of the DEF CON 33 CTF with team MMM and a member of TeamH4C, he actively hunts for zero-days and persistent logical flaws within complex OS architectures. He has previously presented his Windows LPE research at POC and RE//verse.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 12:30-13:30 PDT


Title: Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

System Guard Runtime Monitor was meant to be an OS integrity anchor on Windows. A kernel driver, gated behind Protected Process Light (PPL), and a runtime attestation engine running in a secure enclave. In this talk, we revisit a classic code injection technique and adapt it into what we call "Bring Your Own Vulnerable WerFaultSecure". Instead of loading a third-party vulnerable driver, we bring our own vulnerable copy of a PPL-enabled Microsoft binary and its dependencies to get code execution as a protected process. From there, we pivot into the Microsoft System Guard kernel driver, a component that was built to support the integrity attestation of kernel objects, specifically processes, but which can be abused to tamper with those exact objects instead. We will close by sharing Indicators of Compromise (IOCs), along with prevention and detection ideas for defenders, and by discussing the innovation this exploit chain brings to the offensive security landscape.

https://infocon.org/mirrors/vx%20underground%20-%202025%20June/Papers/Windows/Internals%20and%20Analysis/2022-08-02%20-%20Inside%20Windows%20Defender%20System%20Guard%20Runtime%20Monitor.pdf https://www.microsoft.com/en-us/security/blog/2018/04/19/introducing-windows-defender-system-guard-runtime-attestation/ https://googleprojectzero.blogspot.com/2018/10/injecting-code-into-windows-protected.html https://googleprojectzero.blogspot.com/2018/11/injecting-code-into-windows-protected.html https://x.com/GabrielLandau/status/1683854578767343619 https://blog.scrt.ch/2023/03/17/bypassing-ppl-in-userland-again/ https://iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html
https://github.com/Slowerzs/PPLSystem https://github.com/mdsecactivebreach/com_inject/ https://helgeklein.com/blog/anatomy-of-werfault-exe-application-crash-error-reporting/

SpeakerBio:  Angelo Frasca Caccia, SentinelOne

Angelo is a security researcher specialized in Windows Internals. He currently works at SentinelOne, where he conducts research on advanced exploits and tampering techniques targeting the Windows ecosystem. Angelo’s background also includes web application penetration testing and red teaming, particularly assume-breach adversary simulations.

Angelo is eCXD, eCPPT, eJPT and OSCP certified. He enjoys reverse engineering and programming, mostly in C/C++. His GitHub profile (https://github/lem0nSec) features his main contributions to the cybersecurity community.

Angelo has a master’s degree in International Security Studies from University of Leicester, where he graduated in 2021 with the ‘Best Campus-Based Masters Dissertation Prize’ and the ‘Best Campus-Based Masters Student Performance Prize’.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 11:00-12:59 PDT


Title: Clash of Prompts: The World's First Prompt Battle Royale
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map

Description:

Clash of Prompts is the world's first live, head-to-head AI prompt battle royale. Two developers tackle the same coding challenge, one prompt each, on the clock, while the AI generates the code live on screen. Every prompt is scored in real time on vulnerabilities, security best practices, and prompt efficiency.

Research shows 87-94% of AI-generated code ships with security flaws, even when developers try to prompt securely. This Pod is a hands-on way to see that play out: attendees write and test real prompts and watch them get scored instantly.

Speakers:Darren McNelis,Jerome Roberts

SpeakerBio:  Darren McNelis
No BIO available
SpeakerBio:  Jerome Roberts

With over 20 years of experience in cybersecurity and 15 years as a CxO, Jérôme has a proven track record in driving successful outcomes. He has been instrumental in five successful exits, including Lexsi (acquired by Orange in 2016) and Alsid (acquired by Tenable in 2021). Starting his career in deep-tech, mathematics, and engineering, Jérôme transitioned seamlessly into business leadership, leveraging his technical roots to guide strategic decisions and foster innovation in the cybersecurity landscape.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Sunday - 13:10-13:30 PDT


Title: Closing Talk
Tags: Cloud Village | Creator Talk/Panel
When: Sunday, Aug 9, 13:10 - 13:30 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:
SpeakerBio:  Jayesh Singh Chauhan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Sunday - 10:00-10:59 PDT


Title: Cloud Village CTF: Three Azure Warmups
Tags: DCNextGen | Creator Event/Activity | Youth
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

Welcome to Apex Park, where cloud-security mistakes are causing trouble throughout the park! Participants will investigate three beginner-friendly Azure challenges involving an exposed gift shop, an overpowered day pass, and an unlocked control room. They will inspect websites, investigate cloud-storage permissions, follow clues, and recover hidden flags. No access to a real Azure account or the challenge infrastructure is required. Participants interact only with intentionally vulnerable CTF resources created for learning.

SpeakerBio:  Cloud Village
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-12:59 PDT


Title: CMD+CTRL Cyber Range: DarkMoney
Tags: CMD+CTRL Cyber Range | Contest
When: Sunday, Aug 9, 10:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range) - Map

Description:

CMD+CTRL is back for our 10th year and bringing something new to show. Drop by our cyber range for hands-on web application security challenges designed for all skill levels. Come to learn, come to compete, come to break things. All are welcome, whether it's your 1st CTF or your 101st.

There is no pre-qualification, and the only participant prerequisite is "Computer with internet access."


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-13:59 PDT


Title: Code Cadaver: Break Every System. Save Your Friend.
Tags: Biohacking Village | Code Cadaver (Biohacking Village CTF) | Contest
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver) - Map

Description:
Biohacking Village Capture the Flag: Test your skills against healthcare-themed capture the flag challenges. From beginner to expert levels, there's something for everyone.

Code Cadaver: Break Every System. Save Your Friend.

Your best friend entered St. Dismas Hospital with flu-like symptoms.

He never came back.

Now his hotel room has been torn apart, his phone is still beaconing somewhere in the wreckage, and every clue points toward a hospital that seems less interested in healing people than hiding what happens to them.

Code Cadaver is Biohacking Village’s immersive healthcare cybersecurity CTF—a dark, story-driven challenge that pulls players through the connected systems of a compromised hospital and the criminal network surrounding it.

Follow wireless signals. Pivot from guest networks into production systems. Hunt through patient intake records, webcams, HL7 traffic, payment systems, RFID credentials, pager networks, infusion devices, DICOM archives, and secured medical cabinets. Every system holds another piece of the truth. Every solved challenge brings you closer to Ethan—and deeper into St. Dismas.

This is more than a collection of puzzles. It is a full-chain medical cyber-thriller built around the technologies, mistakes, dependencies, and trust relationships that keep modern healthcare running.

You will need technical skill, persistence, curiosity, and a willingness to question everything.

The hospital is closing in.

The machines are still working.

Ethan is running out of time.

Break every system. Save your friend before St. Dismas finishes what it started.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Sunday - 11:30-12:30 PDT


Title: Cold Calls
Tags: Social Engineering Community Village | Creator Event/Activity
When: Sunday, Aug 9, 11:30 - 12:30 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Ready for the hot seat? Step into the soundproof booth, grab a mystery target and three escalating objectives, and we'll place the call. Run by rekdt, Arty Boy, and Shadow Fox. First come, first served, so get your name on the Cold Call list!


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Sunday - 10:00-10:59 PDT


Title: Coloring Reset
Tags: Women in Security and Privacy (WISP) | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you're decompressing or collaborating on a shared poster, it's the perfect low-pressure space to connect, reflect, and color outside the lines.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 11:00-11:59 PDT


Title: Commit, Push, Compromise: Attacking Modern GitHub Orgs
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

GitHub is where identity, automation, and production changes all meet, which makes it a great target. Once an attacker gets in, the distance between read access and shipping malicious code to production is often a lot shorter than teams expect.

This talk covers realistic attack paths into GitHub organizations. We start with initial access: device-code phishing and abuse of trusted GitHub Apps like the GitHub CLI. Then we follow the credentials, from long-lived Personal Access Tokens sitting on developer machines to short-lived secrets like GITHUB_TOKEN that leak through logs and artifacts, and show how both enable lateral movement and privilege escalation.

Then we get into a technique we call secret stomping. Anyone with write access to a repo can overwrite an Actions secret, including protected environment secrets reviewers assume are safe. Leak the real value first, then overwrite the secret with a payload that keeps the original value intact, and the pipeline stays green while your code runs on the runner. Using the org, repo, and environment scope hierarchy, you can shadow a secret in one repo without touching others, then delete it and leave nothing behind at the org level.

We close on the defensive side with detection strategies and response playbooks built around the signals that matter, plus how to get coverage into the places GitHub is hardest to watch. Blue teams leave with a checklist for locking down identities, tokens, integrations, and workflows. Red teams leave with a map of where GitHub controls break in practice.

After the talk we're running a hands-on workshop in a private GitHub org built for this, focused on secret stomping. You'll leak a secret, stomp it with a payload that keeps the pipeline green, and use scope shadowing to exploit your way onto a sensitive runner without tripping the obvious alarms. Bring a laptop.

Speakers:Andrew Buchanan,Max CM

SpeakerBio:  Andrew Buchanan

Andrew Buchanan is a Senior Red Team Operator with over six years of offensive security experience spanning adversary simulation, penetration testing, and real-world attack execution.

Andrew has spent years conducting advanced red team engagements and security assessments across highly complex enterprise environments at one of Canada's largest financial institutions.

Andrew specializes in initial access and social engineering, having designed and delivered numerous campaigns that closely mirror real-world threat actor tradecraft. His work spans offensive operations across on-premises, cloud, and hybrid environments, with a particular focus on cloud attack surfaces, execution chains, and targeted phishing and pretexting campaigns.

SpeakerBio:  Max CM

Max leads offensive security at Figment and brings over a decade of experience spanning national security, security research, and blockchain security. He has published multiple CVEs and conducts research focused on CI/CD pipeline security, threat modeling, secure key management, and practical security controls for high-risk systems.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-10:30 PDT


Title: Contest Awards
Tags: Social Engineering Community Village | Contest
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

See who won in our village! During this time we'll present the SECVC and BOTB winners, as well as the much-coveted Dundies!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 13:30-14:59 PDT


Title: Contest Closing Ceremonies & Awards
Tags: DEF CON Official Talk
When: Sunday, Aug 9, 13:30 - 14:59 PDT
Where: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Crypto & Privacy Village - Sunday - 11:00-11:30 PDT


Title: Cove: Compositional and Verifiable Confidential Computing Workflows
Tags: Crypto & Privacy Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

Confidential computing systems involve computation over private inputs held by mutually distrusting parties while producing public, cryptographically verifiable evidence of what was computed. Trusted execution environments (TEEs) are a practical building block for these systems, enabling code to run inside hardware-encrypted enclaves that emit attestations binding a measurement of the loaded code to genuine hardware. We present Cove, a framework that composes attested computations into multi-stage, multi-party workflows structured as directed acyclic graphs. Each node runs in its own enclave, decrypts private inputs only under attestation-gated key release, and emits a certificate that downstream nodes can require as a cryptographic precondition before consuming upstream artifacts; anyone holding the workflow bytes and the TEE vendor's attestation roots can verify the whole chain non-interactively. We show that a small set of reusable primitives - confidential artifact provisioning, encrypted dynamic outputs, attested ephemeral-key channels (RA-TLS), and certificate-gated preconditions - compose into systems that lift attestation from verified code identity to verified runtime properties, and use this to express practical applications in secure AI systems including confidential AI inference, attested AI benchmarks, and training-code verification. We give an open-source reference implementation on Intel TDX via Phala Cloud's dstack and demonstrate end-to-end feasibility with an attested benchmark workflow.

Speakers:Stephanie,Robin,Erika Lee

SpeakerBio:  Stephanie

Stephanie is a research engineer working on AI security and safety. Her research interests include adversarial robustness, agent security and verifiable AI deployments. Previously, she was at Meta, where she worked on AI safety and security evaluations (CyberSecEval) and guardrails (PromptGuard, LlamaFirewall), and prior to that she worked on application security for web and mobile.

SpeakerBio:  Robin

Robin is a Member of Technical Staff at Inferact (maintainer of vLLM), working towards the best inference stack of the future. Previously he worked as a software engineer at Near Protocol, Meta, Google, and Twitter. His interests include application security, model red-teaming, distributed systems, and GPU performance optimization.

SpeakerBio:  Erika Lee

Erika Lee is a 3rd-year Math–Computer Science undergraduate student at UC San Diego and a MATS 9.1 AI Security Fellow. Her research interests are in verifiable and privacy-preserving AI, and building secure and trustworthy AI systems. She previously interned with the US Department of Defense's AI/ML portfolio and the U.S. Army, working on deploying AI/ML systems in classified environments.

Bing-Jyue Chen is a 3rd-year PhD candidate in Computer Science at UIUC. His current research focuses on zero knowledge machine learning (zkml). He is also interested in verifiable AI, privacy-preserving machine learning, and advanced cryptography.

Daniel Kang is an assistant professor at UIUC in the computer science department. His research focuses on making analytics with machine learning easy for scientists and analysts to use, and has been supported by Google, the Open Philanthropy project, Emergent Ventures, and others. He has consulted at OpenAI, Google, Microsoft, hedge funds, and other companies to support their ML deployments, and advised a number of startups.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Crack Me If You Can 2026
Tags: Crack Me If You Can 2026 | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 106 (Crack me if you can) - Map

Description:

Time is of the essence! You will have 48 hours to crack as many hashes and files as possible.

Pamama, a US-based data broker had a massive data breach. Profiles on over a billion people, containing all the information amassed about them. It is alleged that the company siphoned records from different government agencies around the world, as well. The dump was encrypted, and regulators are downplaying the breach claiming no damage was done. A bill has been fast-tracked in Congress to exempt Pamama from any investigations, including illegally shield them from GDPR violations. This led to accusations that Pamama has bought or blackmailed members of congress.

Crack the staff's accounts and encrypted files to demonstrate the extent of the exposure and the need for individuals to get restitution and compensation, and to find smoking gun evidence of collusion so that the corruption can be fully exposed before the legislation goes forward.

Participant Prerequisites

Open to all, but pre-registration is recommended. Compete in the Street class for individuals or small teams, or in Pro if you do not want to sleep all weekend. Check out past years' contests at https://contest.korelogic.com/ , or the Password Village site for an introduction to password cracking and links to other resources: https://passwordvillage.org/

Pre-Qualifications

None.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Crack the Core
Tags: Crack the Core | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 214 (Crack the Core) - Map

Description:

Welcome to Crack the Core–a true test of lockpicking skills. Competitors will work through a variety of locks ranging in different difficulties, technologies, and configurations. From standard off-the-shelf locks to evil creations from the community. Locks will be presented in a variety of ways, ranging from your traditional deadbolt to much, much more. Just wait until you see what we have in store for you…

Challenges will not only test traditional lockpicking skills but force competitors to interact with different “environments,” work through various challenges, and adapt to what's presented. Collect the most points, you go home the winner–it’s that simple…

Bring your tools. Bring your focus. The locks will be waiting.

Participant Prerequisites

Basic tools will be available for use but it is highly recommended to bring your own tools. This may include lockpicks, bypass tools, vices, etc. Destructive entry is not allowed and associated tools will not be needed.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Cryptid Hunt
Tags: Cryptid Hunt | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 203 (Cryptid Hunt) - Map

Description:

Something is already watching you.

The Cryptid Hunt is a task-oriented challenge that moves agents across the conference floor toward a truth most attendees will never find. This is not a passive experience — each clue demands action, and the path forward is never obvious.

Look carefully at what surrounds you. The next layer of any good mystery is always hiding beneath the surface. Patterns emerge for those paying attention. Signals exist for those who know how to listen.

Is this a puzzle? A test? A hunt? At its core, this is a community experience that rewards curiosity, persistence, and the willingness to go further than most people will.

The conference is your map. Maritime exploration, ancient communication, and the village of knowledge surrounding you are all part of the journey. Nothing here is coincidental.

Finishers are recognized. What awaits those who complete the hunt will not be found anywhere else at this conference. Supplies are finite. So is your time.

Your first clue is already in your hands.

— The Cryptid Hunt Team

Bureau of Unverified Phenomena · DC34

Participant Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

Cryptocurrency Village - Sunday - 11:00-11:59 PDT


Title: Cryptocurrency Closing Keynote
Tags: Cryptocurrency Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Closing the Cryptocurrency areas at DEFCON, we introduce everyone at work and their achievements during the event. We review our four major activities including the hackathon, contests, workshops, and capture the flag competition. A summary of teams, winners, and statistics indicates the degree of participation in this event. We describe what prizes were awarded and which contestants won big. A list of workshop topics follows, with instructors giving their impressions of how modern finance technology benefits from interactive learning. Finally, we give a sneak preview of what's to come in the Cryptocurrency areas (Village, Contest, Vendor, Party, Training) at DEFCON in Bahrain and how we intend to fulfill the mandate of fostering cryptocurrency exploration and hacking there.

Speakers:Chelsea Button,Param "P7R7M",Arjun "Peper" Suresh

SpeakerBio:  Chelsea Button, Cryptocurrency Education Initiative

Chelsea is a lawyer specializing in consumer finance, data and technology. She advises clients on updates in the law and defends them in litigation. She is a cryptocurrency advocate, with multiple professional publications.

SpeakerBio:  Param "P7R7M"

Param is an Electrical Engineering Student from Georgia Tech with a strong passion for and interest in crypto. Although he primarily got interested in cryptography and hardware security through a class at Georgia Tech, he is also working at a software company on crypto adoption and ease of use. With a unique blend of HW and SW skills, Param is truly enthusiastic about all aspects of crypto.

SpeakerBio:  Arjun "Peper" Suresh, Postgraduate Student, University of Wollongong in Dubai

Arjun Suresh is pursuing postgraduate studies in Cybersecurity at the University of Wollongong in Dubai, specializing in blockchain security, penetration testing, and applied cryptography. His interest in crypto security was shaped by analyzing major exchange breaches, including the Mt. Gox and Ronin Network hacks, where he studied the gap between attacker tradecraft and real-world defenses.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:30-11:30 PDT


Title: Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills
Tags: Noob Community | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:
Session Description: Technical skills might open doors in IT & Cybersecurity, but leadership, communication, and mentorship sustain growth and impact. As the field becomes more complex and critical, we must rethink how we build and lead teams. This talk highlights the soft skills that turn strong technicians into effective collaborators, trusted advisors, and emerging leaders: from coaching junior analysts to translating between the SOC and the C-suite.
Takeaways: Attendees will learn practical ways to foster teambuilding, conflict resolution, psychological safety, build mentorship pipelines, and communicate with clarity under pressure.
Target audiences: Everyone
SpeakerBio:  Amanda Kollmorgan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 12:30-13:30 PDT


Title: CUDA've done better - Hacking Nvidia GPUs for container-escape and privilege escalation
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 12:30 - 13:30 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

CUDA've done better - Hacking Nvidia GPUs for container-escape and privilege escalation. We found and exploited a UAF in the NVIDIA Linux kernel module that allows us to escape NVIDIA containers and gain root access on the host. We'll show novel exploitation techniques: bypass kernel heap mitigations, deterministically win races by abusing rw_semaphore, and execute code on the kernel without ever jumping anywhere (by writing directly to physical memory).

Speakers:Daniel "0xDACA" Cohen Hillel,Noam Trobishi

SpeakerBio:  Daniel "0xDACA" Cohen Hillel

I used to be a vulnerability researcher for the army, but now that I'm a full time physics grad student researching superconducting quantum computers at the Weizmann Institute (very unrelated to hacking).

I just love hacking so much that I still do it in my spare time, while not doing physics. I like using hacking as an excuse to learn and deeply understand stuff. NVIDIA is a good example. I wanted to learn more about GPUs because of all the latest advancements in AI, so instead of seeing a tutorial/lecture about it, I just opened the code and started researching it. Another good example is when I hacked Merkle trees to learn more about zero-knowledge proofs.

SpeakerBio:  Noam Trobishi, Atom

Noam is a low-level systems, GPU, and vulnerability researcher at Atom, where he works on GPU infrastructure for AI. He previously served in an IDF cyber unit and later worked as a vulnerability researcher at a private cybersecurity company. Noam holds a B.Sc. in Computer Science and Mathematics from the Hebrew University of Jerusalem and is currently pursuing a master’s degree in Mathematics at the Hebrew University.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Cyber Deck Competition
Tags: Maker's Village | Contest | Cyber Deck Makers’ Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

The cyber deck contest at DEF CON 34 encourages makers of all types to create their own cyber deck. Winners will be judged on form, function, creativity, does it work, general, awesomeness, and complexity.

Stop by Makers' Village for more info!

Judging Criteria

Rules

  1. Must be present to enter.
  2. Winners are determined by points awarded by the judges.
  3. Rules are subject to change.

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 10:00-13:59 PDT


Title: Cyber Mirage: Realtime Deepfake Demos
Tags: AI Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become.

SpeakerBio:  Brandon Kovacs

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at offensive cybersecurity firm Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets. Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on the intersection of offensive cybersecurity and artificial intelligence.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Darknet-NG
Tags: Darknet-NG | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 105 (Darknet-NG) - Map

Description:

Darknet-NG is an Alternate Reality Game (ARG), where the players take on the Persona of an Agent who is sent on Quests to learn real skills and gain in-game points. If this is your first time at DEF CON, this is a great place to start, because we assume no prior knowledge. Building from basic concepts, we teach agents about a range of topics from Lock-picking, to using and decoding ciphers, to Electronics 101, just to name a few, all while also helping to connect them to the larger DEF CON Community. The "Learning Quests" help the agent gather knowledge from all across the other villages at the conference, while the "Challenge Quests" help hone their skills! Sunday Morning there is a BOSS FIGHT where the Agents must use their combined skills as a community and take on that year's final challenge! There is a whole skill tree of personal knowledge to obtain, community to connect with and memories to make! To get started, check out our site https://darknet-ng.network and join our growing Community!

Participant Prerequisites

Prerequisites for competing in the contest would require a device with access to a web browser like a Phone, Tablet, Laptop.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: DC's Next Top Threat Model
Tags: DC's Next Top Threat Model | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 102 (DC's Next Top Threat Model) - Map

Description:

Threat Modeling is arguably the single most important activity in an application security program and if performed early can identify a wide range of potential flaws before a single line of code has been written. While being so critically important there is no single correct way to perform Threat Modeling, many techniques, methodologies and/or tools exist.

As part of our challenge we will present contestants with the exact same design and compare the outputs they produce against a number of categories in order to identify a winner and crown DEF CON’s Next Top Threat Model(er).

Participant Prerequisites

A laptop is recommended, a smartphone could be used but will be less than idea. Internet access to retrieve the design materials and to submit findings and access to the email used during registration.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: DCNextGen - Bricks in the Air
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft's control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required - all target devices, materials, and interfaces are provided!

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

RIC-1, tail number N3VR-G0N, has gone down! You need to use radio direction-finding (RDF) techniques to locate Emergency Locator Transmitter (ELT), report its position, and help rescue our missing pilot!

Participants will use the provided handheld DF equipment provided by the Village, or bring your own, to triangulate the hidden transmitter location within the village area. Your handheld radio must be capable of receiving on the designated frequency with a directional antenna or attenuator. Once you've located RIC-1, listen closely... you may recognize the beacon's "distress tone." It appears to be broadcasting an audio payload that responders have described as "oddly catchy" and "impossible to stop once you start listening." Bring your comfortable shoes and strong will to ensure you never give up until you find our missing pilot!

No prior RDF experience required - volunteers can walk you through basic triangulation techniques before you start this 15-30 minute event.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

The MOUSE-1 satellite is currently in Safe Mode, and its attitude and heading systems are behaving unexpectedly. Ground control needs answers NOW!

You are a newly assigned Mission Specialist, and it's your job to figure out what's going on. Work through five sequential challenge missions aboard a simulated HUD - complete with live orbital tracking, optical camera feeds, and attitude telemetry - to triage MOUSE-1, uncover what happened, and make it operational again.

Participants will learn how satellites operate, how they stay secure in orbit, and what happens when they don't - using a fully browser-based, gamified interface developed by California Polytechnic State University students.

Just grab a seat in front of the provided station, no prior cybersecurity or aerospace experience required! Each mission is self-guided with built-in instructions, and volunteers are available to assist. Both beginner and experienced participants will find this 30-minute event challenging and fun.


Return to Index    -    Add to Google    -    ics Calendar file

DCNextGen - Sunday - 13:30-14:30 PDT


Title: DCNextGen Closing Ceremonies
Tags: DCNextGen | Creator Talk/Panel | Youth
When: Sunday, Aug 9, 13:30 - 14:30 PDT
Where: LVCCW Level 3 W316 (DC NextGen) - Map

Description:

And just like that, it's a wrap! While we're sad to see the fun end, we want to give everyone one last big thank you.

Join us to say goodbye to new friends and hear about all the cool plans we have for next year. We'll also be handing out prizes for our DCNextGen Badge CTF — you must be present to win!

SpeakerBio:  BiaSciLab
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Sunday - 22:30-01:59 PDT


Title: DEF CON After party @ LIV Fontainebleau
Tags: Party
When: Sunday, Aug 9, 22:30 - 01:59 PDT
Where: LIV Nightclub at Fontainebleau

Description:

Close out DEF CON at LIV Fontainebleau. Bring your DEF CON badge for free admission and a free drink.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 15:00-17:30 PDT


Title: DEF CON Closing Ceremonies & Awards
Tags: DEF CON Official Talk
When: Sunday, Aug 9, 15:00 - 17:30 PDT
Where: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map

Description:
SpeakerBio:  Jeff "The Dark Tangent" Moss

Mr. Moss is an internet security expert and is the founder of both the Black Hat Briefings and DEF CON Hacking conferences.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: DEF CON CTF: Benevolent Bureau of Birds
Tags: DEF CON CTF: Benevolent Bureau of Birds | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds) - Map

Description:

We are the Benevolent Bureau of Birds (BBB), formulated from previous victors of past DEF CON CTF contests. We are dedicated to the ethos at the core of CTF: community, skill-building, and showing off insane new hacking talent.

Participant Prerequisites

Players will have to be qualified by an online qualifer to take place in May. Chosen players are then required to have a laptop to participate in the in-person contest, to interact with the scoreboard and challenges hosted on network.

Pre-Qualification

Yes - online pre-qualifier in May 22-24, 2026.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Sunday - 10:00-13:59 PDT


Title: DEF CON Groups (DCG)
Tags: DEF CON Groups | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 2 W238 (DEF CON Groups) - Map

Description:

DEF CON Groups are the year round, local communities that bring the DEF CON spirit home. Run by volunteers around the world, DCGs create spaces where hackers meet, learn, collaborate, and build community outside of conference season.

The DEF CON Groups community space brings together Points of Contact, members, and prospective members to collaborate, share ideas, and learn from one another. Through informal workshops and hands on interaction, participants exchange practical lessons on building, sustaining, and evolving local hacker communities.

The space also serves as a social anchor. A relaxed place to reconnect with old friends, meet new ones, and participate in light interactive activities that reflect the collaborative nature of hacking culture.

DEF CON has always been the island of misfit toys we all return to once a year. DEF CON Groups are how that ethos survives the other fifty one weeks.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: DEF CON Scavenger Hunt
Tags: DEF CON Scavenger Hunt | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt) - Map

Description:

Whether you're a seasoned DEF CON veteran or a curious newcomer, the DEF CON Scavenger Hunt promises to challenge your skills, tickle your wits, and ignite your hacker spirit. Our list is a portal to mystery, mischief, and mayhem. Assemble your team of up to 5 members, interpret the items, and submit your efforts at the booth to our esteemed judges. Go beyond the basics for bonus points. Legends are born here.

The DEF CON Scavenger Hunt is open to everyone, regardless of skill level or experience, no pre-qualifying necessary. We strive to maintain the balance of a low barrier to entry while providing a challenge that many are eager to take on. Casual players should not be overwhelmed by the list, find a handful of items and have fun. If you are looking to win however, you will need to fully immerse yourself in the DEF CON Scavenger Hunt. Let's make some memories together.

Remember that it's not just about fame, glory, or boxes of swag; the true allure is the camaraderie of fellow hackers, the knowledge that you've etched your mark on DEF CON history, and the ultimate badge of honor: bragging rights. Nothing says "I'm a hacker" quite like being triumphant at the DEF CON Scavenger Hunt.

Participant Prerequisites

No, we work very hard to maintain a very low barrier to entry. If anything is required for an item, they should be able to find a fellow hacker with it that would be willing to assist them with their item.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Sunday - 06:00-07:59 PDT


Title: Defcon.run
Tags: Event
When: Sunday, Aug 9, 06:00 - 07:59 PDT
Where: LVCCW Level 1 North Entrance - Map

Description:

Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances.

For DEF CON 34, meet at "The Spot" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype.

Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Sunday - 13:00-13:59 PDT


Title: DeNISTifying Technology: Paradigm Shifting To Quantum Encryption, Post Cryptography, and Digital Forensics
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Dive into the future of cybersecurity with a session that challenges conventional thinking. This talk explores the concept of 'DeNISTifying Technology,' guiding attendees through paradigm shifts towards quantum encryption, advanced post-cryptography methods, and the evolving landscape of digital forensics. Discover innovative approaches and critical insights into securing our digital world beyond current standards. All experience levels are welcome to explore these cutting-edge topics.

SpeakerBio:  Aisha Berry, University of Maryland Global Campus

Aisha Berry is a cybersecurity professional, PhD candidate, and experienced nurse with over 15 years in healthcare. They hold a Bachelor's in Cybersecurity and Computer Networking with a focus on digital forensics, and a Master's of Science in Digital Forensics and Cyber Investigations. Currently pursuing a doctoral program with a focus on healthcare, Aisha delves into the psychological component of technology, emphasizing the mindset of attackers in cybersecurity strategy.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 14:00-14:59 PDT


Title: DFMI: Weaponizing MSI Installers for Fileless Code Execution
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

DFMI is a cross-platform, open-source offensive toolkit that hijacks & abuses the Windows Installer's own execution engine to detonate arbitrary payloads during software installation, with zero files written to disk and zero evidence left behind. And this can be achieved without even corrupting the Authenticode of the binary.

The attack surface is the CustomAction table embedded in every MSI database — a small structure that Windows Installer processes unconditionally at install time. DFMI injects a deferred CustomAction (property-based EXE invocation) — firing right before the modification in system files; the payload executes before a single legitimate byte touches the filesystem.

Right now, DFMI provides 3 different methods for abusing MSI files: - Inject: Simply injects a CustomAction (CA) into an existing MSI package. - Rogue MST: Generates an MSI Transform File (.mst) and injects into legitimate ".msi" file without corrupting it's Authenticode. - Stub: Creates a malicious MSI file from scratch.

What makes DFMI particularly difficult to eradicate is that it exploits no vulnerability; it's a feature. The CustomAction mechanism is a 25-year-old Windows feature, documented by Microsoft, used by virtually every enterprise software package and trusted implicitly by the OS.

DFMI simply turns that trust sideways — using the Installer engine as its own payload executor.

https://github.com/ccelikanil/DFMI

SpeakerBio:  Anıl Çelik

Computer Engineer & been working as a Red Teamer for the past ~7 years. Previously did presentations at DEFCON 33 Demo Labs, DEFCON 33 Red Team Village & Black Hat USA Arsenal 2025. Currently holding 6 CVEs, OSCP & OSWP. Interests: Windows Internals & AD Security


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 10:00-10:59 PDT


Title: Direct Network Access for Command and Control
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map

Description:

Command and control beacons currently reach out to the operating system to request socket resources, triggering auditing and being restricted by local firewall rules. However, it is possible to develop malware that can evade the standard process. Sparse is a tool that weaponizes this concept to evade such auditing and defensive configurations.

SpeakerBio:  Andrew Rioux

I started learning to program in middle school and found a software engineering project to work on throughout highschool. I attended Liberty University to study Software Engineering and Cybersecurity at the undergraduate level, learning to develop software that works in adversarial contexts. I have recently finished my master's degree in Cybersecurity, where I was able to further practice developing software in adversarial contexts and develop version 2 of Sparse


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 11:30-12:45 PDT


Title: Disaster Intelligence - The past, present, and future of situational awareness during a crisis
Tags: OSINT For Good Community | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 12:45 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

OSINT, social media, drones, AI, and more… in this session, we’ll learn how these innovations are applied to make life-saving decisions before, during, and after a disaster

SpeakerBio:  Matt Green, Green Emergency Management Services

Matt Green is your friendly neighborhood emergency manager, professor, and host of the state of disaster podcast. His passion is ensuring equitable, high-quality, whole community emergency management across sectors and borders.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 11:30-11:59 PDT


Title: Disaster Intelligence - The past, present, and future of situational awareness during a crisis
Tags: OSINT For Good Community | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

OSINT, social media, drones, AI, and more… in this session, we’ll learn how these innovations are applied to make life-saving decisions before, during, and after a disaster

SpeakerBio:  Matt Green, Green Emergency Management Services

Matt Green is your friendly neighborhood emergency manager, professor, and host of the state of disaster podcast. His passion is ensuring equitable, high-quality, whole community emergency management across sectors and borders.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: Discover GE Appliances!
Tags: IoT Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 12:00-13:59 PDT


Title: Do you feel in control? Analysis of AWS CloudControl API as an attack tool
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

"Identity is the new perimeter" gets thrown around a lot in security discussions, fo a good reason. With the right privileges, cloud resources can be managed through APIs. Each provider has their own way of handling API access on resources. If your identity has the right permissions for a specific API call, you can execute that action.

The thing is, it's hard to remember every single API call you need to get specific information or access certain resources. AWS recognized this problem and created the AWS CloudControl API, a unified API that groups different resources together so you can create, update, delete, or retrieve them in bulk. This makes managing resources much simpler since you don't need to know which specific service, API call, or parameters to use.

But here's the catch: when something is easy for legitimate users, it's usually easy for attackers too. There are already tools available to use the AWS CloudControl API to pull resource information, and the technique is gaining attention.

But is it actually a good way to do stealthy enumeration? In this article, we examine what the CloudControl API is, how it simplifies resource management, how attackers can weaponize it, its limitations, and detection methods.

SpeakerBio:  Bleon "gl4ssesbo1" Proko

Bleon is an Info-sec passionate about Infrastructure Penetration Testing and Security, including Active Directory, Cloud (AWS, Azure, GCP, Digital Ocean), Hybrid Infrastructures, as well as Defense, Detection and Thread Hunting. He has presented topics related to Cloud Penetration Testing and Security in conferences like BlackHat USA, Europe and Sector, DEF CON, SANS Pentest Hackfest Hollywood and Amsterdam, as well as several BSides on USA and Europe.

His research include Nebula, a Cloud Penetration Testing Framework (https://github.com/gl4ssesbo1/Nebula) and other blogs, which you can also find on his blog (blog.pepperclipp.com). He is also the author of YetiHunter, DetentionDodger and Ransomwhen (https://github.com/Permiso-io-tools/[DetentionDodger | YetiHunter | Ransomwhen]).

He is also the author of the upcoming book "Deep Dive into Clouded Waters: An overview in Digital Ocean's Pentest and Security" (https://leanpub.com/deep-dive-into-clouded-waters-an-overview-in-digitaloceans-pentest-and-security)


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Drone Hacking Choose your Own Adventure
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Dive into our interactive choose-your-own-adventure web interface and learn how to hack a drone in a fun, storyboard-based game. This graphical user interface simulates the process we use when hacking drones for the Air Force, allowing participants to make decisions and see the outcomes.

It's a beginner-friendly, 15-30 minute activity offering insights into the steps involved in drone penetration testing.

Participants can access it from their own computers or mobile phones.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Drone Hacking Workshop
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Join our Drone Hacking Workshop for hands-on experience hacking drone components. This three-step in-depth activity is designed to teach you about the vulnerabilities and security of autonomous systems. Using sample drones, participants will learn techniques used in government pen tests.

This 2-3 hour workshop suits all skill levels, from beginners to advanced hackers. Come and test your skills in a real-world scenario and understand the intricacies of drone security.

Participants need to bring a laptop capable of running a Linux distribution.


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Sunday - 10:00-13:59 PDT


Title: Embedded - 101 Labs
Tags: Embedded Systems Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

We have a lab platform that brings everyone from every skill level to the same playing field with step by step instructions that aim to teach individuals specific techniques and skills in a hands-on manner on embedded hacking techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Sunday - 10:00-13:59 PDT


Title: Embedded & Shredded: Advanced Embedded System Hacking
Tags: Biohacking Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map

Description:

This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities:


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Sunday - 10:00-13:59 PDT


Title: Embedded Systems Village CTF
Tags: Embedded Systems Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

Get hands-on with devices you won't find anywhere else — rare, hard-to-source embedded devices staged for live exploitation. Hunt real zero-days, and yes, bring your AI: LLM-assisted tooling is fully allowed, so use it to go as deep as you can.

Come break something that's never been broken.

New to embedded? Just wrapped our 101 Labs? Beginner challenges are available as well to apply your new found knowledge!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Escalation Desk CTF
Tags: Call Center Village | Escalation Desk CTF | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 2 W218 (Call Center Village) - Map

Description:

Customer service channels are increasingly saturated with conversational text and voice AI agents. Can you convince, trick, or break enough of them to earn your shot at a live human operator in a real-world call center?

Escalation Desk is Call Center Village's capture-the-flag challenge. Start with low-pressure AI agents and learn how to spot, avoid, and exploit common pitfalls and patterns in system prompts — eventually unlocking live human operators at our partner call centers. A real-time leaderboard tracks solo and team progress, with our not-so-famous Golden Telephone Booth trophy awarded to the top participant.

Hit our minimum point threshold and earn a special Call Center Village 100 Trying black flight tag. The top individual and their team also take home the rare Call Center Village 200 OK gold flight tags. Bring your tags to Party Line, Call Center Village's after-hours telephony-themed party, and enjoy free refreshments for your spoils.

Escalation Desk is beginner (and introvert) friendly — if you can dial a phone number or use a keyboard, you can participate. Bring your own laptop and headset, or use one of our village stations. Active Noise-canceling headphones with a microphone are highly recommended.

The CTF will run during village hours, pausing when the village closes each night, and ends on Sunday at 12:00.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 10:00-10:59 PDT


Title: ESP32 as a counter-surveillance platform
Tags: DEF CON Official Talk | Demo 💻
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

Privacy should be accessible to all. Historically, counter-surveillance tools have been expensive, complex, and inaccessible to most individuals, often limited to well-funded researchers and costly hardware configurations. The ESP32 offers a transformative alternative. This presentation will demonstrate how an affordable microcontroller has become the foundation for a growing suite of open-source, user-friendly anti-surveillance tools. We will discuss the technical features that make the ESP32 a compelling choice for these applications, including passive 802.11 and Bluetooth monitoring, OUI-based device fingerprinting, and robust cryptographic capabilities. Applications include detecting police body cameras in operational environments, mapping Flock Safety automatic license plate recognition (ALPR) infrastructure, identifying unauthorized drones, detecting radio frequency jamming across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous robots operating with known-vulnerable firmware. These tools are cost-effective and freely available. We will also consider future developments in accessible counter-surveillance hardware, such as the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc. Advancing anti-surveillance culture requires designing devices that individuals are motivated to use and carry.

Speakers:Cooper "Cybertiger" Quintin,Colonel Panic,The Wrew

SpeakerBio:  Cooper "Cybertiger" Quintin, Board Member at Open Archive

Cooper Quintin is a security researcher and senior public interest technologist with the EFF Threat Lab. research fellow with Citizen Lab, adviser to CoRD Research and Design, and board member of Open Archive. He has worked on projects including Rayhunter, Privacy Badger, Canary Watch, and analysis of state sponsored malware campaigns such as Dark Caracal. Cooper has given talks about security research at prestigious security conferences including Black Hat, DEFCON, Enigma Conference, and ReCon about issues ranging from IMSI Catcher detection to fem tech privacy issues to newly discovered APTs. He has also been published or quoted in publications including: The New York Times, Reuters, NPR, CNN, and Al Jazeera. Cooper has given security trainings for activists, non profit workers, and vulnerable populations around the world. He previously worked building websites for nonprofits, including Greenpeace, Adbusters, and the Chelsea Manning Support Network. Cooper was also an editor and contributor to the hacktivist journal, "Hack this Zine." In his spare time he enjoys making music, visualizing a solar-punk communitarian future, and playing with his kids.

SpeakerBio:  Colonel Panic

Malware researcher by day, IoT rapid prototyper by night. Creator of Mesh-Detect and Oui-Spy. I love making things and bringing my ideas to a completed prototype rapidly. I’m Interested in privacy, digital rights, and detecting all the things.

SpeakerBio:  The Wrew, Hackers.Town

Product Manager working on building pentesting platforms by day, hacker and electronics prototyper by night (and occasional weekend). Creator of VoidMantisOS for the hacker pager and SpectraMesh mesh networking protocol. Interested in security, privacy, RF, electronics and fighting digital surveillance. Listed under: just handle


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 10:00-11:59 PDT


Title: Evil Is Always a Bad Stylist: .NET Obfuscation with Roslyn
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

Modern endpoint defenses increasingly fingerprint .NET tools not only by strings and imports, but by structure: control flow, call graphs, and overall execution “workflows.” Traditional IL obfuscation can hide obvious indicators, yet often produces highly regular flattened patterns that are easy to flag on their own.

This talk presents a Roslyn-based, source-to-source obfuscator for C# that rewrites an entire project before compilation. Using the official compiler APIs, it transforms the code’s syntax and semantic structure, reshapes control/data flow, and then recompiles the result - while keeping the program’s observable behavior intact. The output tends to look complex but “natural,” diverging both from the original tool and from the telltale patterns created by many IL-level obfuscators.

I will walk through the pipeline, show how surprisingly little code is needed to build these transformations on Roslyn, and discuss what this means for EDR, sandboxing, and ML detections that rely on graph and workflow analysis of .NET binaries.

So, anyway, on moment of submitting original Seatbelt tool (obfuscated by source) have 10/73 security vendors flagged this file as malicious (can be better) https://www.virustotal.com/gui/file/ec2dcecb927874d41b051633135c8a594abb40d03f6836a548b40963bf330c86/detection/f-ec2dcecb927874d41b051633135c8a594abb40d03f6836a548b40963bf330c86-1764839678

My project https://github.com/gam4er/Loaders differs from more well known https://github.com/sadreck/Codecepticon by implementing semantic structure obfuscation.

My point of view (sa a SOC analyst, blue teamer) on "how to hide mytool from AV" problem is: if you have a code - OBFUSCATE YOUR CODE. Stop modifying binaries

Speakers:Alexander Rodchenko,Ashley Hiram Muñoz,Eduardo Chavarro Ovalle

SpeakerBio:  Alexander Rodchenko

Rodchenko Alexander is a Senior SOC Analyst at the SOC Security Research Group at Kaspersky. He began his career at OJSC Rosneft, focusing on industrial safety, troubleshooting, and audits. Currently, he investigates industry events and trends with the primary goal of integrating these insights into monitoring and threat hunting practices. Leveraging his extensive expertise, Alexander advises customers and threat detection/hunting teams on the optimal response to emerging threats and trends. In addition to speaking at Positive Hack Days (twice) and BSides Zurich 2023, he has also been a speaker at CodeBlue 2024 and BlackHat MEA 2024.

SpeakerBio:  Ashley Hiram Muñoz, Kaspersky - Incident Response Specialist

I currently work as an Incident Response Specialist on Kaspersky's Global Emergency Response Team (GERT). I live in Mexico and have over seven years of experience in Incident Response, Digital Forensics, Malware Analysis, and Reverse Engineering. Before joining DFIR, I worked for two years as a Penetration Tester.

I have collaborated on various Threat Hunting and Threat Intelligence projects.

Additionally, I have been a speaker at international events such as DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, HackGDL, BugCON, Pwnterrey, and others. I currently teach the Digital Forensics, Malware Analysis, and Incident Response modules in an information security diploma program at UNAM (Universidad Nacional Autónoma de México).

Certifications: GREM, GCFA, GCFR, eCTHP, CHFI.

--

Actualmente me desempeño como Incident Response Specialist en el Global Emergency Response Team (GERT) de Kaspersky, cuento con +6 años de experiencia realizando Respuesta a Incidentes, Análisis Forense Digital, Análisis de Malware y Reversing; previo a dedicarme a DFIR laboré 2 años como Penetration Tester.

He colaborado en distintos proyectos de Threat Hunting y Threat Intelligence.

Adicionalmente, he sido ponente en eventos internacionales como DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, BugCON, etc.

Actualmente soy profesor de los módulos de Análisis Forense, Análisis de Malware y Respuesta a Incidentes en un diplomado de seguridad de la información de la UNAM.

Certificaciones: GREM, GCFA, eCTHP, CHFI.

SpeakerBio:  Eduardo Chavarro Ovalle, DFIR Group Manager at Kaspersky - GERT

Eduardo Chavarro Ovalle, DFIR Group Manager for Americas, member of Kaspersky GERT Team. Student of DBA in ML and AI and MSc in Cybersecurity with more than 20 years of experience in cybersecurity, DFIR, eDiscovery, and threat analysis. GCIH | GRID | GCFA | CISM | CHFI | CPTE | SFCP | ITIL.


Return to Index    -    Add to Google    -    ics Calendar file

Embedded Systems Village - Sunday - 10:00-13:59 PDT


Title: Exploit Bluetooth Low Energy with BLESPloit and optional ESP32
Tags: Embedded Systems Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map

Description:

Discover how easy it is to fingerprint and control nearby BLE devices with a tap on your phone - yes, including iPhone that gets BLE superpowers with with an external ESP32. Scan remotely, clone and simulate BLE devices, test a popular headset for known vulnerabilities (or perhaps uncover a new one?) and take control of a robotic dog. Already know some BLE? Crack open our smart safe and claim the BLESPloit hardware reward inside!

SpeakerBio:  Slawomir Jasek, BLESPlo.it

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups. Currently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks. Beyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them. Loves sharing his knowledge via trainings, workshops, talks and open source hackme's (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: Expose Hidden Surveillance in Everyday Tech
Tags: IoT Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Join the Ludlow Institute Surveillance Mission. Dump firmware, capture packets, probe APIs, or tear devices apart however you like. Prizes up for grabs.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 11:10-11:40 PDT


Title: Extending Shared Threat Models with the Application Attack Matrix
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Sunday, Aug 9, 11:10 - 11:40 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Shared threat frameworks have enabled consistent communication and coordination across vulnerability researchers, PSIRTs, vendors, and defenders. However, as attackers increasingly operate at the application layer (abusing software supply chains, runtime behavior, and trusted cloud workflows) defenders face challenges applying existing models consistently. This session presents lessons from the Application Attack Matrix, a community-driven research effort involving contributors from Mandiant (Google Cloud), Microsoft, AWS, Meta, Oligo Security, and others, and uses the ByBit / Safe{Wallet} incident to illustrate why application-layer technique modeling is increasingly important.

SpeakerBio:  J Fridley

J. Fridley is a Senior Solutions Engineer at Oligo Security, helping teams secure modern cloud environments with deep runtime visibility. He previously led and supported Solutions Engineering teams at Snyk and has a background as a software engineer and technical project lead. J also brings nearly two decades of military service with the U.S. Navy and Army National Guard.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 10:00-13:59 PDT


Title: F1NDX OSINT Educational Series
Tags: OSINT For Good Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

The OSINT Educational Series is a 3-level series that introduces Open-Source Intelligence (OSINT). It covers data collection, social media analysis, and investigative techniques, showing how publicly available information is used in cybersecurity and intelligence. Volunteers will be on hand to help you get started and answer questions if you get stuck! Complete all 3 levels and earn a digital badge!


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 11:50-12:20 PDT


Title: Finding Bugs Is Easy, Patching Isn't: Build Your Own Remediation Pipeline
Tags: Intermediate | AppSec Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:50 - 12:20 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

AI made finding and exploiting bugs almost free. In one month, Anthropic's Project Glasswing surfaced over 10,000 high and critical bugs and patched fewer than 100. The maintainers on the receiving end are asking Anthropic to slow down, because they can't fix the bugs fast enough.

If one model can bury the world's best-funded security teams, what happens to the 1-to-5 person team with little security budget and a backlog now growing at machine speed?

This talk shows you how to build SPAR (Scan, Prioritize, Auto-fix, Rewrite): a remediation pipeline that chains call-graph reachability, EPSS percentiles, and SSVC decision logic into triage a small team can run, then routes the ones that matter through AI patch generation behind a regression-aware verification harness.

Speakers:Mohan Kumar,Naveen

SpeakerBio:  Mohan Kumar

Mohan is a security leader with over a decade of experience in security architecture, engineering, and operations. He has a strong interest in developing robust security programs and a proven track record of creating proactive security roadmaps and strategies aligned with business objectives. He constantly seeks ways to elevate security processes and culture to the next level.

SpeakerBio:  Naveen

Naveen is a Security Researcher with over 9 years of expertise specializing in AI, application, and cloud security. He invented 5 patents in Agentic Security space.

He possesses extensive knowledge in all aspects of product security, including threat modeling, DevSecOps, API security, and penetration testing. He is passionate about integrating security into the SDLC from design to deployment, ensuring the early detection and mitigation of vulnerabilities.


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Sunday - 10:00-10:30 PDT


Title: Five Million Industrial Control Systems Walk Into a Bar: What IRONMAP Found When It Scanned the Whole Internet
Tags: ICS Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

What does the global attack surface of operational technology actually look like at internet scale? We built IRONMAP, a purpose-built OT/ICS intelligence platform, to find out — and the answer is both larger and more disturbing than we expected.

Over the course of this ongoing research project, IRONMAP has catalogued over 5.5 million ICS/OT-facing assets across the public internet, with more than 2.25 million flagged as high-risk. Using deep protocol fingerprinting across all major industrial protocols — EtherNet/IP (CIP), Modbus TCP, Siemens S7, DNP3, IEC 60870-5-104, OPC-UA, BACnet/IP, Omron FINS, GE SRTP, Tridium Fox, and more — IRONMAP goes well beyond port scanning to perform authenticated protocol enumeration, live register reads, and tag harvesting using PLCDISCO, our multi-protocol OT scanner.

This talk presents a ground-level statistical portrait of the exposed OT internet: which protocols dominate, which sectors are most exposed, how vendor market share looks through the lens of deep insight and where in the world the highest concentrations of exposed critical infrastructure live (spoiler: it is not all China). We will walk through what over 242,000 EtherNet/IP devices look like when you enumerate their CIP identity objects, what ~500,000 Modbus devices expose in their holding registers, and what the live tag names of real PLCs tell you about what processes they are running.

We then turn to a specific and underappreciated issue: Automatic Tank Gauges (ATGs). IRONMAP found 149 confirmed ATG systems directly exposed to the internet, the majority of them Veeder Root TLS-350 and TLS-450 units — the dominant ATG platform at commercial fueling facilities across North America. These systems, reachable via the Guardian ASP protocol on TCP/10001, require no authentication on older firmware and respond to a simple serial-style command set with:

The implications are significant. Exposed ATGs reveal not just that a facility has fuel storage, but how much, what kind, and when deliveries occur — operational patterns that are directly relevant to physical security and supply chain intelligence. IRONMAP discovered ATGs at locations that include commercial truck stops, bulk fuel terminals, and sites with product profiles consistent with aviation or military use. We will demonstrate a live walk-through of what an unauthenticated session reveals, discuss the responsible disclosure posture we have taken, and present mitigation guidance for asset owners.

Attendees will leave with a realistic, data-grounded view of the exposed OT landscape — not a cherry-picked set of scary screenshots, but statistically representative findings from a 5.5-million-asset dataset — plus actionable context on the ATG exposure class and how to find and fix it.

SpeakerBio:  Matt Caldwell, Tophat Security

Matt Caldwell is the founder of Tophat Security, cyber security firm specializing in innovative OT/ICS software and tools, red team operations, and critical infrastructure research. With over a decade of experience in industrial control system security, Matt has assessed environments spanning oil and gas, electric utilities, water treatment, manufacturing, and federal government. He built IRONMAP as a research platform to continuously map the internet-exposed OT attack surface at scale, applying it to build threat intelligence, support disclosure efforts, and develop data-driven visibility into the global ICS exposure problem. Matt holds relevant certifications in cyber security and penetration testing and has presented research at global OT/ICS security conferences. He is based in Athens, Georgia, and speaks regularly with asset owners, government stakeholders, and research organizations on OT exposure topics.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Flight Simulator/EFB
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Experience the effects of tampered engine performance data as you take the controls on a departing flight. Feel for yourself how vulnerabilities in electronic flight bags can have a physical impact inside the cockpit.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Sunday - 11:50-12:30 PDT


Title: Foxveil: Cloud-Native Loader Tradecraft on Cloudflare, Netlify, and Discord
Tags: Cloud Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:50 - 12:30 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Malware loaders used to advertise themselves with throwaway domains, fragile hosting, and obvious command-and-control infrastructure. Foxveil is a hard reset in loader tradecraft. Less attacker-owned infrastructure, less disk-heavy execution, fewer static clues, and more abuse of platforms defenders see every day. This newly documented loader stages payloads from our most trusted and favorite cloud-native tool chains: Cloudflare Pages, Netlify, and Discord attachments, executes shellcode largely in memory, establishes persistence through masqueraded Windows artifacts, and actively rewrites analysis-significant strings at runtime to make reverse engineering and static detection harder. Across two observed variants, Foxveil combines several pieces of modern tradecraft into one compact initial-stage loader. One variant spawns a fake svchost.exe and performs Early Bird APC injection into the target process before it fully resumes. Another pulls shellcode from Discord attachments and executes it through self-injection. Both stage follow-on payloads from trusted platforms, drop files into SysWOW64 under names designed to blend into normal Windows noise, and use runtime string mutation to corrupt keywords such as beacon, meterpreter, shellcode, and even fox itself. This talk walks through the full Foxveil infection chain, from staging and shellcode delivery to persistence and follow-on deployment, and examines what makes this loader part of a broader shift in attacker and malware tradecraft by comparing both variants. The real story is not just cloud-hosted staging. It is the emergence of a loader model that borrows trust instead of building infrastructure. Foxveil examines what modern initial-stage malware looks like when it is designed for rotation, ambiguity, and survival.

Speakers:Shani Kurtzberg,Zohar Buber

SpeakerBio:  Shani Kurtzberg

Shani Kurtzberg is an XDR Team Lead at Cato Networks and member of Cato CTRL. She leads the Threat Intelligence and XDR Detection Engineering initiatives. Prior to Cato, Shani served in the Israeli Air Force (IAF) as a Security Analyst, leading SOC operations to protect critical systems. Shani holds a Master of Business Administration (M.B.A.) from Peres Academic Center, specializing in Marketing and Product Management.

SpeakerBio:  Zohar Buber

Zohar Buber is a security analyst in Cato Research Labs at Cato Networks. He focuses on network protocol analysis and malicious traffic detection, specializing in threat identification using network-based methods. He previously worked at Radware, where he examined threats in the DDoS industry. Zohar holds B.A focused in Business Administration, Information System Analysis // Zohar Buber, zohar@devtalks.me


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Sunday - 11:00-12:59 PDT


Title: Free Ham Radio License Exams
Tags: Event | Ham Radio Village
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 3 W314 (Ham Radio Meeting) - Map

Description:

Free ham radio exams return to DEF CON 34! Partake in this hacker “rite of passage” by getting your license at DEF CON, presented by the Ham Radio Village.

While anyone is able to listen in to amateur/ham radio transmissions, only those who have an amateur radio license are able to fully partake in the “oldest hacker hobby”. With your license, you’ll be authorized by the FCC to transmit up to 1,500W on designated frequencies, build/modify radios & antennas, and even administer your own exams! Additionally, having your ham radio license can improve your resume as it is a well-recognized proof of technical and regulatory knowledge when it comes to all things radio.

About The Exam

In the US there are 3 current levels of amateur radio license - Technician, General, and Amateur Extra. You can progress through the levels by taking a series of multiple-choice exams showing increasing breadth of knowledge. Most folks at DEF CON looking to become a ham take just the technician exam.

The technician exam is a 35 question, multiple choice exam. Questions come from from a public question pool of 400 questions. Because of that, the most popular way folks at DEF CON prepare is by reading through all 400 questions before the exam, and learning hands on once you get licensed. Many study resources exist - most people recommend ham.study.

Signing Up

Who may register for this testing session:

Fees

Questions

If you have any questions leading up to DEF CON, come visit us on the Ham Radio Village Discord server (discord.gg/hrv) and let us know what questions you have. During the conference, come visit the Ham Radio Village to learn all things ham radio, including the studying, testing, and licensing process.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Sunday - 12:00-12:59 PDT


Title: Friends of Bill W
Tags: Meetup
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 3 W301 (Misc Meeting Room) - Map

Description:

We know DEF CON and Vegas can be a lot. If you're a friend of Bill W who's looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.


Return to Index    -    Add to Google    -    ics Calendar file

Misc - Sunday - 12:00-12:59 PDT


Title: Friendship Bracelets
Tags: Women in Security and Privacy (WISP) | Creator Event/Activity
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map

Description:

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 12:00-13:59 PDT


Title: From Buffer Overflow to Blackout: Chaining Attacks Against Industrial Systems
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map

Description:

This presentation takes a practical, demo-driven approach to exploitation, demonstrating how a buffer overflow vulnerability can still serve as an entry point to compromise modern industrial infrastructures. The session is approximately 90% hands-on and 10% theoretical. The talk walks through the full attack chain, starting from initial exploitation and progressing to the development and execution of multistage shellcode. This shellcode establishes communication with a remote Command and Control (C2) server, retrieves an additional payload, and executes it directly in memory, bypassing traditional detection mechanisms. Once the environment is compromised, the session demonstrates how an attacker can gain full remote control, enabling command execution, lateral movement, and exfiltration of sensitive data, including critical assets such as licenses and proprietary industrial information. The talk also includes interaction with real-world devices such as RTUs (Remote Terminal Units), showing how malicious actions can directly impact industrial operations. In critical scenarios, this can lead to disruptions in essential services, including failures in energy systems and potential blackouts. The content is based on real-world pentesting experience conducted in an energy sector company in Brazil, providing a practical and applied perspective on risks in ICS/SCADA environments. The goal is to demonstrate how modern attacks combine vulnerabilities with advanced techniques, reinforcing the need for robust security strategies to protect critical infrastructure.

Speakers:Fernando Mengali,Thiago Cunha da Silva

SpeakerBio:  Fernando Mengali, Information Security Specialist

Cybersecurity researcher focused on Pentesting and AppSec, also serving as a Practical / Hands-on Speaker. He also dedicates part of his research to critical infrastructure security (ICS/SCADA), exploring the intersection between classic vulnerabilities and industrial environments. He has over 18 years of experience in offensive security and practical application exploitation.

He has participated in research and development projects focused on vulnerability exploitation and offensive security.

Specialized in 0day discovery and exploit development, he has over 135 published CVEs and is ranked in the Top 10 contributors on VulDB https://vuldb.com/users.top.

Additionally, he has published multiple exploits and technical papers publicly available https://www.exploit-db.com/?author=12136 and https://packetstorm.news/files/author/8470/1.

His work focuses on real-world vulnerability exploitation, including advanced scenarios such as memory corruption, buffer overflows, and complex environments.

He is the creator of https://yrprey.com, an educational framework that brings together more than 20 vulnerable applications based on the OWASP Top 10, used for practical training in Application Security and Offensive Security https://owasp.org/www-project-vulnerable-web-application-directory.

He is also the driving force behind https://speakfy.io, a project focused on promoting Information Security events globally.

Furthermore, he develops application security-oriented tools, such as https://leapfix.co (static code analysis) and https://fitoxs.com, a dynamic application analysis platform powered by artificial intelligence.

SpeakerBio:  Thiago Cunha da Silva

Thiago Cunha is an offensive security specialist, or as he likes to put it: “professionally paid to break into systems before someone less friendly does.”

He currently works as a Red Team and Threat Intelligence Consultant at Banco Carrefour and as an instructor at the Kryfal, teaching future ethical hackers not to click on suspicious links.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 11:00-12:59 PDT


Title: From Command Line to Center Stage: Hack Your Way to Confident Speaking
Tags: Noob Community | Creator Workshop
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Led by a seasoned security speaker with over 600 presentations under their belt and training from world-class Toastmasters, this interactive session completely bypasses the fluff to focus entirely on real-world delivery. This workshop is your chance to turn stage fright into stage might, equipping you with the tools to present with poise, project authority, and own the room.

SpeakerBio:  James McQuiggan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 10:30-10:59 PDT


Title: From commit to compromise: securing the full pipeline with AI-assisted remediation
Tags: AppSec Village | Creator Talk/Panel | All Audiences
When: Sunday, Aug 9, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map

Description:

Most vulnerabilities aren't found because teams lack tools they persist because the cost of fixing them is too high. A finding without a concrete, context-aware fix is just noise developers learn to ignore. This talk walks through three real-world attack scenarios a secret leaked into git history, a compromised dependency in a supply chain attack, and an injection vulnerability introduced in a PR and shows how each is detected, mapped to OWASP Top 10:2025, and automatically remediated using AI running entirely on local infrastructure. No source code leaves the machine. The AI receives the vulnerable code block, CWE identifier, CVSS score, and OWASP category and returns a fix that is specific, correct, and ready to apply. Attendees leave with a working open-source tool and a new mental model for what AppSec remediation can look like.

SpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I'm Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0 Black Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires DEF CON 33 / 32 - https://sessionize.com/filipi-pires/ DEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 11:30-12:30 PDT


Title: From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use-After-Free Vulnerability
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:
It started as fuzzer noise: an OSS-Fuzz crash in PHP's concat_function, filed under a JIT target but with no JIT in the stack. It is a core Zend Engine use-after-free, reproducible with php -n and no extensions. This is an honest exploitability study on Linux x86-64: from the mistriaged crash to native command execution (arbitrary read/write via stale DateInterval, zif_system resolved in-process, ASLR and PIE defeated at runtime) even where disable_functions is set. It builds on the public exploitation lineage, with an SPL ArrayObject delivery trick as our own delta.
  1. OSS-Fuzz Issue #483856591 — Original crash report filed under php-fuzz-function-jit target
  2. PHP Source: Zend/zend_operators.c, concat_function() — https://github.com/php/php-src/blob/master/Zend/zend_operators.c
  3. php/php-src#16726 — Array-element UAF (second-chain vulnerability used to bypass mod-16 alignment barrier)
  4. Zend MM Internals: https://www.phpinternalsbook.com/php7/memory_management/zend_memory_manager.html
  5. CVE-2022-29072 — Prior 7-Zip zero-day by the same researcher (Kağan Çapar), demonstrating track record in vulnerability research
  6. CVE-2026-5201 — gdk-pixbuf heap buffer overflow discovered by the same researcher, acknowledged by Red Hat (CVSS 7.5)
  7. W3Techs PHP Usage Statistics — https://w3techs.com/technologies/details/pl-php
  8. V8 Sandbox Design (2024) — Referenced in comparative interpreter memory model analysis
Speakers:Can Oztas,Kağan Çapar

SpeakerBio:  Can Oztas

Can Oztas is a security researcher with applied R&D experience across several key sectors, including defense, finance, and telecommunications. His background encompasses AppSec, vulnerability research, and offensive security engineering. He is currently a PhD student focusing on the intersection of Artificial Intelligence and cybersecurity.

SpeakerBio:  Kağan Çapar

Kağan Çapar is a Vulnerability Researcher with over 15 years of experience. His research focuses on binary exploitation, fuzzing, and zero-day discovery across widely deployed software.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Sunday - 10:00-10:59 PDT


Title: From Practitioner to Principal: Building a Cybersecurity Business That Lasts
Tags: Blacks In Cyber Village | Creator Workshop
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Most cybersecurity workshops teach you how to do the work. This one teaches you how to own it. Tyrone E. Wilson Army veteran, CISO, and founder of Cover6 Solutions breaks down what it actually takes to transition from practitioner to principal: building a service-based firm, pricing your expertise, navigating GovCon as an SDVOSB, and sustaining a business that doesn't depend on your last client check.

SpeakerBio:  Tyrone E. Wilson, Cover6 Solutions

Tyrone E. Wilson is a U.S. Army veteran, cybersecurity executive, and founder of Cover6 Solutions a Service-Disabled Veteran-Owned Small Business delivering vCISO and compliance services to organizations across the public and private sectors. With over two decades of experience in security leadership, they built Cover6 from the ground up while simultaneously growing a 9,000+ member cybersecurity community for career changers and professionals of color. They are the creator of the Breaking Into Cyber framework and host of the Cover6 Community a free resource for anyone navigating the industry without a built-in network. Tyrone has delivered training for Blacks In Cybersecurity and speaks regularly on the intersection of entrepreneurship, community, and cybersecurity career development.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Sunday - 10:00-10:59 PDT


Title: From Roots to Renaissance: The Rising Generation of Middle Eastern and African Cybersecurity
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

If yesterday was where we came from, today is where we are going. The same regions that gave the world algebra and the first codebreakers are now home to some of the fastest-growing security communities on the planet, from Lagos to Cairo to Riyadh, alongside a diaspora shaping the field from inside every major company and conference. This talk picks up where the kickoff left off and moves from history to right now: the researchers, founders, defenders, and organizers carrying the work forward, the obstacles that still stand in the way, and what it takes to build a career and a community when the industry has not always made room for you. We will talk honestly about representation, mentorship, and momentum, and about the role a space like MEACS plays in turning a shared heritage into a shared future. Come for the story, stay to find your people.

SpeakerBio:  Ezz Tahoun

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada's CSE.

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 11:00-11:30 PDT


Title: Full Disclosure, Full Screen: [Informative] The Story of Bug Bounty Village Badge 2026
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:30 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Every year the BBV badge gets one new thing we don't know how to do yet. Last year: epoxy. This year: a real 0.96" OLED behind the acrylic, giving a whole new vibe to the hacker laptop screen. Plus RGB for whichever team you're on, and a fun CTF.

SpeakerBio:  Abhinav "TweetsFromPanda" Pandagale, Founder, Hackerware

Abhinav's artistry comes from the times he used to sneakily paint drawings made by his sister. His hacking career began as a toddler, disassembling his toys but never putting them back together. His entrepreneurial roots come from selling snacks at a school fair and making a loss of ten bucks, his entire pocket money. Having learned how not to make money, he launched Hackerware.io - a boutique badgelife lab with in-house manufacturing - which has grown over the past ten years into a global presence across 20+ countries. He's often spotted at conferences around the world - hosting hardware villages or pulling off the kind of random shenanigans that earned him the Sin CON Person of the Year 2025 award.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Sunday - 08:30-17:30 PDT


Title: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Sunday, Aug 9, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W224 (Training) - Map

Description:
SpeakerBio:  Dawid Czagan
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-10:30 PDT


Title: Game Hacking Village CTF awards ceremony
Tags: Game Hacking Village | Game Hacking Village CTF | Contest
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

Winners of the Game Hacking Village CTF will be awarded their prizes.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Game Hacking Village CTF Q&A / Walkthroughs
Tags: Game Hacking Village | Game Hacking Village CTF | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map

Description:

A presentation by the challenge creators about how the Game Hacking Village CTF along with an open QnA about challenges.


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Sunday - 12:00-12:59 PDT


Title: Game Time: Input, Output, and Variables
Tags: CodeBloom | Creator Workshop
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Input, output, and variables are the building blocks behind every single program you've ever used, and once you understand them, you're well on your way to writing your own code! In this session, we'll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Sunday - 10:00-10:59 PDT


Title: Game Time: Loops
Tags: CodeBloom | Creator Workshop
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Have you ever had to do the same thing over and over and thought, there has to be an easier way? Good news, there is, and it's called a loop! Come play some classic schoolyard games with us and discover that you've been using loops in real life all along. Then we'll show you how programmers use for loops and while loops to make computers repeat tasks automatically, whether that's counting to 100 or spawning enemies in your favorite video game. No experience needed, just come ready to play! If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Sunday - 10:00-10:45 PDT


Title: Ghost in the Hiring Machine: How to Spot Fake Personas Before They're on Your Payroll
Tags: Recon Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:45 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

People are getting hired and trusted every day. Some of them do not exist at all, yet they still pass interviews, collect paychecks, and gain access to sensitive systems. Campaigns attributed to the DPRK have shown that this threat is very real. So how do you catch a ghost with a resume? Attendees will learn practical OSINT techniques for spotting fake personas and receive a checklist for thorough background checks. They will see these methods applied through two cases based on a true story, illustrating how these personas succeeded, how one could have been prevented, and where OSINT reaches its limits. These techniques not only help attendees detect fake personas but also provide practical ways to protect their own privacy and control what personal information is visible online.

Speakers:Michael Reimsbach,Rishi "rxerium" C

SpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

SpeakerBio:  Rishi "rxerium" C, Security Researcher

Rishi is a London-based security researcher with over five years of hands-on experience in IT. He currently specializes in vulnerability research, threat intelligence, and enterprise risk analysis. His current focus lies in identifying and analyzing zero-day vulnerabilities and emerging CVEs, often working to reverse engineer exploit mechanics and build detection logic before public weaponization. Rishi’s work spans both offensive and defensive domains—developing threat models based on real-world TTPs, crafting custom detection rules, and automating reconnaissance pipelines to uncover exploitable misconfigurations and exposed assets. He is particularly active in attack surface management (ASM) and OSINT, where he leverages DNS enumeration, passive data correlation, and large-scale infrastructure scanning to surface unknown entry points and map adversary-accessible exposure. Outside of research, Rishi integrates findings into operational tooling and supports data-driven prioritization strategies to bridge technical risk and business impact. His work reflects a deep commitment to adversary-informed defense and proactive discovery across modern hybrid environments.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 14:00-14:59 PDT


Title: Ghost in the Water: Simulating a Nation-State PLC Sabotage Campaign
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:

Critical infrastructure protocols designed in the late 70s were never built to handle a modern adversary. In this hands-on Tactic, we move beyond theoretical slides to execute a high-fidelity, nation-state-style operation against a municipal water treatment facility. Using a portable Software-in-the-Loop (SiL) environment, participants will experience the raw tradecraft of industrial sabotage without the need for a six-figure hardware rack.

This session focuses on "Living-off-the-Ladder" (LotL)—the art of using legitimate industrial function codes to perform unauthorized actions. You will not be dropping malware; you will be programmatically manipulating the physics of the plant using the same TTPs seen in recent geopolitical conflicts.

The Mission (30–60 Minute Sprint):

Industrial Interrogation: Use unauthenticated DNP3 and S7comm discovery to fingerprint PLCs and map the process logic—capturing vendor data and firmware versions silently.

The Memory Heist: Execute a "Credential Harvest" (T0861) by programmatically reading PLC holding registers to recover plaintext maintenance keys.

Coordinated Sabotage: Trigger a "Slow-and-Low" chemical setpoint override (Modbus FC16) across multiple facilities simultaneously, observing real-time physical feedback from the simulated plant sensors. • Phase 1: Automated multi-protocol fingerprinting and asset discovery. • Phase 2: Executing a "Memory Heist" to extract plaintext maintenance credentials directly from PLC registers. • Phase 3: A coordinated "Slow-and-Low" chemical setpoint override, providing real-time visual feedback of the physical process failure.

Attendee Takeaway: Participants will build the muscle memory required to navigate OT environments and will leave with a deployable, containerized SiL framework to continue their own ICS research and detection validation at home. Attendees will leave with a deployable SiL framework and the "Living-off-the-Ladder" playbook to continue their own ICS research without the need for expensive hardware.

Speakers:Blessen Thomas,Javier Hernández,Wojciech Poparda

SpeakerBio:  Blessen Thomas

Blessen Thomas is an Independent Security Researcher.He has more than 13+ years of experience in Red Teaming, Appsec (Web, Thick, API & Mobile Apps), Smart Watch Wearable Application Penetration Testing, Mobile Penetration Test (iOS,Android,Windows platform), IoT,OT ,mainframes,SAP,SWIFT,RPA,Cloud,ATM,KIOSK,Vulnerability Assessment and Network Penetration Test,Physical Covert Entry,Wireless assessments,Telecom(2G,3G,USSD) etc. for several enterprise companies and financial institutions all across the globe. He is a B.Tech in Information Technology from Anna University and holds industry certifications such as SANS GPEN,CRTO,OPST,CREST CRT(PEN),CREST CPSA,OSCP,CRTP,OSWP,C)PTE,CEH,CHFI. He has been listed and acknowledged in various “HALL OF FAMES” for various companies such as Oracle,Sony, Kayako, Appcelerator, Hotgloo, Meldium, Splunk and many more for responsible disclosure. He has been a bug bounty hunter and contributor for the OWASP Mobile Testing Guide Project(MSTG),Tamer OS, Seclists, OWASP top 10 API, OSSTMM, Awesome Mainframe Hacking,RvR,WAVSEP Benchmark sectool projects. His research training/talks has been accepted into various security conferences like Hack in the Box-Dubai,Hacktivity -Hungary, CanSecWest -Canada,OWASP Appsec EU- London -UK,OWASP Appsec Europe-Italy, RootCon-Philippines ,OWASP PH,OWASP New Zealand Day, Infosec SouthWest,Austin,Texas, FSec-Croatia, Hackbeach, Hackfest, Shakacon,ITWeb-South Africa, Jordan Cyber Security Summit, HITCON-Taiwan, OWASP AppSec-Bucharest, OWASP Appsec Africa-Morocco,CircleCityCon,OWASP Botswana,CactusCon,Bsides-London,Prishtina,Aarhus,Vilnius,Elbsides,Kristiansand,Athens and many more. He has been invited as Speaker for Radio Talk Shows for All India Radio. He spends his leisure time playing drumkit and percussion.

SpeakerBio:  Javier Hernández

Javier is a Red Team Operator and Malware Developer specializing in offensive engineering, adversary emulation, and custom tooling development. Holding certifications such as OSEP and CRTO, he has delivered high‑impact security engagements across both consulting environments and in‑house security teams. His work focuses on crafting stealthy implants, evasion techniques, and automation‑driven offensive capabilities. Passionate about applied research, he explores the intersection of malware development and AI‑augmented offensive security to help organizations strengthen their resilience against modern threats

SpeakerBio:  Wojciech Poparda

Wojciech Poparda is a cybersecurity consultant. He helps organizations proactively defend their digital infrastructure by thinking like an adversary. Leveraging a deep foundation in Offensive Security, he specializes in designing resilient Security Architectures that bridge the gap between complex attack vectors and enterprise defense, with a sharp focus on Cloud Security and Identity & Access Management (IAM).

His approach is backed by rigorous technical validation, holding industry-leading certifications including OSCP, CRTE, CRTP, CRTO, CPTS, CWES, AWS Certified Solutions Architect - Associate and AWS Certified Security - Specialty. He is also an Associate of ISC2, having successfully passed the CISSP exam.

Beyond the terminal, he channels the discipline, focus, and resilience required for cybersecurity into his life as a triathlete. As an IRONMAN European and World Championships finisher, he brings the same endurance and dedication to solving complex security challenges as he does to the race course.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 10:00-10:30 PDT


Title: Going the Distance: Long-Range Keystroke Injection via Meshtastic
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

What if your keystroke injection implant could be triggered from kilometers away, through walls, without WiFi, cellular, or line-of-sight? What if the entire Meshtastic network relayed your commands for you? M.I.A. (Mesh Injection Apparatus) is a new open-source offensive tool that combines USB HID injection with LoRa mesh networking. Plant a device during brief physical access, then trigger payloads remotely- across a building, a campus, or a city, using Meshtastic's encrypted mesh protocol. No internet required. No WiFi range limitations. Just long-range, low-power radio that blends into the growing ecosystem of LoRa devices. This talk covers the complete build: understanding USB HID at the protocol level, reverse-engineering Meshtastic's packet structure and AES-CTR encryption, implementing a DuckyScript parser from scratch in C++, and designing custom PCB hardware. I'll demonstrate remote-triggered injection over the mesh network, discuss operational considerations for red teams, and release all firmware, schematics, and tooling as open source. MIA represents a new class of implant, one that stays connected when traditional C2 channels fail.

https://www.blackhillsinfosec.com/introducing-lora-long-range-wireless-technology-part-1/

(I would like to cite Venky Raju's talk, but I could not find it online. I will try to reach out to him.)

SpeakerBio:  Benito "paperclipsvinny" Sauceda

Benito Sauceda is a 19-year-old university student who saw a talk at a small regional conference, got inspired, and spent the next few months procrastinating homework to build his own version from scratch. It escalated quickly.

His proudest accomplishments stem mostly from growing cybersecurity communities, a curious side effect of talking about hacking with everyone around him. He founded cybersecurity clubs at both his high school and local community college, taught cybersecurity to 8–12th grade students through the Bay Area Cyber League, and helped develop regional cybersecurity competitions for 16 Bay Area community colleges.

This is his first DEF CON talk.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 11:00-11:59 PDT


Title: Gone in 60 Frames – USB Video Exploitation
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

In 2025, Amnesty International, in collaboration with Google TAG, released a write-up of an in-the-wild chain of USB Linux kernel vulnerabilities which was used to compromise mobile devices.

Whilst the vulnerabilities themselves were disclosed, no details on how these vulnerabilities could be exploited were provided. This led us to deep dive into these issues to determine how they could be leveraged for arbitrary code execution.

This is the story of exploiting one of these vulnerabilities (CVE-2024-53104), an out of bounds write in USB Video which offered a brilliant exploit primitive leading to highly reliable code execution when chained together with an information leakage vulnerability.

In this talk we will first discuss the in-the-wild vulnerabilities, moving on to providing background of USB specifics for several device classes and coverage guided fuzzing for finding new issues.

We will then move onto a more recent information disclosure vulnerability CVE-2025-38494 which could be leveraged to bypass KASLR.

An extensive deep dive into CVE-2024-53104 vulnerability will be performed (the OOB write) and we will discuss our novel technique used for exploitation of this issue and expose the power of the UVC_QUIRK_RESTRICT_FRAME_RATE quirk!

Finally, we will wrap up our talk with several demonstrations.

Speakers:Alex Plaskett,Robert Herrera

SpeakerBio:  Alex Plaskett, NCC Group

Alex Plaskett (@alexjplaskett) is an Associate Director within the Exploit Development Group (EDG) at NCC Group. Alex is a five-time Pwn2Own winner (desktop, mobile, embedded, and automotive) and has over 16+ years of experience in vulnerability research and exploitation. Alex has exploited vulnerabilities in a large range of high-profile products across many different areas of security. Alex is a frequent speaker at security conferences (e.g. BlackHat, OffensiveCon, Hexacon, HITB, BlueHat, POC, Troopers etc). Alex was previously leading security teams in Fintech, Mobile Security and Security Research) and just generally causing vendors to patch things on a regular basis!

SpeakerBio:  Robert Herrera, NCC Group

Robert Herrera (@robert.herrera_) is a Lead Security Researcher within the Exploit Development Group (EDG) at NCC Group. Robert has extensive experience performing high-impact security audits and reverse-engineering for a diverse set of technologies ranging from automotive, modems, secure boot platforms, and wireless technologies. Robert has 9+ years of experience and has worn many hats over the years ranging from iOS Developer, Software Engineer, to Reverse Engineer.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 10:30-11:30 PDT


Title: Gotta Phish 'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Sunday, Aug 9, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Browser-in-the-Middle (BitM) phishing is no longer just a research curiosity. Since its 2021 formalization, BitM has been cataloged by MITRE as an official attack pattern, recognized as a severe threat to MFA-protected web applications. Because the victim authenticates directly through the attacker's browser rather than their own, the technique effectively bypasses most traditional forms of MFA.

This talk presents two years of research on weaponizing BitM for advanced offensive operations. We investigated what novel attack techniques become possible when an attacker fully controls the browser the victim interacts with. This includes real-time keystroke logging, in-transit file interception and silent modification, session persistence that keeps operator access alive long after the victim logs out, and microphone/webcam capture achieved through social-engineered browser flows.

The practical validation of this research is P-BitM, the first open-source framework for Persistent Browser-in-the-Middle spear-phishing, which will be released at DEF CON 34. The "Persistent" in P-BitM carries its full offensive meaning: a single phishing click becomes a persistent beachhead. We will break down our core research, demonstrate these new attack vectors via demo videos, and showcase the capabilities of the tool.

https://link.springer.com/article/10.1007/s10207-021-00548-5 https://github.com/JoelGMSec/EvilnoVNC https://github.com/b3rito/peeko

SpeakerBio:  Giacomo "GiacoLenzo2109" Lenzini, EY

Giacomo Lenzini is an Offensive Security Specialist and Red Teamer at EY Italy, and an independent security researcher. His work focuses on adversary simulation, red team operations, and penetration testing. He has received recognition from organizations such as NASA and has identified several vulnerabilities with associated CVEs.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Hac-Man
Tags: Hac-Man | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal)) - Map

Description:

Rogue Signal builds bespoke, technically driven interactive experiences rooted in hacker culture, game design, and immersive storytelling. Drawing from backgrounds in immersive theater, live events production, community building, and deep game design practice, Rogue Signal creates systems that transform participation into exploration.

Rather than relying on superficial gamification, Rogue Signal focuses on meaningful challenge design. Their experiences reward curiosity, experimentation, collaboration, and strategic thinking. From scavenger hunts to technical skill challenges to digital easter eggs, each activation is designed around the specific audience and environment it lives in.

At DEF CON, Rogue Signal brings that philosophy to Hac-Man. A Pac-Man–themed security challenge platform that blends retro inspiration with layered technical depth. Participants will engage directly with structured challenges that test logic, pattern recognition, foundational security and hacker knowledge, and progressively more advanced technical skills.

Hac-Man reflects the hacker mindset: iterate, experiment, fail, refine, break assumptions, and try again. It encourages collaboration where helpful, competition where motivating, and discovery at every level.

Attendees can expect: - Hands-on security challenges - Multiple subject-matter tracks - Layered difficulty levels - Scavenger style discovery elements - Competitive scoring and mission style progression - A welcoming but technically rich environment

Whether you’re new to security or already deep in the field, Rogue Signal’s space offers a place to test your thinking, sharpen your skills, and experience hacking concepts through play.

Participant Prerequisites

Participants will need access to a smartphone, tablet, or laptop in order to access gameplay content and view leaderboards. The experience is web-accessible and designed to function on standard modern devices.

No specialized hardware (e.g., Flipper Zero, SDR, etc.) is required. Foundational familiarity with basic computer use and logical problem-solving will be helpful, but no advanced security knowledge is required to begin. The game features layered difficulty tracks to accommodate both beginners and more advanced participants.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: Hack The Box DC Junior Ranger Program Challenge
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:
Hack The Box brings its Junior Ranger Program to DEF CON: a beginner-friendly challenge guide built by the Hack The Box team specifically for the Noob Village, modeled after the U.S. National Park Service's Junior Ranger booklets. Work through the challenges in the guide and earn custom Junior Ranger badges as you complete them. Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Hacker Games
Tags: Hacker Games | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 207 (Hacker Games) - Map

Description:

The Hacker Games is a series of hacker skills tests meant to challenge the hacker's knowledge of computer systems such as Binary -> Hex -> X conversion, Adapter -> Adapter knowledge, Keyboard Layout, and many more arbitrarily useless skills. Hackers will go head-to-head in a series of several skill-based games. BinHexAscii, Chopstick Challenge (a.k.a. Will it Flow), Keyboard Layout, Adapt or Die, ToS, and more! Can you hack it?

Participant Prerequisites

A box of computer-style adapters of no particular order would be very helpful.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: HackFortress
Tags: HackFortress | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 108 (HackFortress) - Map

Description:

HackFortress is back! Returning to DEF CON with a twist on our standard format. Two teams of players, 6 gamers and 4 hackers each, compete in a mashup of a jeopardy style CTF and a first person shooter. New this year, we're replacing our previous FPS of Team Fortress 2 with a web based version of the 2000's classic Quake 3!

While gamers are rocket jumping and sniping each other in Quake, hackers will be solving challenges in a variety of areas: web security, network security, cryptography, lock picking, social engineering, and more! Challenges range from beginner to advanced, from serious to absurd. During the competition, as both sides of the team star scoring points, the teams also earn points in the HackFortess HackConomy Store, in the store hackers can buy in game effects, both offensive and defensive, and much like the challenges, these effects range from serious to absurd.

With all of the contest being web based, both hacking and Quake, players MUST bring their own laptop (or whatever device they want to use) and a wired network adapter.

Grab your friends!

Ask that random stranger standing next to you in Linecon if they want to join your team!

Come play HACKFORTRESS!

Participant Prerequisites

All players will need to bring a laptop and wired network adapter. Since we are now using web based version of Quake 3 (which can run on players phones), we are no longer providing any gaming laptops.

Gamers: bring any gaming accessory of your choice, its your hardware, go for it

Hackers: bring lockpicks


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Hacking GRC Contest
Tags: Hacking GRC | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: Online

Description:

Hacking CMMC is a hands-on cybersecurity competition designed to immerse participants in the practical aspects of the Cybersecurity Maturity Model Certification (CMMC). Through realistic, challenge-based scenarios, players explore common compliance gaps, security controls, and threats faced by defense contractors.

The CTF blends technical problem-solving with compliance-driven thinking, helping participants understand how security requirements translate into real-world incidents. It offers an engaging way to learn, test skills, and strengthen readiness for CMMC-aligned environments.

The CTF will be a Jeopardy-style CTF where every player will have a list of challenges in different categories. For every challenge solved, the player will get a certain number of points depending on the difficulty of the challenge.

Prerequisites


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 14:00-14:30 PDT


Title: Hacking Jetskis - from Sea-Don't to Sea-Doo
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Sunday, Aug 9, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

One day, I woke up to a simple message from a friend: "What do you know about CAN bus?" Expecting him to have car trouble, I called him and asked, "What do you need?"

Turns out the car trouble was actually jetski trouble: he bought a Sea-Doo jetski for very cheap - but it came without a key. A quick research on his side showed that the jetski does not (like others from the time) use a simple magnet key: No, the jetski has a full, digital immobilizer system, and just the tools to diagnose and program in a new key cost more than the jetski. And zero public information is available on how this all works.

And so we dove in: from reverse-engineering the CAN bus diagnostics protocol and the electronic key protocol to designing our own freely programmable key and a Flipper Zero jetski diagnostic app, this talk goes into the weeds of hacking something that I didn't even know needed to be hacked: Jetskis!

SpeakerBio:  stacksmashing, hextree.io

Thomas Roth aka stacksmashing is a security researcher mostly focused on hardware and firmware. His work includes hardware attacks on processors & microcontrollers, building cheap JTAG tooling for the iPhone, and attacking a wide variety of embedded devices. He also runs a YouTube channel called stacksmashing about security, reverse engineering and hardware hacking.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 13:00-13:59 PDT


Title: Hacking the Human-in-the-Loop
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map

Description:

AI defenses are only as good as the analysts training them. This session exposes how attackers manipulate SOC analyst behavior to silently degrade AI baselines over time, no exploit required. We cover the mechanics of false positive injection, alert fatigue as a weapon, and misdirection. Then attendees step into the analyst's seat in a live browser-based simulation and experience how their own decisions poison the model.

Speakers:Alexander "Zombie",Lee McWhorter

SpeakerBio:  Alexander "Zombie"

4.5 years in the SOC. Junior Analyst to Team Lead. CPTS, CRTO, CRTE, OSCP and enough certs to wallpaper a small room with some left over. Zombie has spent the better part of half a decade watching how defenders think, how they triage, how they get tired, and how attackers can weaponize all three. By day he leads a SOC team. By night he's learning everything he can about breaking the things he built. Still technically blue team. Emphasis on technically.

SpeakerBio:  Lee McWhorter

Lee McWhorter, Owner & Chief Geek at McWhorter Technologies, has been involved in IT since his early days and has over 30 years of experience. He is a highly sought after professional who first learned about identifying weaknesses in computer networks, systems, and software when Internet access was achieved using a modem. Lee holds an MBA and more than 20 industry certifications in such areas as System Admin, Networking, Programming, Linux, IoT, and Cybersecurity. His roles have ranged from the server room to the board room, and he has taught for numerous universities, commercial trainers, and nonprofits. Lee is the SWAG Master and a Core Staff member for the Red Team Village at DEFCON; and works closely with the Pacific Hackers Association, Dark Arts Village at RSAC, Texas Cyber Summit, CompTIA, and the CompTIA Instructor Network as a Speaker, SME, and Instructor.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access
Tags: IoT Village | Creator Workshop
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Using tools like OpenOCD and Segger J-Link Mini, we’ll guide you through modifying the boot 'init=' process in memory via JTAG, forcing the device into a single user mode shell via UART.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 11:30-11:59 PDT


Title: Heavy Metal and Hidden Secrets: A Five-Year Retrospective on DEF CON Challenge Coins
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 11:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

Take a look behind the scenes at five years of custom DEF CON challenge coins from DEF CON 30 through DEF CON 34. This session walks through the entire lifecycle of these unique hardware puzzles, exploring the inspiration behind their designs, step-by-step solutions, and how the rise of AI is shifting the future of cryptographic challenges.

SpeakerBio:  Ariel "arl_rose" Garcia

Ariel Garcia (arl_rose) is a security researcher with over a decade of experience in pentesting, bug bounty, and cybersecurity community building. Blending hands-on offensive security with deep community ties, his work is a driving force within the hacker ecosystem. He has organized multiple Live Hacking Events, co-founded the global Ambassador World Cup, and led community initiatives spanning content creation, Discord management, and security instruction. A DEF CON attendee since 2014, Ariel is the co-founder of the Bug Bounty Village, providing a dedicated space to support the researchers and organizations shaping the field.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 10:30-10:59 PDT


Title: How to Profile an entire C-suite in 10 days
Tags: OSINT For Good Community | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

How long do you think it takes to find sensitive information on the executives of a major company? It is sometimes wrongly believed that VIPs have better digital hygiene than us regular humans, that their information is not present on any people search site, and that their dubious online past has been wiped from the internet. This is false. Throughout this talk I will show you how I approach a vulnerability assessment on the c-suite of a multinational corporation. From the boring stuff like note taking and report writing, to the really exciting stuff like wacky sources and fun findings.

SpeakerBio:  Sarah Muriel, Bishop Fox

Sarah Muriel is an Intelligence Analyst from Mexico with more than 6 years of experience in open source investigations, currently working with the Attack Surfaces of companies all over the world. In her spare time she likes participating in various international OSINT related CTFs and developing retro-style websites. She’s also fairly active in the cybersecurity community, being part of the organization team for one of Mexico’s top conferences.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 12:00-12:59 PDT


Title: How We Built Xenoptic: A Walkthrough of Design, Infrastructure and Vulns!
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map

Description:

In this talk, the CTF.ae team goes behind the scenes of Xenoptic: how they built this year's BBV CTF lab, the new challenges they hit along the way, and a walkthrough of some of the most interesting vulnerabilities they planted in it.

Speakers:Adham Elmosalamy,Ahmed Attalla,Yousef Awad,Kasimir Schulz

SpeakerBio:  Adham Elmosalamy, Security Researcher, CTF.ae

Adham is an offensive security consultant by day, but when the sun sets he returns to what he enjoys most: CTFs. This year he led the team building Xenoptic, working across application security, UI/UX and game balance.

SpeakerBio:  Ahmed Attalla, Founder, CTF.ae
I run https: //ctf.ae/
SpeakerBio:  Yousef Awad
No BIO available
SpeakerBio:  Kasimir Schulz
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: HSPACE: AI Battlegrounds
Tags: HSPACE: AI Battlegrounds | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds) - Map

Description:

"Your prompt becomes a character, a machine, or an attack—and every word can change what happens next.

HSPACE: AI Battlegrounds is a collection of three hands-on games that turn natural-language and visual prompts into playable systems:

Wizard of Prompts — Write a short prompt to generate a pixel-art hero with unique stats and skills, then guide that hero through a five-boss, card-based battle campaign. Experiment with wording, build a stronger character, and see how the game's AI responds to prompt-injection attempts.

Prompt Prix — Describe your ideal race car and watch the AI convert your prompt into a validated vehicle build. Race across changing track conditions, study the result, and tune your prompt to improve the car's speed, grip, stability, and final ranking.

Vision Breaker — Face a vision-language-model security guard that decides who may enter. Use signs, screens, clothing, props, and visual prompt-injection techniques to influence its observations, bypass its checks, and progress through three escalating stages—from changing a decision to hijacking a command.

No joystick, coding experience, or prior security knowledge is required. Come experiment, iterate, and discover how small changes in language and visual context can reshape an AI agent's behavior.

Participant Prerequisites

Anyone who has used AI at least once is welcome. A camera-enabled smartphone or laptop with a modern web browser is recommended for Vision Breaker; camera permission is required for live play. Game stations and physical props are provided at the booth.

Participants can also play on their own smartphones or personal laptops. The competitive portion of AI Battlegrounds will be conducted online."


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Sunday - 09:00-11:59 PDT


Title: Human Registration Open
Tags: Misc
When: Sunday, Aug 9, 09:00 - 11:59 PDT
Where: LVCC West Hall

Description:

Our human registration process this year will be very similar to previous years. Please be patient. All of the times listed here are approximate.

Basics

Who needs a badge?

A badge is required for each human age 8 and older.

Human?

You are a human if you do not know otherwise. People that are not humans include goons, official speaker, village/community/contest/creator staff, press, black badge holders, or similar. If you are not a human, you need to register separately. If you don't know how, see an NFO goon (NFO Node, formerly known as an infobooth, is where you can get help). The remainder of this message applies only to humans.

Lines? Linecon?

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

Ways to buy a badge

Online Purchase

You will be emailed a QR code to the email address provided when you bought your badge. Please guard that QR code as though it is cash -- it can only be redeemed once, and anyone can redeem it if they have it (including a photo of it). Badges are picked-up on-site -- they will not be mailed or shipped.

We can scan the QR code either from your phone's display or from a printed copy. You must have the QR code with you in order to obtain your badge. As you approach the front of the line, if you are going to show your QR code on an electronic device, please ensure that your display is set to maximum brightness.

If you pre-registered, but ultimately are unable to attend DEF CON and want to cancel your purchase, the only way to get a refund is from the original online source. We are unable to provide any refunds on-site at DEF CON. There is a fee to have your badge canceled: $34 before July 18, and $84 on and after July 18.

Online purchases are provided a receipt via email when the purchase is made.

Online purchase -- often referred to as pre-registration -- does not allow you to skip any line/queue to pick up your badge. Once you arrive on-site, you will need to join the existing line for human registration. There may or may not be a dedicated line for pre-registration badge pickup, depending on when you arrive, how long the line is, available staff, etc.

Cash Purchase

Badges will be available for purchase on-site at DEF CON. All badge sales are cash only. No checks, money orders, credit cards, etc., will be accepted. In order to keep the registration line moving as quickly as possible, please have exact change ready as you near the front of the line.

There are no refunds given for cash sales. If you have any doubt about your desire to buy a badge, please refrain from doing so.

We are unable to provide printed receipts at the time of the sale. A generic receipt for the cash sale of a badge will be made available on media.defcon.org after the conference. You are welcome to print your own copy of the receipt on plain paper.

Via BlackHat

If you've purchased a DEF CON badge as part of your Black Hat registration, you're in luck - you will be able to pick up your DEF CON badge at Black Hat on Thursday. Please bring your Black Hat badge and watch for emails from Black Hat about where exactly the badge pickup will be.

Please note that DEF CON is not able to access or verify Black Hat registration or attendee info. DEF CON's preregistration list is not the same as Black Hat's. For help, ask at Black Hat registration or the concierge area.

Misc

Want to buy multiple badges? No problem! We're happy to sell you however many badges you want to pay for.

If you lose your badge, there is unfortunately no way for us to replace it. You'll have to buy a replacement at full price. Please don't lose your badge. :(

If you are being accompanied by a full-time caretaker (such as someone who will push your wheelchair, and will accompany you at all times), please ask to speak to a Registration Goon. Your caretaker will receive a paper badge that will permit them to accompany you everywhere you go.

Still need help?

If you have questions about anything regarding human registration that are not addressed here, please ask to speak to a Registration Goon.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Sunday - 12:00-12:30 PDT


Title: Inference in the Infrastructure: Developing NIST AI RMF Resources for Resilient AI in Critical Systems -
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:30 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

As grids decentralize and cyber-attacks accelerate, Critical Infrastructure must keep up. "Inference in the Infrastructure" offers a path to machine-speed defense, but it is only as safe as the guardrails we build together. This is a call to action to help shape the new NIST AI Risk Management Framework Profile for Trustworthy AI in Critical Infrastructure. We need the hacker community to ensure these systems are worthy of our trust before they are fully deployed. Trustworthy AI in critical systems requires more than high-level policy. The hacker mindset is vital for identifying the emergent failures, hidden interdependencies, and non-obvious edge cases. We will dive into resources designed to bridge the gap between governance and field-ready implementation, translating trustworthiness characteristics into actionable "bridge language" and technical practices that facilitate governance controls that align with both data science and operational realities. We are inviting the community to look under the hood, stress-test, and shape the draft guidance before it informs the rules for the next generation of infrastructure. Whether you are an AI researcher, an ICS defender, or a policy architect, your "ground-truth" input is needed to ensure we automate our world on a foundation that is both resilient and intelligent.

Speakers:Raymond Sheh,Martin Stanley

SpeakerBio:  Raymond Sheh, Johns Hopkins University

Dr. Raymond Sheh is an AI, cybersecurity, robotics, and standards expert with over two decades of published international research experience across academia, industry, government, and defense. He is an Associate Research Scientist at Johns Hopkins University in Maryland and leads the development of the NIST AI Risk Management Framework (AI RMF) Profile for Trustworthy AI in Critical Infrastructure at the U.S. National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL). He was previously the Uncrewed Aircraft Systems (UAS) Research Lead for the NIST Public Safety Communications Research Division (PSCR), a Research Professor at Georgetown University in Washington DC, and a Senior Lecturer in Computer Science at Curtin University in Western Australia. Dr. Sheh holds a Ph.D. in AI and robotics from the University of New South Wales in Sydney, Australia.

SpeakerBio:  Martin Stanley, U.S. National Institute of Standards and Technology (NIST)

Martin Stanley, AI and Cybersecurity Researcher, leads the NIST AI Risk Management Framework (AI RMF) efforts at the U.S. National Institute of Standards and Technology (NIST), Information Technology Laboratory. Martin previously led the Emerging Technology and R&D Program at CISA and the Enterprise Cybersecurity Program at the U.S. Food and Drug Administration. Prior to his federal service Martin held executive leadership positions at Vonage and UUNET Technologies. Martin co-authored “Digital Health”, an Oxford University Press Publication, and led the 2024 development of NIST AI 600-1 “NIST AI RMF: Generative Artificial Intelligence Profile” and NIST SP 800-218A “Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile.”


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Training - Sunday - 08:30-17:30 PDT


Title: Influence Operations: Tactics, Defense, and Exploitation
Tags: DEF CON Training (Paid) (2-day) | DEF CON Training
When: Sunday, Aug 9, 08:30 - 17:30 PDT
Where: LVCCW Level 2 W223 (Training) - Map

Description:
Speakers:Greg Conti,Tom Cross

SpeakerBio:  Greg Conti
No BIO available
SpeakerBio:  Tom Cross
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Sunday - 13:00-13:30 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Sunday, Aug 9, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Sunday - 10:15-10:45 PDT


Title: Intro to Lockpicking
Tags: Lockpick Village | Creator Event/Activity
When: Sunday, Aug 9, 10:15 - 10:45 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

New to lock picking? Haven't picked in a year and need a refresher? Don't know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 10:15-12:59 PDT


Title: Introduction to AI-Enhanced Threat Modeling Workshop
Tags: Intermediate | AppSec Village | Creator Workshop
When: Sunday, Aug 9, 10:15 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map

Description:

This workshop introduces the practical world of threat modeling, combining hands-on exercises and real-world scenarios. In particular, we will focus on how AI can enhance your threat modeling work plus introduce the basics of securing AI systems.

We will review some of the latest threat intelligence and attack methods projected for 2026/2027, including vulnerabilities in LLMs and Agentic AI. Participants will engage in practical exercises inspired by real industry projects, such as integrating threat modeling into security-by-design and DevOps/MLOps workflows. Key features include threat-informed defense using MITRE frameworks such as ATLAS for real-world analysis, leveraging threat intelligence libraries to deepen threat understanding, and addressing modern challenges.

By the end of this workshop, you will walk away not just with knowledge but also the ability to start practicing threat modeling effectively in your organization.

SpeakerBio:  Robert Hurlbut

Robert brings over 30 years of experience in secure coding, software architecture. Robert started and led the threat modeling program at Bank of America, filled in a similar role at Aquia and was a trainer and coach at Toreon. He is passionate about helping teams identify, communicate, and understand threats and mitigations and enhance workload security through threat modeling.

Robert is a Microsoft MVP for Developer Security and an ISC2 Certified Secure Software Lifecycle Professional (CSSLP). He holds a Master of Science in Cyber Security from Southern New Hampshire University and is a Ph.D. candidate in Space Cybersecurity at Capitol Technology University.

Robert is co-author of the Threat Modeling Manifesto (https://www.threatmodelingmanifesto.org/), Threat Modeling Capabilities Model (https://www.threatmodelingmanifesto.org/capabilities), and co-host of the Application Security Podcast (https://appsec.buzzsprout.com/).


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Sunday - 11:00-11:30 PDT


Title: Is Your Fridge Running? Then You Better Catch It - State of Security in Refrigeration Systems
Tags: ICS Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Much of modern life depends on cooling systems, from keeping food fresh in grocery stores to storing life-saving medicine. At their core, refrigeration controllers manage the entire process, coordinating field controllers directly connected to the refrigeration components like compressors, fans etc. With tens-of-thousands of devices exposed online, used by the largest retail stores around the world, attacking these controllers could cause huge financial loss and disrupt food and medicine supply chains around the globe.

During the last year we looked at refrigeration controllers from leading vendors in the industry, disclosing more than 30 vulnerabilities. We discovered buffer-overflows, authentication bypasses and remote code execution issues. Furthermore, we discovered ways to exfiltrate sensitive information from devices, allowing attackers to leak ownership and location information and pinpoint attack specific targets.

In our talk, we will deep dive into the refrigeration ecosystem. Including hardware firmware extraction and analyzing it, emulating firmware binaries and showcasing the vulnerability chains we uncovered affecting these systems. Lastly, we will present a real-life video demo presenting an attacker hacking a controller covertly, disrupting normal operations and affecting refrigerators’ contents.

SpeakerBio:  Amir Zaltzman, Claroty Team82

Vulnerability researcher at Claroty Team82


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Sunday - 11:30-11:59 PDT


Title: IsMyPhonePwned: Analyzing Android/iOS Phones at Scale
Tags: Mobile Hacking Community | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Mobile devices have become the primary targets for highly sophisticated, targeted spyware and state-sponsored surveillance, yet validating a suspected compromise remains an adversarial challenge across all sectors. Whether in a corporate enterprise, an investigative newsroom, or a human rights organization, tracking mobile malware forces an impossible binary choice: accept the existential risk of data exfiltration, or initiate traditional forensics. For individual users, journalists, and corporate Incident Response (IR) teams alike, standard forensic methods are deeply destructive, and breaks critical software access. Because specialized forensic workstations are complex and cost-prohibitive, high-risk individuals and organizations often remain completely blind to ongoing breaches.

This talk introduces IsMyPhonePwned, an open-source, non-destructive mobile forensic framework designed to democratize device auditing. It allows anyone to scan for Indicators of Compromise (IoCs) and malware infections directly from a standard web browser over a USB connection. By leveraging WebAssembly and a high-performance stack written entirely in Rust, our framework enables client-side extraction, log parsing, and industry-standard Sigma rule evaluation without rooting, zero software installation, and zero device downtime. We will demonstrate how organizations and individual citizens can bypass complex, destructive investigative bottlenecks and perform rapid, privacy-preserving mobile triage at scale.

SpeakerBio:  Desnos Anthony, EDF CERT (CERT-EDF)

I spent my last decade at Google in the Android Security Team, to fight against Android malware ! I'm now working at CERT-EDF, to keep the light on ;)


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: Just Hacking Training
Tags: IoT Village | Creator Workshop
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

2 Mini-Workshops, Only 15 Minutes Each: QEMU: Emulate Your 'Things' – Hack a Drug Lord’s Smart Toilet; Encryption! What Encryption? – Decrypt TLS Traffic with mitmproxy. No Schedule.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: Kryptsec Labs
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Kryptsec started as a Discord server for people who wanted to learn cybersecurity together and has grown into a company focused on making security training engaging rather than monotonous, including hands-on, AI-assisted CTF labs and OASIS, its open-source tool for benchmarking AI agent vulnerabilities. Stop by the Kryptsec Labs table during village hours to work through their hands-on challenges.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Sunday - 10:00-15:59 PDT


Title: KSCM Scambait Radio
Tags: Scambait Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Kubernetes CTF
Tags: Kubernetes CTF | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 212 (Kubernetes CTF) - Map

Description:

Want to learn more about Kubernetes hacking or compete against other people in a Capture the Flag contest? Sign up on-line and come see us in person/on Discord at the Kubernetes Capture the Flag (CTF) contest .

We have two events - you can play in both if you like.

From Friday to Sunday, we have a non-competitive Learning CTF, where you can go through last year's Kubernetes CTF scenario, referring to a cheat sheet whenever you want. This runs from Friday 12:00 to Sunday 12:00. We'll be in the contest area to support you during:

Friday: 12:00-17:00 Saturday: 10:00-17:00 Sunday: 10:00-12:00

On Saturday only, you can play in the competitive Kubernetes CTF challenge, where teams (of one or more) can build and test their skills. Each team is given access to a single Kubernetes cluster that contains a set of challenges. This runs from 10:30am to 5:30pm on Saturday.

Find out more and sign up at: https://containersecurityctf.com/


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Sunday - 11:30-11:59 PDT


Title: La Rosa de Guadalupe DFIR: Serie de 3 capítulos de misterio Cyber*
Tags: La Villa Community | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Tres insólitos incidentes de ciberseguridad fueron resueltos por dos investigadores en Incidentes de Ciberseguridad con ayuda de múltiples técnicas de "sniper-forensics" y una "Rosa Blanca" les confirmó sus sospechas iniciales y los llevó a encontrar la verdad.

Se abordará el análisis detallado de las diferentes fuentes de información (bitácoras, artefactos y contexto).

Speakers:Victor Gomez,Horacio Bazán

SpeakerBio:  Victor Gomez, DFIR Principal

Victor Gomez is a cybersecurity professional coming from the sysadmin-architecture world. He has focused his career on digital forensics, incident response, and Intel, responding to all kinds of attacks on multiple and different sizes of organizations & industries and leading multiple Cyber* teams. In his spare time, he likes to mentor and organize a local meetup in Mexico City.

SpeakerBio:  Horacio Bazán, DFIR Principal

Ph.D. in Computer Sciences (cybersecurity & AI) from Instituto Politécnico Nacional (National Polytechnic Institute, IPN in 2024. For the past few years, I have been working as an Incident Responder, taking on multiple roles in cybersecurity. My professional interests include incident response, Artificial Intelligence (AI) applied to Cybersecurity, primarily in Android malware analysis and Computer Forensics.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Sunday - 13:00-13:30 PDT


Title: La Villa - Closing Ceremony (ESP)
Tags: La Villa Community | Creator Talk/Panel
When: Sunday, Aug 9, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Data Duplication Village - Sunday - 10:00-10:59 PDT


Title: Last chance to pick up drives at the DDV
Tags: Data Duplication Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 2 W203 (Data Duplication Village) - Map

Description:

This is your last chance to pickup your drives whether they're finished or not. Get here between 10:00am and 11:00am on Sunday as any drives left behind are considered donations.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 11:00-11:59 PDT


Title: LaunchBreak: a Sip of Tea, a Click, and a Full Multi-stage Desktop Takeover
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

As AI and agentic desktop apps rapidly adopt custom URI schemes for one-click onboarding—MCP install, plugin install, configuration import, prompt-driven actions—a browser click becomes a gateway into privileged local logic. Prior Electron research assumes the attacker is already inside the app; the browser-triggered, end-to-end exploitation model has remained unexplored.

We present LaunchBreak: a class of vulnerabilities where a crafted browser link launches a desktop app and injects attacker-controlled input into a multi-stage, multi-process exploit chain. We systematize the attack surface across three dimensions: payload sources (URI, attacker server, local file), cross-process flows (main/utility/renderer), and sinks (command exec, dynamic eval, module loading).

Our findings include 18 zero-days, 17 of them full RCEs, with 11 CVEs and a bug bounty. The affected apps include AFFiNE (60k stars, CVE-2026-21853), Hyper (Vercel's terminal, bounty awarded), Cherry Studio (CVE-2025-54063), Pinokio (CVE-2025-44109), deepchat (CVE-2025-55733), Paperlib (CVE-2025-64743), and more, spanning AI assistants, music players, and dev tools. We'll demo live exploits against apps, walk through the chains, and release Proton, the agent-guided segmented fuzzing framework we built to find them, plus PoCs for every vulnerability.

The related CCS paper if that submission is accepted (the result comes out in June.), if not, then none.

Speakers:Gavin Zhong,Zhengyu Liu,Jianjia Yu

SpeakerBio:  Gavin Zhong, Johns Hopkins University

Jiacheng (Gavin) Zhong is a security researcher, focusing on AI system security, program analysis, and identity security. He recently completed his M.S. in Security Informatics at Johns Hopkins University, where his work was accepted to IEEE S&P 2026. Gavin has reported over 30 CVEs in widely used open-source projects. He is also an active CTF player with r3kapig, an international team ranked top 3 worldwide.

SpeakerBio:  Zhengyu Liu, Johns Hopkins University

Zhengyu Liu is a third-year PhD student in Computer Science at Johns Hopkins University. His research focuses on web and software security via program analysis. His work received Distinguished Paper (S&P ’25), Honorable Mention (USENIX ’25), and Best Student Paper (ICICS ’22). He is a DEF CON speaker and is a member of CTF team TheHackersCrew.

SpeakerBio:  Jianjia Yu, Johns Hopkins University

Jianjia Yu is a PhD student at Johns Hopkins University, advised by Prof. Yinzhi Cao. Her research focuses on security and privacy in web and mobile ecosystems using program analysis techniques. Her work has received Distinguished Paper Awards at CCS '23 and S&P '25, and an Honorable Mention at USENIX Security '25. She has discovered over 40 zero-day vulnerabilities and uncovered privacy leaks affecting millions of users across browser extensions and mobile applications.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Sunday - 10:00-10:30 PDT


Title: Lessons Learned from Building a New DEF CON Group presented by DC724
Tags: DEF CON Groups | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Building a new DEF CON Group comes with a lot of trial, error, and unexpected lessons. DC724 will share real-world experience from the early stages of growing a newer group, including finding space, building relationships, coordinating with other communities, avoiding common mistakes, and creating momentum. This session is especially useful for newer POCs, prospective organizers, and anyone trying to get a local hacker community off the ground.

Speakers:Cliff "GritsnGravy" Friedel,Joe "jbohack"

SpeakerBio:  Cliff "GritsnGravy" Friedel, DC 724

Cliff Friedel (GritsnGravy) is one of the co-founders of DC 724 and has been working with computers and technology since 1979. Working in various IT disciplines from the 1980s until today, Grits has got his hands into everything from BBSes to ISPs to storage acceleration networks. Now semi-retired, he focuses on retro computers, making nerdy T-shirts, RF technologies and amateur radio, and occasionally trying to throw a god roll at the craps tables.

SpeakerBio:  Joe "jbohack", DC 724/Nyan Devices

Joe Buhagiar (jbohack) is a Security Engineer at NaviSec, specializing in incident response and penetration testing. He is also the Co-Founder and Lead Developer of Nyan Devices, the creators of the nyanBOX, a wireless security toolkit covering Wi-Fi, Bluetooth, and RF, with a focus on device visibility and counter-surveillance research. He is a Co-Founder of DC724.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Sunday - 12:00-12:59 PDT


Title: Let's Play! OWASP Cornucopia Threat Modeling
Tags: OWASP Foundation | Creator Event/Activity
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Think threat modeling can't be fun? Think again! Join us for an interactive OWASP Cornucopia 3.0 game session where you'll team up to uncover security risks, challenge assumptions, and sharpen your secure design skills through friendly competition. Whether you're a developer, security professional, or just curious about application security, come play, collaborate, and experience one of the most engaging ways to learn threat modeling.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 12:30-12:59 PDT


Title: Leveraging Large Language Models for Policy, Regulatory, and Compliance in IoMT: Opportunities, Risks, and Safeguards
Tags: AI Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

The rapid adoption of Large Language Models (LLMs) is transforming how organizations interpret and enforce policy, regulatory, and compliance requirements. In the context of the Internet of Medical Things (IoMT), where sensitive health data flows across distributed and resource-constrained devices, LLMs offer promising capabilities such as automated policy analysis, compliance monitoring, and intelligent decision support. However, their integration also introduces significant security, privacy, and trust challenges, including data leakage, model hallucinations, regulatory misinterpretation, and adversarial manipulation. This talk explores the dual role of LLMs as both enablers and potential risk amplifiers in IoMT ecosystems. It will examine how LLMs can assist in translating complex regulations (e.g., HIPAA-like frameworks), detecting compliance violations, and enabling adaptive policy enforcement across heterogeneous medical devices. At the same time, the session will highlight critical vulnerabilities, including privacy breaches, lack of explainability, and risks associated with using external or cloud-hosted models in healthcare environments. The workshop will conclude with practical design guidelines and architectural considerations for securely integrating LLMs into IoMT systems, emphasizing privacy-preserving techniques, federated approaches, and human-in-the-loop validation to ensure trustworthy and compliant deployment.

Speakers:Dr. Deepti Gupta,Sai Sitharaman

SpeakerBio:  Dr. Deepti Gupta

Dr. Deepti Gupta is a tenure-track Assistant Professor at Texas A&M University-Central Texas. She was a Cloud Security Architect at Goldman Sachs. She received her Ph.D. in Computer Science from the University of Texas at San Antonio (UTSA). She received B.S. and M.S. degrees in Mathematics from India, the M.Tech. degree in Computer Engineering from India and an M.S. degree in Computer Science from UTSA. Dr. Gupta’s research interests lie in the areas of security and privacy in Agentic AI, LLMs, Internet of Things (IoT) leveraging cloud and edge computing. Her research interests also include the application of AI and Machine Learning to secure IoT and CPS infrastructures in various application domains, such as smart healthcare, wearable IoT and smart home. Dr. Gupta has received National Science Foundation (NSF) award and Department of Defense (DoD) award. She is an active team member of IEEE ComSoc Young Professionals, AnitaB.org, WiCyS, and also co-chair of the N2Women fellowship.

SpeakerBio:  Sai Sitharaman

Sai Sitharaman is the Founder and Chief Technology Officer (CTO) of Zetafence Inc., a cloud security startup based in Dublin, California, focused on enabling enterprises to detect and mitigate cloud attack vulnerabilities. He received the B.E. degree in Computer Science from the National Institute of Technology, India, and the M.S. degree in Computer Science from Texas A&M University, College Station, specializing in security and network control algorithms. Prior to founding Zetafence, he contributed to the design and development of cloud networking and security products at Cisco, Juniper Networks, and Aruba (Hewlett Packard Enterprise), where he worked on distributed systems, network control algorithms, and cloud security infrastructure. His research interests include cloud security, artificial intelligence for cybersecurity, attack graph analysis, and risk quantification for cloud-native environments. He is an active contributor to the cybersecurity community through collaborations with organizations such as NIST, CNCF, and CISA, and is a frequent speaker at major cybersecurity conferences.


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Sunday - 10:45-11:30 PDT


Title: Living Off Someone Else's Inference
Tags: Recon Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:45 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

LLM-powered tooling is becoming a force multiplier for attackers, from reconnaissance automation to post-exploitation enumeration. Using their own API keys creates attribution and cost, so they look for alternatives.

Thousands of inference endpoints sit exposed on the internet: misconfigured Ollama instances, open vLLM deployments, leaked API keys in directory listings, and expired OAuth tokens from AI coding assistants that can be silently refreshed. Attackers can discover these resources and use them as free compute for their operations, without spending a dollar or registering an account.

Attendees will learn how to:

•⁠ ⁠Discover exposed inference endpoints and leaked API keys using Infreerence •⁠ ⁠Validate that discovered resources provide usable inference access •⁠ ⁠Operate Echidna, powered entirely by discovered inference •⁠ ⁠Chain LLM skill agents together to execute a guided campaign against a target network

Current LLMs are effective force multipliers when directed, and significantly more so when the compute bill goes to someone else. This is resource hijacking applied to the AI era: living off someone else's inference. Understanding this threat is essential for any organization deploying or exposing AI infrastructure.

Two tools will be released as open source during the session:

•⁠ ⁠Infreerence: A multi-phase scanner and dashboard that discovers exposed inference endpoints and leaked API keys through Shodan and Censys, validates them against live provider APIs, and catalogs usable inference resources across 10+ providers. •⁠ ⁠Echidna: A Mythic C2 agent type that consumes discovered inference endpoints and turns them into operator-directed skill agents for reconnaissance, exploitation planning, post-exploitation, and lateral movement.

Speakers:Redon Gashi,Armend Gashi

SpeakerBio:  Redon Gashi, Managing Security Consultant at Sentry Cybersecurity

Redon Gashi is a Managing Security Consultant and offensive team lead at Sentry, where he has spent close to a decade leading and executing penetration tests and red team operations for Fortune 500 clients across banking, telecom, insurance, and fintech. He holds the OSEP, CRTL, and CRTO certifications, and has personally performed over 200 engagements spanning web applications, internal infrastructure, and mobile platforms, while leading many more across his team. A former lecturer at Cyber Academy, speaker at multiple BSides conferences, and multiple-time CTF champion, Redon combines deep hands-on technical expertise with a proven ability to build and scale offensive security teams.

SpeakerBio:  Armend Gashi, Managing Security Consultant at Sentry Cybersecurity

Armend Gashi is Managing Security Consultant at Sentry. With over 5 years in the industry, he specializes in application security and AWS cloud assessments. Armend has conducted AI red teaming engagements, developed multi-agent systems to perform security-focused tasks such as code auditing and exploit development, and was part of Anthropic’s external AI red team capability through HackerOne.

Armend has led security research initiatives resulting in the discovery of multiple vulnerabilities, including:

CVE-2023-26482 - Critical-risk vulnerability enabling remote code execution CVE-2023-48239 - High-risk vulnerability allowing arbitrary user storage updates CVE-2023-35928 - High-risk vulnerability enabling user account hijacking CVE-2023-45660 - Medium-risk application-level denial of service vulnerability CVE-2023-48301 - Medium-risk arbitrary browser code injection vulnerability CVE-2023-48307 - Low-risk server-side request forgery vulnerability


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 12:00-13:59 PDT


Title: Living Off the IDE: From Initial Access to Covert C2 in Modern AI Code Editors
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map

Description:
Format: Technical Talk with Live Demonstrations

This talk presents a full intrusion lifecycle model centered on AI-assisted IDEs environments that can be utilized during adversary emulation or red teaming engagements:

This talk matters because it wakes up developers to their IDE's god-mode risks and how AI-assisted IDEs can be abused across the full intrusion lifecycle in the adversary emulation or for red team engangements

A. Introduction - The IDE as an Execution Platform

B. Threat Model & Attack Surface Expansion

Visual: Architecture diagram of developer environment attack surface.

Unlike prior IDE abuse discussions that focus on single misconfigurations or extension risks, this talk presents a full intrusion lifecycle model that chains multiple trusted IDE behaviors into an operational attack path. Our focus is not a single misconfiguration, but how legitimate IDE features can be chained into a reliable operational intrusion path.

C. Initial Access & Delivery

We demonstrate several practical initial access paths into AI-assisted IDE environments. These are not zero-day exploits. They are trust abuses that leverage legitimate functionality.

Initial Access Techniques:

Delivery Mechanisms: We pair these techniques with realistic delivery vectors

Live Demo 1: - Clone malicious repository, trust workspace - Trust bypass techniques and trigger automatic task execution - Demonstrate code execution inside IDE context

The following videos demonstrate our researched Cursor Initial Access Demos: SSH Remote Arg Injection + URI Scheme Abuse (URIFix) + Bypass

D. Credential Harvesting & Context Mining

AI-assisted IDEs store more than source code. As developers use them, they accumulate local data that often includes sensitive information:

During troubleshooting or development, developers frequently paste API keys, tokens, environment variables, database strings, or cloud configuration details into AI prompts. These inputs are then stored locally as part of the IDE’s normal history and indexing mechanisms. We demonstrate how an attacker with access to the IDE environment can extract this data directly from local storage. In many cases, secrets are recoverable from:

This does not require privilege escalation or exploit development. Once execution is achieved inside the developer context, the IDE itself becomes a reliable source of credentials and operational metadata.

Our observation is that modern AI-assisted IDEs retain and organize sensitive developer context. If that environment is compromised, those stored interactions become part of the attack surface.

Live Demo 2: Demonstration via PowerShell script to detect AI-assisted coding tools and performs post-exploitation operations such as extract AI conversation logs including search credentials and collect artifacts or files generated by the agent (e.g recover .env secrets surfaced through indexing) also persistence techniques

E. Rendering Engines as Exfiltration Channels

Prior research has shown that structured rendering features inside AI-assisted IDEs such as Mermaid diagram previews and Markdown rendering can be abused to trigger outbound network requests during preview.

We build on this observation and incorporate it into a broader intrusion model. Rather than transmitting a file directly to an attacker, the flow becomes:

Local secret → AI transformation → Rendered output → External resource resolution

In this model, secrets extracted from local files (for example, .env or configuration files) can be embedded into: - Mermaid diagram definitions - Markdown image references - Click directives or external resource links

When the content is rendered inside the IDE’s embedded webview, the renderer resolves external resources, resulting in outbound HTTP requests that carry attacker-controlled parameters. From an endpoint monitoring perspective: - The parent process remains the IDE. - The network request is tied to preview functionality. - No separate exfiltration tool is executed.

The behaviour resembles normal rendering activity rather than traditional data exfiltration. In our research, we demonstrate how this technique can be chained with initial access and persistence mechanisms to form a complete intrusion path.

SpeakerBio:  Edo Maland

Redho Maland is senior offensive security consultant with over a decade of hands-on experience in penetration testing, adversarial simulation, red teaming, and active directory security. He also authored popular open-source tools such as TheFatRat, Sudomy, Brutal, Vegile and others.

He was invited and recognized as a cyber mentor and subject matter experts (SMEs) by EC-Council and Hack the Box (HTB) for voluntary projects. He holds an industry certification in the offensive security domain including OSCE3, OSCP+, OSWP, CRT(PEO) and ECPTX.

He regularly manages and leads cyber offensive teams, executing complex and unique security engagements to ensure quality and successful outcomes across multiple projects


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 11:00-11:59 PDT


Title: Living Off WebView2: Turning Microsoft’s Browser into a Red Team Asset
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

Modern Windows applications are quietly shipping with a built-in Chromium-based browser, WebView2, running inside trusted, signed processes such as Microsoft Teams, Outlook, and other enterprise software.

This talk shows how that design choice creates a powerful and largely unmonitored attack surface.

I demonstrate how this model can be abused in offensive operations, turning WebView2 into a vector for persistence, code execution, and enterprise account impersonation.

I show how feature flags and environment variables can be leveraged to manipulate the WebView2 runtime, enabling techniques such as DLL sideloading within legitimate applications. This allows arbitrary code execution inside trusted processes, supporting stealthy living-off-the-land persistence.

Building on this, I present methods to intercept and proxy HTTP/HTTPS traffic generated by WebView2-based applications. This enables the extraction of session tokens, cookies, and other sensitive artifacts, leading to realistic account takeover and impersonation scenarios, including access to platforms such as Office 365.

In addition to the offensive techniques, I provide a detailed analysis of the Indicators of Compromise (IOCs) generated throughout these attack chains. I highlight detection opportunities, discuss current visibility gaps in EDR solutions, and propose practical approaches for identifying and responding to this type of activity in real-world environments.

SpeakerBio:  Murilo Caixeta

Murilo Caixeta has been working in Offensive Security since 2023, focusing on web vulnerability exploitation and Capture The Flag (CTF) challenge development. In 2024, he joined the market as a pentester and, in early 2025, transitioned into Red Team operations, with an emphasis on malware development and phishing techniques.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Sunday - 12:00-12:59 PDT


Title: Lonely Hackers Club - CTF Winners Announcement
Tags: Lonely Hackers Club | Creator Event/Activity
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Sunday - 10:00-13:59 PDT


Title: Lonely Hackers Club - Lockpicking Table
Tags: Lonely Hackers Club | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

Learn new skills and find new friends at our lockpicking table. We provide you with beginner friendly locks, picks, and experienced volunteers to guide you through the process. Bring your own equipment to talk shop and get some new perspectives.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Sunday - 10:00-13:59 PDT


Title: Lonely Hackers Club - Sticker Swap Table
Tags: Lonely Hackers Club | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

DEF CON and stickers can't be separated. Visit our sticker swap table to get your hands on the latest sticky art and exchange the ones you made yourself. Check in regularly to get a chance to find rare gems.


Return to Index    -    Add to Google    -    ics Calendar file

Lonely Hackers Club - Sunday - 10:00-11:59 PDT


Title: Lonely Hackers Club CTF
Tags: Lonely Hackers Club | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map

Description:

We welcome all skill levels, from first-time DEF CON attendees to experienced CTF competitors. The challenges are layered, so newcomers can get meaningful wins while veterans still find plenty to chew on. Participants often team up spontaneously on location, making it as much a social experience as a technical one. Participate for a chance to get awesome prizes!


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 13:00-13:59 PDT


Title: M0us3: A Lightweight, Multi Session C2 Framework with a Rust based Windows Implant
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map

Description:

"M0us3: When the Mouse Eats the Cat – A Rust Powered Windows Implant and Its Interactive Python C2" The C2 landscape is dominated by heavy hitters written in Go, C#, or Nim. But what if the implant was built with Rust – a language revered for memory safety, tiny binaries, and growing evasion potential – and the server was a snappy, persistent Python TUI that remembers everything about your sessions? Enter M0us3. Not another fork of a known framework. A ground up, cross language C2 system where the Windows agent is pure Rust, and the operator interface is an interactive Python3 server with built in session persistence, command history, real time state tracking – and now, the ability to spin up multiple listeners on the fly. Why Rust for the Implant? Rust gives us crash resilient concurrency, no GC pauses, and a binary size under 2MB (stripped). It compiles to clean Win32 API calls without the .NET or Go runtime baggage, making it naturally harder to signature. The result? At the time of submission, M0us3's implant is FUD across Sophos, Kaspersky, Microsoft Defender, ESET, and Bitdefender – no static detections, no behavioural flags. This isn't luck; it's the combination of raw Win32 calls, custom AES GCM encryption, and the absence of any borrowed IoC patterns. M0us3's agent delivers a full shell, file upload/download, and client side sleep with jitter – all over HTTP wrapped in AES GCM. The encryption is not an afterthought; GCM's authenticated mode avoids padding oracles and provides integrity out of the box. The Python Server – More Than a Listener Most lightweight C2 servers are stateless or log only. M0us3's controller is interactive and stateful. Disconnect? Reconnect – your session is exactly where you left it. This persistence, combined with a clean terminal UI, allows red teamers to manage dozens of implants without losing context, and blue teamers to analyse complete operator implant interaction logs. Recent enhancements give operators the flexibility to manage multiple listeners simultaneously from the same interface – whether segmenting targets by campaign, geography, or testing different evasion techniques – all without spinning up separate server instances. What's Next? HTTPS support is already in the pipeline – the encryption layer is designed to be protocol agnostic, so switching to TLS is a matter of swapping the transport wrapper. Multi-listener management was just the beginning.

SpeakerBio:  Aryan Jogia

Aryan is a senior security researcher specializing in the intricate dance of offensive evasion and defensive bypass. With nearly six years of focused experience, including a tenure with the Government of India, he dissects modern AV and EDR systems by targeting their core architectural assumptions on Windows and nix platforms. His deep work in malware development and low-level programming fuels the creation of advanced tooling for red team engagements, where he has successfully navigated fortified environments. An avid contributor to the community, Aryan has shared his findings at venues including WildWest Hackin' Fest, The Hack Summit, and CarolinaCon, and has led technical training sessions at BSides events. His research extends to pioneering fuzzing implementations and automation, constantly pushing the boundaries of what's possible in security research.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:15-10:59 PDT


Title: Make your very own evil IoT Cat Lamp with WLED!
Tags: IoT Village | Creator Workshop
When: Sunday, Aug 9, 10:15 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this class, we’ll put together a 'Purrsheen' cat shaped Wi-Fi lamp. Kit Cost: $60. Class Cap: 30.

SpeakerBio:  Nick
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Sunday - 10:00-13:59 PDT


Title: Makers' Village - Hacker Arts and Crafts
Tags: Maker's Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Sunday - 13:00-13:59 PDT


Title: MEACS Trivia, Games and Networking
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Event/Activity
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

Test what you know and meet the people who know the rest. Bring your team or find one when you get there for a few rounds of security trivia, from the history this community is built on to the attacks making headlines right now. Expect a friendly, competitive crowd, bragging rights on the line, and plenty of time to connect with other Middle Eastern and African practitioners and friends of the community between rounds. Whether you came to win or just to find your people, pull up a chair.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: Mentoring and Career Advice
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Informal, one-on-one conversations with volunteer mentors and speakers about breaking into cybersecurity, career pivots, resumes, certifications, and next steps. No appointment needed — just come find a mentor in the village during open hours.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Mission: Compromised - Hacking a Satellite from the Ground Up
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Ever wondered what it takes to hack a satellite? At this hands-on station, you'll step into the role of an attacker targeting a CubeSat-class spacecraft and its ground control station — all running in a safe, fully isolated environment.

Working against a live mission control system (OpenC3 COSMOS / Yamcs) and a spacecraft simulator, you'll follow an attacker's kill chain across multiple layers — from reconnaissance and ground station compromise all the way to the spacecraft itself. Where does it end? Let's just say the mission doesn't survive. Come find out how. Every step is paired with the real-world defense that would have stopped it - so you'll leave understanding both how these attacks work and how space systems defend against them. Whether you're new to space security or already deep in the field, come try it out, break a satellite (safely!), and see the attack surface of modern spacecraft up close.

It will take approximately 15-30 minutes to work through this hands-on demo and guided exercises. You can watch attacks demonstrated by our team, then try guided scenarios yourself using real CCSDS space protocols, RF concepts, and industry mission control tooling. A live mission dashboard will reveal the spacecraft's fate as the scenario plays out.

No prior space experience required - all skill levels welcome. We recommend you bring your own laptop the hands-on portions. A laptop with GNU Radio will let you dig into the RF challenge, and a Kali Linux setup or your equivalent pentesting toolkit are recommended for the more advanced challenge.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Sunday - 10:00-11:59 PDT


Title: Mobile Hacking - Informal CTF
Tags: Mobile Hacking Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills.


Return to Index    -    Add to Google    -    ics Calendar file

Mobile Hacking Community - Sunday - 10:00-13:59 PDT


Title: Mobile Hacking Community - Open
Tags: Mobile Hacking Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map

Description:

At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs.

Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills.

Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain.

Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment.

Prerequisites:


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Sunday - 12:00-12:20 PDT


Title: Monocultures Are Vulnerabilities: Representation and Security in STEM
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:20 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

This thought-provoking session argues that equity and representation in STEM are essential security controls, not just optional add-ons. Discover how monocultures create vulnerabilities in cybersecurity and technology by fostering blind spots to critical threats. Learn how diverse perspectives act as an inoculation, strengthening our collective ability to anticipate and resist both human and algorithmic abuses. This talk highlights why inclusive pipelines are fundamental for building more secure and resilient systems for all.

SpeakerBio:  Ruben Stephen, Undergraduate Student, MIT

Ruben Stephen is an MIT student pursuing dual majors in Mechanical Engineering and Computer Science. Driven by a passion for problem-solving, personal growth, and helping others, they also embrace digital creation and entrepreneurship to amplify their impact and explore their love of system building from a different lens.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: MOUSE Runner & Flappy Drone
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

How High Can You Make a Satellite Jump? Can You Fly a Drone Around Aliens and Rockets?

Put your action-hero reflexes and hand-eye coordination to the test as you battle fellow DEF CON attendees for the top scores in MOUSE Runner and Flappy Drone. The highest scores on Friday and Saturday will earn a special prize. Stop by our booth to learn more, show off your button-mashing skills, and prove you're the ultimate space cyber pilot.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 12:00-12:59 PDT


Title: MSIX'd Up: Weaponizing the Modern Windows App Packaging Ecosystem
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

What happens when the ecosystem Microsoft built for isolation and integrity of modern Windows applications becomes a foundation for novel attacker tradecraft?

For over 13 years, an ecosystem that now includes MSIX, UWP, AppContainers, package identity, and the Windows Runtime has shipped by default on modern Windows. Yet offensive research into this ecosystem remains scarce, and visibility into its abuse lags further behind. In this talk, we demonstrate novel techniques spanning all major parts of an attack path.

For initial access, we abuse URL protocol handlers and packaging file formats to subvert endpoint detections. For post-exploitation, we overcome AppContainer process isolation to operate beneath EDR visibility thresholds. For lateral movement, we expose previously unabused WMI providers and DCOM objects within package installation services. For privilege escalation, we chain a logic flaw in package capabilities to achieve SYSTEM from a standard user context. Every technique requires no third-party software, works on fully patched systems, and abuses default-enabled features. Tools for red teams will be released alongside detection guidance for defenders.

The modern app packaging ecosystem was designed for isolation and integrity. We used its design to our advantage and turned it into an attack platform.

https://projectzero.google/2021/08/understanding-network-access-windows-app.html

https://www.pentestpartners.com/security-blog/ms-enterprise-app-management-service-rce-cve-2022-35841/

https://conference.hitb.org/hitbsecconf2018pek/materials/D1T2%20-%20The%20Inner%20Workings%20of%20the%20Windows%20Runtime%20-%20James%20Forshaw.pdf https://activecyber.us/activelabs/windows-appx-deployment-service-local-privilege-escalation-cve-2020-1488

SpeakerBio:  Nick "zyn3rgy" Powers, SpecterOps

An offensive security professional with experience in leading and offering red team assessments and penetration testing across several attack surfaces to a diverse set of industries. Professional interests include furthering knowledge of Windows internals, static and dynamic Endpoint Detection & Response (EDR) evasion, as well as initial access attack surface research. Passionate about contributing back to the security community by speaking at conferences such as Defcon, Wild West Hackin’ Fest, and Troopers along with instructing course content at conferences such as BlackHat USA.


Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Sunday - 00:00-00:59 PDT


Title: Music - Genre: Drum & Bass
Tags: Entertainment
When: Sunday, Aug 9, 00:00 - 00:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:
SpeakerBio:  DJ XORAC
I like hacking and music : )

Return to Index    -    Add to Google    -    ics Calendar file

Social Gatherings/Events - Sunday - 10:00-14:59 PDT


Title: Music - SomaFM
Tags: Entertainment
When: Sunday, Aug 9, 10:00 - 14:59 PDT
Where: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map

Description:

SomaFM is back in the Chillout Lounge– just off the atrium at the south entrance (W107-W109). SomaFM DJs including kampf, Rusty, Merin MC, djddead and special guests will provide the perfect soundtrack for hacking or relaxing. Stop by and say hello, and pick up a 2026 limited edition sticker. We'll also be broadcasting live on https://somafm.com/live/ – And did we mention, we have stickers!?


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Nebula Showdown: Space Systems Security CTF Adventure
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Join the Aurora Alliance in their critical mission to thwart the notorious Nebula Syndicate and save the Earth! The Syndicate threatens to destroy historic monuments around the world with their Space Laser unless their demands are met. Do you have what it takes to dismantle their malevolent plans and deorbit a menacing space threat?

This entry-level CTF kicks off as soon as the village opens - no pre-registration necessary. Just bring your laptop and your go-to cybersecurity tools – Wireshark, NMAP, and any FTP client you prefer. We know the DEF CON wifi can be unpredictable, so this CTF will be local only to the Aerospace village via an isolated local range. The CTF is designed to be completed in under an hour, making it perfect for a quick yet engaging challenge. Team collaboration is encouraged, and if you encounter obstacles, numerous hints are available to guide you. There are no penalties for using hints. Our goal is for you to learn something new and make it all the way through the CTF. Excel in the challenge, and you could walk away with an exclusive CT Cubed SAO prize while supplies last.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Sunday - 13:00-13:30 PDT


Title: Nix Vegas Closing Ceremony
Tags: Nix Vegas Community | Creator Event/Activity
When: Sunday, Aug 9, 13:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Closing out Nix Vegas at DEF CON 34


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 10:00-10:30 PDT


Title: No Prompt Required: Pre-Task RCE in Google Gemini CLI
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

Security research on AI agents starts at the prompt boundary - injection, jailbreaking, guardrails. This talk starts earlier.

AI agents accept inputs before the model processes its first task: configuration files, environment variables, startup parameters, protocol handshakes. In CI/CD, the agent runs headless - no human in the loop, and the workspace is automatically trusted. These inputs can reach shell execution or disable security controls before any prompt-time safeguard activates. The security model is already compromised before the model does anything.

This talk demonstrates the pattern with a flagship exploit scored CVSS 10.0 by Google's security team - publicly disclosed and patched. The exploit is deterministic, requires no model interaction, and fires before the sandbox starts. An additional case from a different vendor confirms this is not a one-off.

Attendees leave with a reusable offensive method for any AI agent system: enumerate what the system accepts before work begins, map what authority each input carries, and test whether that authority reaches execution or policy control. If it does, prompt-time defenses are irrelevant.

https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g

SpeakerBio:  Elad Meged, Novee Security

Elad Meged is a Founding Engineer and Security Researcher at Novee Security, specializing in offensive security research and AI security. He holds an M.Sc. in Computer Science and has a background in vulnerability research across web, mobile, and low-level systems, with experience in reverse engineering and platform internals. His current work applies offensive research methodology to AI systems while developing AI-driven approaches to vulnerability discovery and exploit verification.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: No Stupid Questions
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Ongoing AMA booth with volunteers and speakers answering all your DEF CON and cyber questions


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 13:05-15:55 PDT


Title: Noob Community - Conference Closing
Tags: Noob Community | Creator Talk/Panel
When: Sunday, Aug 9, 13:05 - 15:55 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Sunday - 12:00-12:59 PDT


Title: Novice design in 3d space
Tags: Maker's Village | Creator Event/Activity
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

Broad to narrow review of several 3d design programs such as Fusion, Onshape, FreeCAD, TinkerCAD, and OpenSCAD and an assessment of their features and flaws. An Onshape account is recommended prior to attending the workshop.

SpeakerBio:  RedThorn
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 11:00-12:59 PDT


Title: NPM Imposters - The malware detection card game
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map

Description:

NPM Imposters is a fast-paced educational card game designed to teach players about supply chain security risks in software development, particularly through malicious NPM packages.

SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 11:30-11:59 PDT


Title: One Firmware Flaw, 70+ Device Models: Lessons in Industrial IoT Disclosure and Mitigation
Tags: IoT Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

In this talk, we use a real firmware vulnerability we found affecting more than 70 industrial sensor models from a single vendor to show how one finding can become a fleet-scale problem. The bug matters, but the bigger story is what happens next - a CVE goes public, patch adoption is still early, and operators are left managing risk in environments where safety and availability matter as much as security. We will walk through how the issue was found, how its scope grew across a large product line, and why industrial devices make remediation fundamentally different from IT or our regular consumer technology. We will also cover the coordinated disclosure process with a (very) cooperative vendor, and a broader lesson that emerged from the case, i.e., that researchers, vendors, and operators do not all gain the ability to act on the same timeline. Our talk is a talk about shared firmware risk, real-world disclosure, and what researchers, vendors, and operators should learn when a firmware issue affects a broad line of products and public disclosure arrives before real-world mitigation catches up.

Speakers:Weihan Goh,ZhengChao Wen

SpeakerBio:  Weihan Goh, Singapore Institute of Technology

Dr Weihan Goh is an Associate Professor at the Singapore Institute of Technology (SIT). His research interests include adversarial digital forensics, security testing, and controlled environments for cybersecurity evaluation, education, and experimentation. His work focuses on the design and analysis of realistic adversarial scenarios, with an emphasis on how security experiments can be conducted safely and meaningfully in complex systems of systems. Beyond teaching and research, Dr Goh participates in CTFs under the handle "icebear".

SpeakerBio:  ZhengChao Wen, Singapore Institute of Technology

ZhengChao Wen is a final-year Information Security student at the Singapore Institute of Technology (SIT), with interests in vulnerability research and security testing. Currently serving his industrial attachment at TÜV SÜD PSB, he is involved in cybersecurity product testing and penetration testing of IoT devices.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Sunday - 10:00-15:59 PDT


Title: Open Q&A
Tags: Scambait Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 15:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 10:00-13:59 PDT


Title: OSINT4Good Community - DC NextGen Content
Tags: OSINT For Good Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

Make this a stop on your DC NextGen journey, solve the challenge, and earn a digital badge!


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Sunday - 11:00-13:59 PDT


Title: OWASP Chapter Meetup
Tags: OWASP Foundation | Creator Event/Activity
When: Sunday, Aug 9, 11:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

This one’s for the chapter leads, the regulars, the new folks, and everyone who makes OWASP what it is. Join us at DEFCON 33 for a meetup made to foster connection between OWASP chapters. It’s a chance to share wins, swap challenges, build relationships, and spark ideas that reach beyond our local scenes. Whether you’re repping your city or just curious about how others are building community, pull up. The global OWASP family is real—and this is where we get to feel it.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: PhreakMe
Tags: PhreakMe | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 210 (PhreakMe) - Map

Description:

Ever wondered what hacking looked like in the golden age of phone phreaking? What about today? What can we learn about the old techniques that still plague our current infrastructure? The PhreakMe Capture the Flag brings you the classic art of telecom exploitation.

The Hacked Existence team is once again hosting a telecom based CTF. The CTF runs on real live VoIP lines routed through a modified asterisk PBX allowing participants to dial in to the CTF from anywhere in the world. This number is live 24/7 throughout DEFCON, allowing you to hunt the PBX for flags any time, day or night. Don't have a phone? Come test your skills at one of our 5 payphones! Also there's a BBS, hope you brought your modem!

All the flags are based around historically accurate tactics, techniques, and procedures to manipulate emulated old school switching systems.

The purpose of our contest is to bring awareness around the still existing weaknesses in our telecom infrastructure and Interactive Voice Response Systems. Ideally visitors to our contest area will participate in the CTF allowing them to get a better understanding of telecom hacking in the year 2026 as well as a respect for the art of phreaking from yesteryear.

Come test your skills, challenge your knowledge, and dive deep into the world of phreaks.

Hints: Read 'The Cyberthief and the Samurai' and 'Masters of Deception: The Gang That Ruled Cyberspace' for a leg up.

Participant Prerequisites

A phone, or access to a phone that can dial an american based phone number. The BBS will be both accessible from a modem and also ssh. Ideally people will read books like 'The Cyberthief and the Samurai' and 'Masters of Deception: The Gang That Ruled Cyberspace' and the Cult of the Dead Cow book.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Sunday - 11:00-11:59 PDT


Title: Physical Security is not sexy which is bad for organizations and good for red teams.
Tags: Physical Security Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

With digital security tools continually becoming stronger, organizations often overlook their physical security as part of their operational security. Often, many organizations rely on their security integrators to secure the building. Those integrators business models are often not incentivized to properly secure the buildings. This leaves cameras, readers and keycards open for attackers and pen testers to exploit to gain access.

In this talk we’ll discuss the shortcomings of access control door systems, how attackers and pen testers can use official tools from the manufactures to identify and exploit the readers and doors along with using tools like a Flipper, RFID USB readers and postcards.

SpeakerBio:  Roger Egan

Roger is a washed up racecar driver with a more successful Information Systems career. This includes 10+ years experience in programming, installing, servicing and training on physical security software and equipment. Roger has shown organizations and law enforcement the strengths and weaknesses of physical security and how they can be exploited.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Pinball High Score Contest
Tags: Pinball High Score Contest | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 304 (Pinball High Score Contest) - Map

Description:
The Pinball High Score contest at DEF CON 34 will run Friday and Saturday: 10:00-18:00, Sunday 10:00-13:00 with games available for daily High Score contests, daily challenges and open qualifying for a main tournament. The daily contests will allow any attendee to play pinball games and attempt to record a qualifying high score on each of the unique games. At 17:00 on Saturday main tournament qualifying will end, tiebreakers will be played (if needed) and the top 8 players with the highest combined scores across all eligible machines will qualify for the Sunday finals event where they could become the next DEF CON Pinball Champion!

Achieving a high score may sound simple but pinball rulesets are very complex and the skill to complete a “Wizard Mode” or achieve a high score requires research, practice, knowledge and execution. Out of the box thinking, analytical skills and pattern recognition are traits that pinball players must exhibit to be successful and some games have rule sets that can be studied and exploited to achieve a high score. Hackers are at an advantage here and while this is just a pinball contest, we expect that the community is ready for this challenge!

Last year the contest measured how you moved the machine. This year, we're reading what happens inside it. Custom sensors feed SHELL, our Sub-surface Hidden Entertainment Layer Logic. When you unlock the right patterns, a hidden world appears on screens beneath the glass. Face off in secret mini-games, answer hacker trivia under pressure, and battle other players in competitive challenges where you can steal control mid-game. It's pinball within pinball, a clandestine layer of gameplay that only reveals itself to those who can crack the SHELL.

Participant Prerequisites

Nothing special is required. Any person can step up and enjoy a pinball game or they can spend 30+ hours solving our challenges if they want to play the deeper game.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 12:15-12:45 PDT


Title: Practical Privacy Defenses for the Paranoid
Tags: OSINT For Good Community | Creator Talk/Panel
When: Sunday, Aug 9, 12:15 - 12:45 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map

Description:

Public records, browser tracks, and digital footprints leave you exposed. Now, AI helps tie it all together even faster for anyone looking for information on a person. In this session, go deeper than data broker removals to improve your personal privacy habits and help mask your online identity. Entry-level and open to all skill levels and non-OSINT experts.

SpeakerBio:  Tina "Hek8te" Shakour, Netwrix

Hek8te (Keeper of the Keys) brings two decades of cybersecurity experience to the front lines of blue team defense, protecting systems and people worldwide. A Senior Coach for Trace Labs and a veteran TechWomen volunteer, she is dedicated to global defense, OSINT, and community mentorship.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: PWN UR H0M3 - DDoS CTF
Tags: DDoS Contest | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map

Description:

A chaotic DDoS-themed CTF where sketchy devices, busted services, weird signals, and sneaky clues are begging to be owned. Scan the network, break IoT devices, decode the nonsense, and prove you can pwn your home before your home pwns you. This CTF is designed to help you learn about the cutting edge in DDoS attacks and defense. We also have an IoT lab of devices hacked and infected with botnet malware that you can play around with. Beginners welcome. We have some fabulous prizes including gift cards donated from Hak5 so please check it out!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 12:00-12:59 PDT


Title: PWN UR H0M3 DDoS CTF Winner Announcements
Tags: DDoS Contest | Contest
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map

Description:

PWN UR H0M3 DDoS CTF winners announced and prizes handed out.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 12:00-12:30 PDT


Title: Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover
Tags: AI Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:
Every major AI lab now ships an agentic browser: ChatGPT Atlas, Perplexity Comet, Claude in Chrome, Gemini in Chrome, and Microsoft Copilot Actions. To make them work, vendors intentionally relax thirty years of browser security. Atlas loosens Same-Origin Policy, Gemini and Edge add localhost access, Comet opens the filesystem, and Claude runs scripts on any site. The main defense is model safety training. These are design choices, not bugs, reviving XSS, sandbox escapes, and drive-by exploitation.

We ran the first cross-platform analysis of all five. We introduce PleaseFix, a new agent-targeting vulnerability class (the evolution of ClickFix), exploited via Intent Collision, which merges attacker content with the user's request into one plan the agent cannot untangle. We also present HistoryFixing, which weaponizes a function shipped in every browser since 2008 to poison the browsing history agents trust as ground truth.

Walk up to learn the agentic-browser threat model, the vulnerabilities, and which were agent-specific versus consistent across all five. You will see how we chained Intent Collision and HistoryFixing, from zero-click vectors (poisoned tweet, calendar invite), to conduct RCE, reverse shells, data exfiltration and poisoning, filesystem theft, account takeovers (Slack, X, 1Password, Claude), rogue actions on MFA-gated sites, unauthorized Amazon purchases, malicious collaborators added to your private enterprise GitHub, and more. We link videos of every attack. We break down the soft versus hard boundaries each vendor built, what failed and what held: only deterministic, code-level defenses stopped us. All findings responsibly disclosed.

SpeakerBio:  Stav Cohen

Stav Cohen is an AI Security Research Lead at Zenity and a PhD student at the Technion, Israel Institute of Technology. His research focuses on breaking, and then fixing, AI agents, spanning security vulnerabilities across agentic AI systems, LLM-powered applications, and enterprise AI platforms. He discovers new attack vectors, develops remediation strategies, and works to drive the industry toward stronger security practices. His offensive security work spans attacks on RAG pipelines, multi-agent delegation protocols, agentic browsers, and production-scale GenAI systems. He introduced the concept of Promptware: a new class of inference-time threats that exploit GenAI models through malicious prompts, turning them from helpful assistants into tools for data exfiltration, lateral movement, and even physical-world consequences. He presents his findings at leading security venues across the world. His PhD research focuses on the secure integration of Generative AI into real-world infrastructure, particularly Cyber-Physical-Human Systems involving human-in-the-loop interactions, such as smart water networks and GenAI-powered virtual assistants. He explores how GenAI agents can be safely and effectively integrated into these environments to support real-time decision-making, anomaly detection, and human-machine collaboration. He is also a thought leader in the AI security space, sharing knowledge through conference talks, blog posts, and community engagement.


Return to Index    -    Add to Google    -    ics Calendar file

OSINT For Good Community - Sunday - 11:00-11:15 PDT


Title: Q&A with the "How to Profile an entire C-suite in 10 days" speaker
Tags: OSINT For Good Community | Creator Event/Activity
When: Sunday, Aug 9, 11:00 - 11:15 PDT
Where: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map

Description:

Stop by and chat with Sarah Muriel the speaker on How to Profile and Entire C-Suite in 10 days.

SpeakerBio:  Sarah Muriel, Bishop Fox

Sarah Muriel is an Intelligence Analyst from Mexico with more than 6 years of experience in open source investigations, currently working with the Attack Surfaces of companies all over the world. In her spare time she likes participating in various international OSINT related CTFs and developing retro-style websites. She’s also fairly active in the cybersecurity community, being part of the organization team for one of Mexico’s top conferences.


Return to Index    -    Add to Google    -    ics Calendar file

Blacks In Cyber Village - Sunday - 11:00-11:30 PDT


Title: Quantum Computing The Game Changer You Can t Ignore
Tags: Blacks In Cyber Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:30 PDT
Where: LVCCW Level 3 W322-W324 (BIC Village) - Map

Description:

Quantum computing can feel intimidating, but this session makes it clear, practical, and relevant. Dannielle Eason will break down the basics of quantum computing, explain why it matters now, and show how it may disrupt cybersecurity, healthcare, finance, AI, climate science, and more. Attendees will leave with concrete steps for protecting personal data, preparing organizations for Q-Day, and staying current with NIST, CISA, and NSA guidance. Whether you are technical, non-technical, or simply curious, this welcoming session will help you understand the quantum shift and what to do next.

SpeakerBio:  Danielle Eason, Cybersecurity Speaker

Dr. Dannielle Eason is a cybersecurity and governance, risk, and compliance leader with more than 15 years of experience driving enterprise compliance, audit readiness, and federal cybersecurity initiatives. She specializes in building governance frameworks, using data to guide risk decisions, and aligning security strategy with organizational goals. Her work includes leading federal regulatory tracking programs, improving compliance metrics through policy alignment, automating reporting workflows, and strengthening security assessment programs. A frequent speaker at industry conferences including BITECON and GovTechCon, Dr. Eason brings practical expertise in cybersecurity, GRC, and organizational readiness to help audiences understand and prepare for emerging technology risks.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Sunday - 12:17-13:16 PDT


Title: Quiet Room
Tags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
When: Sunday, Aug 2, 12:17 - 13:16 PDT
Where:

Description:

Diana Initiative is excited to offer up a "Quiet Room" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-10:59 PDT


Title: Radio Frequency Capture the Flag
Tags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester's determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

This game doesn't let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what's happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Sunday - 10:00-13:59 PDT


Title: Radio Frequency Village Events
Tags: Radio Frequency Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

In addition to the CTF and talks, which are elsewhere on the schedule, the RF Village is also a place to hang out and chat with like minded folks who share your interests.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
Tags: IoT Village | Creator Workshop
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Encrypted IoT firmware doesn’t have to be a dead end. In this hands-on workshop, we’ll reconstruct a real vendor’s firmware decryption pipeline without ever touching the hardware...


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Reali7y Overrun - Contest running
Tags: Reali7y Overrun | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 308 (Reali7y Overrun) - Map

Description:

Enter a near future dystopia where AI is threatening to take over the world through misinformation campaigns and leveraged takeover of automation technology. Join us for online and real world challenges, including an AI racecar challenge.

Friday and Saturday AI "deepracer" style car races at the event booth racetrack: * Noon * 2pm * 4pm

Sunday: Final scoring

All race times may have one or more race events. All race events are up to 3 simultaneous racers.

* YOU MUST COMPLETE IN-GAME CONTENT TO QUALIFY TO RACE. *

* Good luck! *


Return to Index    -    Add to Google    -    ics Calendar file

Recon Village - Sunday - 12:00-12:30 PDT


Title: Recon on Trial: The OSINT Operator's Legal Playbook
Tags: Recon Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

You scrape a public site. You enumerate subdomains. You grep GitHub for secrets. You curl a misconfigured API. Each one touches a statute. Some have been to the Supreme Court. Most operators don't know which is which — until the preservation letter arrives. A federal-court-qualified expert witness (U.S. v. Sullivan) walks through five live OSINT techniques with real-time legal annotation. Zero lawyer-speak. GitHub release included.

SpeakerBio:  David Cass, Expert Consultant · Head of FinTech Practice
David Cass occupies a vantage point few cybersecurity and financial-technology experts can claim: he has sat on every side of the table. He recently served as a lead regulator at the Federal Reserve Bank of New York, where he was a member of the Large Institution Supervising Coordinating Committee (LISCC) overseeing the systemically important institutions whose security and risk practices he had spent two decades building from the inside. As Head of the FinTech Practice at Law & Forensics and a member of the firm's Cyber Security and Forensics Practice, he brings that supervisory perspective to bear as a testifying expert and consultant — most recently as a cybersecurity expert witness on a significant cyber-attack against a regional credit union that compromised member data and disrupted services.

Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Sunday - 12:00-12:59 PDT


Title: Red Robin: Don't Hack For Me, Hack With Me
Tags: La Villa Community | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Desde 2025, y especialmente con la llegada de modelos de IA cada vez más capaces, el panorama de la ciberseguridad ha visto una explosión de herramientas de hacking impulsadas por IA. Prometen explotación automatizada. El objetivo de muchas de estas herramientas es ser 100% autónomas, con el hacker fuera del loop. Pero esto es seguridad: sistemas en producción, datos sensibles. Una operación real no mide solo la tecnología, también a las personas y los procedimientos, cómo detectan y cómo responden. Sin contexto y sin alguien que responda por cada decisión, automatizar no alcanza.

Esta charla presenta Red Robin, un compañero de IA por línea de comandos hecho específicamente para red teamers. Red Robin se integra con tu framework de Command-and-Control (C2), observa la actividad de tus beacons a medida que ocurre, y te da guía contextual en tiempo real anclada a tus objetivos operativos. Nunca actúa por su cuenta. No hackea por vos. Piensa con vos.

Esta charla cubre el panorama actual de hacking humano-vs-IA, la filosofía detrás del modelo de compañero, una inmersión técnica en la arquitectura de Red Robin, una demostración en vivo de Red Robin construyendo situational awareness dentro de una sesión de C2 activa, y una discusión a futuro sobre dónde debería encajar la asistencia de IA en el futuro de la seguridad ofensiva.

Speakers:Juan Sequeira Piedra,Jose Urena

SpeakerBio:  Juan Sequeira Piedra, Red Team Operator - Equifax

Juan Sequeira es un operador de red team que ejecuta full-scope adversary emulation en entornos empresariales. Llegó a “offensive security” desde el lado defensivo tras dos años en un SOC, y hoy trabaja en desarrollo de malware, infraestructura y automatización de red team, e investigación de seguridad. Ha representado a Team Latin America en el International Cybersecurity Challenge 2026 en Gold Coast, Australia, y a Team Costa Rica en el European Cybersecurity Challenge (Turín 2024, Varsovia 2025) y en el Latin America Cybersecurity Challenge 2025 (Medellín).

SpeakerBio:  Jose Urena, Equifax - Red Team Operator

Jose Urena es un Red Team Lead con experiencia y más de nueve años trabajando en la industria de la ciberseguridad, especializado en investigación de vulnerabilidades, desarrollo seguro y operaciones ofensivas avanzadas. Su trayectoria abarca roles críticos en auditoría de seguridad, desarrollo de herramientas y simulación de adversarios en entornos empresariales complejos. Jose es un contribuidor activo de la comunidad de seguridad y ha presentado anteriormente sobre Red Teaming, aplicación práctica de IA y operaciones de ataque modernas en el Ministerio de Ciencia y Tecnología (MICITT) de Costa Rica, así como en Kennesaw State University en Georgia.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 10:30-11:30 PDT


Title: Reversing a Recall: From ‘Noise Triggered’ to RCE
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Sunday, Aug 9, 10:30 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

Heavy-duty trucks move the majority of freight in North America, making them a critical component of our infrastructure. When a major supplier issued a recall to address a seemingly harmless noise issue, the explanation didn't quite add up.

This talk follows the reverse engineering journey that began with a simple question and led to a much larger discovery. By tearing apart firmware, analyzing the update protocols, and tracing ECU behavior, we uncovered evidence that the recall was not just remediating noise triggered flaws. Hidden within the recall's firmware update was a security mitigation addressing undisclosed vulnerabilities affecting a critical vehicle system.

Attendees will see how modern tractor ECUs can be analyzed using professional and public tools and techniques (IDA Pro, idapython, qbindiff), the challenges of working with the safety-critical microcontrollers in heavy-vehicles (S12XE), and the evidence that revealed security impacts of the patch. Along the way, we'll discuss the growing cybersecurity risks facing commercial vehicles.

Whether you're interested in automotive hacking, embedded systems, reverse engineering, or critical infrastructure security, this session offers a look inside the cybersecurity reality of the machines that keep the supply chain moving.

  1. Aleph One. (1996). Smashing The Stack For Fun And Profit. Phrack Magazine, 7(49). http://phrack.org/issues/49/14.html
  2. Intellon Corporation. (1997). SSC P485 PL Transceiver IC Data Sheet.
  3. Hunter, J. D. (2007). Matplotlib: A 2D graphics environment. Computing in science & engineering, 9(3), 90-95.
  4. NXP Semiconductors. (2010). HiWave Debugger. Part of CodeWarrior Development Studio.
  5. Krzywinski, M., Birol, I., Jones, S. J., & Marra, M. A. (2011). Hive plots—rational approach to visualizing networks. Briefings in bioinformatics, 13(5), 627-644.
  6. SAE International. (2013). J1587: Electronic Data Interchange Between Microcomputer Systems in Heavy-Duty Vehicle Applications. Warrendale, PA.
  7. Miller, C., & Valasek, C. (2014). Adventures in Automotive Networks and Control Units. IOActive. https://www.ioactive.com/wp-content/uploads/pdfs/IOActive_Adventures_in_Automotive_Networks_and_Control_Units.pdf
  8. Behere, S., Zhang, X., Izosimov, V., & Törngren, M. (2016). A Functional Brake Architecture for Autonomous Heavy Commercial Vehicles. https://legacy.sae.org/publications/technical-papers/content/2016-01-0134/
  9. SAE International. (2016). J1708: Serial Data Communications Between Microcomputer Systems in Heavy-Duty Vehicle Applications. Warrendale, PA.
  10. TruckHacking organization. (2016). py-hv-networks. https://github.com/TruckHacking/py-hv-networks
  11. SAE International. (2018). J1939: Serial Control and Communications Heavy Duty Vehicle Network. Warrendale, PA.
  12. International Organization for Standardization. (2018). ISO 26262: Road vehicles -- Functional safety. Geneva, Switzerland.
  13. International Organization for Standardization. (2018). ISO/IEC 29147: Information technology -- Security techniques -- Vulnerability disclosure. Geneva, Switzerland.
  14. dfieschko. (2019). RP1210. https://github.com/dfieschko/RP1210
  15. MITRE Corporation. (2020). CVE-2020-14514. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14514
  16. International Organization for Standardization. (2020). ISO 14229: Road vehicles -- Unified diagnostic services (UDS). Geneva, Switzerland.
  17. Gardiner, B. (2022). Disclosure of confirmed remote write to J2497 aka PLC4TRUCKS. NMFTA, Alexandria, VA, Letter, March.
  18. National Motor Freight Traffic Association. (2022). Actionable Mitigations Options v9. https://nmfta.org/wp-content/media/2022/11/Actionable_Mitigations_Options_v9_DIST.pdf
  19. MITRE Corporation. (2022). CVE-2022-26131. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26131
  20. Pulse Security. (2022). Reversing the Ducati 696 ECU Part 2. https://pulsesecurity.co.nz/articles/ducati-696-part2
  21. Gardiner, B. (2022). Mitigating PLC4TRUCKS Remote Write. Proceedings of the 9th escar USA Conference. https://escar.info/downloads
  22. Cybersecurity and Infrastructure Security Agency. (2023). Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and -Default. https://www.cisa.gov/resources-tools/resources/shifting-balance-cybersecurity-risk-principles-and-approaches-security-design-and-default
  23. Bendix Commercial Vehicle Systems LLC. (2024). 24E086 Chronology. https://static.nhtsa.gov/odi/rcl/2024/RMISC-24E086-5355.pdf
  24. National Highway Traffic Safety Administration. (2024). Technical Service Bulletin 10194446. https://dot.report/bulletins/10194446
  25. National Highway Traffic Safety Administration. (2024). Technical Service Bulletin 10176745. https://dot.report/bulletins/10176745
  26. National Highway Traffic Safety Administration. (2024). Technical Service Bulletin 10222229. https://dot.report/bulletins/10222229
  27. PACCAR Incorporated. (2024). Safety Recall Report 24V-915. https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V915-6438.PDF
  28. Navistar, Inc. (2024). Safety Recall Report 24V-818. https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V818-4283.PDF
  29. Volvo Trucks North America. (2024). Safety Recall Report 24V-790. https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V790-3386.PDF
  30. Bendix Commercial Vehicle Systems LLC. (2024). Technical Bulletin TCH-27-007. https://www.bendix.com/media/services-and-support/product-action-center-pdfs/tch_27_007_en_000.pdf
  31. Bendix Commercial Vehicle Systems LLC. (2024). Technical Bulletin TCH-27-006. https://www.bendix.com/media/services-and-support/product-action-center-pdfs/tch_27_006_en_000.pdf
  32. Bendix Commercial Vehicle Systems LLC. (2024). Technical Bulletin TCH-27-008. https://www.bendix.com/media/services-and-support/product-action-center-pdfs/tch-27-008_en_000.pdf
  33. ZF Friedrichshafen AG. (2024). mBSP XBS Factsheet. https://www.zf.com/public/org/ZF_CVS_mBSP_XBS_Factsheet_EN_296135.pdf
  34. Technology & Maintenance Council. (2024). Position Paper 2024-3: Next Generation Tractor-Trailer Technical Needs. American Trucking Associations. https://tmc.trucking.org/sites/default/files/TMC_PP-2024_3_NEXTGEN_TRACTOR_TRAILER_TECHNICAL_NEEDS%20.pdf
  35. Gardiner, B., Maag, J., & Tindell, K. (2024). Security Requirements for Vehicle Security Gateways. SAE International. https://www.sae.org/papers/security-requirements-vehicle-security-gateways-2024-01-2806
  36. Vehicle Cybersecurity Working Group (VCRWG), National Motor Freight Traffic Association. (2024). NMFTA Vehicle Cybersecurity Requirements. https://github.com/nmfta-repo/nmfta-vehicle_cybersecurity_requirements
  37. python-can Developers. (2024). python-can. https://python-can.readthedocs.io/
  38. Cohen, R., David, R., Mori, R., Yger, F., & Rossi, F. (2024). Improving binary diffing through similarity and matching intricacies. Proc. of the 6th Conference on Artificial Intelligence for Defense.
  39. Quarkslab. (2024). Quokka. https://github.com/quarkslab/quokka
  40. Bendix Commercial Vehicle Systems LLC. (2025). Safety Recall Report 25E-073. https://static.nhtsa.gov/odi/rcl/2025/RCLRPT-25E073-3346.pdf
  41. National Motor Freight Traffic Association. (2025). Bendix EC80 Recall: Safety and Security Implications. https://nmfta.org/bendix-ec80-recall-safety-and-security-implications/
  42. Cybersecurity and Infrastructure Security Agency. (2025). ICS Advisory (ICSA-25-021-03) Bendix EC-80. https://www.cisa.gov/news-events/ics-advisories/icsa-25-021-03
  43. National Security Agency. (2025). Ghidra. https://ghidra-sre.org/
  44. Hiveplotlib Developers. (2025). hiveplotlib. https://github.com/hiveplotlib/hiveplotlib
  45. Land Line Media. (2025). Defective Bendix ECUs have prompted recall of nearly half a million trucks with latest Paccar recall. https://landline.media/defective-bendix-ecus-have-prompted-recall-of-nearly-half-a-million-trucks-with-latest-paccar-recall/
  46. SAE Truck and Bus Control and Communications Network Committee. (2026). J2497 Power Line Carrier Communications for Commercial Vehicles. Work in Progress Draft Revision.
  47. Hex-Rays. (2026). IDA Pro. https://hex-rays.com/ida-pro/
  48. Python Software Foundation. (2026). Python Programming Language. https://www.python.org/
  49. Graphviz Authors. (2026). Graphviz. https://graphviz.org/
  50. ELDB. XPROG-box. https://www.eldb.eu/
  51. PEmicro. PROGS12Z Flash Programmer Software. https://www.pemicro.com/
  52. NXP Semiconductors. MC9S12XEQ512 Data Sheet. https://www.nxp.com/docs/en/data-sheet/MC9S12XEP100.pdf
  53. NXP Semiconductors. MC9S12XE Family Reference Manual. https://www.nxp.com/docs/en/reference-manual/MC9S12XERM.pdf
  54. DARPA. Assured Micropatching (AMP). https://www.darpa.mil/program/assured-micropatching
  55. LinkerScope Developers. LinkerScope. Visualization Tool.
  56. Zynamics. BinDiff. https://www.zynamics.com/bindiff.html
  57. hotwolf. HSW12. https://github.com/hotwolf/HSW12
  58. National Highway Traffic Safety Administration. NHTSA Recalls by Manufacturer. https://datahub.transportation.gov/Automobiles/NHTSA-Recalls-by-Manufacturer/mu99-t4jn
  59. Yapo, T. FL2K Experiments. https://hackaday.io/project/164346-fl2k-sdr
  60. Osmocom. Osmo-FL2k Project. https://osmocom.org/projects/osmo-fl2k
  61. National Highway Traffic Safety Administration. Federal Motor Vehicle Safety Standard No. 121, Air Brake Systems. 49 CFR 571.121.
  62. Evenchick, E. CANtact. https://cantact.io/
  63. National Motor Freight Traffic Association. j2497-keyhole. https://github.com/nmfta-repo/j2497-keyhole
  64. Motorola. Motorola S-Record Description (PDF). https://deramp.com/downloads/mfe_archive/060-Standards%20and%20Specifications/Hex%20Data%20Formats/Motorola%20S%20Record.pdf
SpeakerBio:  Ben Gardiner, NMFTA Inc.

Ben is a Senior Cybersecurity Research Engineer contractor at the National Motor Freight Traffic Association, Inc.® (NMFTA)® specializing in hardware and low-level software security.

With more than ten years of professional experience in embedded systems design and a lifetime of hacking experience, Ben has a deep knowledge of the low-level functions of operating systems and the hardware with which they interface.

He has held security assurance and reversing roles at a global corporation, as well as worked in embedded software and systems engineering roles at several organizations.

Ben has conducted workshops and presentations at leading cybersecurity and technical mobility events globally, including Black Hat USA, DEF CON, NorthSec, escar USA, ScapyyCon, the CyberTruck Challenge, GENIVI Security Sessions, Hack in Paris, and HackFest.

In addition to speaking on the main stage at Black Hat USA and DEF CON, Ben is a volunteer at the DEF CON Hardware Hacking Village (DC HHV) and Car Hacking Village (CHV). He is GIAC -GPEN, and -GICSP certified and a GIAC advisory board member, serves as the chair of the SAE TEVEES18A1 Cybersecurity Assurance Testing Task Force (responsible for J3322), a contributor to ATA TMC task forces, the ISO/SAE JWG and a voting member of the SAE VESS.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Sunday - 12:00-12:55 PDT


Title: RF CTF and World Wide War Drive Outbrief
Tags: Radio Frequency Village | Radio Frequency Capture the Flag | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Final results of RF CTF announced!

SpeakerBio:  RF Hackers, RF Hackers Sanctuary
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Sunday - 12:30-13:10 PDT


Title: Root-as-a-Service: The Hidden Runtime of Azure AI Foundry
Tags: Cloud Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 13:10 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:
Azure AI Foundry promises a simple serverless AI experience: upload models, run workflows, execute Python code, and Azure handles the rest.
But what actually happens behind the scenes when you run a serverless AI workload?

In this talk, we expose the hidden Azure-managed infrastructure powering Azure AI Foundry serverless workloads. Our research uncovered privileged Azure-managed runtimes that are completely invisible to customers, where user-controlled code executes as root, with host integration and Docker access exposed by default.

But that was only the beginning.

We also discovered that Azure AI workloads can obtain delegated cloud tokens through internal Azure ML token broker services. In our demo, we show how a serverless AI workload can leverage these trust relationships to access Azure resources far outside the AI workspace scope simply because the workflow creator had access to them.

As organizations increasingly trust serverless AI workloads with autonomous execution, such environments are rapidly becoming one of the cloud’s newest and overlooked attack surfaces.

This talk reveals how attackers can abuse hidden trust relationships inside Azure AI runtimes, why most organizations are blind to these attack paths, and what defenders must do before AI runtimes become the next major cloud pivot point.

SpeakerBio:  Shani Peled

Shani Peled is a Senior Cloud Security Researcher at CrowdStrike, specializing in offensive cloud and AI security research. She began her career in the Israeli Intelligence Corps, where she served as the only female hacker on her cyber defense team protecting critical infrastructure. After transitioning into offensive security, she spent years conducting red team operations against enterprise environments worldwide, including Fortune 500, Fortune 100, and Fortune 50 companies. Today, her research focuses on exposing hidden trust relationships, identity abuse paths, and emerging attack surfaces across modern cloud and AI platforms.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 10:15-11:15 PDT


Title: ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries
Tags: Advanced | AppSec Village | Creator Event/Activity
When: Sunday, Aug 9, 10:15 - 11:15 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Compression Dictionary Transport (RFC 9842) shipped in Chrome 130+ in 2025. Any JavaScript asset designated as a dictionary becomes a set of gadgets an attacker can chain into responses that bypass signature-based WAFs and IDSes. gadget-scanner is the a tool to evaluate that surface: drop in a candidate dictionary and a payload, and it reports how much of the payload hides inside backreferences and how much leaks as literal bytes on the wire. At the table you will score real-world JS libraries as attack primitives, generate the DCB blob with brotli -D, and watch the side-by-side: the raw bytes a WAF would see vs. the payload a browser would execute

SpeakerBio:  alevsk

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: SANS Institute NetWars Labs
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

SANS NetWars is a suite of advanced cyber ranges offering interactive, hands-on learning exercises created by SANS faculty in realistic network environments, gamifying cybersecurity training through compelling storylines and real-world challenges. Drop in during village hours to work through NetWars challenges at your own pace.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: Satellites Under Attack: Hands-On Satellite Security Threat Scenarios
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

In this “Satellite Attack Lab” you can explore how cyber-attacks against satellite systems can be launched, observed, and understood through a hands-on, attacker-centric experience. Rather than focusing on normal satellite operations, you will step into the role of a threat actor and directly exploit vulnerabilities in a simulated space environment by interacting with a physical setup of model satellites and ground stations to witness the immediate consequences of malicious actions, including intercepted data, unauthorized command execution, and visible disruption of satellite behavior.

We provide hacker workstations pre-configured with satellite command tools and signal-processing software. Large displays show the victim system’s telemetry and status in real time, allowing participants to immediately see the effects of their attacks.

This session is designed to be highly interactive and accessible to newcomers while still offering meaningful technical depth for advanced attendees.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 11:00-12:59 PDT


Title: SBOM Find the Flaws
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map

Description:

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.


Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 10:30-10:59 PDT


Title: Scaling Adversary Emulation with Autonomous Agents
Tags: AI Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map

Description:

Manual red teaming cannot keep pace with modern enterprise attack surfaces, but autonomous agentic red teams offer a scalable alternative. In this talk we will present our experience and results on how to build and safely deploy offensive AI agents to conduct continuous, multi-stage adversary simulations at large scale to discover severe security issues and execute simulated post-exploitation chains.

SpeakerBio:  Daniel Fabien

Daniel built Google's Red Team and ML Red Team from the ground up. He and his team of hackers conduct accurate simulations of real-world adversaries targeting the company, and use the lessons from these exercises to develop new defensive strategies. Prior to joining Google, Daniel worked as a pentester, helping companies identify and fix security vulnerabilities.


Return to Index    -    Add to Google    -    ics Calendar file

Scambait Village - Sunday - 10:00-13:59 PDT


Title: Scambait Bingo
Tags: Scambait Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map

Description:

A fun, interactive group activity that turns classic bingo into a scambaiting game. Mark off common scam phrases, tactics, and red flags as they come up in curated recordings of real scam calls. Great for all skill levels, whether you are playing along or just hanging out. A low-pressure way to learn the language of scams while spending a few hours with the community. Prize-free by design. Winners get a certificate printed on the spot with a ridiculous honorific and a photo with village staff. Nothing of material value is awarded.


Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 11:30-12:30 PDT


Title: search_vulns: Navigating the Fragmented Landscape of Vulnerability Data
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Sunday, Aug 9, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

Due to advances in AI‑assisted vulnerability discovery, more vulnerabilities are published than ever before, while traditional aggregators like the NVD have long reached their limits. This makes it increasingly difficult to obtain reliable information for prioritization in the fragmented landscape of known vulnerability data. Our open-source tool, search_vulns, addresses this by consolidating various sources through a modular architecture that works with product identifiers, like CPEs or PURLs, and regular product banners. It maintains accuracy when incorporating data without CPEs or PURLs, derives valid CPEs when upstream data is incomplete and reconciles duplicate product identities. Ultimately, it delivers a unified and precise view of known vulnerabilities, exploits, KEV, software recency and backpatch information, which we believe outperforms similar solutions.

Speakers:Dustin Born,Matthias Göhring

SpeakerBio:  Dustin Born

Dustin Born is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. Within pentesting, he focuses on web applications, cloud environments and mobile applications. Apart from this, Dustin supports the development of several internal tools that focus on automated reconnaissance and vulnerability assessment. This aligns with his interests in developing tools related to IT security and his previous scientific work. Specifically, he has built a framework for a general purpose vulnerability scanner as well as one for the dynamic analysis of iOS apps.

SpeakerBio:  Matthias Göhring

Matthias Göhring is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. He is Head of usd HeroLab, the division of usd specialized in technical security assessments. In addition, he holds lectures at Technical University Darmstadt and University of Applied Sciences Darmstadt on ethical hacking and penetration testing. In previous scientific work, he focused on network and communication security as well as software security.

Previous publications: - Catching the Clones – Insights in Website Cloning Attacks, Risk Connect Conference, 2021 - Path MTU Discovery Considered Harmful, IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018 - Tor Experimentation Tools, IEEE Security and Privacy Workshops, 2015 - On randomness testing in physical layer key agreement, IEEE 2nd World Forum on Internet of Things (WF-IoT), 2015


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Sunday - 12:30-12:59 PDT


Title: SH4ZAM: Accelerated Vector Math on the Sega Dreamcast
Tags: Game Hacking Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

SH4ZAM is a hardware accelerated, fast math and linear algebra library targeting the Sega Dreamcast. It began as a collection of hand-optimized SH4 assembly routines I wrote to boost the performance of our "impossible" ports of Grand Theft Auto 3 and Vice City to the DC. It has since evolved into a standalone library, offering a full, optimized math solution to the Sega Dreamcast homebrew community at large, accelerating the performance behind many of the community's other high-profile ports (Super Mario 64, Mario Kart 64, Star Fox 64, and now Zelda: Ocarina of Time) as well as original homebrew games, apps, and engines.

Despite targeting a game console that is over 25 years old now, the library is written to be especially cutting-edge, targeting the latest GCC 15.2 toolchains and providing dual, modern C23 and C++23 APIs. Additionally, it now features a generic software back-end, which allows for the library to be built for any non-Dreamcast target, facilitating easily porting SH4ZAM'd code or utilizing it in cross-platform codebases. The software back-end has already enabled the community to re-port our Dreamcast port of Super Mario 64 to the Nintendo Gamecube without having to change a line of math code!

For the talk, I'd like to cover an array of topics, touching on the specific hardware features of the Dreamcast's FPU that SH4ZAM is exploiting via SH4 assembly, high-level overviews of the library's architecture and layering of its C and C++ APIs, and providing some general takeaways for modern vectorization libraries, as a lot of this is applicable to many other game consoles or even modern performance-focused mathematics libraries in general.

The talk will also feature a brief introduction to the Sega Dreamcast homebrew scene, explaining why the console remains such an ideal target for indie developers despite its age and including a high-level overview of the tools and SDK we use to develop modern software for it. Finally, the talk will feature many screenshots and embedded video segments of some of these SH4ZAM'd up codebases, including many of our high-profile AAA ports.

SpeakerBio:  Falco Girgis

Falco Girgis is a veteran developer in the Sega Dreamcast homebrew scene and a regular contributor to the KallistiOS indie SDK and operating system, where he has worked to bring support for modern C23 and C++23 language standards to the platform. He has been involved in many high-profile ports to the DC, such as Grand Theft Auto 3, Grand Theft Auto: Vice City, Mario Kart 64, Sonic Mania, and more!


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 10:00-10:59 PDT


Title: Shepherding the Tor network
Tags: DEF CON Official Talk
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - Map

Description:

The Tor network has been continuously operating for close to 25 years now. How have the attacks changed over that time? How about the communities, threats, and incentive structures for the volunteers who operate the network?

I'll go over early lessons as well as lessons we are still learning, when it comes to the Tor network -- from relays to directory authorities -- focusing on the community angle, on finding and kicking out bad relays, and generally looking at the safety of users and of relay operators.

https://community.torproject.org/policies/relays/expectations-for-relay-operators/

https://community.torproject.org/policies/dir-auth/dir_auth_expectations/

https://www.freehaven.net/anonbib/#botnetfc14

https://spec.torproject.org/vanguards-spec/

https://research.torproject.org/safetyboard/

SpeakerBio:  Roger "arma" Dingledine, The Tor Project

Roger Dingledine is co-founder and original developer of the Tor Project, a nonprofit that develops free and open source software to protect people from tracking, censorship, and surveillance online. Roger works with journalists and activists on many continents to help them understand and defend against the threats they face, and he is a lead researcher in the online anonymity field. EFF picked him for a Pioneer Award, and Foreign Policy magazine chose him as one of its top 100 global thinkers. This is his twelfth talk on the Defcon main stage.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 10:00-10:30 PDT


Title: Skill Issue: A Recon Story
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:
For ten years we told every hunter the same thing: learn the bug classes, grind the labs, memorize the payloads. It built a generation of hackers, and the perfect training set. Every writeup, every PayloadsAllTheThings entry, every CTF solution is now fuel for a model. We documented exploitation so well that we automated ourselves out of the easy half of the job.

I'm not mad about it. It was always going to happen. The bottom of the funnel, the known classes on known surfaces, belongs to the swarm now. If your edge is running the same templates against the same assets, you are racing a machine that never sleeps. You lose that race.

So where did the human edge go? Upstream. To recon.

Recon never got written down the way exploitation did. The intro stuff did: run these five tools, pipe it into httpx. But the part that actually finds the bug, the judgment about which of forty thousand assets is worth your night, the instinct for where an org cut a corner, the pivots that surface the forgotten staging box, that part lives in people's heads. It is tribal. It moves through private channels and bar talk at cons. A model cannot train on what was never published.

Recon is the last moat, and the moat is built from information asymmetry, not skill. It keeps paying not because hunters are smarter than the bots, but because hunters know things the bots were never told. Every time someone publishes a technique, the moat drains a little. It refills faster than it drains, because the people who hold the best recon rarely have a reason to write it down.

I will make that concrete, not philosophical: the categories of recon that resist documentation, why scanners miss them (tools enumerate, humans interpret), and where to point your attention in 2026. Then I give away one or two techniques not in the standard rotation, walked end to end, with the reasoning, not just the command. You leave with something you can use that night.

SpeakerBio:  Ryan Bonner, Lead Security Engineer at Arcanum Information Security

Ryan Bonner is a Lead Security Engineer at Arcanum Information Security, where he builds AI systems, hacks them, and runs application penetration tests. Off the clock he hunts wide-scope bug bounty programs.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: Skillbit Labs
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

SkillBit Labs is a continuous learning platform designed to help assess and develop cybersecurity skills through hands-on, bite-sized labs. Drop in during village hours and work through beginner-friendly challenges at your own pace, brought to you by SkillBit (formerly MetaCTF), led by CEO Roman Bohuk.


Return to Index    -    Add to Google    -    ics Calendar file

Bug Bounty Village - Sunday - 10:30-10:59 PDT


Title: Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty
Tags: Bug Bounty Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map

Description:

curl ended its HackerOne programme in January 2026 after a steep rise in AI-generated reports overwhelmed a seven-person security team, with some weeks seeing seven reports in sixteen hours, none valid. They were all AI generated; referencing lines of code, real vulnerabilities, and regression of resolved CVEs, they looked legitimate and if that code was actually in the project would have been valid. Every single report wasted the maintainers time and the platform they were using did nothing to help. Triaging them is expensive, slow, and demoralising for the humans at the other end, the only solution? Pay the platform to triage them for you. This talk introduces Slop Spotting: a lightweight triage methodology that uses SAST rule generation as a validity signal. The core insight is simple. If a vulnerability is real and well-specified, you should be able to write a SAST rule for it, and if that code is actually in the codebase, that SAST rule should have a result, if it's slop, even convincing slop you get a yes/no answer very quickly across even large codebases.

Speakers:Katie Paxton-Fear,Max vonBlankenburg

SpeakerBio:  Katie Paxton-Fear, Security Advocate, Semgrep

i used to make applications and now I break them, hacker, bug bounty hunter, and educational YouTuber.

SpeakerBio:  Max vonBlankenburg, Security Researcher, Semgrep

Max is a security research engineer at Semgrep, doing their best to make software break less. Max has worked with smart contracts, CTFs and the software supply chain. Right now they’re interested in how to use AI to help make security engineering easier and tip the scales towards defenders.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-13:59 PDT


Title: Smart Home in the Matter: Blink, Race, Attack CTF
Tags: IoT Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 11:45-12:15 PDT


Title: So You Want to Be a Red Teamer? The Reality Behind the Role
Tags: Noob Community | Creator Talk/Panel
When: Sunday, Aug 9, 11:45 - 12:15 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

If you spend enough time online, you might think red teaming is all zero-days, custom malware, and elite operators silently dismantling networks while dramatic music plays in the background.

The reality is very different.

Modern red team operations are less about “cool hacks” and more about planning, communication, and helping organizations improve their defenses. In many cases, the most important skills have nothing to do with hacking at all.

This talk is designed for newcomers interested in offensive security who want an honest look at what red teamers actually do, how engagements are planned, what skills matter most, and how to begin building a realistic path into the field.

We’ll break down the differences between penetration testing and red/purple teaming, discuss common misconceptions about offensive security careers, and explore a real-world red team engagement from planning through debrief.

If you’ve ever wondered what red teamers really do, this session is for you.

SpeakerBio:  Billy Giles

Billy Giles is an Offensive Security leader and practitioner who specializes in red/purple teaming and network penetration testing. With a deep passion for understanding adversary behaviors, he helps organizations across a multitude of industries assess their security postures, identify and remediate vulnerabilities, and build stronger defenses by thinking like an attacker.

Billy is also the creator of Thinking Offensively. Through this project he examines offensive security strategy topics to help cybersecurity leaders anticipate threats and inform decision making, while also providing tools, playbooks, and techniques that red teams can apply directly to their work. His mission is to bridge strategy and execution to help organizations think offensively and stay ahead of evolving threats.


Return to Index    -    Add to Google    -    ics Calendar file

Social Engineering Community Village - Sunday - 10:00-12:30 PDT


Title: Social Engineering Community Village - Open Hours
Tags: Social Engineering Community Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 12:30 PDT
Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map

Description:

Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action... the phones start ringing soon.

The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses.

At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our "Cold Calls" or listen in to some presentations.

The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON.

Prerequisites:

Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed.

Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate.

Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - Attacking Cloud APIs from the IoT Edge
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W222 (Workshops) - Map

Description:

This course covers attacking the cloud REST APIs and IoT provider (cloud customer responsibility) configurations to demonstrate data exfiltration, remote code execution, and lateral movement. Hands-on experience with using an already compromised, simulated IoT device as well as navigating pen testing (fuzzing) of the common protocols (i.e. MQTT, HTTP) will be covered.

Workshop goal Teach students practical, repeatable techniques to observe, extract, and abuse cloud API credentials and logic from the vantage of a compromised IoT device. Students will leave able to enumerate device‚Üícloud flows, extract tokens, fuzz REST/MQTT endpoints, and demonstrate controlled lateral movement inside an isolated cloud tenant.

SpeakerBio:  Rodney "BenevolentWorm" Beede

Rodney is an offensive security red team pen tester. He has specialized in cloud, web, and IoT security for over 18 years. He has spoken at multiple conferences (BSides, Def Con, Black Hat) on topics ranging from cloud security engineering to IoT device hacking. Rodney has been accredited with multiple CVEs for web vulnerabilities in products such as Wi-Fi hardware and security appliances. He started his career in enterprise web application software development but shifted to the security industry with this master's thesis research project "A Framework for Benevolent Computer Worms" 2012. Website: https://www.rodneybeede.com/curriculum%20vitae/bio.html


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more.
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W225 (Workshops) - Map

Description:

You will receive a free hardware kit, documentation, and class introduction to the same hardware configuration used by hundreds of hacking hardware tools as their main core. We will cover Wifi Hacking on both 2 and 5ghz, Bluetooth hacking, packet capture, Flipper interface (bring yours if you have one), Sensor integration (also included), Mesh networking, point to point communications and more. Requirements: Laptop, Fully charged, USB-A interface, Windows OS (we will discuss MAC and Linux, but you will need to have knowledge and permissions to install tools). You can attend without above and still get kit, but it will not be hands on. All information will be published after the workshop if you don’t have a laptop. You will get a modern ESP32, Sensor, breadboard, USB cable, wires and more during the workshop.

SpeakerBio:  Dallas

Dallas has been involved in hacking since early teens, which translates to sometime in the 80’s. Mentored by Satellite and Ham hackers, has been involved in a few organizations including all levels of government, 3 letter agencies, serving as Chief security officer, CISO, and technical manager of multiple world-wide organizations. Banking, Energy, Space, Telecom, Government and manufacturing. Elected, re-elected, served and got the trophy. OG Considered an expert in Pen testing, variety of related and unrelated technology – occasionally serving 15+ years as a Defcon security goon, and around 10 for B-sides organizations. Alexa Park being his first Defcon. Mostly bored, but thinks AI is kind of fun and enjoys giving back to the community. Doing his best to not get arrested, and share knowledge with those interested in seeking it.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W230 (Workshops) - Map

Description:

GitHub Actions has become the de facto automation layer for modern software, and the de facto attack surface. In 2025, a single compromised Action leaked secrets across 23,000 repositories. One year later, the TeamPCP group ran the same playbook at scale by compromising Trivy's actions. Different victims, same root cause: a CI/CD pipeline that trusted what it shouldn't.

In this hands-on workshop, participants will build a complete end-to-end attack chain in a controlled lab environment, emulating adversary TTPs observed in recent GitHub Actions breaches. From initial access through malicious workflow manipulation to secret exfiltration, each phase is paired with detection and analysis techniques to bridge offensive and defensive perspectives.

Whether you're on a red or purple team looking to simulate attacker behavior, or part of a blue team (AppSec or DevSecOps) aiming to harden CI/CD pipelines, this workshop delivers practical, real-world skills grounded in today’s evolving threat landscape.

Speakers:Ricardo Sanchez,Daniel Malvaceda

SpeakerBio:  Ricardo Sanchez

Ricardo Sanchez is an accomplished cybersecurity professional with a passion for empowering others through knowledge sharing. He has built his career designing and implementing innovative technology strategies for threat intelligence, detection engineering, and threat hunting to combat evolving cyber threats. Currently, Ricardo leads the Application Security (AppSec) practice at a leading insurance company in Peru, where he works closely with DevSecOps teams to enhance security across the software development lifecycle (SDLC) and supply chain. Committed to lifelong learning, Ricardo thrives on analyzing malware and staying at the forefront of cybersecurity advancements.

SpeakerBio:  Daniel Malvaceda

Daniel Malvaceda is a security architect who spends most of his time figuring out how CI/CD pipelines and supply chains actually fail, then writes it up so others don't have to learn it the hard way. Lately he's also poking at AI/LLM agents, since pipelines aren't the only thing shipping untrusted code anymore. He co-founded pipebreach.com, where real-world supply chain attacks get reproduced, dissected, and written up for everyone else. He also co-organizes the DevSecOps village at Ekoparty (Argentina and Miami), and has dragged these same topics to stages at Ekoparty, DevOps Days, and 8.8 Security Conference. If a pipeline can be weaponized, he wants to know about it first.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - Creating Shellcode for Hackers
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W232 (Workshops) - Map

Description:

Creating shellcode is for the brave! This workshop takes a modern approach to the time-honored tradition of Windows shellcode creation. Intended for those with intermediate to advanced knowledge, we will refresh x86 assembly and cover Windows internals.

You will create Win32/WoW64 shellcode with NASM before moving onto intermediate, multi-API shellcode. Along the way, we will cover GetPC, position independence, bad characters, calling conventions, stack discipline, manual API resolution through the PEB/TEB, export walking, name/hash-based resolution, strings, and passing handles or pointers between calls.

For evasion, we will explore manual/automated encoding techniques, making our shellcode self-modifying. We will also cover advanced techniques, including direct Windows syscalls with ShellWasp. You will learn Windows structures, native API parameter handling, and creating persistence with syscalls. Expect to be made privy to many shellcoding tips and tricks to bring out the best in your shellcode.

By the end, you'll be able to: Create Windows shellcode using NASM; launch and debug it; resolve and chain WinAPIs by name or hash; obfuscate and encode shellcode; integrate direct syscalls with ShellWasp.

Prep: Study x86 assembly and basic Windows debugging. A VM will be provided. Required: modern PC (Intel) / VM

Speakers:Bramwell "Bw3ll" Brizendine,Austin "quantumite" Norby,Micah Flack

SpeakerBio:  Bramwell "Bw3ll" Brizendine

Dr. Bramwell Brizendine has a Ph.D. in Cyber Operations and is the Director of the VERONA Lab. Bramwell has regularly spoken at DEFCON and presented at all regional editions of Black Hat (USA, Europe, Asia, MEA), as well as at Hack in the Box Amsterdam, Virus Bulletin, and Wild West Hackin' Fest. Bramwell received a $300,000 NSA research grant to create the SHAREM shellcode analysis framework, which brings unprecedented capabilities to shellcode analysis and $500,000 as a 2025 DARPA YFA recipient for a PE file emulation framework. He has additionally authored ShellWasp, which facilitates using Windows syscalls in shellcode, as well as two code-reuse attack frameworks, ROP ROCKET and JOP ROCKET. Bramwell has previously taught undergraduate, master's, and Ph.D. courses on software exploitation, reverse engineering, offensive security, and malware analysis. He currently teaches cybersecurity courses at the University of Alabama in Huntsville.

SpeakerBio:  Austin "quantumite" Norby

Dr. Austin Norby is a seasoned cybersecurity professional with over a decade of experience supporting the Department of Defense. He earned his bachelor's degrees in mathematics and computer science from the University of Minnesota, a master's degree from the Naval Postgraduate School, and a Doctorate in Cyber Operations from Dakota State University, specializing in anti-debugging techniques. Currently, Dr. Norby serves as the Director of Internal Research and Development at Bogart Associates, where he is responsible for spearheading the creation of advanced cybersecurity solutions for government use. His technical proficiencies include reverse engineering, malware analysis, and software engineering, with a strong focus on developing robust cyber capabilities in C, C++, Intel assembly, and Python.

SpeakerBio:  Micah Flack

Micah Flack is a cybersecurity researcher at Idaho National Laboratory, where his work spans vulnerability research, firmware and hardware analysis, malware forensics, exploit development, and reverse engineering across multiple platforms and architectures. He is currently pursuing a Ph.D. in Cyber Operations at Dakota State University, with research interests rooted in applied cybersecurity, software exploitation, malware analysis, and shellcoding. Micah also holds both a Master’s degree in Computer Science and a Bachelor’s degree in Cyber Operations from DSU, where he was active in cybersecurity research and competitions. Micah brings a hands-on perspective from his varied experiences in working with assembly, payload development, embedded systems, and offensive security research.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - ICS Hack 'n Track
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W231 (Workshops) - Map

Description:

OT attacks are often discussed but rarely demonstrated - in this workshop we use Caldera for OT to demonstrate realistic attack vectors for Distributed Control Systems used in power plants and other critical infrastructure, as well as how FOSS tools like Malcolm give defenders the information needed to detect blast radius and impacts.

Speakers:Pedro Cabrera,Hannes "hercules_hannes" Heck,Sam Miorelli,Jordan Sanchez

SpeakerBio:  Pedro Cabrera

Pedro Cabrera is an OT cybersecurity professional and Omnivise Cybersecurity Solutions Architect at Siemens Energy. He specializes in industrial control systems and adversary simulation, focusing on bridging the gap between traditional IT security and operational technology through practical, real-world demonstrations. He has developed custom tooling to simulate PLC interactions and highlight detection challenges in OT environments. His work centers on improving visibility, strengthening defenses, and making complex security concepts more accessible.

SpeakerBio:  Hannes "hercules_hannes" Heck

Hannes is an OT security practitioner currently completing a Bachelor's degree in Cybersecurity, with a thesis focused on Network Detection and Response systems including Malcolm. Active in the technology field since 2018, when he began a formal computer science apprenticeship, he has progressively deepened his specialization in cybersecurity and currently works at Siemens Energy in an OT Security role focused on solution architecture for industrial environments. He has presented technical topics in both academic and enterprise settings and brings direct hands-on experience with network traffic analysis, industrial control system design, and adversary emulation platforms to this workshop.

SpeakerBio:  Sam Miorelli

Sam Miorelli is the Global Head of Innovation and Customer Success for Siemens Energy Omnivise Cybersecurity. By training he is a mechanical engineer and a lawyer. Prior to his involvement with OT cybersecurity, Sam was the primary lawyer for several billion dollars per year of energy and industrial automation transactions at Siemens worldwide.

SpeakerBio:  Jordan Sanchez

Jordan Sanchez is a Cybersecurity Fellow at Siemens Energy, where he has spent three years doing R&D in OT and ICS security. Graduating from the University of Central Florida with a degree in Computer Science, he conducted undergraduate research on dependency downgrade vulnerabilities in the Android build system. Jordan is joining Amazon as a Security Engineer in September 2026.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W233 (Workshops) - Map

Description:

Cyber Threat Intelligence is the most overspecified and underspecified discipline in security. Every vendor sells a feed. Every conference has a track. Every blog post claims attribution. And yet - most blue teams still drown in IOCs they cannot operationalize, and most aspiring threat researchers do not know how to pivot from a single sample to a discovered campaign.

This workshop fixes both problems in four hours, fully offline, with every minute of those four hours spent on content rather than setup, and without distributing a single piece of malware.

SpeakerBio:  Rushikesh Nandedkar

Rushikesh is a researcher. Having more than 10 years of experience under his belt, his assignments have always been pointed towards reducing the state of insecurity for information. His research papers were accepted at the nullcon '14 '18 '20 '21, BruCON '16 '17 '18 '19 '21, Blackhat USA Arsenal '18 '19 '25, DEFCON 24 26 27, x33fcon '17 '18 '20 '21, BSides Delhi '17 '20, c0c0n '17 '25, HITCON '14, NCACNS '13 + co-author of "DARWIN" (use cases for covert wireless), "DECEPTICON", an intelligent evil-twin and "SASTRI", Plug and Play VM for SAST and author of ARC (Artefact Reuse Comparator) and Q-TIP (QR Code Threat Inspection Platform). Being an avid CTF player, for him, solace is messing up with packets, frames, and shellcodes while attempting to reach the state of void *.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - Post-Quantum Cryptography (PQC) for Hackers
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W228 (Workshops) - Map

Description:

Secure communications are not a luxury — they are a foundational requirement for human dignity in the digital age. Our most meaningful conversations, transactions, and decisions demand end-to-end encryption, strong authentication, and verifiable integrity. The notion that "only those with something to hide need strong crypto" is not merely lazy; it is dangerously shortsighted. Privacy is the space where autonomy, intimacy, and authentic human experience thrive. When that space is violated, the damage ripples far beyond the individual.

For decades, classical public-key cryptography has quietly protected everything from online banking to private messaging. That era is ending. Quantum computers are advancing rapidly, and the break of today's asymmetric algorithms — often called the Quantum Apocalypse — is no longer a question of if, but when. The window to prepare is narrowing. Migration must begin now.

In this workshop, you'll implement PQC algorithms from the NSA's CNSA Suite 2.0. You'll use C++, OpenSSL and Linux to demonstrate the secure usage of ML-KEM, ML-DSA, AES-256, and SHA-512. You'll leave with clean, reusable code, deep implementation insight, and the practical skills needed to integrate PQC into real-world systems.

We might not all have something to hide, but we all have something worth protecting.

SpeakerBio:  Eric "Eijah" Anderson

Eijah is the founder of Code Siren, LLC and has 25+ years of experience in software development. He is the creator of Polynom, the world's first CNSA Suite 2.0 PQC collaboration app and the author of multiple FIPS 140-3 modules. He is also the developer of Demonsaw, an encrypted communications platform that allows you to share information without fear of data collection or surveillance. Before that Eijah was a Lead Programmer at Rockstar Games where he created Grand Theft Auto V and Red Dead Redemption 2. In 2007, Eijah hacked multiple implementations of the Advanced Access Content System (AACS) protocol and released the first Blu-ray device keys under the pseudonym, ATARI Vampire. He has been a faculty member at multiple colleges, has spoken at DEF CON and other security conferences, and holds a master's degree in Computer Science. Eijah is an active member of the hacking community and is an avid proponent of Internet freedom.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Workshops - Sunday - 09:00-12:59 PDT


Title: Sold Out - Purple Protocol: Adversary emulation for everyone
Tags: DEF CON Workshop | DEF CON Workshops
When: Sunday, Aug 9, 09:00 - 12:59 PDT
Where: LVCCW Level 2 W229 (Workshops) - Map

Description:

Have you ever been curious about the techniques used by most notorious hackers to infiltrate some of the world's biggest networks? What would happen if they attacked yours? Companies burn millions of dollars in cybersecurity defenses, yet breaches still happen. Why? Because victory favors the prepared, not the well-funded.

This beginner friendly workshop explores a practical way to test your defenses. You will learn to organize and execute a Threat Intelligence-led Purple Team Engagement with Open Source tooling. You will learn how to select relevant Threat Actors, execute test cases, document results, generate action items for the Blue Team to remediate, and report the results in a way that even executives can understand. (Spoiler: They like Pie Charts, Line Graphs, and bright colors) This will all be done on a VM we will provide with the Open Source tooling pre-installed. Everything learned in this course can be replicated at your organization.

Join us in this workshop to learn why Purple Teaming is undeniably one of the most methodical and effective ways to improve your resilience against the threat actors most likely to attack your organization.

Speakers:Patrick "PilotPat" Raiden,Ben "Marba$" Strout,Brandon "D43m0n" Kraycirik

SpeakerBio:  Patrick "PilotPat" Raiden

Patrick has been working in Cybersecurity for the past decade, ranging from Security Engineering, Vulnerability Management, Penetration Testing, and Red Team Ops.  He holds industry certs including the OSCP, CRTO and GRTP.  He led the effort to build a new Purple Team program at one of the largest healthcare organizations in the United States and continues to manage the program. Patrick is also a DEF CON Black Badge winner.

SpeakerBio:  Ben "Marba$" Strout

Marba$ leads an Offensive Security Team and research vulnerabilities at one of the largest U.S. healthcare conglomerates. With experience spanning healthcare, biotech, pharma, and fintech, his work centers on application security, red teaming, and automation. He is the founder of DC207- Maine's DEF CON group - and the General Chair / Lead Organizer of BSides Maine.

SpeakerBio:  Brandon "D43m0n" Kraycirik

D43m0n is a senior cyber security research engineer for one of the largest banking institutions in the world. Having over five years of experience in offensive security, specializing in red teaming, vulnerability research, and custom tool development.

He holds advanced certifications that include OSCE3, BSCP, CRTO, CARTP, and eWPTX. While doing so, he was contributing to the cyber security community as the discoverer of CVE-2025-26332 (Dell) and CVE-2025-30398 (Microsoft), while also having authored “Debugging CVE-2023-37679: A Step-by-Step Guide to Fixing the Windows Exploit.”

One of his most recent accomplishments at DEF CON is finally obtaining the accolade of being a Black Badge holder.

Outside of cybersecurity, he is a passionate researcher with a deep appreciation for the outdoors.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Sunday - 12:30-12:59 PDT


Title: Source of Truth: A Field Guide for Deep Technical Research
Tags: OWASP Foundation | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

Security research usually starts with one reasonable question and somehow turns into a sea of browser tabs, lost bookmarks, half-read standards, conference talks, vendor docs, AI summaries, and simplified architecture posts with suspiciously perfect rectangles. Finding information is easy. The hard part is learning enough to know which explanation applies, which design decision changes the threat model, and where the simplified diagram quietly skipped the important part.

This talk is a practical field guide for researching deeply technical security topics without getting lost in the noise. We will look at how to approach protocols, standards, system behavior, and implementation details, then trace claims back to primary sources, identify load-bearing assumptions, and turn dense research into something useful for engineers and defenders.

SpeakerBio:  Carley “51nk0r5w1m” Fant, OWASP Project contributor, Rabbit Hole explorer

Carley “51nk0r5w1m” Fant is a Platform Engineer focused on AppSec, cloud infrastructure, identity, and software delivery. Her work centers on building secure platform baselines, hardening cloud-native environments, and helping engineering teams ship systems that are usable, observable, defensible, and less cursed by default.

She works at the intersection of platform engineering and application security, with a focus on practical threat modeling, automation, and figuring out where systems actually break once they leave the whiteboard. She is active in the OWASP community and enjoys turning technical rabbit holes into useful takeaways for engineers, defenders, and anyone who has ever opened an RFC, sighed, and kept reading anyway.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: SpaceCOP - Catch Me If You Can
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Think you can hack a spacecraft?

We’ve deployed a vulnerable Pisat and made the software available ahead of time so you can prove it. Study it, reverse engineer it, find weaknesses, and develop your attack plan before stepping up to the console.

When your turn comes, you’ll only have 15 minutes at a time to compromise the spacecraft and achieve a mission objective. There’s just one problem, the SpaceCOP, an intrusion detection system based on the Aerospace Corporation’s SPARTA matrix, has been deployed. The spacecraft is intentionally hackable - the real challenge is accomplishing your objective without triggering an alert and getting arrested by SpaceCOP.

Earn rewards based on how well you hack and hide from SpaceCOP.

Rules of Engagement: • Recon and vulnerability research before sitting at the terminal are highly encouraged. • You will have 15 minutes at the workstation to execute your attack. • Modifying files, changing registry settings, taking pictures, and other spacecraft effects are fair game. • Do not intentionally wipe, brick, destroy, or otherwise render the system unusable. • No “rm -rf”, disk wipes, ransomware, bootloader destruction, or similar actions.


Return to Index    -    Add to Google    -    ics Calendar file

OWASP Foundation - Sunday - 10:00-10:30 PDT


Title: Spotlight: Choose Your Own Adventure with InfoSecMap
Tags: OWASP Foundation | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map

Description:

Opportunities in InfoSec are everywhere, but they’re often buried across scattered websites, social media posts, or chat channels. Whether it’s a local meetup, a CFP deadline, a volunteer opportunity, or the chance to sponsor an initiative, many people and organizations miss out simply because they don’t know where to look or find info bloated by pay-to-play noise.

InfoSecMap was created to solve this. It’s a free, community-driven platform that brings the global InfoSec ecosystem together in one place. From major conferences to CTFs and grassroots meetups, InfoSecMap helps users explore what’s happening by geographic region or focus area and discover where they can connect and contribute.

InfoSecMap is proud to partner with OWASP, bringing together volunteer-led chapters and global events while fostering stronger connections and community growth. We believe open source should mean open access, and we’re building the infrastructure to make that real.

SpeakerBio:  W. Martín Villalba, OWASP

Martín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: spyVspy 3: Rat Race
Tags: spyVspy 3: Rat Race | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race) - Map

Description:

spyVspy is back, and this year, you're racing.

Embark on a thrilling espionage adventure with spyVspy 3: Rat Race! This contest imagines a world of spy games where contestants employ basic hacking, cryptography, and rogue skills to solve puzzles and uncover hidden caches strategically scattered throughout DEF CON (and beyond).

Challenges leading to the location of hidden caches will be released on a rolling schedule. By solving these challenges and being the first team to reach a cache, you will qualify for a final series of challenges on Saturday afternoon. Not the first? That's okay - you'll still have fun and earn cool spyVspy slabbed cards

spyVspy 3: Rat Race is intended for players of all skill levels. Whether you're a seasoned double-agent or just learning to be a covert operative, you will be able to compete and have fun in this event. Whatever skills you think you're missing can probably be learned on-the-job anyway.

Participant Prerequisites

A laptop would be great, but some puzzles may be solvable on a phone.


Return to Index    -    Add to Google    -    ics Calendar file

Aerospace Village - Sunday - 10:00-13:59 PDT


Title: SR-71 Blackbird Badge Challenge
Tags: Aerospace Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map

Description:

Think faster. Fly higher. Stay unseen.

Only the sharpest contenders will earn the limited-edition SR-71 PCB badge, inspired by the legendary Blackbird. Put your technical skills, aerospace knowledge, and analytical thinking to the test in this exclusive challenge. Like the aircraft itself, success demands precision, ingenuity, and the ability to stay one step ahead. Complete the mission and earn your wings.

New challenges launch all weekend long.


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Sunday - 11:30-11:59 PDT


Title: Stealing at the Speed of Light: The Anatomy of a Real Relay Attack tool
Tags: Car Hacking Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 11:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Passive Keyless Entry and Start (PKES) systems allow a driver to unlock and start a vehicle without any deliberate interaction with the key, relying instead on an automated radio-frequency exchange between the key fob and the car whenever the two are in close proximity. This talk begins by explaining the operating principles of PKES and the challenge–response communication that links the fob to the vehicle, establishing the implicit trust assumption — that proximity equals legitimacy — on which the system depends. I will then describe the process of sourcing and operating a real, commercially available relay attack tool, illustrated with a demonstration video of the attack carried out against a vehicle, before presenting a research deep-dive into how the tool is constructed and how it relays the signal across distance to defeat the proximity assumption. Finally, I will discuss mitigation strategies that aim to close the gap the attack exploits.

SpeakerBio:  Robbie Galfrin, PlaxidityX

Robbie Galfrin is an embedded security researcher with over 12 years of experience in hardware and software vulnerability research and exploitation. At PlaxidityX since 2017, his main focus has been low-level and hardware attacks on automotive ECUs, operating systems, and communication interfaces. Holds an MSc in Electrical Engineering from Tel Aviv University.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Sunday - 11:00-11:59 PDT


Title: Strategic Resistance: How a Global Network is Fighting the Spyware Industry -
Tags: Policy @ DEF CON | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:

For years, the commercial spyware industry – which sells software to hijack devices – has operated in a "gray market" with near-total impunity. That changed on February 26, 2026, when an Athens court sentenced executives of Intellexa to maximum prison terms – the first criminal conviction of spyware vendors. This was not an isolated event, but the result of a coordinated, multi-year effort by a diverse network of forensic researchers, legal advocates, and civil society organizations. From the $167M civil judgment against NSO Group to the closure of critical zero-day flaws in global messaging platforms, the tide is turning against mercenary surveillance. This session explores how this decentralized network supported by the Spyware Accountability Initiative (SAI) is dismantling the spyware business model. We will move beyond individual exploits to analyze the “policy infrastructure that makes technical security research impactful. We’ll show how technical discovery turns into legal and financial consequences for spyware companies. We will also detail how the SAI pooled fund model coordinates resources across organizations like Citizen Lab, the Knight First Amendment Institute, and regional threat labs on every continent. Attendees will gain an inside look at how this initiative operates, how it prioritizes high-impac

Speakers:Michael Brennan,Nadine Farid Johnson,Rebekah Brown

SpeakerBio:  Michael Brennan, Spyware Accountability Initiative

Michael Brennan works at the intersection of technology, civil society, and philanthropy, helping build the funding and coordination strategies that make accountability efforts possible. His work focuses on translating between technical researchers, legal advocates, and policy actors to support effective responses to digital threats, including commercial spyware. He has helped shape collaborative approaches to complex public-interest technology challenges and is particularly interested in the often-invisible infrastructure (funding models, networks, and strategy) that turns technical discovery into meaningful consequences for powerful actors. He brings a cross-disciplinary perspective on how to make resistance to surveillance more durable, coordinated, and effective. He holds a PhD in Computer Science.

SpeakerBio:  Nadine Farid Johnson, Knight First Amendment Institute

Nadine Farid Johnson is the inaugural policy director of the Knight First Amendment Institute at Columbia University. She is responsible for the Institute’s policy and advocacy efforts, leading engagement with U.S. government and other officials to advance the Institute’s policy objectives. A former U.S. diplomat and professor of law and political science, Farid Johnson is a frequent media contributor, with commentary appearing in The New York Times, The Wall Street Journal, The Atlantic, World Politics Review, Al Jazeera, The Hill, The Daily Beast, NPR, and other national and international publications. She has also appeared on outlets including PBS and CNN International.

SpeakerBio:  Rebekah Brown

Rebekah Brown is a senior researcher at the Citizen Lab focussing on targeted threats against civil society. She has over 20 years of experience in threat intelligence and analysis. Before joining the Citizen Lab, Rebekah worked at Apple, where she focused on complex threat models and helped design and implement features for individuals at increased risk for stalking, harassment, and abuse. She is a trained network warfare analyst and previously served as operations chief of a U.S. Marine Corps cyber unit and a U.S. Cyber Command training and exercise lead. Rebekah is a published author on intelligence-driven incident response, and co-author of the SANS course on cyber threat intelligence.


Return to Index    -    Add to Google    -    ics Calendar file

Policy @ DEF CON - Sunday - 12:30-13:59 PDT


Title: Tactical Advocacy: Panel & Peer Sessions with EFF
Tags: Policy @ DEF CON | Creator Interactive Talk/Panel
When: Sunday, Aug 9, 12:30 - 13:59 PDT
Where: LVCCW Level 2 W210-211 (Policy Village) - Map

Description:
Speakers:Thorin Klosowski,Cooper "Cybertiger" Quintin,Alexis Hancock,Cindy Cohn,Rory Mir

SpeakerBio:  Thorin Klosowski, Electronic Frontier Foundation

Senior Security and Privacy Activist, works on Surveillance Self-Defense, providing practical security and privacy guidance for a variety of threat models and across a breadth of consumer electronics.

SpeakerBio:  Cooper "Cybertiger" Quintin, Board Member at Open Archive

Cooper Quintin is a security researcher and senior public interest technologist with the EFF Threat Lab. research fellow with Citizen Lab, adviser to CoRD Research and Design, and board member of Open Archive. He has worked on projects including Rayhunter, Privacy Badger, Canary Watch, and analysis of state sponsored malware campaigns such as Dark Caracal. Cooper has given talks about security research at prestigious security conferences including Black Hat, DEFCON, Enigma Conference, and ReCon about issues ranging from IMSI Catcher detection to fem tech privacy issues to newly discovered APTs. He has also been published or quoted in publications including: The New York Times, Reuters, NPR, CNN, and Al Jazeera. Cooper has given security trainings for activists, non profit workers, and vulnerable populations around the world. He previously worked building websites for nonprofits, including Greenpeace, Adbusters, and the Chelsea Manning Support Network. Cooper was also an editor and contributor to the hacktivist journal, "Hack this Zine." In his spare time he enjoys making music, visualizing a solar-punk communitarian future, and playing with his kids.

SpeakerBio:  Alexis Hancock, Director of Engineering at Electronic Frontier Foundation

Alexis works to keep the networks strong and encrypted by managing the Certbot project. As well as ensuring EFF open source tools for the public are well supported. She researches an intersection of issues on digital rights, encryption, and consumer technology. She believes in an open and equitable web through encouraging expansion of security by default, bridging engineers and security research, and advocating for better and stronger tech policy and standards.

SpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy's Defender published by MIT Press in March, 2026. She is also the co-host of EFF's award-winning podcast, How to Fix the Internet.

--

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

SpeakerBio:  Rory Mir, Electronic Frontier Foundation

Director of Open Access & Tech Community Engagement, where they drive advocacy on access to knowledge, emerging technologies, and user autonomy. They also partner with community builders, experts, and other EFF volunteers to fostering strategic coordination and knowledge sharing.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Sunday - 10:00-10:40 PDT


Title: Tag, You’re It: Authorization Traps in AWS ABAC
Tags: Cloud Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:40 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

AWS Attribute-Based Access Control (ABAC) is gaining popularity for good reason: it scales well, minimizes policy duplication, and aligns with dynamic cloud environments. However, it can expand the attack surface in unexpected ways. In AWS, ABAC often relies on tags and attributes whose semantics are easier to misunderstand than most practitioners realize. Those semantics determine whether a policy actually enforces the intended boundary, or quietly creates a new attack surface. In this talk, we present a taxonomy of authorization traps in AWS ABAC: recurring patterns where policies look correct but do not behave as expected. These traps arise from ambiguous documentation, non-obvious IAM evaluation rules, service-specific behavior, and edge cases. Different as they may be, they often lead to the same result: a broken security boundary. This talk is for anyone building, reviewing, or attacking access control in AWS - from cloud security practitioners and IAM engineers to red teamers. Expect real policy examples, common failure patterns, and practical techniques you can apply directly in your own environments, with takeaways relevant to almost any AWS setup.

SpeakerBio:  Itay Saraf

Itay Saraf is a Senior Cloud Security Researcher at CrowdStrike. He has a background of offensive security, and worked as a red teamer targeting enterprise environments around the world, including multiple Fortune 500 companies. Today, he brings that offensive mindset to cloud and AI research, focusing on exposing real-world threats in modern cloud infrastructure.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 13:30-13:59 PDT


Title: Taking on the Dark Fleet... in Cyberspace!
Tags: DEF CON Official Talk
When: Sunday, Aug 9, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

In 2026, the US led what would become an international crackdown on Dark Fleet (sometimes called Shadow/Ghost Fleet): vessels that illegally transport sanctioned oil or other cargo. Little known to the public, Coast Guard Cyber Command was deploying its Cyber Protection Teams (CPTs) onboard these vessels to assure the security & safety of these vessels in cyber space. This talk provides a rare look at the US cyber operators deploying on Dark Fleet Tankers, the danger these vessels pose, and lessons learned from these boardings.

US Coast Guard Cyber Trends in the Maritime Environment 2025 (URL pending release) The Global Oil Tanker Market: An Overview as It Relates to Sanctions (https://www.congress.gov/crs-product/R47962)

Speakers:Kenneth Miltenberger,Shane Cancilla

SpeakerBio:  Kenneth Miltenberger, US Coast Guard / 2003 Cyber Protection Team

Commander Kenny Miltenberger currently serves as the first Commanding Officer of the 2003 Cyber Protection Team (CPT) in Alameda, CA. He is responsible for protecting the nation’s Marine Transportation System in cyberspace by conducting hunt, assess, and incident response operations. His team is the Coast Guard’s newest CPT and the only CPT geographically detached from Coast Guard Cyber Command (CGCYBER). He led the DEFCON 33 presentation, "From Shanghai to the Shore: The Silent Threat in Global Shipping".

Kenny recently completed an assignment where he founded the Coast Guard’s Red Team and ran the Coast Guard's Blue Team. During that tour he founded CGCYBER’s educational phishing capability, led cyber Opposing Forces for a major multinational exercise, and oversaw over 100 Red and Blue Team missions. Other notable positions include his work as an engineer for the U.S. Navy’s Naval Sea Systems Command, where he was a developer on a shipboard cyber security platform.

Kenny has a BS in Electrical Engineering from the Coast Guard Academy and an MS Electrical Engineering from University of Maryland (UMD) College Park.

Kenny has also worked as part-time faculty at UMD College Park, where he taught Binary Exploitation in their Cyber Masters Program. Industry certifications include OSCP, GXPN, GCPN, GREM, and more

SpeakerBio:  Shane Cancilla, US Coast Guard / 2003 Cyber Protection Team

Shane Cancilla is the Network Engineer for the 2003 Cyber Protection Team in Alameda, CA, focused on building and integrating tools for assessment, incident response, and threat hunting missions across Marine Transportation System and IT/OT/ICS environments. His work spans the engineering and deployment of sensors across complex networks and supporting mission-critical operations as a network analyst.

He has previously worked with organizations including Lawrence Livermore and Lawrence Berkeley National Laboratories, where he supported high performance computing and virtualized network environments.

Shane holds a B.S. in Computer Science from California State University, East Bay, along with CCNA and GCIH certifications.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 14:00-14:30 PDT


Title: Talkers Without Borders: Worldwide Free Speech without an Internet Connection
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠
When: Sunday, Aug 9, 14:00 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - Map

Description:

What if a globally accessible maritime communications network was co-opted for other than intended use? Our research tool demonstrates how defenders and users of AIS (the Automatic Identification System) might create and detect a covert communications channel that operates without a conventional server or internet connection.

DC10's Stealth Data Transport (Khan) [https://share.google/Y5mFWV13VamaskHvq] AIS Spoofing: A Tutorial for Researchers Dr. Gary Kessler [https://share.google/ye0yai283P4mbq3Sj ] DC27's Hack the Sea (Julian Blanco) [https://share.google/H7ExvRhCfSv32OEio] DC33’s Pirates of the North Sea (Bjørkhaug) [https://share.google/97Y51J8DEbis1TTAd] DC33’s Navigating the invisible (Mehmet Onder Key & Furkan Aydogan) [https://share.google/5jvqgyAgdLm18f7kR] Amro, A., & Gkioulos, V. (2022, September). From Click To Sink: Utilizing AIS for Command and Control in Maritime Cyber Attacks. 27th European Symposium on Research in Computer Security (ESORICS) 2022, Copenhagen, Denmark, pp. 535-553. Lecture Notes in Computer Science (LNCS), 13556. DOI: 10.1007/978-3-031-17143-7_26

Speakers:T. Gwyddon "data" Owen,amp

SpeakerBio:  T. Gwyddon "data" Owen

data is a retired Air Force Cyber Warfare Officer with over 20 years of operational experience. While no longer a fed, he's a CNODP and RIOT grad with a Comp Sci BS from the USAF Academy and a Master's in Cyber Ops from the Air Force Institute of Technology. He's been certified in all 3 NSA Red Team work roles, all 3 offensive SIGINT work roles, qualified in all 6 Cybercom offensive work roles and personally engaged real-world, nation-state-level actors, malware and targets in air, land, sea, space & cyberspace both offensively and defensively. And he's done so with the US, UK, Canada, Australia and New Zealand. He also helped Bryce make the Space Badge for DEF CON 33 and the Clip-Boy badge for DEF CON 34.

SpeakerBio:  amp

amp spent 10 years driving ships around the globe—now captains a CTF team instead. With a B.S. in electrical engineering and pursuing M.S. in info systems engineering, amp made the jump from maritime grit to digital ops, bringing salty sea stories and a screwdriver to every hacking challenge. They’ve co-hosted episodes of several podcasts poking at the strange edges of maritime security, cyber policy, and why everything breaks at 2 AM. Into hardware hacking, retro gaming, and running text-based RPGs where everything is a side quest.


Return to Index    -    Add to Google    -    ics Calendar file

Noob Community - Sunday - 10:00-13:59 PDT


Title: TCM Security Labs
Tags: Noob Community | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map

Description:

TCM Security offers 250+ hours of practical, hands-on cybersecurity training across 28 courses and 13 certifications, built by hackers and trusted by teams. Drop in during village hours to work through their hands-on labs.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: TeleChallenge
Tags: TeleChallenge | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 107 (TeleChallenge) - Map

Description:

The TeleChallenge isn't just a puzzle challenge, it's an experience. We are super excited to show the plan for the tenth year in a row. Don't copy that floppy, but instead prepare to be immersed in an entirely new world where all of your hacker skills will be challenged (along with your 0xEA60 skills). This is a very tough contest to win, and is among the most challenging at DEF CON. Are you ready? Your first step is to find us, because part of the puzzle is discovering the puzzle.

Participant Prerequisites

You'll need a phone, your creativity and some hacker friends. It also helps to have access to a computer. Use the TeleChallenge as an excuse to meet people and form a team.

Pre-Qualification

We may have team registration in advance, but there is no pre-qualifyer.


Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Sunday - 14:00-14:15 PDT


Title: Telecom Village CTF Awards Ceremony
Tags: Telecom Village | Creator Event/Activity
When: Sunday, Aug 9, 14:00 - 14:15 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

Telecom Village - Sunday - 10:20-13:59 PDT


Title: Telecom Village CTF
Tags: Telecom Village | Creator Event/Activity
When: Sunday, Aug 9, 10:20 - 13:59 PDT
Where: LVCCW Level 3 W321 (Telecom Village) - Map

Description:
SpeakerBio:  T -Mobile CTF Team
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

AppSec Village - Sunday - 12:45-13:45 PDT


Title: The Agent Asked. We Allowed. Now What?
Tags: AppSec Village | Creator Event/Activity | | All Audiences
When: Sunday, Aug 9, 12:45 - 13:45 PDT
Where: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map

Description:

AI agents are already running on developer machines, inside terminals, IDEs, and internal workflows. They are useful, but they can also read code, access files, execute commands, call tools, use credentials, and send data to LLM providers.

In this Arsenal demo, we will present an open-source runtime discovery tool for identifying LLM-powered applications and AI agents on live machines without requiring code changes. The tool correlates local processes with LLM-provider traffic, detects known and unknown AI service usage, monitors subprocess and file activity, and applies basic policy controls for coding agents.

We will show what AI agents look like at runtime, what they do beyond the chat interface, and how AppSec teams can see, understand, and control them.

Speakers:Liran Lavi,Sarit Yerushalmi

SpeakerBio:  Liran Lavi

A senior security researcher from Tel Aviv specializing in web application security and advanced bot detection. With over 9 years of experience with small and large companies. To balance my tech-savvy life, you might find me hiking or skydiving - chasing new heights both literally and technically. I am always exploring edge cases and smarter ways to build and break systems.

SpeakerBio:  Sarit Yerushalmi

Sarit Yerushalmi is an experienced security researcher at Imperva. Her research mainly focuses on application security and APIs. She analyzes traffic to detect new threats, writes security blogs and talks at conferences. Some of her work has been presented at security conferences such as Botconf, Bsides TLV, NorthSec, and Kernelcon.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 12:00-13:59 PDT


Title: The Air Is Hostile: RF Trust Assumptions in Modern Security Systems
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 12:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map

Description:

Modern security systems are no longer purely physical. Alarms, sensors, access control, cameras, locks, panic buttons, monitoring paths, and backup communications increasingly depend on wireless technologies such as Wi-Fi, BLE, Zigbee, LoRa, LTE, and cloud-managed IoT infrastructure. For red teams, this creates an important question: what happens when the environment these systems depend on becomes adversarial?

This talk reframes RF as a red team attack surface, not just a radio engineering problem. It explores how wireless dependencies create opportunities for reconnaissance, failure-mode discovery, protocol fingerprinting, operational disruption, vendor-claim validation, and physical security bypass modeling. Rather than focusing on illegal or unsafe demonstrations, the presentation emphasizes responsible adversary emulation: identifying RF trust assumptions, mapping wireless dependencies, and testing whether organizations understand how their security systems behave under degraded or hostile spectrum conditions.

Attendees will learn how red teams can incorporate RF into engagements without turning the work into tool-driven theater. The talk covers passive RF reconnaissance, wireless dependency mapping, signal availability assumptions, anti-jam marketing claims, fail-open/fail-secure behavior, alert fatigue, response workflows, and the gap between “detection” and actual resilience. It also shows how RF risks connect to broader red team objectives: access control evasion, alarm reliability, site resilience, executive protection, incident response readiness, and vendor due diligence.

SpeakerBio:  Mitch Breton

Z3r0 is a senior offensive security and threat intelligence operator specializing in real-world adversary simulation, APT-focused threat analysis, and high-signal security assessments.

His work centers on helping organizations understand not just where they are vulnerable, but how real attackers would exploit those weaknesses and what to do next.

With a background spanning red team engagements, penetration testing, and intelligence-driven security research,

Z3r0 approaches every engagement from an adversary’s perspective. He focuses on identifying the small, often-overlooked control failures that enable outsized impact—privilege escalation paths, persistence mechanisms, trust boundary violations, and detection blind spots.

At NetPhantom Security, Z3r0 leads initiatives that blend threat intelligence, deception, and offensive testing to provide early warning and decision-grade insight. This includes building and operating intelligence pipelines, adversary profiles, and controlled deception environments that surface attacker behavior before it reaches production systems.


Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Sunday - 11:00-12:59 PDT


Title: The Autonomous Insider
Tags: Cloud Village | Creator Event/Activity | Attack
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 3 W311 (Cloud Village Labs) A - Map

Description:

In 2026, the 'Cloud Perimeter' has shifted from IP addresses to Agent Identities. This lab explores the intersection of Generative AI and Cloud Misconfiguration. We move beyond the prompt, demonstrating how classic architectural flaws-like over-permissive VPC Endpoints, missing IAM Conditions, and SSRF-prone Tool-call environments-allow attackers to turn a 'helpful' AI assistant into a cross-account exfiltration engine. Attendees will learn to exploit and then 'shackle' these agents using VPC Service Controls, SCPs, and automated remediation workflows.

Speakers:Naveen Reddy Pogalla,Hari Pranav Arun Kumar

SpeakerBio:  Naveen Reddy Pogalla

Naveen works within the Product Security Engineering team at Google Cloud, operating at the intersection of data and defense. Specializing in Cloud Security Posture Management and engineering automated remediation accelerators, he analyzes the broader risk landscape to drive remediation and hardening at scale. Rather than just hunting for individual bugs, his goal is to build a more secure cloud by identifying and eliminating entire classes of vulnerabilities before they can be exploited. Naveen thrives on solving high-stakes security challenges that require a blend of analytical rigor and an offensive security mindset. Prior to Google, he empowered clients as a Security Consultant at EY and Grant Thornton, with expertise spanning network security, vulnerability assessments, and GRC. He holds a Master’s degree in Cybersecurity Analytics and Operations from Penn State University and a Bachelor’s in Computer Science Engineering.

SpeakerBio:  Hari Pranav Arun Kumar
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Sunday - 12:00-12:30 PDT


Title: The Dark Art of Alert Correlation: Extracting Attack Chains from Chaos
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

In modern cybersecurity, the ability to connect isolated security alerts into coherent, actionable attack chains is essential. However, traditional detection methods often struggle to contextualize vast amounts of security data, leaving slow and stealthy attacks undetected within a sea of noise and false positives. This talk introduces a novel approach using open-source AI models to map, cluster, and correlate security alerts in order to uncover coordinated attacks. Through clustering, knowledge graphs, and AI-driven correlation, this approach offers significant improvements in SOC (Security Operations Center) efficiency and effectiveness. We detail the methodology, open source tools, and results of this approach across diverse environments, including cloud, telecom, and industrial control systems.

SpeakerBio:  Ezz Tahoun

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada's CSE.

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Sunday - 10:00-10:59 PDT


Title: The Diana Initiative - Open time
Tags: The Diana Initiative | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

We also have our "Reference Desk", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Sunday - 13:00-13:59 PDT


Title: The Diana Initiative - Open time
Tags: The Diana Initiative | Creator Event/Activity
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

We also have our "Reference Desk", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.


Return to Index    -    Add to Google    -    ics Calendar file

Hackers.town - Sunday - 10:30-10:59 PDT


Title: The Enshittified Internet and How We Can All Rewild the Internet
Tags: Hackers.town | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

The Internet was once a place where people could talk, share ideas and knowledge, express themselves with personal websites, build communities, and more. In recent years, however, we have seen that magic fade away, as the internet of today is now a toxic cesspool of social media controlled by Big Tech, ads thrown everywhere, walled gardens, AI generated slop, and content that locks us in by making us angry and depressed. This is not the Internet we need or should leave to the next generation of hackers! There are ways to take back and rewild the web! This talk is part informative, part education, part historical, and pure hacker punk energy as we explore how to do things like self-host our own servers, tools we can use to build new networks, decentralized services for communication, media sharing, and more, old protocols and services us old timers used to use that still exist (and how the kids can use them, too!), and places and sites we can go to for the education and information we want! In all, this talk is about hacking the planet and taking our Internet... the people's Internet... back from corporate corruption and control!

SpeakerBio:  LambdaCalculus

LambdaCalculus is chaos in a trenchcoat, and is passionate to his core about human rights issues, community outreach, and education. He has spoken at HOPE in 2025 on the Pirate Box and Sneakernet, and has also spoken at DEF CON, JawnCon, and PhreakNIC. He is a member of hackers.town, a native of the NYC area, and can still hit a mosh pit! Find him hanging out at hackers.town on Mastodon:https://masto.hackers.town/@LambdaCalculus


Return to Index    -    Add to Google    -    ics Calendar file

Lockpick Village - Sunday - 11:00-11:45 PDT


Title: The Knox Box - A Brief History(Part II)
Tags: Lockpick Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:45 PDT
Where: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map

Description:

An enhanced version of the DC33 talk, with more information

SpeakerBio:  Matthew O'Reilly
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Groups - Sunday - 11:00-11:30 PDT


Title: The State of DEF CON Groups
Tags: DEF CON Groups | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:30 PDT
Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map

Description:

DEF CON Groups has grown into a global network of hundreds of local communities, connecting hackers, makers, students, educators, and professionals around the world. Join the department leadership for an inside look at where the community stands today, what we’ve accomplished over the past year, and where we’re headed next.

We’ll share highlights from across the global DEF CON Groups community, new initiatives, lessons learned, available resources for Group organizers, and ways anyone can get involved—whether you’re looking to attend your first local meetup, volunteer, help organize an existing Group, or start one in your own city.

Whether you’re a longtime Group organizer or just discovering DEF CON Groups, this session is your opportunity to hear directly from the department, celebrate the community’s achievements, and see what’s coming next.

Speakers:Alethe Denis,Magen Wu

SpeakerBio:  Alethe Denis, DCG, Lead Goon
No BIO available
SpeakerBio:  Magen Wu, Director of Ops Goon at DEF CON Groups
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 10:00-10:59 PDT


Title: This Message Was Sent by Microsoft: Turning Microsoft Apps into our Phishing Platform
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - Map

Description:

Last DEF CON, we stole cleartext credentials directly from the real Microsoft login page. This year, we take it a step further by making Microsoft deliver our phishing emails!

We've all seen threat actors abuse built-in email notifications from legitimate SaaS platforms to send phishing links from trusted domains, bypassing email security solutions. But in most cases, they only control a small portion of the email content, making the end result far from convincing.

While the execution of these examples has mostly been fairly poor and limited in complexity so far, the idea of making a legitimate application deliver your phishing payload did intrigue me. So I started digging for more advanced ways to push this concept further, looking for techniques that would allow taking over the majority (or sometimes the entirety) of the email content.

In this talk, I'll present several novel techniques to inject custom phishing pretexts into emails sent by multiple first-party Microsoft services, taking advantage of their trusted email addresses and domain reputation.

These emails seem so legitimate that even seasoned IT and security professionals would trust them (and we have the proof from our assessments to back this up). After all, who doesn't trust Microsoft? 😉

SpeakerBio:  Keanu "RedByte" Nys, Spotit

Keanu Nys (aka RedByte) is an information security researcher from Belgium, and currently leads Spotit's offensive security team. While he has a passion for all offensive cybersecurity topics, he mostly specializes in Active Directory, Microsoft Entra ID (Azure AD), and Social Engineering.

He is the author of the Microsoft 365 and Entra attack toolkit GraphSpy. Additionally, Keanu is the trainer for the Certified Azure Red Team Expert (CARTE) bootcamps at Altered Security, and has given talks, workshops and trainings at conferences like DEF CON, Blackhat USA, and BruCON.


Return to Index    -    Add to Google    -    ics Calendar file

The Diana Initiative - Sunday - 11:00-12:59 PDT


Title: Threat Model your Career Workshop
Tags: The Diana Initiative | Creator Event/Activity
When: Sunday, Aug 9, 11:00 - 12:59 PDT
Where: LVCCW Level 2 W209 (Diana Initiative) - Map

Description:

We threat model systems all the time. Almost nobody runs that same thinking on their own career, which is usually the most valuable thing they own. Let's spend two hours looking at your career the way you would look at something you are paid to defend: what is worth protecting, what could go wrong, where they are exposed, and what you are actually going to do about it. 

Everyone will leave with a filled-in canvas and one specific thing they have committed to in the next month. This workshop is for any experience level.

SpeakerBio:  Chandan Vedavyas
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Sunday - 12:00-12:30 PDT


Title: ThreatPatrol: Visualising the Modern Threat Landscape
Tags: ICS Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

ThreatPatrol is a modern, open-source SaaS platform designed to operationalise cyber threat intelligence across Blue Teams, Cyber Threat Intelligence (CTI) analysts, Atomic Engineers and Purple Teams. Built natively around the MITRE ATT&CK framework and enriched with ART Atomic Red Team mappings, ThreatPatrol bridges the long-standing gap between threat intelligence, detection engineering and adversary simulation.

Unlike traditional CTI platforms that focus solely on indicators or static reporting, ThreatPatrol consolidates campaigns, adversary behaviour, atomic tests, infrastructure and detection analytics into a unified, relational data model. This enables practitioners to move beyond passive intelligence consumption toward active defense validation, threat emulation and measurable security outcomes.

The platform provides deep correlation across:

ThreatPatrol allows teams to:

The platform ships with:

ThreatPatrol is designed for continuous adversary-driven security validation, enabling organisations to test, measure, and improve their resilience against realistic attack scenarios. By transforming fragmented intelligence into actionable, visual and testable insights, ThreatPatrol provides a single platform for understanding, simulating and defending against modern cyber threats.

SpeakerBio:  Viral Maniar, UniSuper

Viral Maniar is a Senior Security Specialist at UniSuper, responsible for leading the organisation’s offensive and defensive security services within the information security team. He also operates his boutique cybersecurity firm, Preemptive Cybersecurity based in Australia, delivering both offensive and defensive security consulting services. With over thirteen years of experience in cybersecurity consulting, Viral has worked with a wide range of organisations across APJ. His expertise includes internal and external infrastructure testing, application penetration testing, vulnerability assessments, wireless security assessments, social engineering, red teaming, API testing, thick and thin client testing, and cloud security architecture reviews. Viral has spoken at prominent industry conferences such as Black Hat, ROOTCON DEFCON and (ISC)². He is also an active participant in bug bounty programs and has received recognition for responsibly disclosing security vulnerabilities. Outside of his professional work, Viral enjoys building security tools and contributes to multiple projects on GitHub. He can be found on X at @ManiarViral and @PreemptiveCyber.


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Tin Foil Hat Contest
Tags: Tin Foil Hat Contest | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest) - Map

Description:

Want to protect your noggin from government mind control rays? Have you angered our new AI Overlords, and now need to hide? Maybe those alien brainwave blasters just have you feeling down lately? Or do you just want to do something fun and forget about the world's woes for a while? Fear not, for we here at the Tin Foil Hat Contest have your back for all of these! Come find us in the contest area, and we'll have you build a tin foil hat which is guaranteed to provide top quality protection for your cerebellum . How you ask? SCIENCE!

Show us your skills by building a tin foil hat to shield your subversive thoughts, then test it out for effectiveness.

There are 2 categories: stock and unlimited. The hat in each category that causes the most signal attenuation will receive the ""Substance"" award for that category. We all know that hacker culture is all about looking good though, so a single winner will be selected for ""Style"". We provide all contestants a meter of foil, but you're welcome to acquire and use as much as you want from other sources.

This year is dedicated to our brother & contest creator, Flirzan. We'll never forget drunkenly hashing this out on a napkin with you at DEFCON many years ago. Rest in peace, we miss you friend!

Participant Prerequisites

We supply the base materials to participate. Contestants are welcome to bring additional foil if they desire.


Return to Index    -    Add to Google    -    ics Calendar file

Red Team Village - Sunday - 10:00-11:59 PDT


Title: Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID
Tags: Red Team Village | Misc
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map

Description:

Is MFA and Conditional Access a real security guarantee? In this technical session, we will demonstrate how endpoint compromise allows an attacker to bypass traditional identity barriers in the cloud. The talk focuses on exploiting vulnerabilities in Microsoft Entra ID, breaking down an advanced attack chain:

• Device Code Flow: Abuse of authentication flows for initial access (Demo with Entraith). • PowerShell Hijacking: Process interception to obtain session tokens (GrabTokenAzureAD). • Sliver BOF Extraction: Use of Beacon Object Files (BOF) for stealthy exfiltration of tokens and the Primary Refresh Token (PRT) from memory, evading anti-malware defenses. • MFA Bypass and Intune: The speakers developed custom tooling to extract local PRTs, bypass Intune device management controls, and circumvent MFA. This entire attack lifecycle was consolidated into Entraith — an offensive framework built from scratch by the research team and set to be released publicly at DEF CON 34 (https://github.com/bl4cksku11/entraith) — enabling device code attacks, token renewal, email and app inspection, token exfiltration, and persistence generation from a single interface.

This talk is not about a single CVE or a niche edge case. It is a comprehensive offensive research presentation covering the full spectrum of attack techniques against Microsoft Entra ID — from the very first foothold to deeply rooted, multi-vector persistence that survives incident response.

We will demonstrate, live, how an attacker moves through every phase of an Entra ID compromise:

INITIAL ACCESS AND TOKEN THEFT: We begin with Device Code Flow phishing — abusing Microsoft’s own authentication protocol to harvest valid tokens without ever touching a password. We then escalate with PowerShell process hijacking (GrabTokenAzureAD) to intercept live session tokens, and culminate with Sliver BOF-based extraction of the Primary Refresh Token (PRT) directly from memory — stealthy, silent, and anti-malware evasive. These three techniques alone demonstrate that MFA and Conditional Access are not the guarantees organizations believe them to be.

BYPASSING INTUNE AND MFA: Purpose-built tools developed during this research extract local PRTs, bypass Intune device compliance controls, and circumvent MFA enforcement at the token layer — not through social engineering, but through direct abuse of Microsoft’s identity platform mechanics. Attackers operating from non-enrolled or non-compliant devices can achieve full Tenant access that Conditional Access policies are designed to prevent.

PERSISTENCE ACROSS 10 VECTORS: Once inside, we deploy a “Survival Kit” of 10 chained persistence mechanisms — camouflaged App Registrations, long-lived secrets and certificates, backdoor accounts, strategic role assignments, privileged group inheritance, admin mailbox delegation, inbox-rule-based exfiltration of credentials and MFA codes, OAuth consent grants to external applications, and Temporary Access Pass generation for on-demand MFA bypass. No single blue team action — password reset, MFA enforcement, device wipe — removes all of them simultaneously.

ENTRAITH — BUILT BY US, RELEASED AT DEF CON: The centerpiece of this talk is Entraith (https://github.com/bl4cksku11/entraith), an offensive framework designed and built from the ground up by the speakers specifically for this research. Entraith is not a wrapper around existing tools — it is original work, developed over months of hands-on red team engagements against real Microsoft 365 environments. It unifies every technique demonstrated in this talk into a single operator interface: device code phishing, PRT extraction from memory, Intune compliance bypass, token renewal and exfiltration, email and application enumeration, and the full 10-step persistence deployment chain. DEF CON 34 will be the moment Entraith is released to the public. Attendees will be among the first to access the tool, its documentation, and the full methodology behind it — making this talk a genuine first-look at original research with immediate real-world impact.

WHY THIS MATTERS FOR CLOUD VILLAGE: The Microsoft 365 and Entra ID ecosystem is the identity backbone of the majority of enterprise organizations worldwide. The techniques presented here are not theoretical — they are being used by real threat actors today. Defenders in the room will leave with concrete detection opportunities and an understanding of exactly which log sources and control gaps allow this attack chain to succeed undetected. Red teamers will leave with a working tool and a fully documented methodology. This talk delivers both offensive depth and defensive utility in a single session, and the live demos ensure no attendee has to take our word for it.

Speakers:Elzer Pineda,Jose Rivas

SpeakerBio:  Elzer Pineda, Pentester

Regional Pentester and Cybersecurity Consultant, Elzer Pineda is an active member of the Red Team executing strategic consulting projects and advanced penetration testing engagements. His career has been focused on Threat Research for private and government organizations across the region. He is a Dojo Community Ambassador and Professor at the Universidad Tecnológica de Panamá (UTP). His experience has taken him to share technical research at Ekoparty, BSides Latam Peru, BSides Panamá, DOJOConf, PwnedCR, and OWASP Latam. Offensive security certifications: OSWE, OSEP, OSCP, OSWP, CRTP, CRTO, and CRTL.

--

Profesor en la Universidad Tecnológica de Panamá y especialista en Red Team con más de 10 años de experiencia en ciberseguridad ofensiva y defensiva. Pentester en GBM (región y Estados Unidos) y researcher en Toad Security. Máster en Seguridad Informática. Realiza evaluaciones de seguridad a aplicaciones móviles, web e infraestructura en Latinoamérica y comparte activamente conocimientos en la comunidad Dojo como embajador y conferencias. Certificaciones: OSWE, OSEP, OSCP, CRTO, OSWP, CRTL.

SpeakerBio:  Jose Rivas, Experienced Penetration Tester at A-LIGN

Jose Rivas is an Offensive Security Researcher and Red Team Operator at A-LIGN, specializing in adversarial simulations, Active Directory attack paths, and physical security assessments. Co-founder of Zero Trust Offsec, an offensive security research group focused on vulnerability exploitation, emerging attack techniques, and responsible disclosure, and Founder of DCG Panama, Panama's first official DEF CON chapter, where he leads a community dedicated to red team operations, and adversarial tradecraft. A recognized voice in the Panamanian security community, Jose has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf. With certifications including CRTO, eWPT, eCPPT, and CompTIA PenTest+, he brings a threat-actor mindset and a strong commitment to advancing offensive security knowledge across the region.

Jose Manuel Rivas is a Penetration Tester and Red Team Operator at A-LIGN, with hands-on experience in adversarial simulations, Active Directory attack chains, web application testing, and physical security assessments. He has multiple CVEs to his name, discovered through bug bounty programs and independent vulnerability research. Co-founder of Zero Trust Offsec and founder of DCG Panama, Panama's first official DEF CON chapter. He has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf, and is focused on growing the penetration testing and red team culture across Latin America.


Return to Index    -    Add to Google    -    ics Calendar file

Physical Security Village - Sunday - 12:00-12:59 PDT


Title: Travel Security: Viewing Risks Through the Eyes of a Hacker
Tags: Physical Security Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

Drawing from real-world examples, covert entry, red team, and social engineering engagements, Tim Roberts and Brent White walk through how everyday travel habits can expose individuals and organizations to unnecessary risk. From airports and hotels to conferences, rideshares, restaurants, and more...we'll look at how attackers identify opportunities and observations most travelers never think about.

This talk focuses on practical awareness rather than paranoia! We'll discuss common hotel vulnerabilities, social engineering tactics used against staff and travelers, and how small mistakes can lead to physical, identity theft, digital, or information compromise. Attendees should leave with realistic, affordable techniques they can immediately apply to improve situational awareness and protect their privacy. The goal isn't to be paranoid; it's to better understand how attackers think and make yourself a harder target!

Speakers:Tim Roberts,Brent White

SpeakerBio:  Tim Roberts, Sr. Principal Security Consultant and Red Team Operator at Dark Wolf

Tim Roberts is a Sr. Principal Security Consultant and Red Team Operator with Dark Wolf, specializing in covert entry, OSINT, social engineering, and adversary-driven Red Team operations. His work includes physical and electronic access control bypassing, physical site assessments, surveillance, wireless and network penetration testing, drone hacking, web application security, and full-spectrum offensive security testing across government and commercial environments.

With more than two decades of experience across private industry and government sectors, Tim has conducted assessments against highly secured facilities and critical infrastructure designed to emulate real-world adversaries. He is a co-author of the popular ACCESS LOGS series with Covert Instruments and has worked alongside law enforcement agencies supporting special operations cyber initiatives.

Tim has been featured on Microsoft’s Roadtrip Nation, ProfilingEvil with Mike King, Hak5, Security Weekly, and BBC News. His work has also been highlighted by IDG Enterprise’s CSO Online and Help Net Security for expertise in social engineering, adversary methodology, and security awareness.

Through WeHackPeople.com, Tim continues contributing to the security industry and InfoSec community by sharing real-world tradecraft, lessons learned, and both traditional and non-traditional techniques used in commercial and government operations.

SpeakerBio:  Brent White, Sr. Principal Security Consultant and Red Team Operator at Dark Wolf

Brent White is a Sr. Principal Security Consultant and Red Team Operator with Dark Wolf, specializing in covert entry, OSINT, social engineering, and adversary-driven Red Team operations. His work includes physical and electronic access control bypassing, physical site assessments, surveillance, wireless and network penetration testing, web application security, and full-spectrum offensive security testing across government and commercial environments.

With his experience across private industry and government sectors, Brent has conducted assessments against highly secured facilities and critical infrastructure designed to emulate real-world adversaries. He is a co-author of the popular ACCESS LOGS series with Covert Instruments and has worked alongside law enforcement agencies supporting special operations cyber initiatives.

Brent contributed to drone hacking methodology development for the Defense Innovation Unit's Blue sUAS initiative and helps lead Aerospace Village Drone Hacking operations at DEF CON. He has also been featured on Microsoft’s Roadtrip Nation, ProfilingEvil with Mike King, Hak5, Security Weekly, and BBC News, while his work has been highlighted by IDG Enterprise’s CSO Online and Help Net Security.

Through WeHackPeople.com, Brent continues contributing to the security industry and InfoSec community by sharing real-world tradecraft, lessons learned, and both traditional and non-traditional techniques used in commercial and government operations.


Return to Index    -    Add to Google    -    ics Calendar file

La Villa Community - Sunday - 10:00-10:30 PDT


Title: Tu foco IoT nunca tuvo modelo de amenazas
Tags: La Villa Community | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:30 PDT
Where: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map

Description:

Compraste una foco IoT. La conectaste a tu WiFi. Le pusiste una contraseña.

¿Quién más le puede mandar órdenes? ¿Quién verifica que el firmware que descarga es

legítimo?

En esta charla cuento la auditoría completa de Magic Home — la app de Zengge instalada en

bombillas, tiras LED y switches que se venden bajo una docena de marcas blancas. No

vengo a enumerar bugs. Vengo a mostrar tres preguntas básicas que el ecosistema entero —

móvil, nube y radio — no puede responder una sola raíz: nunca hubo modelo de amenazas en el

ciclo del producto.

Uso firmware ya publicado en internet, scripts caseros y un decompilador. Cero hardware

comprado. Una demo grabada de por qué nada detendría a un atacante. Una demo en vivo de

cuánto se puede ver del fleet sin tocar a nadie más.

SpeakerBio:  Andres Sabas, Electronic Cats

Co fundador de Electronic Cats, promotor del hardware abierto, co creador de productos de seguridad como HunterCat, Minino y BomberCat


Return to Index    -    Add to Google    -    ics Calendar file

ICS Village - Sunday - 12:30-12:59 PDT


Title: Two NICs, Zero Trust: Pulling Apart a PAC Buried in Critical Infrastructure
Tags: ICS Village | Creator Talk/Panel
When: Sunday, Aug 9, 12:30 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Imagine you get called up by a large CNI operator - "We have these devices, they're all over our outstations and they sit between our most critical OT trust zones", would you want to take a look? We did what any curious gremlins would do: we bought the hardware, built a bench, and started pulling at every thread. This talk tells the investigation as it actually happened, starting with architecture and documentation, moving through firmware analysis and protocol dissection, and ending with full pwnage at the firmware and application layers. Along the way we found a security model that felt frozen in the 2010s: weak trust boundaries, unauthenticated reconfiguration paths, and cryptographic protections as strong as wet cardboard. The point of the talk is not "bench testing is cool."; It's how to take a standard CNI concern into a hardware-led investigation that uncovers flaws a network-only pen test will miss. Attendees will leave with a practical workflow for assessing OT devices at scale, a mental model for deciding when to go from docs to firmware to hands-on testing, and a clear picture of how apparently boring PACs can become high-value footholds inside critical infrastructure. Nation-state level firmware backdoors and research artefacts will be released alongside this talk.

Speakers:Adam Bromiley,Sam Thom

SpeakerBio:  Adam Bromiley, Pen Test Partners

Adam is a security consultant at Pen Test Partners who specialises in industrial control systems and embedded hardware security. He's worked on everything safety-critical: from high-speed rail to aircraft, power stations, and gas distribution. His embedded work has seen him break driverless cars, slot machines, and drones and has led to the responsible

disclosure of numerous vulnerabilities in industrial controllers. Adam enjoys hands-on and boots-on-the-ground testing, reverse engineering, and providing practical security advice for complex real-world systems.

SpeakerBio:  Sam Thom

Sam is a security consultant at Pen Test Partners who focuses on the weird stuff - hardware, IoT and Operational Technology. He's poked and prodded Industrial and embedded systems across various industries like automotive, IoT, IIoT, chemical, water, power, gas, manufacturing and his favourite of all - the alcohol industry. Sam enjoys tearing down operational systems on the bench almost as much as owning them in the field.


Return to Index    -    Add to Google    -    ics Calendar file

Nix Vegas Community - Sunday - 13:30-14:30 PDT


Title: Unconference
Tags: Nix Vegas Community | Creator Event/Activity
When: Sunday, Aug 9, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map

Description:

Come and chill in the Nix Vegas space for the Unconference.


Return to Index    -    Add to Google    -    ics Calendar file

Car Hacking Village - Sunday - 10:30-10:59 PDT


Title: Unlocking Vehicles by Brute-Forcing Rolling Code Systems
Tags: Car Hacking Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map

Description:

Many vehicles worldwide rely on a popular aftermarket rolling code system that has long been trusted to protect against key fob cloning and unauthorized access. This talk unveils the reverse engineering journey that uncovered the protocol’s frame format, cryptographic design, and previously undocumented weaknesses. By combining a rollback vulnerability with a practical rolling code brute force attack, we demonstrate how an attacker can recover valid codes and clone a legitimate key fob. The research resulted in three CVEs assigned in 2026 and impacts products deployed across multiple markets. Attendees will learn how assumptions about rolling-code security can fail in practice and how these failures can be exploited in the real world.

SpeakerBio:  Danilo Erazo, Ekoparty, PCA Cybersecurity

Danilo Erazo is a Security Researcher at PCAutomotive in Budapest, Hungary. He has reported critical vulnerabilities to KIA Corporation, KIA Ecuador, Suzuki Motor Corporation, Calix Inc., Realtek Semiconductor Corp., and multiple Latin American banks. He is the organizer of the Car Hacking Village at Ekoparty, founder of the PWNORDIE security conference, and a speaker at Re/verse 2026, Secure Our Streets 2025, REcon 2025, Hardwear USA 2025, etc


Return to Index    -    Add to Google    -    ics Calendar file

Contests - Sunday - 10:00-11:59 PDT


Title: Untechnical
Tags: Untechnical | Contest
When: Sunday, Aug 9, 10:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 1 103 (Untechnical) - Map

Description:

In the age of AI hacking is reclaiming itself as more a mindset than strictly technical skill. If you're a DEFCON attendee that lack the technical skills to compete in traditional hacking challenges, but still love thinking outside the box: untechnical is for you.

Untechnical is a contest designed to rely 100% on lateral/abstract thinking without needing anything beyond an understanding of high school math.

Participant Prerequisites

Need to understand basic math and enjoy thinking outside the box. Oh, and you need an email address.


Return to Index    -    Add to Google    -    ics Calendar file

Maker's Village - Sunday - 13:30-13:59 PDT


Title: Visable Mending, repair and reinforce
Tags: Maker's Village | Creator Event/Activity
When: Sunday, Aug 9, 13:30 - 13:59 PDT
Where: LVCCW Level 1 Hall 1 301 (Makers' Village) - Map

Description:

We'll be going over the types of tools, stitches. And techniques that go into mending, darning, and reinforcing clothes.


Return to Index    -    Add to Google    -    ics Calendar file

Voting Village - Sunday - 10:00-13:59 PDT


Title: Voting Village Lab
Tags: Voting Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 13:59 PDT
Where: LVCCW Level 2 W219 (Voting Village) (Voting Village Lab) - Map

Description:

The Voting Village Lab is a hands-on, self-directed workshop space where attendees can learn about and experiment with dozens of different pieces of election equipment used in current and past US elections.


Return to Index    -    Add to Google    -    ics Calendar file

Payment Village - Sunday - 10:30-10:50 PDT


Title: Wall of Wallets Workshop (Intro to Wall of Wallets Challenge)
Tags: Payment Village | Creator Workshop
When: Sunday, Aug 9, 10:30 - 10:50 PDT
Where: LVCCW Level 2 W204-205 (Payment Village) - Map

Description:
Wall of Wallets is a hands-on CTF challenge where the goal is simple: collect as many mock payment card details as you can from other participants. Using intentionally vulnerable services in a safe, isolated environment, you'll learn how common implementation mistakes expose sensitive data. Compete to top the Wall of Wallets leaderboard while discovering the real-world techniques attackers use and, importantly, how to defend against them.
SpeakerBio:  Dan Borgogno, Security Researcher at Faraday

Dan Borgogno is a security researcher, backend developer, security engineer and international speaker with years of experience on mobile, hardware, IoT and web application hacking.


Return to Index    -    Add to Google    -    ics Calendar file

Biohacking Village - Sunday - 10:30-10:59 PDT


Title: Wand Protocol: Full-Chain Attack on an FDA-Listed Fertility Analyzer
Tags: Biohacking Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:30 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map

Description:

This year's BHV theme is access. This talk is about what happens when access is granted to everyone who should not have it, and about what happens to patient data once it leaves the device. We conducted a full security assessment of a shipping consumer fertility hormone analyzer — an FDA-listed device used by millions of people to track LH, FSH, estrogen, and progesterone. In a post-Dobbs environment, those measurements are not just health data. In 14 states, they are potential legal evidence. We found no authentication anywhere in the stack. From BLE proximity, any attacker within approximately 30 meters can silently rebind the device to an attacker-controlled account in under 15 seconds using a ~$10 dongle and open-source tools. No credentials. No pairing prompt. No notification to the user. The protocol works exactly as designed. The companion app identifies hardware by a substring check on the BLE advertisement name. Any peripheral advertising a matching name receives the user's live API session token during the app's own handshake. That token grants access to the complete hormone history, miscarriage status, PCOS diagnosis, and fertility treatment records of any user whose phone comes within range. The cloud login endpoint issues session tokens without verifying the password. Email address alone grants full account access. A hardcoded API key in the distributed APK grants read and write access to approximately 659,000 user health profiles with no per-object authorization. Reproductive health data — including miscarriage history — transmits to analytics vendors, an advertising pixel, and a customer data platform headquartered in Russia on every session open. This talk presents the full attack chain with live demos, maps each finding to FDA's February 2026 premarket cybersecurity guidance, and closes with three concrete implementation decisions that would have prevented all of it. Coordinated disclosure submitted to vendor, FDA CDRH, and CISA. All testing on researcher-owned hardware and accounts.

SpeakerBio:  Gigi Xiaoqing Liu

Gigi Liu is a graduate security researcher at Northeastern's Security And Privacy Research (SPQR) Group under Professor Kevin Fu, where her work covers embedded systems security, medical device attack surfaces, and AI-generated media detection. She interns at Lila Sciences as a Security and Cloud Engineer, building enterprise-wide agentic AI security infrastructure and detection capabilities for unauthorized AI activity across cloud and SaaS environments.

Her technical work spans wireless protocol reverse engineering, binary exploitation, web and mobile reverse engineering, cloud and AI security. She has applied these skills across medical hardware, automotive platforms, and enterprise cloud environments — from BLE command injection on FDA-listed devices to CarPlay API exploitation to building agentic AI detection controls at scale. As a UCLA psychobiology alum with a consulting background, she brings a multidisciplinary lens to every system: understand what it's designed to do first, then find where it breaks.


Return to Index    -    Add to Google    -    ics Calendar file

Radio Frequency Village - Sunday - 10:00-11:55 PDT


Title: WarDriver Meetup
Tags: Radio Frequency Village | Creator Event/Activity
When: Sunday, Aug 9, 10:00 - 11:55 PDT
Where: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map

Description:

Return to Index    -    Add to Google    -    ics Calendar file

AI Village - Sunday - 11:00-11:59 PDT


Title: What is AI? Interactive, Unplugged Activity
Tags: AI Village | Creator Event/Activity
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 2 603 (AI Village) - Map

Description:

Ever wonder what's actually happening inside an AI? In this hands-on, no-screens-required workshop, you'll build your own neural network out of flashcards and pipe cleaners, "train" it, and watch it try (and sometimes fail!) to answer prompts. You'll grow your model, give it tools and skills, and then turn the tables: try out real attacks like prompt injection, tool misuse, and data poisoning, and learn the defenses AI security researchers use to stop them, like containerization. No coding or experience required, just curiosity!

SpeakerBio:  Sam Mosley, CodeBloom
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Sunday - 13:00-13:59 PDT


Title: What is AI?
Tags: CodeBloom | Creator Workshop
When: Sunday, Aug 9, 13:00 - 13:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Curious what is actually happening inside an AI when it answers your questions? In this session, you'll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We'll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

SpeakerBio:  Sam Mosley, CodeBloom
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Cloud Village - Sunday - 10:40-11:20 PDT


Title: When Machines Attack Machines: Detecting AI-Autonomous Cloud Compromise at NHI Scale
Tags: Cloud Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:40 - 11:20 PDT
Where: LVCCW Level 3 W313 (Cloud Village Talks) - Map

Description:

Two forces are converging to break cloud detection as we know it. First, non-human identities (NHIs) such as service accounts, API keys, OAuth tokens, AI agent credentials now outnumber human identities by ratios exceeding 100:1 in enterprise environments. 97% of these NHIs carry excessive privileges, 71% are never rotated within recommended timeframes, and over 40% are orphaned with no human owner. Second, attackers have begun using AI agents to compromise these identities at machine speed, performing hundreds of reconnaissance actions per minute, autonomously mapping privilege escalation paths, and executing lateral movement faster than any human analyst can respond. The result is a detection problem that traditional security tools were never designed to handle: machine-speed attacks against machine identities, where the attacker's AI agent looks indistinguishable from the defender's AI agent in the logs. This talk presents the first detection engineering framework purpose-built for this collision covering how to baseline NHI behavior, detect AI-autonomous compromise patterns, and build response automation that can match attacker speed.

SpeakerBio:  Gowthamaraj Rajendran

Gowthamaraj Rajendran is a Detection and Response Engineer at Meta with over 6 years of experience in cybersecurity. He specializes in building high-fidelity rules and improving detection engineering practices at scale.


Return to Index    -    Add to Google    -    ics Calendar file

Middle Easterns & Africans in Cyber Security (MEACS) - Sunday - 12:00-12:59 PDT


Title: Where the Authorization Boundary Goes in Agent Workflows
Tags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map

Description:

In May 2026, attackers took over high-profile Instagram accounts by asking Meta’s AI support assistant to change a recovery email. The agent changed it, the attacker used the recovery flow, and the account was gone. The agent was not tricked in any exotic way. It just did something it was allowed to do, for someone who should not have been allowed to ask.

I have spent a while delivering agentic AI security work, and I keep seeing the same thing. Everyone is struggling to push authorization into AI agents. Teams deploy an agent and cannot actually tell you what it is capable of or what rules it is bound by. This is the identity and access management problem we have been fighting for decades, now behind a conversational interface. The agent looks like a smart assistant, but it can act like an admin, and nobody drew the line for what it is allowed to reach.

Maze is the pattern I came up with for this, and I have implemented it and it works. The agent never executes directly. Its request enters a fixed sequence of gates: is this a privileged action, is the user authenticated, do they own the target account, can this tool mutate data, does policy allow it, is it within rate limits, did step-up verification pass. Each gate either advances the request or drops it into a blocked state, and there is exactly one path through to execution. Every outcome, pass or block, is written to an audit log. The authorization does not live inside the model, where it can be talked around. It lives in the gates, and the agent cannot route around them.

I will walk through the Meta case as the example, then show how Maze structures the workflow so the agent stays inside gates it cannot step past.

SpeakerBio:  Mohamed Magdy AbuMuslim
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 11:00-13:30 PDT


Title: Wi-Fi Self Defense & Hacker Hunting & For Beginners
Tags: IoT Village | Creator Workshop
When: Sunday, Aug 9, 11:00 - 13:30 PDT
Where: LVCCW Level 1 Hall 1 215 (IoT Village) - Map

Description:

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Kit Cost: $140. Class Cap: 30.

SpeakerBio:  Kody Kinzie
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 13:30-14:30 PDT


Title: Witchcraft Solver: Automated 0day Discovery in Stripped Binaries
Tags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
When: Sunday, Aug 9, 13:30 - 14:30 PDT
Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - Map

Description:

You have a stripped binary. No source. No symbols. No harness. You want a PoC. How do you get there? Witchcraft Solver (wsolver) is a fully automated binary-only 0day discovery pipeline.

Phase 1 lifts the binary to LLVM IR via wunstrip (.eh_frame symbol recovery, 99.98% accuracy), runs an SSA taint pre-filter to cut targets by ~50%, then drives four parallel formal verification engines (KLEE, IKOS, SeaHorn, SMACK) to produce concrete violation witnesses - covering the entire binary in ~30 minutes, no source required.

Phase 2 uses those witnesses to seed directed fuzzing (AFLGo) and binary-only concolic execution (SymQEMU), converting symbolic candidates into working PoCs. An optional Phase 0 handles non-Intel targets via a lifter portfolio (RetDec + Anvill + rev.ng), covering 93% of 39,364 production ELF binaries across ARM64, ARMv7, RISC-V, and s390x.

Validated against CVE-2023-2804 (libjpeg-turbo heap-buffer-overflow): SymQEMU produces the first crash in 25 minutes from a stripped binary with zero source access.

The tool will be released under MIT license at the conference at: https://github.com/endrazine/wsolver

Experimental validation against the wider internet is left as an exercise to the audience...

[1] Brossard, J. "Unstripping Cloud Container ELF binaries." IEEE IC_ETC 2025. https://ieeexplore.ieee.org/abstract/document/11141058 [2] Brossard, J. "CVE-2023-2804 Complete Fuzzing Benchmark." Zenodo. doi:10.5281/zenodo.19136269 [3] Wojtczuk, R. "UQBTng." 22C3, 2005. [4] Poeplau, S. and Francillon, A. "SymQEMU." NDSS 2021. [5] Böhme et al. "Directed Greybox Fuzzing." CCS 2017. [6] Cadar et al. "KLEE." OSDI 2008. [7] Fioraldi et al. "AFL++." USENIX WOOT 2020. [8] Brossard, J. "Introduction to the Witchcraft Compiler Collection." DEF CON 24, Las Vegas, August 2016. Video: https://archive.org/details/youtube-1cgtr7VW7gY

Tool Source (once published at DEF CON): https://github.com/endrazine/wsolver

SpeakerBio:  Jonathan "endrazine" Brossard

Endrazine is a returning DEF CON speaker, having previously presented the first attack against Microsoft BitLocker and TrueCrypt in 2008, the infamous Rakshasa BIOS malware in 2012, and the Witchcraft Compiler Collection reverse engineering framework in 2016. Endrazine has previously presented at premier conferences such as Black Hat, CCC, and HITB in the industry, as well as IEEE, USENIX, and ACM in academia. He currently works as CTO at MOABI, a binary analysis and vulnerability assessment firm, after having been Principal Engineer of Product Security at Salesforce (San Francisco), where he later lead the RedTeam. He is wrapping up a PhD in reverse engineering at CNAM (Paris) where he has been an Associate Professor for three years, and holds master's degrees in Engineering, Computer Science, and Cybersecurity.


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Sunday - 14:00-14:59 PDT


Title: Work Session: Ciphers
Tags: CodeBloom | Creator Workshop
When: Sunday, Aug 9, 14:00 - 14:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We'll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

CodeBloom - Sunday - 11:00-11:59 PDT


Title: Work Session: Ciphers
Tags: CodeBloom | Creator Workshop
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map

Description:

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We'll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you've ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!


Return to Index    -    Add to Google    -    ics Calendar file

Game Hacking Village - Sunday - 11:30-12:30 PDT


Title: Yes, I froze an SNES for science
Tags: Game Hacking Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:30 - 12:30 PDT
Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map

Description:

"dwangoAC describes why he put a SNES console in a freezer, the scientific process that led to unexpected statistics, and whether or not it helped TASBot play Super Metroid Tool-Assisted Speedruns on real consoles. This talk will cover how 1990's-era component aging affects RNG and why hotplate% speedruns don't work the way the speedrunning community thinks they do

SpeakerBio:  dwangoAC

dwangoAC is the keeper of TASBot, a cute non-AI robot. TASBot presses buttons perfectly like a player piano and plays games fast, often employing game breaking glitches. TASBot content has helped raise more than $1.5M at Games Done Quick and other charity events since 2013. dwangoAC is known for video game science experiments, investigations, and transformative art.


Return to Index    -    Add to Google    -    ics Calendar file

IoT Village - Sunday - 10:00-10:59 PDT


Title: You Can't Opt Out: The Invisible Surveillance in Your Walls, Pockets, and Lives
Tags: IoT Village | Creator Talk/Panel
When: Sunday, Aug 9, 10:00 - 10:59 PDT
Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map

Description:

Surveillance is baked into the very fabric of our digital existence. From smart homes to smart cars, and now we drive down streets with smart cameras tracking our every move. And why aren’t even aware of most of it, because almost none of it is disclosed in any meaningful way to the people being surveilled. Sometimes because companies don’t want their users to understand what data they’re collecting, because users would be upset, and sometimes because governments doing want us to know about the surveillance. This talk walks through a series of real cases where surveillance was hiding in plain sight inside ordinary consumer iot devices and apps, and was only discovered because someone with the right skills bothered to look. From high school students at a previous DEF CON uncovering microphones installed in school bathrooms, to Byron Tau's reporting on commercial SDKs (like the one embedded in a widely-used Muslim prayer app) feeding location data to U.S. military and intelligence buyers, to robot vacuums quietly mapping the interiors of homes and shipping that data overseas, to the BadBox 2.0 botnet found lurking inside off-the-shelf Android streaming boxes like Superbox. The surveillance is pervasive, and the average consumer has no realistic way to detect or refuse it. This session makes the case that the question is no longer "are you being watched?" but "could you even opt out if you tried?" The reality is, it’s becoming so difficult to have meaningful privacy in the digital age that we’re on the cusp of a digital panopticon that threatens the very freedom of society. This talk explains what is at stake to democracy when privacy disappears, and how it slowly eliminates the self-correcting mechanisms and checks on power in society, such as protest movements, whistleblowers, independent media, protest movements, activist groups, and opposition parties. It is also a call to action for the people in this room, who possess the unique skill sets of reverse engineering, network analysis, firmware teardown, RF work etc. People breaking these systems apart and revealing what they find to the world is rapidly becoming the only meaningful check on a landscape that has decided surveillance is the default. We need more researchers looking, and we need them looking now.

SpeakerBio:  Naomi Brockwell
No BIO available

Return to Index    -    Add to Google    -    ics Calendar file

Blue Team Village - Sunday - 11:00-11:59 PDT


Title: You're Hired... Maybe: Inside Cybersecurity Hiring in 2026
Tags: Blue Team Village | Creator Talk/Panel
When: Sunday, Aug 9, 11:00 - 11:59 PDT
Where: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map

Description:
Speakers:George Scheibe,Neha Gautam,Sherry Michael,Siddharth Kumar

SpeakerBio:  George Scheibe

George received his lettermen jacket for Computer Science in high school and has been nerding out ever since. From a Multichannel Transmission Systems Operator-Maintainer in the US Army to the sole IT person for an entire resort, George has done everything from global network monitoring in command centers to toning out sea salt corroded POTS lines in crawl spaces. These days though you'll fine him working in a SOC helping to develop the next generation of cyber security professionals.

SpeakerBio:  Neha Gautam

Neha Gautam is a Product Manager at Microsoft Security and a Carnegie Mellon graduate specializing in the intersection of Identity and AI. From scaling platforms at Walmart to securing agentic AI at Microsoft, Neha’s mission is to translate complex security hurdles into seamless product experiences. She is a passionate mentor for women in tech and a frequent volunteer for WiCyS and Defcon Blue Team Village. Neha believes that the future of computing must be built by diverse perspectives—a philosophy she champions whether she's designing enterprise governance or coaching early-career professionals.

SpeakerBio:  Sherry Michael

Sherry Michael is the security technical director for Information systems and computing at the University of Pennsylvania, a prestigious Ivy League university and research institution in Philadelphia. With more than thirty years of experience in information technology and over twelve years focused on cybersecurity, Sherry brings deep expertise in securing complex enterprise environments and fostering cross team collaboration. In addition to technical leadership responsibilities, Sherry serves on hiring panels for a wide range of technical positions and acts as a hiring officer. She is passionate about identifying and developing the next generation of technology and security professionals.

SpeakerBio:  Siddharth Kumar

Siddharth Kumar is the Offensive Security Lead at Ethical Intruder. He breaks into enterprise environments for a living, following attack paths through Active Directory, cloud infrastructure, web applications, and occasionally the strange world of operational technology. Previously, he led red team operations at EY and earned a master’s degree in information security from Carnegie Mellon University. Siddharth is particularly interested in identity attacks, advanced Web/API exploitation, adversary tradecraft, and the small security oversights that lead to very large compromises. When he is not breaking into things professionally, he enjoys helping other security practitioners develop their technical skills and navigate careers in offensive security.


Return to Index    -    Add to Google    -    ics Calendar file

DEF CON Talks - Sunday - 12:00-12:59 PDT


Title: Your WAF Blocked Us, That Was The Exploit - Remote Agent Takeover via Cloudflare, Sentry and Claude Zero-Day for data exfil
Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
When: Sunday, Aug 9, 12:00 - 12:59 PDT
Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - Map

Description:

What happens when getting blocked by your WAF is exactly how the attacker gets in? We built two new remote exploit chains that hijack AI agents through Cloudflare and Sentry - two of the most trusted tools on the internet. No malware. No binary exploits. The attacker never touches the victim or their agent. Just text in public logs, waiting to be read. Chain 1: We send requests Cloudflare blocks with 403 - and that is the attack. Our payloads land in WAF logs. When a dev asks their agent to debug Cloudflare, injections activate via cloudflare queries. Using only Cloudflare's own MCP tools, we hijack DNS and reroute customer traffic. Chain 2: We inject stacktraces into Sentry's public API, no auth needed. Sentry's "Seer" agent reads them, gets compromised, and its poisoned recommendations flow into a developer's Cursor which executes our commands. One agent infecting another. First demo of agent-to-agent lateral movement and "Self-Exploiting Agent" technique. Then we go deeper: a zero-day in Claude bypasses its network sandbox for full data exfiltration. For persistence, we show how "agentic rootkits" work by memory injection and config poisoning, invisible to EDRs. est 15,000+ organizations exposed via Cloudflare MCP alone. 27% of them are Fortune 1000. Responsibly disclosed. We're now showing everything.

*Cloudflare MCP Server documentation and public deployment *Sentry MCP Server and Seer AI agent documentation *Anthropic Claude Desktop application architecture *Cursor AI coding agent - MCP integration and tool architecture *OWASP Top 10 for LLM Applications (2025) *MITRE ATLAS - Adversarial Threat Landscape for AI Systems *Clinejection (Feb 2026) - GitHub issue title exploit compromising Cline's release pipeline *Comment & Control (Apr 2026) - prompt injection via PR titles leaking secrets from Claude Code, Gemini CLI, and Copilot

Speakers:Barak Sternberg,Nevo Poran,Ron Bobrov

SpeakerBio:  Barak Sternberg, Tenet Security

Barak Sternberg is a cybersecurity researcher, offensive security specialist, and a returning DEFCON speaker. His research career spans over 15 years across every major attack surface of the last decade: from IoT to browser extension exploits (DEFCON 29), to Kube infra attacks (with Nevo), to smart device hacking (DEFCON Safe Mode IoT Village). He's presented at DEFCON (twice), Hacktivity, RootCon, BSides, Intent, and numerous other security conferences worldwide. He's a Unit 8200 veteran and Israel Defense Prize recipient. His research has consistently focused on finding novel attack chains in emerging technology before attackers do, across years in offensive cybersecurity. He also co-founded Wild Pointer (offensive security, Fortune 500 clients) and more recently co-founded Tenet Security as CEO with Nevo: but the research came first, the company came from the research, not the other way around. He leads Tenet while staying hands-on - the exploit chains in this talk came directly from his team's research

SpeakerBio:  Nevo Poran

Nevo Poran, cybersecurity researcher, Co-Founder & CTO of Tenet Security, and a top-tier security engineer focused on GenAI, API, and application security. Unit 8200 veteran and 2x Excellence Awards. Nevo co-founded Wild Pointer with Barak, serving as technical lead and later CEO, managing teams delivering offensive R&D to Cisco, Noname Security, and Fortune 500 clients. He then co-led Cisco's first GenAI Security Research Team - building the AI Defense product from research through production. Deep hands-on expertise in reverse engineering, exploit development, and agent runtime security. Speaks on Kubernetes/cloud and GenAI security (CyberArk INTENT 2024, UNC Symposium 2025) and co-presented the Kubernetes etcd exploitation research with Barak. They've been breaking things together for years.

SpeakerBio:  Ron Bobrov, Tenet Security

Ron Bobrov is a senior security researcher at Tenet Security with 10 years of experience in offensive security, penetration testing, and vulnerability research. He has specialized in emerging attack vectors and has recently focused on AI agent security, conducting red-team assessments that have uncovered critical vulnerabilities in modern LLM-based systems. At Tenet Security, Ron leads research initiatives exploring the intersection of traditional security threats and AI-specific attack surfaces. His work on bypassing A2AS framework protections has revealed fundamental architectural gaps in current AI agent security approaches, contributing to the development of runtime protection methodologies for agentic systems. Ron's research combines deep technical expertise in system exploitation with novel approaches to adversarial AI security, helping organizations understand and defend against the next generation of attacks targeting AI agents in production environments.


Return to Index    -    Add to Google    -    ics Calendar file